Repository navigation
fix(python-sdk): a decoded record verifies offline (G-85) - #115
Merged
Merged
Conversation
The decoder keeps the server JSON on every decoded model (not a field), and encode() returns a copy of it, so a decoded model goes back out exactly as the server sent it. An explicit null, such as previousChainHash on every Postgres backed record, was dropped before, which changed the canonical hash: verify_execution_trust_record_offline rejected intact records, and refusal and intent verification sent the server a different record. A model changed with dataclasses.replace() has no source and is encoded from its fields. Test on the real sandbox record with the sandbox public key. Docs: the next release section, the 1.4.0 warning, Playground, changelog, G-85. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
pavancharak
added a commit
that referenced
this pull request
Oct 2, 2026
Resolves docs/REMAINING-WORK.md section K: keeps retention built (this branch) and G-85 fixed in code (#115). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Fixes G-85: the Python SDK rejected its own decoded Execution Trust Record when the server sent
previousChainHash: null, which every Postgres backed record carries (production, the sandbox).decoder.py: every decoded model keeps the server JSON in_parmana_source_json(not a dataclass field, so equality, repr andfields()are unchanged).encoder.py: a model with a source encodes to a copy of exactly that JSON. A model built by hand, or changed withdataclasses.replace(), is encoded from its fields as before.refusal_recordverification and Execution Intent verification, which send a decoded model back to the server.Test
python/tests/test_decoded_record_verifies.py, on the real sandbox record (deploy/sandbox/evidence/check-record.json) with the sandbox public key: the raw JSON verifies, the decoded model now verifies, the model encodes back to the server JSON, encoding returns a copy, and a changed model fails. Full Python suite 166 passed before the new file; ruff, black, mypy clean; full preflight in the hook.Docs
Python SDK page (next release section, the 1.4.0 warning now says it is fixed next release), Playground note, changelog, G-85 marked fixed in code, REMAINING-WORK. Reaches users with the next Python release; 1.4.0 keeps the bug, so the Playground script still verifies raw JSON.
🤖 Generated with Claude Code