Skip to content

fix(deps): replace trace update with aligned requirements and valid receipts - #4270

Open
Ricky Gummadi (Ricky-G) wants to merge 1 commit into
mainfrom
ricky-g-agentrust-trace-update
Open

Ricky Gummadi (Ricky-G) wants to merge 1 commit into
mainfrom
ricky-g-agentrust-trace-update

Conversation

@Ricky-G

@Ricky-G Ricky Gummadi (Ricky-G) commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Related Issue

Replacement for #4246. Credit to Dependabot for the original dependency update, observed at cdd2d11a5062dd91e8f20e8c4f168b379aa6039f. The original remains open pending maintainer verification of this replacement; this PR does not close it automatically.

If no related issue is linked above, you must complete "Problem & Solution", "Impact on Your Work", and "Alternatives Considered" below.

Problem & Solution

Summary

Preserve the requested agentrust-trace>=0.11.0,<0.12.0 update in agent-mesh's dev extra, align the contradictory consolidated-core runtime requirement, and correct unanchored TRACE receipt serialization. Add real signed-record and requirement-alignment regressions without changing enforcement, trust, appraisal, software-only runtime, or SLSA defaults.

Original failures and compatibility

The actual logs from CI run 37444908126 show ResolutionImpossible before tests run in agent-mesh Python 3.11/3.12/3.13, Engine API conformance, and docker-compose-test: mesh's updated dev extra requires TRACE 0.11 while agent-governance-toolkit-core requires <0.6.0. The core wheel force-includes the mesh implementation, so updating the core constraint is a tightly coupled installation fix, not a separate dependency upgrade.

After resolving that conflict, an independent trusted-key verification regression found that the existing transparency: null output passes the Pydantic-only check but fails TRACE 0.11's JSON-schema verification. Both unanchored serializers now omit the optional absent receipt; no fake URI, broad null stripping, relaxed schema check, or trust fallback is introduced. The exported local dataclass remains unchanged. Neither serializer currently accepts an anchored receipt input.

The integration calls load_signing_key, sign_record, and TrustRecord.model_validate directly, not upstream TraceAGTAdapter or TraceSandboxAdapter; their newly mandatory enforcement_mode argument does not require an AGT API change. Real verification covers the emitted profile, trusted key, canonical unpadded signature, and tamper rejection.

Changes

File Change
agent-governance-python/agent-mesh/pyproject.toml Preserve Dependabot's TRACE 0.11 range in the existing optional dev extra.
agent-governance-python/agent-governance-toolkit-core/pyproject.toml Align the runtime requirement so core and mesh can resolve together.
agent-governance-python/agent-mesh/src/agentmesh/governance/trace_sink.py Omit the absent receipt, document that serialization, and update the missing-dependency install hint.
agent-governance-python/agent-mesh/src/agentmesh/governance/trace_model.py Make the other unanchored serializer schema-compatible without changing its dataclass or enforcement configuration.
agent-governance-python/agent-mesh/tests/governance/test_trace_sink.py Cover requirement alignment and extra placement, the install hint, real trusted-key verification, padding rejection, and tamper rejection.
agent-governance-python/agent-mesh/tests/governance/test_trace_model.py Check absent-receipt serialization and real signing/verification of the model mapper.

Impact on Your Work

Unblocks the approved independent replacement for the stuck dependency update while ensuring the upgraded dependency can actually verify AGT's emitted records. No unrelated packages or shared CI architecture are modified.

Timeline

None. Maintainer review and passing required checks are needed before merge. No merge or auto-merge has been requested by this child session.

Alternatives Considered

The one-line mesh-only update is unresolvable with the core requirement. Downgrading TRACE, disabling verification, inventing a receipt, removing the integration, or changing enforcement defaults would not preserve the requested update and were rejected. The chosen fixes are confined to the contradictory requirement and invalid optional-field representation.

Type of Change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update
  • Maintenance (dependency updates, CI/CD, refactoring)
  • Security fix

Package(s) Affected

Core & runtime:

  • agent-governance-toolkit-core
  • agent-primitives
  • agent-os
  • agent-mesh
  • agent-runtime
  • agent-sre
  • agent-compliance

Governance & security:

  • agent-mcp-governance
  • agent-rag-governance
  • agent-sandbox
  • agent-discovery
  • agt-policies
  • policy-engine

Platform & tooling:

  • agent-hypervisor
  • agent-lightning
  • agent-marketplace
  • agent-governance-toolkit-cli
  • agent-governance-toolkit-integrations
  • agent-governance-toolkit-protocols
  • agentmesh-integrations (framework integrations)

CLI plugins:

  • agent-governance CLI plugins (copilot-cli / claude-code / opencode / antigravity-cli)

Shared / other:

  • schemas
  • action (GitHub Action)
  • examples
  • docs / root

Testing

Local environment: Windows, Python 3.14.7 in a session-specific virtual environment inheriting already installed dependencies; no shared-environment packages were changed. Local Python 3.11/3.12/3.13 were unavailable, so their results must come from this PR's CI. OPA 0.70.0 was downloaded from its official release and SHA256-verified; real ACS/OPA replay was required, not bypassed.

Unit Testing

Added four regressions: mesh/core requirement alignment with unchanged extra placement; the supported missing-dependency hint; persisted-record verification with a real generated test key plus padding/tamper refusal; and signing/verification of the other mapper. Updated two assertions to distinguish an absent optional receipt from an invalid null receipt.

Before the fix, the requirement/hint regressions failed against main, the original core wheel plus TRACE 0.11 reproduced ResolutionImpossible, and the new verification regression failed specifically at transparency: None is not of type 'string'. These are observed failures, not inferred bot-specific problems.

Manual Testing

In the commands below, python denotes the session venv interpreter and $a is the session artifact directory. Package tests ran from agent-governance-python/agent-mesh; other commands ran from the repository root. Source runs used checkout mesh/compliance/agt-policies source paths; the separate wheel integration run used the installed rebuilt core's agentmesh package with no mesh source override.

Command Result
python -m pytest tests -q --tb=short 4439 passed, 86 skipped, no failures; existing optional/platform-dependent skips retained.
python -m pytest tests/engine_api/conformance -q --cov=tests.engine_api.conformance.assertions --cov=tests.engine_api.conformance.conftest --cov=tests.engine_api.conformance.contract --cov=tests.engine_api.conformance.target --cov-report=term-missing --cov-fail-under=95 --tb=short with AGT_ENGINE_API_REQUIRE_REPLAY=1, ACS_OPA_PATH and PATH pointing to verified OPA 91 passed, 96.10% coverage; real replay exercised.
python -m pytest agent-governance-python/agent-mesh/tests/governance/test_trace_sink.py agent-governance-python/agent-mesh/tests/governance/test_trace_model.py agent-governance-python/agent-mesh/tests/test_audit_reader_consistency.py -q --tb=short 68 passed against checkout source and again against the rebuilt installed core wheel.
python -m build --wheel --no-isolation agent-governance-python/agent-governance-toolkit-core --outdir "$a/updated-wheels" Passed; inspected wheel metadata and validated the installed artifact.
python -m build --wheel --no-isolation agent-governance-python/agent-mesh --outdir "$a/updated-wheels" Passed; TRACE requirement remains marked extra == 'dev'.
python -m pip install --dry-run --no-build-isolation --report "$a/updated-resolver-report.json" "$a/updated-wheels/agent_governance_toolkit_core-5.0.0-py3-none-any.whl" "$a/updated-wheels/agentmesh_platform-5.0.0-py3-none-any.whl[dev]" Passed; original contradictory requirements no longer fail resolution. Newly installed resolver artifacts were age/hash-audited, then installed with --require-hashes.
python -m pip check Passed: No broken requirements found.
python -m ruff check agent-governance-python/agent-mesh/src --select E,F,W --ignore E501 Passed.
python -m ruff check agent-governance-python/agent-mesh/tests/governance/test_trace_sink.py agent-governance-python/agent-mesh/tests/governance/test_trace_model.py --select E,F,W --ignore E501 Passed; the changed test files also pass their default Ruff rules.
python scripts/check_license_headers.py agent-governance-python/agent-mesh/src/agentmesh/governance/trace_sink.py agent-governance-python/agent-mesh/src/agentmesh/governance/trace_model.py agent-governance-python/agent-mesh/tests/governance/test_trace_sink.py agent-governance-python/agent-mesh/tests/governance/test_trace_model.py Passed.
python scripts/check_release_age.py --base origin/main --min-age-days 7 --explicit pypi:agentrust-trace@0.11.0 Passed.
python scripts/check_install_scripts.py --base origin/main --strict --max-deps 2000 and python scripts/check_build_hooks.py --base origin/main --strict Passed; no new npm dependencies or build hooks.
python -m pytest tests/ci/test_shared_dependency_contracts.py -q 1 passed.
git diff --check Passed.

Supply-chain evidence: TRACE 0.11.0 was uploaded to PyPI on 2026-09-25T23:30:00Z, is not yanked, and its wheel SHA256 is 7de621eaf795449e365d04967a82a551a18d75c99d248b4a0923f6d593bdb09e, matching the downloaded artifact. Its release tag resolves to commit 7d8df347ada4ce84356640c9252ea2cc1d467b58. Reviewed the release notes/changelog and metadata delta: new direct transitives referencing and rfc3986-validator, raised minima for jsonschema, pydantic, and rfc8785; no GPL format extra was introduced. All newly installed remote resolver/build artifacts passed the seven-day rule, non-yanked check, and PyPI hash comparison before installation.

