diff --git a/examples/weight-custody-manifest/README.md b/examples/weight-custody-manifest/README.md index 339c1c1..05e87a4 100644 --- a/examples/weight-custody-manifest/README.md +++ b/examples/weight-custody-manifest/README.md @@ -51,7 +51,7 @@ Each script is one runnable feature with mock (software) attestation, so they ru ### Closed-weight vs open-weight -The same machinery, two trust settings. **Closed** weights (a frontier model deployed into someone else's infra) need secrecy. **Open** weights (Llama, Mistral, SmolLM) are already public, so the flow instead does integrity, license, and derivative custody. +The same machinery, two trust settings. **Closed** weights (a frontier model deployed into someone else's infra) need secrecy. **Open** weights (SmolLM and other public checkpoints) are already public, so the flow instead does integrity, license, and derivative custody. - **`closed_model_e2e.py`** -- the closed/frontier flow where secrecy is the job (`base_confidentiality: confidential`): sign, attestation-gated release of the real decryption key, wipe-on-lapse custody, and the honest hostile-owner caveat. - **`open_model_e2e.py`** -- the full six-step flow on an open model, honest about which steps are real work versus theater for a public base (the base's secrecy is theater; integrity, license, derivative custody, and the kill switch are the point). diff --git a/examples/weight-custody-manifest/manifest.example.json b/examples/weight-custody-manifest/manifest.example.json index 75811db..88c5a6a 100644 --- a/examples/weight-custody-manifest/manifest.example.json +++ b/examples/weight-custody-manifest/manifest.example.json @@ -8,7 +8,7 @@ "release_terms": { "license": "customer-deployment-agreement-ref:CDA-2026-0091", "permitted_derivatives": "fine-tune-only, no re-export of base weights", - "permitted_environments": ["opaque-cmcp-attested-enclave"], + "permitted_environments": ["cmcp-attested-enclave"], "jurisdiction_restriction": "US, EU" }, "release_policy": { @@ -54,14 +54,14 @@ } }, "custody": { - "custodian": "opaque-systems", + "custodian": "example-custodian", "custodian_type": "opaque-hosted", "kbs_image": { "measurement": "sha256:abcd1234abcd1234abcd1234abcd1234abcd1234abcd1234abcd1234abcd1234", - "signer": "ed25519:opaque-key-placeholder", - "note": "the key release service runs in an attested enclave in every profile, Opaque-hosted included" + "signer": "ed25519:custodian-key-placeholder", + "note": "the key release service runs in an attested enclave in every profile, custodian-hosted included" }, - "enclave_id": "did:opaque:example-enclave-04", + "enclave_id": "did:example:enclave-04", "attestation_cadence": "24h", "kbs_attestation_cadence": "24h" }, diff --git a/examples/weight-custody-manifest/open_model_e2e.py b/examples/weight-custody-manifest/open_model_e2e.py index e78c40e..7265c3f 100644 --- a/examples/weight-custody-manifest/open_model_e2e.py +++ b/examples/weight-custody-manifest/open_model_e2e.py @@ -12,7 +12,7 @@ The reframe that drives this demo --------------------------------- For a closed frontier model the job is secrecy: don't let the weights leak. For -an OPEN-weight model (Llama, Mistral, SmolLM, ...) the base weights are already +an OPEN-weight model (SmolLM or any public checkpoint) the base weights are already downloadable, so encrypting them and gating decryption behind attestation protects nothing - anyone can just download the same checkpoint. Saying that plainly matters. What the same six-step machinery still does, and why you'd run @@ -130,13 +130,13 @@ def main() -> None: gov_custodian = generate_ed25519() rule("Open-weight model: base weights are PUBLIC") - # Pretend this blob is a downloaded checkpoint (in reality: your - # Llama-3.1 / Mistral / SmolLM safetensors). We hash the real bytes. + # Pretend this blob is a downloaded checkpoint (in reality, the + # any public safetensors checkpoint). We hash the real bytes. checkpoint = b"" base_hash = sha256(checkpoint) serving = sha256(b"vllm-0.6.3 + policy-bundle-v2 (the certified serving stack)") print("base weights_hash :", base_hash) - print("license : Llama-3.1-Community (usage + scale restrictions)") + print("license : example-community-license (usage + scale restrictions)") print("NOTE: encrypting a *public* base protects nothing. The mechanism below") print(" does INTEGRITY + LICENSE work here, not secrecy.") @@ -144,7 +144,7 @@ def main() -> None: rule("Step 0 - Certify the base: manifest (integrity + license), jointly signed") base_doc = build_manifest( weights_hash=base_hash, - license_text="Llama-3.1-Community", + license_text="example-community-license", serving_measurement=serving, builder_id="acme-model-governance", custodian_id="acme-model-governance", @@ -213,7 +213,7 @@ def main() -> None: deriv_hash = sha256(derivative_weights) deriv_doc = build_manifest( weights_hash=deriv_hash, - license_text="Llama-3.1-Community + Acme-proprietary-derivative", + license_text="example-community-license + Acme-proprietary-derivative", serving_measurement=serving, builder_id="acme-model-governance", custodian_id="acme-model-governance", diff --git a/examples/weight-custody-manifest/real_lora_custody.py b/examples/weight-custody-manifest/real_lora_custody.py index bb06fa3..d4d2605 100644 --- a/examples/weight-custody-manifest/real_lora_custody.py +++ b/examples/weight-custody-manifest/real_lora_custody.py @@ -240,29 +240,29 @@ def main() -> int: serving = "sha256:" + hashlib.sha256(b"wcm-local-lora-serving-stack-v1").hexdigest() manifest_doc = build_manifest( weights_hash=envelope["artifact_digest"], - license_text="Apache-2.0 + OPAQUE-private-derivative", + license_text="Apache-2.0 + private-derivative", serving=serving, - builder_id="opaque-wcm-builder", - custodian_id="opaque-wcm-custodian", + builder_id="example-wcm-builder", + custodian_id="example-wcm-custodian", derivatives="none", derived_from=base_digest, - rights_holder={"base": model_id, "derivative": "OPAQUE"}, + rights_holder={"base": model_id, "derivative": "example-derivative-owner"}, ) manifest_doc["provenance"] = { "model_signing": { "method": "openssf-model-signing", "signed_digest": provenance_digest, "transparency": "local-key; publication pending", - "signer": "opaque-wcm-builder", + "signer": "example-wcm-builder", } } manifest = WeightCustodyManifest.model_validate(waive_mock_verification(manifest_doc)) manifest = manifest.with_signatures([ Ed25519Signer(builder).sign( - manifest.unsigned_dict(), role="builder", signer="opaque-wcm-builder" + manifest.unsigned_dict(), role="builder", signer="example-wcm-builder" ), Ed25519Signer(custodian).sign( - manifest.unsigned_dict(), role="custodian", signer="opaque-wcm-custodian" + manifest.unsigned_dict(), role="custodian", signer="example-wcm-custodian" ), ]) context = VerificationContext() diff --git a/integrations/comply54/README.md b/integrations/comply54/README.md index 5c01704..169c7ed 100644 --- a/integrations/comply54/README.md +++ b/integrations/comply54/README.md @@ -59,7 +59,7 @@ with open("result.json", "w") as f: ```bash python src/comply54_to_trace.py result.json \ --agent-id payments-agent \ - --model anthropic/claude-sonnet-4-6 + --model example-provider/example-model ``` Output: `claim.jwt` (signed JWT, compact format) + printed to stdout. diff --git a/integrations/comply54/examples/emit_record.py b/integrations/comply54/examples/emit_record.py index 9e63d8b..d969dd2 100755 --- a/integrations/comply54/examples/emit_record.py +++ b/integrations/comply54/examples/emit_record.py @@ -46,7 +46,7 @@ def main() -> int: parser.add_argument("--out", required=True, help="Path for the trace-tests-gradable record") parser.add_argument("--result", default=str(DEFAULT_RESULT), help="comply54 ComplianceResult JSON path") parser.add_argument("--agent-id", default="payments-agent", help="Agent SPIFFE identity suffix") - parser.add_argument("--model", default="anthropic/claude-sonnet-4-6", help="Model in provider/model-id format") + parser.add_argument("--model", default="example-provider/example-model", help="Model in provider/model-id format") args = parser.parse_args() result = json.loads(Path(args.result).read_text(encoding="utf-8")) diff --git a/integrations/comply54/src/comply54_to_trace.py b/integrations/comply54/src/comply54_to_trace.py index 187e7dd..36f6d7d 100644 --- a/integrations/comply54/src/comply54_to_trace.py +++ b/integrations/comply54/src/comply54_to_trace.py @@ -6,7 +6,7 @@ Usage: python comply54_to_trace.py result.json - python comply54_to_trace.py result.json --agent-id payments-agent --model anthropic/claude-sonnet-4-6 + python comply54_to_trace.py result.json --agent-id payments-agent --model example-provider/example-model The JWT is written to claim.jwt and printed to stdout. Set TRACE_PRIVATE_KEY_PEM to supply a persistent Ed25519 key; otherwise a diff --git a/integrations/comply54/tests/test_comply54_to_trace.py b/integrations/comply54/tests/test_comply54_to_trace.py index 46fc279..6f9c2d1 100644 --- a/integrations/comply54/tests/test_comply54_to_trace.py +++ b/integrations/comply54/tests/test_comply54_to_trace.py @@ -82,19 +82,19 @@ class TestAppraisalMapping: def test_allow_maps_to_affirming(self): - payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model") assert payload["appraisal"]["status"] == "affirming" def test_deny_maps_to_contraindicated(self): - payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model") assert payload["appraisal"]["status"] == "contraindicated" def test_escalate_maps_to_warning(self): - payload = comply54_to_trace_payload(ESCALATE_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(ESCALATE_RESULT, "agent-1", "example-provider/example-model") assert payload["appraisal"]["status"] == "warning" def test_audit_maps_to_warning(self): - payload = comply54_to_trace_payload(AUDIT_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(AUDIT_RESULT, "agent-1", "example-provider/example-model") assert payload["appraisal"]["status"] == "warning" @@ -102,68 +102,68 @@ def test_audit_maps_to_warning(self): class TestTraceEnvelope: def test_eat_profile_present(self): - payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model") assert payload["eat_profile"] == "tag:agentrust-io.com,2026:trace-v0.2" def test_iat_is_integer(self): - payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model") assert isinstance(payload["iat"], int) assert payload["iat"] > 0 def test_subject_contains_agent_id(self): - payload = comply54_to_trace_payload(ALLOW_RESULT, "payments-agent", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(ALLOW_RESULT, "payments-agent", "example-provider/example-model") assert "payments-agent" in payload["subject"] assert payload["subject"].startswith("spiffe://") def test_policy_bundle_hash_is_sha256(self): - payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model") assert payload["policy"]["bundle_hash"].startswith("sha256:") assert len(payload["policy"]["bundle_hash"]) == 71 # "sha256:" + 64 hex chars def test_policy_bundle_hash_is_deterministic(self): - p1 = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") - p2 = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + p1 = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model") + p2 = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model") assert p1["policy"]["bundle_hash"] == p2["policy"]["bundle_hash"] def test_runtime_platform_is_software_only(self): - payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model") assert payload["runtime"]["platform"] == "software-only" def test_model_provider_parsed_correctly(self): - payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "openai/gpt-4o") - assert payload["model"]["provider"] == "openai" - assert payload["model"]["model_id"] == "gpt-4o" + payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "other-provider/other-model") + assert payload["model"]["provider"] == "other-provider" + assert payload["model"]["model_id"] == "other-model" # ── comply54 extension claims ───────────────────────────────────────────────── class TestComply54Claims: def test_audit_id_preserved(self): - payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model") assert payload["comply54"]["audit_id"] == "test-audit-002" def test_overall_decision_preserved(self): - payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model") assert payload["comply54"]["overall"] == "deny" def test_jurisdictions_extracted(self): - payload = comply54_to_trace_payload(PAN_AFRICAN_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(PAN_AFRICAN_RESULT, "agent-1", "example-provider/example-model") assert "NG" in payload["comply54"]["jurisdictions"] assert "KE" in payload["comply54"]["jurisdictions"] assert "ZA" in payload["comply54"]["jurisdictions"] def test_packs_evaluated_sorted(self): - payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model") packs = payload["comply54"]["packs_evaluated"] assert packs == sorted(packs) def test_violations_only_non_allow(self): - payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model") for v in payload["comply54"]["violations"]: assert v["action"] != "allow" def test_allow_result_has_no_violations(self): - payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model") assert len(payload["comply54"]["violations"]) == 0 @@ -183,7 +183,7 @@ def test_jwk_has_correct_fields(self): def test_signed_jwt_is_decodable(self): key = load_or_generate_key() - payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6", key=key) + payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model", key=key) token = pyjwt.encode(payload, key, algorithm="EdDSA", headers={"alg": "EdDSA", "typ": "JWT"}) decoded = pyjwt.decode(token, options={"verify_signature": False}) assert decoded["eat_profile"] == "tag:agentrust-io.com,2026:trace-v0.2" @@ -191,13 +191,13 @@ def test_signed_jwt_is_decodable(self): def test_signed_jwt_has_three_parts(self): key = load_or_generate_key() - payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6", key=key) + payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model", key=key) token = pyjwt.encode(payload, key, algorithm="EdDSA", headers={"alg": "EdDSA", "typ": "JWT"}) assert len(token.split(".")) == 3 def test_signature_is_cryptographically_verified(self): key = load_or_generate_key() - payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6", key=key) + payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model", key=key) token = pyjwt.encode(payload, key, algorithm="EdDSA", headers={"alg": "EdDSA", "typ": "JWT"}) public_key = key.public_key() decoded = pyjwt.decode(token, public_key, algorithms=["EdDSA"]) @@ -227,19 +227,19 @@ def _core(payload: dict) -> dict: class TestSchemaConformance: def test_allow_result_core_conforms_to_trace_schema(self): - payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model") jsonschema.validate(_core(payload), _load_schema()) def test_deny_result_core_conforms_to_trace_schema(self): - payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model") jsonschema.validate(_core(payload), _load_schema()) def test_escalate_result_core_conforms_to_trace_schema(self): - payload = comply54_to_trace_payload(ESCALATE_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(ESCALATE_RESULT, "agent-1", "example-provider/example-model") jsonschema.validate(_core(payload), _load_schema()) def test_audit_result_core_conforms_to_trace_schema(self): - payload = comply54_to_trace_payload(AUDIT_RESULT, "agent-1", "anthropic/claude-sonnet-4-6") + payload = comply54_to_trace_payload(AUDIT_RESULT, "agent-1", "example-provider/example-model") jsonschema.validate(_core(payload), _load_schema()) def test_appraisal_status_is_valid_enum(self): @@ -254,7 +254,7 @@ def test_appraisal_status_is_valid_enum(self): def _build_signed_payload(result_fixture: dict) -> dict: """Return a complete TRACE payload (cnf.jwk included via the mapping function).""" key = load_or_generate_key() - return comply54_to_trace_payload(result_fixture, "test-agent", "anthropic/claude-sonnet-4-6", key=key) + return comply54_to_trace_payload(result_fixture, "test-agent", "example-provider/example-model", key=key) def _run_level0(result_fixture: dict) -> dict: diff --git a/integrations/computeid-agentpassport-trace/offline-verifier.js b/integrations/computeid-agentpassport-trace/offline-verifier.js index 80280c9..4a61ed8 100644 --- a/integrations/computeid-agentpassport-trace/offline-verifier.js +++ b/integrations/computeid-agentpassport-trace/offline-verifier.js @@ -1,5 +1,5 @@ #!/usr/bin/env node -// ComputeID — Standalone Offline Verifier (OPAQUE diligence deliverable) +// ComputeID — Standalone Offline Verifier // // Reads a saved evidence bundle (the exact JSON response from // GET /v1/agents/:id/verify) and INDEPENDENTLY recomputes every @@ -7,7 +7,7 @@ // present in the bundle. Runs with ZERO network calls once the // evidence file exists. // -// FIXED (per Imran Siddique / OPAQUE Systems review of PR #176): +// FIXED (per maintainer review of PR #176): // classical_signature_valid and ml_dsa_signature_valid previously read // the service's own claimed signature_valid/pq_signature_valid fields // rather than independently recomputing the signatures. That meant the diff --git a/integrations/computeid-agentpassport-trace/verify-audit-chain.js b/integrations/computeid-agentpassport-trace/verify-audit-chain.js index ac40b6d..1fab4c3 100644 --- a/integrations/computeid-agentpassport-trace/verify-audit-chain.js +++ b/integrations/computeid-agentpassport-trace/verify-audit-chain.js @@ -1,5 +1,5 @@ #!/usr/bin/env node -// ComputeID — Audit Hash-Chain Integrity Verifier (OPAQUE diligence deliverable) +// ComputeID — Audit Hash-Chain Integrity Verifier // // Walks the ENTIRE mcp_audit_log table in order and independently recomputes // each entry's hash, confirming the chain has not been tampered with or had diff --git a/integrations/langchain/test_langchain_to_trace.py b/integrations/langchain/test_langchain_to_trace.py index 0c8b5dc..9f30ba3 100644 --- a/integrations/langchain/test_langchain_to_trace.py +++ b/integrations/langchain/test_langchain_to_trace.py @@ -71,9 +71,9 @@ def test_model_is_read_from_invocation_params() -> None: def test_caller_can_override_a_guessed_provider() -> None: """The class-name mapping is best effort and must never win over a caller.""" record = _handler_with_two_tools().build_record( - **_kwargs(), model_provider="bedrock", model_id="claude-3-5-sonnet" + **_kwargs(), model_provider="example-hosting-provider", model_id="example-model" ) - assert record["model"] == {"provider": "bedrock", "model_id": "claude-3-5-sonnet"} + assert record["model"] == {"provider": "example-hosting-provider", "model_id": "example-model"} def test_end_without_start_is_recorded_not_dropped() -> None: @@ -228,7 +228,7 @@ def test_attestation_lifts_the_same_record_to_hardware() -> None: def test_no_tools_omits_the_transcript_block() -> None: """Absent is not the same as zero calls observed.""" h = TraceCallbackHandler() - record = h.build_record(**_kwargs(), model_provider="openai", model_id="gpt-4") + record = h.build_record(**_kwargs(), model_provider="example-provider", model_id="example-model") assert "tool_transcript" not in record @@ -239,8 +239,8 @@ def test_build_record_is_usable_without_the_handler() -> None: enforcement_mode="advisory", workload_digest=DIGEST, data_class="internal", - model_provider="openai", - model_id="gpt-4", + model_provider="example-provider", + model_id="example-model", transcript=b"[]", tool_count=0, ) diff --git a/integrations/openshell/README.md b/integrations/openshell/README.md index 97422ea..bd513c1 100644 --- a/integrations/openshell/README.md +++ b/integrations/openshell/README.md @@ -58,8 +58,8 @@ evidence = OpenShellEvidence( record = build_openshell_record( evidence, subject="spiffe://example.org/agent/codex", - model_provider="openai", - model_id="gpt-5", + model_provider="example-provider", + model_id="example-model", data_class="internal", workload_digest=image_digest, jwk=public_jwk, diff --git a/integrations/openshell/demo/build_signed_record.py b/integrations/openshell/demo/build_signed_record.py index f5c1573..a0334e8 100644 --- a/integrations/openshell/demo/build_signed_record.py +++ b/integrations/openshell/demo/build_signed_record.py @@ -32,8 +32,8 @@ def build_signed_demo_record() -> dict: unsigned = build_openshell_record( evidence, subject="spiffe://demo.agentrust.io/agent/support-bot", - model_provider="openai", - model_id="gpt-5", + model_provider="example-provider", + model_id="example-model", data_class="internal", workload_digest=WORKLOAD_DIGEST, jwk=jwk, diff --git a/integrations/openshell/demo/effective-policy.yaml b/integrations/openshell/demo/effective-policy.yaml index 35f37c7..c5193c2 100644 --- a/integrations/openshell/demo/effective-policy.yaml +++ b/integrations/openshell/demo/effective-policy.yaml @@ -5,5 +5,5 @@ filesystem_policy: network_policies: default: endpoints: - - host: api.openai.com + - host: api.example-provider.com port: 443 diff --git a/integrations/openshell/demo/openshell-ocsf.jsonl b/integrations/openshell/demo/openshell-ocsf.jsonl index a6b45e2..07709ba 100644 --- a/integrations/openshell/demo/openshell-ocsf.jsonl +++ b/integrations/openshell/demo/openshell-ocsf.jsonl @@ -1 +1 @@ -{"action":"Allowed","action_id":1,"activity":"Open","activity_id":1,"category_name":"Network Activity","category_uid":4,"class_name":"Network Activity","class_uid":4001,"container":{"image":{"name":"ghcr.io/nvidia/openshell-sandbox@sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"},"name":"support-bot","uid":"sandbox-abc123"},"dst_endpoint":{"domain":"api.openai.com","port":443},"firewall_rule":{"name":"default","type":"mechanistic"},"metadata":{"product":{"name":"OpenShell Sandbox Supervisor","vendor_name":"OpenShell","version":"0.0.105"},"profiles":["security_control","network_proxy","container"],"uid":"sandbox-abc123","version":"1.7.0"},"severity":"Informational","severity_id":1,"time":1786579200000,"type_name":"Network Activity: Open","type_uid":400101} +{"action":"Allowed","action_id":1,"activity":"Open","activity_id":1,"category_name":"Network Activity","category_uid":4,"class_name":"Network Activity","class_uid":4001,"container":{"image":{"name":"ghcr.io/nvidia/openshell-sandbox@sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"},"name":"support-bot","uid":"sandbox-abc123"},"dst_endpoint":{"domain":"api.example-provider.com","port":443},"firewall_rule":{"name":"default","type":"mechanistic"},"metadata":{"product":{"name":"OpenShell Sandbox Supervisor","vendor_name":"OpenShell","version":"0.0.105"},"profiles":["security_control","network_proxy","container"],"uid":"sandbox-abc123","version":"1.7.0"},"severity":"Informational","severity_id":1,"time":1786579200000,"type_name":"Network Activity: Open","type_uid":400101} diff --git a/integrations/otel-genai/test_otel_to_trace.py b/integrations/otel-genai/test_otel_to_trace.py index 4f06a5a..a4d3908 100644 --- a/integrations/otel-genai/test_otel_to_trace.py +++ b/integrations/otel-genai/test_otel_to_trace.py @@ -28,8 +28,8 @@ def span(op, **attrs): def chat_span(**over): a = { - "gen_ai.provider.name": "anthropic", - "gen_ai.request.model": "claude-sonnet-4-6", + "gen_ai.provider.name": "example-provider", + "gen_ai.request.model": "example-model", "gen_ai.conversation.id": "conv-1", } a.update(over) @@ -67,8 +67,8 @@ def test_record_validates_against_the_model() -> None: TrustRecord = pytest.importorskip("agentrust_trace.models").TrustRecord record = build([chat_span(), tool_span("search", "c1"), tool_span("pay", "c2")]) parsed = TrustRecord.model_validate(record) - assert parsed.model.provider == "anthropic" - assert parsed.model.model_id == "claude-sonnet-4-6" + assert parsed.model.provider == "example-provider" + assert parsed.model.model_id == "example-model" assert parsed.tool_transcript is not None assert parsed.tool_transcript.call_count == 2 @@ -93,13 +93,13 @@ def test_otlp_json_attribute_lists_are_accepted() -> None: "name": "chat", "attributes": [ {"key": "gen_ai.operation.name", "value": {"stringValue": "chat"}}, - {"key": "gen_ai.provider.name", "value": {"stringValue": "openai"}}, - {"key": "gen_ai.request.model", "value": {"stringValue": "gpt-4"}}, + {"key": "gen_ai.provider.name", "value": {"stringValue": "other-provider"}}, + {"key": "gen_ai.request.model", "value": {"stringValue": "other-model"}}, {"key": "gen_ai.conversation.id", "value": {"stringValue": "conv-9"}}, ], } record = build([otlp]) - assert record["model"]["provider"] == "openai" + assert record["model"]["provider"] == "other-provider" assert record["origin"]["source_event_id"] == "conv-9" @@ -146,12 +146,12 @@ def test_no_spans_is_refused() -> None: def test_missing_model_is_refused_not_guessed() -> None: """gen_ai.request.model is only Conditionally Required upstream.""" with pytest.raises(MissingEvidence, match="gen_ai.request.model"): - build([span("chat", **{"gen_ai.provider.name": "anthropic"})]) + build([span("chat", **{"gen_ai.provider.name": "example-provider"})]) def test_missing_provider_is_refused() -> None: with pytest.raises(MissingEvidence, match="gen_ai.provider.name"): - build([span("chat", **{"gen_ai.request.model": "gpt-4"})]) + build([span("chat", **{"gen_ai.request.model": "other-model"})]) def test_mixed_conversations_are_refused() -> None: @@ -173,6 +173,6 @@ def test_policy_bundle_is_still_required() -> None: def test_conversation_id_may_be_absent() -> None: """Conditionally Required upstream, so a record without one is still buildable.""" - record = build([span("chat", **{"gen_ai.provider.name": "anthropic", - "gen_ai.request.model": "gpt-4"})]) + record = build([span("chat", **{"gen_ai.provider.name": "example-provider", + "gen_ai.request.model": "other-model"})]) assert "source_event_id" not in record["origin"] diff --git a/noxfile.py b/noxfile.py index 8e4e120..6f8a66c 100644 --- a/noxfile.py +++ b/noxfile.py @@ -99,6 +99,7 @@ def wcm_integrations(session: nox.Session) -> None: Pinned to an exact release rather than a floor. These adapters are sensitive to what the published package actually exports, and 0.27.0 is the release that first published wcm.artifact_digest, runtime_records and memory_sweep. + The pin matches the version wcm-integrations-tests.yml installs (0.28.4). A silent upgrade should show up as a failing pin here, where the reason is written down, rather than as a behaviour change nobody attributed to a dependency. @@ -109,7 +110,7 @@ def wcm_integrations(session: nox.Session) -> None: than a fake. """ session.install( - "weight-custody-manifest==0.27.0", + "weight-custody-manifest==0.28.4", "agent-manifest>=0.11.1", "pytest>=8", "pyyaml", diff --git a/packages/agentrust-trace-adapters/README.md b/packages/agentrust-trace-adapters/README.md index 92d9792..d0b728c 100644 --- a/packages/agentrust-trace-adapters/README.md +++ b/packages/agentrust-trace-adapters/README.md @@ -58,8 +58,8 @@ record = build_record( source_event_id="evt-7f3a", ), subject="spiffe://example.org/agent/support-bot", - model_provider="anthropic", - model_id="claude-sonnet-4-6", + model_provider="example-provider", + model_id="example-model", # The policy bytes being bound into the evidence. Most control planes do not put # the bundle in their telemetry; that is not a reason to hash something else. policy=PolicyEvidence( @@ -106,8 +106,8 @@ evidence = OpenShellEvidence( record = build_openshell_record( evidence, subject="spiffe://example.org/agent/support-bot", - model_provider="anthropic", - model_id="claude-sonnet-4-6", + model_provider="example-provider", + model_id="example-model", data_class="internal", workload_digest="sha256:...", jwk=public_jwk, diff --git a/packages/agentrust-trace-adapters/tests/test_builder.py b/packages/agentrust-trace-adapters/tests/test_builder.py index c310888..7572bbb 100644 --- a/packages/agentrust-trace-adapters/tests/test_builder.py +++ b/packages/agentrust-trace-adapters/tests/test_builder.py @@ -27,8 +27,8 @@ def _kwargs(**overrides): base = dict( source=SourceSystem(producer="vendor-gateway/2.1", source_event_id="evt-1"), subject="spiffe://example.org/agent/imported", - model_provider="anthropic", - model_id="claude-sonnet-4-6", + model_provider="example-provider", + model_id="example-model", policy=PolicyEvidence(bundle=b'{"rules": []}', enforcement_mode="declared"), data_class="internal", jwk=JWK, diff --git a/packages/agentrust-trace-adapters/tests/test_openshell.py b/packages/agentrust-trace-adapters/tests/test_openshell.py index 7cc3c7d..dc68a9a 100644 --- a/packages/agentrust-trace-adapters/tests/test_openshell.py +++ b/packages/agentrust-trace-adapters/tests/test_openshell.py @@ -68,8 +68,8 @@ def build(ev: OpenShellEvidence | None = None) -> dict: return build_openshell_record( ev or evidence(), subject="spiffe://example.org/agent/codex", - model_provider="openai", - model_id="gpt-5", + model_provider="example-provider", + model_id="example-model", data_class="internal", workload_digest=WORKLOAD, jwk=JWK, diff --git a/packages/agentrust-trace-adapters/tests/test_untrusted_input.py b/packages/agentrust-trace-adapters/tests/test_untrusted_input.py index 9c7316c..b0a0ae8 100644 --- a/packages/agentrust-trace-adapters/tests/test_untrusted_input.py +++ b/packages/agentrust-trace-adapters/tests/test_untrusted_input.py @@ -95,7 +95,7 @@ def _record(**overrides) -> dict: values = dict( source=SourceSystem(producer="vendor-gateway/2.1"), subject="spiffe://example.org/agent/imported", - model_provider="anthropic", + model_provider="example-provider", model_id="m", policy=PolicyEvidence(bundle=b"policy", enforcement_mode="declared"), data_class="internal",