Skip to content

fix(core): fix dependency pins blocking agent-governance-toolkit-core installs - #4017

Merged
MohammadHaroonAbuomar merged 9 commits into
microsoft:mainfrom
karimad:fix/core-agt-policies-optional-dep
Sep 17, 2026
Merged

MohammadHaroonAbuomar merged 9 commits into
microsoft:mainfrom
karimad:fix/core-agt-policies-optional-dep

Conversation

@karimad

@karimad Karim Mehalebi (karimad) commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Related Issue

None filed for the original problem yet — happy to file one if maintainers would rather track this separately before review. Filed #4019 for a follow-on gap this PR discloses but doesn't close (see "Known remaining gap" below).

Problem & Solution

Problem: agent-governance-toolkit-core's dependencies pin agt-policies>=5.1.0,<6.0 (bumped in #3939). agt-policies's own main pins agent-control-specification>=0.4.0b0,<0.5.0. Neither version is published to PyPI — PyPI tops out at agt-policies==5.0.0 and agent-control-specification==0.3.1b1 — so a plain pip install agent-governance-toolkit-core (or the [full] extra) cannot resolve today. This is the same recurring bug class as #3414 (closed) and #3733 (open), just a different pair of packages, and it isn't covered by either.

I hit this trying to depend on the fix from #3924 (merged, adds contains/startswith/endswith to the condition DSL) from an external project — there's currently no way to pip install/uv sync to a commit containing that fix without a --no-deps git overlay.

Solution:

  1. agt-policies backs only the v4-to-ACS manifest migration CLI (agt migrate). I grepped agent-mesh/src/agentmesh/ (where govern(), GovernanceDenied, and policy.py/PolicyEngine actually live) for any import of agt or agent_control_specification — there are none. The base governance runtime doesn't use this dependency at all; it was pulled into the required set as part of the "merged dependencies" consolidation, not because anything imports it. This PR moves agt-policies out of dependencies and into a new migrate optional-dependency extra, matching the existing pattern already used for other CLI/framework-specific pieces (mcp, redis, django, etc.).
  2. Review caught that step 1 alone would break agent_os (force-included into this same wheel), which directly imports agent_control_specification in providers.py, cli/cmd_validate.py, integrations/_native_adapter_runtime.py, and integrations/openai_agents_sdk.py — it previously received that package only transitively via agt-policies. Fixed by declaring agent-control-specification>=0.3.1b0,<0.4.0 as its own direct base dependency, matching the currently-published range.

full does not pull in migrate, so pip install agent-governance-toolkit-core[full] resolves cleanly against what's actually published today.

Known remaining gap: the migrate extra's own agt-policies>=5.1.0,<6.0 pin is untouched by this PR and is still unresolvable on its own (5.1.0 isn't published), and will conflict with this PR's new base agent-control-specification pin once it is (5.1.0 will require ACS >=0.4.0b0, base here requires <0.4.0). There's no ACS release yet that both sides could share, so this isn't fixable in this PR — documented in the CHANGELOG and next to the extra, tracked in #4019.

Impact on Your Work

Blocked me from cleanly depending on the #3924 fix in a downstream project without a manual --no-deps overlay script. Filing this so the next person hitting the same resolver error doesn't have to reinvent that workaround.

Timeline

None.

Alternatives Considered

Widening the base agent-control-specification pin to accept the unpublished 0.4.0b0 beta instead of pinning the currently-published 0.3.1b1 range — rejected because it would just reintroduce the same "depends on something PyPI doesn't have" problem this PR is fixing, one level down.

Type of Change

  • Bug fix (non-breaking change that fixes an issue)

Package(s) Affected

  • agent-governance-toolkit-core

Testing

Unit Testing

No new tests added — packaging-only change. Ran the existing suite covering the condition DSL and govern() (test_policy_rule_string_operators.py, test_govern.py, 51 passed) against a venv built from this branch to confirm nothing regressed.

Manual Testing

In a clean venv, built from this branch's local source:

pip install ".../agent-governance-toolkit-core[full]"

resolves and installs successfully (confirmed via pip show: agent-control-specification is present at 0.3.1b1; agt-policies is absent, as expected).

Then verified the actual governance path still works end-to-end in that same venv:

from agentmesh.governance import govern, GovernanceDenied

def deliver(action):
    return action["response"]

governed = govern(deliver, policy="policy.yaml", agent_id="test:contains-check")
# policy.yaml: deny when action.response contains 'rm -rf'

governed(action={"response": "sure, run rm -rf /tmp/x"})  # -> raises GovernanceDenied
governed(action={"response": "hello world"})               # -> returns "hello world"

Both the contains deny path (#3924) and the benign allow path passed.

Also confirmed agent_os's own use of agent_control_specification still works (agent_os.cli.cmd_validate._validate_manifest() runs end-to-end), and that agt-policies is still installable and pinned correctly when explicitly requested via the new extra (agent-governance-toolkit-core[migrate]) — this PR only changes when it's pulled in, not the pin itself.

Checklist

  • I have linked a related issue above, or completed "Problem & Solution", "Impact on Your Work", and "Alternatives Considered"
  • My code follows the project style guidelines (ruff check) — no source touched, pyproject.toml/CHANGELOG.md only
  • I have added tests that prove my fix/feature works — reused/re-ran existing suite (see Testing); no new source code to add unit tests for
  • All new and existing tests pass (pytest)
  • I have updated documentation as needed (CHANGELOG.md)
  • I have signed the Microsoft CLA

Attribution & Prior Art

  • This contribution does not contain code copied or derived from other projects without attribution
  • Any external projects that inspired this design are credited in code comments or documentation
  • If this PR implements functionality similar to an existing open-source project, I have listed it below

Prior art / related projects (if any):
None — this mirrors the repo's own existing extras pattern (mcp, redis, django).

AI Assistance

  • I can explain every meaningful change in this PR: what it does, why, and what tradeoffs were considered
  • I have run tests and verification appropriate for this change
  • No part of this PR was autonomously submitted by an AI agent without my review
  • I have not used AI to generate review comments on others' PRs

AI tools were used to draft the diagnosis, code changes, commit messages, and this description; I reviewed and verified every change myself (see Testing) before pushing.

IP, Patents, and Licensing

  • This contribution does not implement patent-pending or patent-encumbered techniques
  • This contribution does not require an NDA or licensing agreement to understand or use
  • Any AI tools used have terms compatible with the MIT License

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@github-actions

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@github-actions github-actions Bot added dependencies Pull requests that update a dependency file size/S Small PR (< 50 lines) size/XS Extra small PR (< 10 lines) documentation Improvements or additions to documentation and removed size/S Small PR (< 50 lines) size/XS Extra small PR (< 10 lines) labels Sep 17, 2026
agent-governance-toolkit-core's dependencies pin agt-policies>=5.1.0,<6.0,
which in turn pins agent-control-specification>=0.4.0b0,<0.5.0. Neither
version is published to PyPI (PyPI tops out at agt-policies 5.0.0 and
agent-control-specification 0.3.1b1), so a plain
'pip install agent-governance-toolkit-core' or '[full]' cannot resolve.

agt-policies backs only the v4-to-ACS manifest migration CLI ('agt
migrate'). Nothing in agentmesh.governance (govern(), GovernanceDenied,
policy.py/PolicyEngine) imports agt or agent_control_specification -
confirmed by grepping agent-mesh/src/agentmesh/ for both. The base
governance runtime does not need this dependency at all.

Moves it to a new 'migrate' extra instead, matching the existing
optional-dependencies pattern for other CLI/framework-specific pieces
(mcp, redis, django, etc.). Verified: a clean venv can now
'pip install agent-governance-toolkit-core[full]' and exercise
govern()'s contains/startswith/endswith operators (microsoft#3924) end-to-end
without agt-policies or agent-control-specification installed at all.

Signed-off-by: karimad <kmehaleb@gmail.com>
Signed-off-by: karimad <kmehaleb@gmail.com>
Review caught that agent_os (force-included into this same wheel) imports
agent_control_specification directly in 4 places: providers.py,
cmd_validate.py, _native_adapter_runtime.py, and openai_agents_sdk.py.
That package previously arrived only transitively via agt-policies's own
pin, which the prior commit removed from the base dependency set -
trading the original unresolvable-install failure for a quieter
ImportError at runtime the moment agent_os actually exercised one of
those paths.

Fix: declare agent-control-specification>=0.3.1b0,<0.4.0 directly in
agent-governance-toolkit-core's own dependencies, matching the range
agt-policies 5.0.0 already resolved to before microsoft#3939. Verified in a clean
venv: all four previously-broken agent_os modules import cleanly, and
cmd_validate.py's _validate_manifest() actually runs end-to-end (not
just import-checked). govern()'s contains/startswith/endswith path
(microsoft#3924) still passes both the deny and allow cases.

One related, pre-existing gap surfaced during this verification and is
NOT fixed here (out of scope for a packaging PR): _native_adapter_runtime
.py's _session_for() imports HostSession from agent_control_specification,
which genuinely does not exist in any published release yet (checked
0.3.1b1's exports directly). That call path was already broken before
this PR - it depends on ACS 0.4.0b0's API regardless of how the
agt-policies/agent-control-specification pins are arranged - so it's
unaffected by this change either way.

Also: moved the new 'migrate' extra out from under the '--- Bundles ---'
header (it's a single-package extra like redis/django, not a bundle),
and added a CHANGELOG.md [Unreleased]/Fixed entry.

Signed-off-by: karimad <kmehaleb@gmail.com>
Signed-off-by: karimad <kmehaleb@gmail.com>
The migrate extra's agt-policies>=5.1.0,<6.0 pin predates this PR and is
unchanged by it. It's still unresolvable on its own today (agt-policies
5.1.0 isn't published), and will conflict with this PR's new base ACS pin
once it is (agt-policies would then require ACS>=0.4.0b0, base requires
<0.4.0). Documented in the CHANGELOG and the extra itself, tracked in
microsoft#4019 so it isn't rediscovered fresh.

Signed-off-by: Karim Mehalebi <kmehalebi@egencia.com>
Signed-off-by: Karim Mehalebi <kmehalebi@egencia.com>
@karimad
Karim Mehalebi (karimad) force-pushed the fix/core-agt-policies-optional-dep branch from 57f422d to 7211fb9 Compare September 17, 2026 13:05
@karimad Karim Mehalebi (karimad) changed the title fix(core): move agt-policies to an opt-in extra, not a base dependency fix(core): fix dependency pins blocking agent-governance-toolkit-core installs Sep 17, 2026
@karimad
Karim Mehalebi (karimad) marked this pull request as ready for review September 17, 2026 13:09
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Comment thread agent-governance-python/agent-governance-toolkit-core/pyproject.toml Outdated
Comment thread agent-governance-python/agent-governance-toolkit-core/pyproject.toml Outdated
Comment thread CHANGELOG.md Outdated
…requires

Reviewer found 0.3.1b1 lacks HostSession and rejects every in-repo
manifest, breaking the adapter runtime and agent-os validate despite
the install itself resolving. Update the base pin and changelog entry
to match.

Signed-off-by: Karim Mehalebi <kmehaleb@gmail.com>
@karimad
Karim Mehalebi (karimad) force-pushed the fix/core-agt-policies-optional-dep branch from 34329fe to d7419b7 Compare September 17, 2026 15:33
@github-actions github-actions Bot added the tests label Sep 17, 2026
@karimad
Karim Mehalebi (karimad) force-pushed the fix/core-agt-policies-optional-dep branch from 39da963 to bc1d80c Compare September 17, 2026 15:34

@MohammadHaroonAbuomar MohammadHaroonAbuomar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • Commit be9c593 has no Signed-off-by trailer, so the DCO check will fail once the gated runs execute. Please git rebase --signoff origin/main (or amend that commit with --signoff) and force-push. Blocking; everything else is in place.
  • scripts/ci/check_native_policy_wheels.py:80 asserts "Requires-Dist: agt-policies" in metadata; after this change only the ; extra == 'migrate' line satisfies it, so the check no longer proves what it was written for. Assert the full Requires-Dist: agt-policies<6.0,>=5.1.0; extra == 'migrate' line, or drop the assertion. Non-blocking.

Comment thread agent-governance-python/agent-governance-toolkit-core/pyproject.toml Outdated
@karimad
Karim Mehalebi (karimad) force-pushed the fix/core-agt-policies-optional-dep branch from bc1d80c to 2725cd6 Compare September 17, 2026 15:54
@karimad

Copy link
Copy Markdown
Contributor Author
  • Commit be9c593 has no Signed-off-by trailer, so the DCO check will fail once the gated runs execute. Please git rebase --signoff origin/main (or amend that commit with --signoff) and force-push. Blocking; everything else is in place.
  • scripts/ci/check_native_policy_wheels.py:80 asserts "Requires-Dist: agt-policies" in metadata; after this change only the ; extra == 'migrate' line satisfies it, so the check no longer proves what it was written for. Assert the full Requires-Dist: agt-policies<6.0,>=5.1.0; extra == 'migrate' line, or drop the assertion. Non-blocking.

all fixed thanks

@MohammadHaroonAbuomar MohammadHaroonAbuomar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified at 3e22d99: every commit now carries a matching sign-off, the pyproject comment is updated, and the one-line test key change in tests/ci/test_release_tooling.py is the fix main's #3939 test needs (25 pass). The base pin matches agt-policies 5.1.0's range; install coherence passes. The check_native_policy_wheels.py assertion note stays open as a follow-up, not a blocker. The docker-compose-test failure was the known relay knock flake, green on rerun. Thanks.

@MohammadHaroonAbuomar
MohammadHaroonAbuomar merged commit 26aaf36 into microsoft:main Sep 17, 2026
237 of 239 checks passed
Yuvraj Singh (yuvrajsingh2428) pushed a commit to yuvrajsingh2428/agent-governance-toolkit that referenced this pull request Oct 1, 2026
… installs (microsoft#4017)

* fix(core): move agt-policies to an opt-in extra, not a base dependency

agent-governance-toolkit-core's dependencies pin agt-policies>=5.1.0,<6.0,
which in turn pins agent-control-specification>=0.4.0b0,<0.5.0. Neither
version is published to PyPI (PyPI tops out at agt-policies 5.0.0 and
agent-control-specification 0.3.1b1), so a plain
'pip install agent-governance-toolkit-core' or '[full]' cannot resolve.

agt-policies backs only the v4-to-ACS manifest migration CLI ('agt
migrate'). Nothing in agentmesh.governance (govern(), GovernanceDenied,
policy.py/PolicyEngine) imports agt or agent_control_specification -
confirmed by grepping agent-mesh/src/agentmesh/ for both. The base
governance runtime does not need this dependency at all.

Moves it to a new 'migrate' extra instead, matching the existing
optional-dependencies pattern for other CLI/framework-specific pieces
(mcp, redis, django, etc.). Verified: a clean venv can now
'pip install agent-governance-toolkit-core[full]' and exercise
govern()'s contains/startswith/endswith operators (microsoft#3924) end-to-end
without agt-policies or agent-control-specification installed at all.

Signed-off-by: karimad <kmehaleb@gmail.com>

* trim comment on the migrate extra

Signed-off-by: karimad <kmehaleb@gmail.com>

* fix(core): give agent-control-specification its own base dependency

Review caught that agent_os (force-included into this same wheel) imports
agent_control_specification directly in 4 places: providers.py,
cmd_validate.py, _native_adapter_runtime.py, and openai_agents_sdk.py.
That package previously arrived only transitively via agt-policies's own
pin, which the prior commit removed from the base dependency set -
trading the original unresolvable-install failure for a quieter
ImportError at runtime the moment agent_os actually exercised one of
those paths.

Fix: declare agent-control-specification>=0.3.1b0,<0.4.0 directly in
agent-governance-toolkit-core's own dependencies, matching the range
agt-policies 5.0.0 already resolved to before microsoft#3939. Verified in a clean
venv: all four previously-broken agent_os modules import cleanly, and
cmd_validate.py's _validate_manifest() actually runs end-to-end (not
just import-checked). govern()'s contains/startswith/endswith path
(microsoft#3924) still passes both the deny and allow cases.

One related, pre-existing gap surfaced during this verification and is
NOT fixed here (out of scope for a packaging PR): _native_adapter_runtime
.py's _session_for() imports HostSession from agent_control_specification,
which genuinely does not exist in any published release yet (checked
0.3.1b1's exports directly). That call path was already broken before
this PR - it depends on ACS 0.4.0b0's API regardless of how the
agt-policies/agent-control-specification pins are arranged - so it's
unaffected by this change either way.

Also: moved the new 'migrate' extra out from under the '--- Bundles ---'
header (it's a single-package extra like redis/django, not a bundle),
and added a CHANGELOG.md [Unreleased]/Fixed entry.

Signed-off-by: karimad <kmehaleb@gmail.com>

* shorten comments

Signed-off-by: karimad <kmehaleb@gmail.com>

* docs: disclose still-unresolvable migrate-extra pin, file tracking issue

The migrate extra's agt-policies>=5.1.0,<6.0 pin predates this PR and is
unchanged by it. It's still unresolvable on its own today (agt-policies
5.1.0 isn't published), and will conflict with this PR's new base ACS pin
once it is (agt-policies would then require ACS>=0.4.0b0, base requires
<0.4.0). Documented in the CHANGELOG and the extra itself, tracked in
microsoft#4019 so it isn't rediscovered fresh.

Signed-off-by: Karim Mehalebi <kmehalebi@egencia.com>

* docs: tell agt migrate users they now need the migrate extra

Signed-off-by: Karim Mehalebi <kmehalebi@egencia.com>

* fix(core): pin agent-control-specification to 0.4.0b0 range agent_os requires

Reviewer found 0.3.1b1 lacks HostSession and rejects every in-repo
manifest, breaking the adapter runtime and agent-os validate despite
the install itself resolving. Update the base pin and changelog entry
to match.

Signed-off-by: Karim Mehalebi <kmehaleb@gmail.com>

---------

Signed-off-by: karimad <kmehaleb@gmail.com>
Signed-off-by: Karim Mehalebi <kmehalebi@egencia.com>
Signed-off-by: Karim Mehalebi <kmehaleb@gmail.com>
Co-authored-by: Karim Mehalebi <kmehalebi@egencia.com>
Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file documentation Improvements or additions to documentation size/S Small PR (< 50 lines) tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants