Skip to content

docs(examples): add policy condition-DSL string-operator example - #4020

Merged
MohammadHaroonAbuomar merged 1 commit into
microsoft:mainfrom
karimad:docs/policy-condition-dsl-string-operators-example
Sep 17, 2026
Merged

MohammadHaroonAbuomar merged 1 commit into
microsoft:mainfrom
karimad:docs/policy-condition-dsl-string-operators-example

Conversation

@karimad

@karimad Karim Mehalebi (karimad) commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Related Issue

None

If no related issue is linked above, you must complete "Problem & Solution", "Impact on Your Work", and "Alternatives Considered" below.

Problem & Solution

Problem: PolicyRule's condition DSL gained contains/startswith/endswith operators in #3924, fixing a bug where those operators silently fell through to False (a deny rule using them never fired, with no warning). No example in the repo shows these operators in use, or demonstrates the fail-closed/fail-open semantics on non-string data that the fix also established.

Solution: adds examples/policy-condition-operators/README.md and a runnable string_operators.py — a minimal, dependency-free (beyond agent-governance-toolkit-core itself) example showing the three operators plus the before/after failure mode they replace, consistent with how other examples/ entries pair a README with a runnable script.

Impact on Your Work

Authored the underlying fix in #3924; this closes the documentation gap so other users adopting the new operators have a runnable reference.

Timeline

None

Alternatives Considered

None — this is additive documentation, no other approach considered.

Type of Change

  • Documentation update

Package(s) Affected

  • examples

Testing

Unit Testing

N/A — docs-only change, no new code paths.

Manual Testing

Ran examples/policy-condition-operators/string_operators.py directly (not just copy-pasted blocks) against the local agent-mesh source (post-#3924 fix), in an isolated venv with pydantic installed. All 9 print() outputs matched the inline comments exactly (True/False for each contains/startswith/endswith match/no-match case, plus the fail-closed deny-fires-on-non-string-or-missing-field cases and the fail-open-prevention allow-does-not-fire case). Log output confirmed the fail-closed/fail-open mechanism ('contains' cannot match — treating as MATCH/NO-MATCH).

Checklist

  • I have linked a related issue above, or completed "Problem & Solution", "Impact on Your Work", and "Alternatives Considered"
  • My code follows the project style guidelines (ruff check) — N/A, Markdown only
  • I have added tests that prove my fix/feature works — N/A, docs-only
  • All new and existing tests pass (pytest) — N/A, docs-only
  • I have updated documentation as needed
  • I have signed the Microsoft CLA

Attribution & Prior Art

  • This contribution does not contain code copied or derived from other projects without attribution
  • Any external projects that inspired this design are credited in code comments or documentation
  • If this PR implements functionality similar to an existing open-source project, I have listed it below

Prior art / related projects (if any):
None

AI Assistance

  • I can explain every meaningful change in this PR: what it does, why, and what tradeoffs were considered
  • I have run tests and verification appropriate for this change
  • No part of this PR was autonomously submitted by an AI agent without my review
  • I have not used AI to generate review comments on others' PRs

If AI tools materially shaped this change, briefly note what was used:
Claude Code was used to draft the example and verify it against the real fixed source before submission; all content reviewed by me.

IP, Patents, and Licensing

  • This contribution does not implement patent-pending or patent-encumbered techniques
  • This contribution does not require an NDA or licensing agreement to understand or use
  • Any AI tools used have terms compatible with the MIT License

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@github-actions github-actions Bot added documentation Improvements or additions to documentation size/M Medium PR (< 200 lines) and removed documentation Improvements or additions to documentation labels Sep 17, 2026
@github-actions

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Sep 17, 2026
Comment thread examples/policy-condition-operators/string_operators.py
Comment thread examples/policy-condition-operators/README.md Outdated
Comment thread examples/policy-condition-operators/string_operators.py Outdated
Karim Mehalebi (karimad) added a commit to karimad/agent-governance-toolkit that referenced this pull request Sep 17, 2026
…l loudly

Addresses review from MohammadHaroonAbuomar on microsoft#4020:
- string_operators.py was missing its MIT license header (scripts/check_license_headers.py --fix).
- README's pip-install path doesn't work today: contains/startswith/endswith
  landed in microsoft#3924 (merged 2026-09-15) but no agent-governance-toolkit-core
  release includes it yet (latest on PyPI is 5.0.0, 2026-08-03) — following
  the old instructions silently reproduces the exact bug this example
  demonstrates. Documented that gap and gave a working PYTHONPATH-based run
  path from a checkout.
- string_operators.py only printed results for the reader to eyeball; on a
  stale install every check prints False with nothing to signal the
  mismatch. Replaced with a check() helper that asserts each expected value,
  so a stale/pre-fix install now fails loudly with an AssertionError instead
  of silently demonstrating the bug it's supposed to show was fixed.

Signed-off-by: Karim Mehalebi <kmehaleb@gmail.com>
Comment thread examples/policy-condition-operators/README.md Outdated
@karimad
Karim Mehalebi (karimad) force-pushed the docs/policy-condition-dsl-string-operators-example branch from 579774f to f2bfc37 Compare September 17, 2026 16:10
Comment thread examples/policy-condition-operators/README.md Outdated
PolicyRule's condition DSL gained contains/startswith/endswith operators
in microsoft#3924, fixing a bug where those operators silently fell through to
False (a deny rule using them never fired, with no warning). Adds
examples/policy-condition-operators/ demonstrating the three operators
and their fail-closed/fail-open semantics, since no existing example
covered them.

string_operators.py asserts each expected value rather than just
printing it, so a pre-microsoft#3924 install fails loudly with an AssertionError
instead of silently reproducing the bug it's meant to demonstrate.

The operators aren't in any released agent-governance-toolkit-core yet
(latest on PyPI is 5.0.0, predating microsoft#3924's 2026-09-15 merge), so the
README documents that gap and gives a working checkout-based run path
(PYTHONPATH into agent-mesh/agent-hypervisor/agt-policies, plus
pydantic[email]/pyyaml/cryptography/httpx/python-dateutil - verified in
a genuinely clean venv) rather than a pip-install path that would
silently reproduce the fixed bug.

Signed-off-by: Karim Mehalebi <kmehaleb@gmail.com>
@karimad
Karim Mehalebi (karimad) force-pushed the docs/policy-condition-dsl-string-operators-example branch from f2bfc37 to 31a173e Compare September 17, 2026 16:40

@MohammadHaroonAbuomar MohammadHaroonAbuomar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified at 31a173e: the README install line now lists the packages the example needs, and running the documented commands literally in a clean Python 3.12 venv prints "All assertions passed" with exit 0. The check() helper fails loudly against the released 5.0.0 as asked, the unreleased-operators caveat is documented, both files carry the MIT header, and the commit is signed off. All checks green. Thanks for sticking with it.

@MohammadHaroonAbuomar
MohammadHaroonAbuomar merged commit acea82d into microsoft:main Sep 17, 2026
95 checks passed
@toolstree

Copy link
Copy Markdown

🔍 General Boring Work (github-research)
docs(examples): add policy condition-DSL string-operator example
#4020
Tier: Micro $1

Draft: Hi, saw "docs(examples): add policy condition-DSL string-operator example" — I do boring paperwork: memos, contracts, SOWs.
Set & forget, Telegram only, $1-$50 USDC. Want me to take this off your plate?

@karimad
Karim Mehalebi (karimad) deleted the docs/policy-condition-dsl-string-operators-example branch September 18, 2026 08:34
@toolstree

Copy link
Copy Markdown

Hi, saw "docs(examples): add policy condition-DSL string-operator example" — PR #4020 · microsoft/agent-governance-toolkit

I do boring paperwork: memos, contracts, SOWs. Set & forget, Telegram only, $1-$50 USDC. Want me to take this off your plate?

Start here:
https://t.me/Saturnking_bot?start=lead_4020

Yuvraj Singh (yuvrajsingh2428) pushed a commit to yuvrajsingh2428/agent-governance-toolkit that referenced this pull request Oct 1, 2026
…rosoft#4020)

PolicyRule's condition DSL gained contains/startswith/endswith operators
in microsoft#3924, fixing a bug where those operators silently fell through to
False (a deny rule using them never fired, with no warning). Adds
examples/policy-condition-operators/ demonstrating the three operators
and their fail-closed/fail-open semantics, since no existing example
covered them.

string_operators.py asserts each expected value rather than just
printing it, so a pre-microsoft#3924 install fails loudly with an AssertionError
instead of silently reproducing the bug it's meant to demonstrate.

The operators aren't in any released agent-governance-toolkit-core yet
(latest on PyPI is 5.0.0, predating microsoft#3924's 2026-09-15 merge), so the
README documents that gap and gives a working checkout-based run path
(PYTHONPATH into agent-mesh/agent-hypervisor/agt-policies, plus
pydantic[email]/pyyaml/cryptography/httpx/python-dateutil - verified in
a genuinely clean venv) rather than a pip-install path that would
silently reproduce the fixed bug.

Signed-off-by: Karim Mehalebi <kmehaleb@gmail.com>
Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/M Medium PR (< 200 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants