Repository navigation
docs(examples): add policy condition-DSL string-operator example - #4020
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
…l loudly Addresses review from MohammadHaroonAbuomar on microsoft#4020: - string_operators.py was missing its MIT license header (scripts/check_license_headers.py --fix). - README's pip-install path doesn't work today: contains/startswith/endswith landed in microsoft#3924 (merged 2026-09-15) but no agent-governance-toolkit-core release includes it yet (latest on PyPI is 5.0.0, 2026-08-03) — following the old instructions silently reproduces the exact bug this example demonstrates. Documented that gap and gave a working PYTHONPATH-based run path from a checkout. - string_operators.py only printed results for the reader to eyeball; on a stale install every check prints False with nothing to signal the mismatch. Replaced with a check() helper that asserts each expected value, so a stale/pre-fix install now fails loudly with an AssertionError instead of silently demonstrating the bug it's supposed to show was fixed. Signed-off-by: Karim Mehalebi <kmehaleb@gmail.com>
579774f to
f2bfc37
Compare
PolicyRule's condition DSL gained contains/startswith/endswith operators in microsoft#3924, fixing a bug where those operators silently fell through to False (a deny rule using them never fired, with no warning). Adds examples/policy-condition-operators/ demonstrating the three operators and their fail-closed/fail-open semantics, since no existing example covered them. string_operators.py asserts each expected value rather than just printing it, so a pre-microsoft#3924 install fails loudly with an AssertionError instead of silently reproducing the bug it's meant to demonstrate. The operators aren't in any released agent-governance-toolkit-core yet (latest on PyPI is 5.0.0, predating microsoft#3924's 2026-09-15 merge), so the README documents that gap and gives a working checkout-based run path (PYTHONPATH into agent-mesh/agent-hypervisor/agt-policies, plus pydantic[email]/pyyaml/cryptography/httpx/python-dateutil - verified in a genuinely clean venv) rather than a pip-install path that would silently reproduce the fixed bug. Signed-off-by: Karim Mehalebi <kmehaleb@gmail.com>
f2bfc37 to
31a173e
Compare
MohammadHaroonAbuomar
left a comment
There was a problem hiding this comment.
Verified at 31a173e: the README install line now lists the packages the example needs, and running the documented commands literally in a clean Python 3.12 venv prints "All assertions passed" with exit 0. The check() helper fails loudly against the released 5.0.0 as asked, the unreleased-operators caveat is documented, both files carry the MIT header, and the commit is signed off. All checks green. Thanks for sticking with it.
|
🔍 General Boring Work (github-research) Draft: Hi, saw "docs(examples): add policy condition-DSL string-operator example" — I do boring paperwork: memos, contracts, SOWs. |
|
Hi, saw "docs(examples): add policy condition-DSL string-operator example" — PR #4020 · microsoft/agent-governance-toolkit I do boring paperwork: memos, contracts, SOWs. Set & forget, Telegram only, $1-$50 USDC. Want me to take this off your plate? Start here: |
…rosoft#4020) PolicyRule's condition DSL gained contains/startswith/endswith operators in microsoft#3924, fixing a bug where those operators silently fell through to False (a deny rule using them never fired, with no warning). Adds examples/policy-condition-operators/ demonstrating the three operators and their fail-closed/fail-open semantics, since no existing example covered them. string_operators.py asserts each expected value rather than just printing it, so a pre-microsoft#3924 install fails loudly with an AssertionError instead of silently reproducing the bug it's meant to demonstrate. The operators aren't in any released agent-governance-toolkit-core yet (latest on PyPI is 5.0.0, predating microsoft#3924's 2026-09-15 merge), so the README documents that gap and gives a working checkout-based run path (PYTHONPATH into agent-mesh/agent-hypervisor/agt-policies, plus pydantic[email]/pyyaml/cryptography/httpx/python-dateutil - verified in a genuinely clean venv) rather than a pip-install path that would silently reproduce the fixed bug. Signed-off-by: Karim Mehalebi <kmehaleb@gmail.com> Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Related Issue
None
Problem & Solution
Problem:
PolicyRule's condition DSL gainedcontains/startswith/endswithoperators in #3924, fixing a bug where those operators silently fell through toFalse(a deny rule using them never fired, with no warning). No example in the repo shows these operators in use, or demonstrates the fail-closed/fail-open semantics on non-string data that the fix also established.Solution: adds
examples/policy-condition-operators/README.mdand a runnablestring_operators.py— a minimal, dependency-free (beyondagent-governance-toolkit-coreitself) example showing the three operators plus the before/after failure mode they replace, consistent with how otherexamples/entries pair a README with a runnable script.Impact on Your Work
Authored the underlying fix in #3924; this closes the documentation gap so other users adopting the new operators have a runnable reference.
Timeline
None
Alternatives Considered
None — this is additive documentation, no other approach considered.
Type of Change
Package(s) Affected
Testing
Unit Testing
N/A — docs-only change, no new code paths.
Manual Testing
Ran
examples/policy-condition-operators/string_operators.pydirectly (not just copy-pasted blocks) against the localagent-meshsource (post-#3924 fix), in an isolated venv withpydanticinstalled. All 9print()outputs matched the inline comments exactly (True/Falsefor eachcontains/startswith/endswithmatch/no-match case, plus the fail-closed deny-fires-on-non-string-or-missing-field cases and the fail-open-prevention allow-does-not-fire case). Log output confirmed the fail-closed/fail-open mechanism ('contains' cannot match — treating as MATCH/NO-MATCH).Checklist
Attribution & Prior Art
Prior art / related projects (if any):
None
AI Assistance
If AI tools materially shaped this change, briefly note what was used:
Claude Code was used to draft the example and verify it against the real fixed source before submission; all content reviewed by me.
IP, Patents, and Licensing