From b1b5248f072ff082c576617fc17b8eb32aa91694 Mon Sep 17 00:00:00 2001 From: Imran Siddique Date: Thu, 1 Oct 2026 16:34:57 -0700 Subject: [PATCH] refactor(docker-sandbox-kit): use PolicyEvidence now that 0.2.0 ships declared Drops the stand-in DeclaredPolicy and pins agentrust-trace-adapters 0.2.0. Records are unchanged: the claude-acp-set fixture still yields bundle_hash sha256:c04f322f..., and the 19 tests and Level 0 pass on the PyPI release. Co-Authored-By: Claude Opus 5.5 --- integrations/docker-sandbox-kit/README.md | 4 --- .../docker-sandbox-kit/kit_to_trace.py | 35 ++----------------- .../docker-sandbox-kit/requirements.txt | 2 +- 3 files changed, 4 insertions(+), 37 deletions(-) diff --git a/integrations/docker-sandbox-kit/README.md b/integrations/docker-sandbox-kit/README.md index 72080be..d531a6e 100644 --- a/integrations/docker-sandbox-kit/README.md +++ b/integrations/docker-sandbox-kit/README.md @@ -93,7 +93,3 @@ The suite builds, schema-checks, signs and verifies a record from both Kits with the released packages pinned in `requirements.txt`, and checks every refusal above. A signed record from either Kit passes `trace-tests verify --level 0`. - -`agentrust-trace-adapters` 0.1.1 predates the `declared` mode, so the adapter -passes `build_record` a small policy object of its own. It switches to -`PolicyEvidence` once a release includes that mode. diff --git a/integrations/docker-sandbox-kit/kit_to_trace.py b/integrations/docker-sandbox-kit/kit_to_trace.py index e5c84f3..cb1c424 100644 --- a/integrations/docker-sandbox-kit/kit_to_trace.py +++ b/integrations/docker-sandbox-kit/kit_to_trace.py @@ -50,7 +50,7 @@ from dataclasses import dataclass from typing import Any -from agentrust_trace_adapters import MissingEvidence, SourceSystem, build_record, digest_bytes +from agentrust_trace_adapters import MissingEvidence, PolicyEvidence, SourceSystem, build_record SPEC_URL = "https://github.com/docker/sandbox-kit-spec/blob/main/docs/spec/SPEC-v3.md" ADAPTER_URI = "https://github.com/agentrust-io/integrations/tree/main/integrations/docker-sandbox-kit" @@ -70,36 +70,6 @@ _REFERENCE_RE = re.compile(r"^[a-z0-9]+([._-][a-z0-9]+)*(:[0-9]+)?(/[a-z0-9]+([._-][a-z0-9]+)*)+$") -@dataclass(frozen=True) -class DeclaredPolicy: - """``policy`` block for a descriptor nothing evaluated. - - ``agentrust_trace_adapters.PolicyEvidence`` 0.1.1, the released version, - predates ``declared`` and rejects it; ``agentrust-trace`` 0.9.0 and later - accept it. ``build_record`` reads only ``bundle_hash`` and ``to_policy()``, - so this carries the same two members with the mode fixed. Replace it with - ``PolicyEvidence`` once a release includes the ``declared`` mode. - """ - - bundle: bytes - version: str - policy_uri: str | None = None - - @property - def bundle_hash(self) -> str: - return digest_bytes(self.bundle) - - def to_policy(self) -> dict[str, object]: - block: dict[str, object] = { - "bundle_hash": self.bundle_hash, - "enforcement_mode": "declared", - "version": self.version, - } - if self.policy_uri is not None: - block["policy_uri"] = self.policy_uri - return block - - @dataclass(frozen=True) class KitEvidence: """A Kit's published descriptor, taken from a manifest the caller holds.""" @@ -250,8 +220,9 @@ def build_from_kit( model_provider=model_provider, model_id=model_id, model_version=model_version, - policy=DeclaredPolicy( + policy=PolicyEvidence( bundle=evidence.descriptor, + enforcement_mode="declared", version="docker-sandbox-kit-v3", policy_uri=policy_uri, ), diff --git a/integrations/docker-sandbox-kit/requirements.txt b/integrations/docker-sandbox-kit/requirements.txt index 0e4cdf5..3c702c6 100644 --- a/integrations/docker-sandbox-kit/requirements.txt +++ b/integrations/docker-sandbox-kit/requirements.txt @@ -1,4 +1,4 @@ agentrust-trace==0.11.0 -agentrust-trace-adapters==0.1.1 +agentrust-trace-adapters==0.2.0 agentrust-trace-tests==0.6.1 pytest>=8