Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 0 additions & 4 deletions integrations/docker-sandbox-kit/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -93,7 +93,3 @@ The suite builds, schema-checks, signs and verifies a record from both Kits
with the released packages pinned in `requirements.txt`, and checks every
refusal above. A signed record from either Kit passes
`trace-tests verify --level 0`.

`agentrust-trace-adapters` 0.1.1 predates the `declared` mode, so the adapter
passes `build_record` a small policy object of its own. It switches to
`PolicyEvidence` once a release includes that mode.
35 changes: 3 additions & 32 deletions integrations/docker-sandbox-kit/kit_to_trace.py
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@
from dataclasses import dataclass
from typing import Any

from agentrust_trace_adapters import MissingEvidence, SourceSystem, build_record, digest_bytes
from agentrust_trace_adapters import MissingEvidence, PolicyEvidence, SourceSystem, build_record

SPEC_URL = "https://github.com/docker/sandbox-kit-spec/blob/main/docs/spec/SPEC-v3.md"
ADAPTER_URI = "https://github.com/agentrust-io/integrations/tree/main/integrations/docker-sandbox-kit"
Expand All @@ -70,36 +70,6 @@
_REFERENCE_RE = re.compile(r"^[a-z0-9]+([._-][a-z0-9]+)*(:[0-9]+)?(/[a-z0-9]+([._-][a-z0-9]+)*)+$")


@dataclass(frozen=True)
class DeclaredPolicy:
"""``policy`` block for a descriptor nothing evaluated.

``agentrust_trace_adapters.PolicyEvidence`` 0.1.1, the released version,
predates ``declared`` and rejects it; ``agentrust-trace`` 0.9.0 and later
accept it. ``build_record`` reads only ``bundle_hash`` and ``to_policy()``,
so this carries the same two members with the mode fixed. Replace it with
``PolicyEvidence`` once a release includes the ``declared`` mode.
"""

bundle: bytes
version: str
policy_uri: str | None = None

@property
def bundle_hash(self) -> str:
return digest_bytes(self.bundle)

def to_policy(self) -> dict[str, object]:
block: dict[str, object] = {
"bundle_hash": self.bundle_hash,
"enforcement_mode": "declared",
"version": self.version,
}
if self.policy_uri is not None:
block["policy_uri"] = self.policy_uri
return block


@dataclass(frozen=True)
class KitEvidence:
"""A Kit's published descriptor, taken from a manifest the caller holds."""
Expand Down Expand Up @@ -250,8 +220,9 @@ def build_from_kit(
model_provider=model_provider,
model_id=model_id,
model_version=model_version,
policy=DeclaredPolicy(
policy=PolicyEvidence(
bundle=evidence.descriptor,
enforcement_mode="declared",
version="docker-sandbox-kit-v3",
policy_uri=policy_uri,
),
Expand Down
2 changes: 1 addition & 1 deletion integrations/docker-sandbox-kit/requirements.txt
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
agentrust-trace==0.11.0
agentrust-trace-adapters==0.1.1
agentrust-trace-adapters==0.2.0
agentrust-trace-tests==0.6.1
pytest>=8
Loading