Baseline findings, not hidden: the generic dependency-confusion CLI reports six false positives from existing pip install prose comments in mesh's TOML (PR, brings, everything, needed, for, tests.), identically on main and this branch. Its manifest-aware check_pyproject_toml() passes for both changed manifests. Full default Ruff reports the same two pre-existing UP045 annotations in trace_model.py; Black would reformat both existing test files on main as well. CI's E/F/W rules pass; unrelated formatting/scanner changes were not bundled.

Docker Compose was not run locally. Its original failure was the same dependency conflict and is covered by resolver reproduction; actual Docker and Python-matrix results remain pending CI. This is not a claim that every repository test or required CI check has passed.

Checklist

  • I have linked a related issue above, or completed "Problem & Solution", "Impact on Your Work", and "Alternatives Considered"
  • My code follows the project style guidelines (ruff check)
  • I have added tests that prove my fix/feature works
  • All new and existing tests pass (pytest)
  • I have updated documentation as needed
  • I have signed the Microsoft CLA

Attribution & Prior Art

  • This contribution does not contain code copied or derived from other projects without attribution
  • Any external projects that inspired this design are credited in code comments or documentation
  • If this PR implements functionality similar to an existing open-source project, I have listed it below

Prior art / related projects (if any):

Dependabot's #4246 supplies the original dependency-update intent. API compatibility was checked against agentrust-io/trace-spec v0.11.0 (Apache-2.0); no upstream implementation was vendored. This extends the existing ADR-0032 integration, not a new framework integration.

AI Assistance

  • I can explain every meaningful change in this PR: what it does, why, and what tradeoffs were considered
  • I have run tests and verification appropriate for this change
  • No part of this PR was autonomously submitted by an AI agent without my review
  • I have not used AI to generate review comments on others' PRs

If AI tools materially shaped this change, briefly note what was used:

GitHub Copilot performed the investigation, implementation, tests, and PR preparation under the user's explicit authorization. This PR was autonomously submitted for maintainer review; human review, CLA status, and the template's human attestations are not claimed. The commit includes the repository-required DCO signoff.

IP, Patents, and Licensing

  • This contribution does not implement patent-pending or patent-encumbered techniques
  • This contribution does not require an NDA or licensing agreement to understand or use
  • Any AI tools used have terms compatible with the MIT License

Preserve the Dependabot update from #4246, align the consolidated core runtime constraint, and omit absent optional transparency receipts for TRACE schema verification. Add real signing and dependency-alignment regressions.

Signed-off-by: Microsoft Corporation <agentgovtoolkit@microsoft.com>
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
pip/agentrust-trace >= 0.11.0,< 0.12.0 UnknownUnknown

Scanned Files

  • agent-governance-python/agent-governance-toolkit-core/pyproject.toml

@github-actions github-actions Bot added dependencies Pull requests that update a dependency file tests agent-mesh agent-mesh package size/M Medium PR (< 200 lines) labels Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

📦 Dependency diff (SBOM)

Comparing main → ricky-g-agentrust-trace-update.

✅ No dependency changes detected.

@MohammadHaroonAbuomar

Copy link
Copy Markdown
Collaborator

Verified at 985fc10: the core runtime pin and the agent-mesh dev pin both move to agentrust-trace >=0.11.0,<0.12.0 (0.11.0 on PyPI since 2026-09-25, wheel checksum matches the description), the install hint follows, and the real fix is dropping the explicit transparency: None from both serializers. Reproduced the baseline: main's serializers against 0.11.0 fail the TRACE v0.2 schema (None is not of type string) in 5 tests, and sign_record does not validate, so main would emit unverifiable records; with this PR 36 pass, and the governance suite passes (173). The new tests cover real Ed25519 sign and verify, unpadded base64url, padding rejection, tamper rejection and pin alignment. sign_record and load_signing_key are unchanged in 0.11, so no enforcement_mode change is needed here. Scanners pass and CI is green. Same two items as on #4268 before I approve: the commit is signed off as Microsoft Corporation agentgovtoolkit@microsoft.com rather than a named person, and the AI Assistance attestations, the CLA box and the third IP box are unticked while the description says Copilot produced and submitted the change. Please tick them under your own name. One optional note: trace_model.py:104 and trace_sink.py:130 still pass transparency=None to TrustRecord while the dict omits it; a one-line comment that absence is intentional at Level 0 and 1 would keep the rationale the deleted comment carried. Once this merges, dependabot #4246 can be closed as superseded.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agent-mesh agent-mesh package dependencies Pull requests that update a dependency file size/M Medium PR (< 200 lines) tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants