Skip to content

fix(dapr-agents): rerun vs dapr-agents 1.0.5, chaining fix, real denial demo - #41

Open
StevenMih wants to merge 2 commits into
mainfrom
task/dapr-agents-demo-run
Open

fix(dapr-agents): rerun vs dapr-agents 1.0.5, chaining fix, real denial demo#41
StevenMih wants to merge 2 commits into
mainfrom
task/dapr-agents-demo-run

Conversation

@StevenMih

Copy link
Copy Markdown
Contributor

Summary

  • Rerun of the dapr_agents adapter demo against the current dapr-agents release (1.0.5; no dapr-agents 1.18 exists — see drift note).
  • @emitter.tool() gains an optional prior_capsule_id kwarg so a tool-call fyi capsule can chain onto a preceding decide capsule (previously only record_hitl() supported chaining).
  • examples/dapr-agents-capsule/demo.py extended to a real 3-capsule chain: fyi → decide (real HITL denial, verdict=blocked) → fyi (escalation), all anchored on the live public anchor and offline-verified.
  • docs/adapters/dapr_agents.md Limitations section updated: dapr-agents ≥1.0.x added a native before_tool_call/RequireApproval hook system (partially resolves L1); L2/L3/L5 confirmed still true, including in that new native flow.
  • pyproject.toml: dapr-agents extra floor bumped >=0.1>=1.0.

Full run transcript, permalinks, raw inclusion JSON, and drift findings: _work/dapr-demo-run/ (outside this repo, in the asg workspace _work/).

Test plan

  • pytest tests/ -q — 368 passed, 6 skipped (fresh venv, dapr-agents==1.0.5 installed)
  • ruff check clean
  • Live demo run: 3 capsules anchored on anchor.agentactioncapsule.org (leaves 237–239), each verify().ok and verify_receipt True
  • CI green on this PR

🤖 Generated with Claude Code

stevenmih and others added 2 commits July 30, 2026 18:07
…eal denial demo

Rerun of the dapr_agents adapter against the current dapr-agents release
(fresh venv; no dapr-agents 1.18 exists on PyPI — that pins the Dapr core
SDK, not the dapr-agents package; see the drift note in the doc for both).

- capsule_emit/adapters/dapr_agents.py: add prior_capsule_id to
  @emitter.tool() so a tool-call fyi capsule can chain onto a preceding
  decide capsule (previously only record_hitl() supported chaining) —
  needed for a real fyi -> decide(blocked) -> fyi chain.
- tests/test_dapr_agents.py: cover the new chaining path.
- examples/dapr-agents-capsule/demo.py: extend the demo to a real 3-capsule
  chain including a genuine HITL denial (verdict=blocked,
  effect.status=planned), anchored + inclusion-proven + offline-verified
  end to end.
- docs/adapters/dapr_agents.md: update Limitations (L1 partially resolved —
  dapr-agents >=1.0.x added a native before_tool_call/RequireApproval hook
  system; L2/L3/L5 confirmed still true, including in that new native flow)
  and record the version-naming + drift findings.
- pyproject.toml: bump the dapr-agents extra floor from >=0.1 to >=1.0.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: stevenmih <stevenmih88-3@gmail.com>
…in run

The committed transcript was stale relative to demo.py, which was updated
(2026-07-31) to script a 3-capsule chain with a real HITL denial but never
re-executed. Ran it live against anchor.agentactioncapsule.org: leaf 242
(fyi), leaf 243 (decide/REJECTED, blocked), leaf 244 (fyi escalation past
the denial). All three verified offline (agent_action_capsule.verify +
scitt_cose.verify_receipt) and confirmed via independent curl re-check.

Root cause of the first failed run: the globally registered capsule-emit
editable install pointed at a different, already-merged worktree lacking
the prior_capsule_id chaining parameter added in this worktree (db08e63).
Re-ran `pip install -e .` from this worktree to fix.

Also investigated the reported verify.agentactioncapsule.org auto-load-
fragment gap: confirmed via live test + source inspection of capsule.js
that fragment auto-load is currently wired and working correctly (not a
bug) — documented in the transcript with the finding and recommendation.

Signed-off-by: stevenmih <stevenmih88-3@gmail.com>
StevenMih added a commit that referenced this pull request Aug 6, 2026
)

The adapter-author half of the #22 commission; the normative half is the
Privacy Considerations section in action-state-group/agent-action-capsule#35
(merged as #41). On any conflict, the profile text wins — this page says so
up front.

One page: the three admission classes as a table (clear-safe handles /
digest-only payloads / never-enters identity+secrets, including as digests),
the binding-not-naming class test, allow-list-as-code with the ADK adapter's
_SAFE_CONTEXT_ATTRS tuple as the reference shape, the MCP adapter's
documented client-software-only session reach as the one deliberate
exception that proves the floor, and a five-question authoring checklist as
the pre-ship audit.

Original PR #26 (thisjody, fork context-hygiene branch) failed the
neutrality gate solely because fork PRs don't receive the NEUTRALITY_TERMS
secret by design. Rebased as this same-repo branch so the gate can actually
run. Author credit preserved — content is Jody's own, unchanged.

Signed-off-by: stevenmih <stevenmih88-3@gmail.com>
Co-authored-by: stevenmih <stevenmih88-3@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant