Repository navigation
[AAASM-6155] 🐛 core(assembly): Keep an sdk-only register failure non-fatal - #343
Merged
Chisanan232 merged 3 commits intoSep 22, 2026
Merged
Conversation
`_register_agent_with_gateway` decided whether a failed `register` aborts init from `enforcement_mode` alone, so once that guard became `_local_posture_is_enforce` an unset `enforcement_mode` of None fail-closed in every mode — including `sdk-only`, the one mode documented as the in-process-only layer that starts no sidecar and needs no gateway. The documented offline path therefore raised ConfigurationError instead of warning. Thread `mode` through and gate on `_register_failure_is_fatal`: an explicit `enforce` still aborts in every mode, and every mode other than `sdk-only` keeps the AAASM-4130 posture for the None default. Governed tool calls are untouched — the interceptor still denies under enforce when no authoritative decision is available. refs AAASM-6155 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Adds the AAASM-6155 regression: sdk-only with no enforcement_mode warns and comes up, with auto/proxy/ebpf as the controls that must still fail closed so the case cannot pass by the guard being removed. Also asserts the relaxed init still denies a governed tool call, and pins all 16 mode x enforcement_mode cells of `_register_failure_is_fatal`. refs AAASM-6155 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The page calls the two knobs independent. A failed agent registration is the one place they are not, so state which mode warns, which fails init closed, and what stays true in both cases. refs AAASM-6155 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Chisanan232
deleted the
v0.0.1/AAASM-6155/fix/sdk_only_registration_posture
branch
September 22, 2026 14:18
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



What changed
_register_agent_with_gatewaynow receivesmodeand decides whether a failedregisteraborts init via a new
_register_failure_is_fatal(mode=..., enforcement_mode=...):modeenforcement_moderegistersdk-onlyNone)sdk-onlyenforceauto/proxy/ebpfNone)observe/disabledOne cell of that matrix changes. Everything else is exactly what
mainalready did.Why it changed
init_assembly(mode="sdk-only")with noenforcement_moderaised on a gateway it could notregister with:
The guard was
_local_posture_is_enforce(enforcement_mode), which returnsTrueforNone. Thathelper is deliberate and correct under AAASM-4130 —
Noneregisters under the gateway'sserver-side default of live
enforce, so the SDK's own error posture must match. What wasunintended is its interaction with
mode:_register_agent_with_gatewaynever receivedmode, sothe one mode whose documented purpose is to run without a gateway became the mode that
hard-failed without one.
sdk-onlyis documented in this repo as the in-process-only layer that starts no network sidecarand is "the best choice for deterministic, offline examples and tests", and
docs/quick-start.mdstates the offline path warns that the agent is unregistered. The raise contradicted both.
This does not let an
sdk-onlysession run ungovernedOnly whether
init_assembly()raises changes. In the warn case:_warn_agent_unregisteredstderr warning is unconditional (loggingconfig cannot silence it);AssemblyContext.registeredreportsFalse;unreachable runtime or an unauthoritative
query_policystill denies the tool call(AAASM-3106, AAASM-4760).
test_sdk_only_register_failure_still_denies_governed_tool_callsasserts that last point directly.How to verify
Unit tests
test/unit/core/test_init_registration.pygains 21 cases:test_sdk_only_default_posture_warns_on_register_failure— the defect itself.test_non_sdk_only_default_posture_still_propagates_register_failure[auto|proxy|ebpf]— thecontrols. Without them the case above would also pass if the guard had simply been deleted.
test_sdk_only_register_failure_still_denies_governed_tool_calls— the relaxation does not reachthe tool-call path.
test_register_failure_fatality_matrix— all 16mode×enforcement_modecells.Result, run locally over the whole unit suite:
Against the same interpreter on unmodified
mainthe suite is1350 passed, 4 skipped— thedelta is exactly the 21 new cases, and nothing regressed.
The new tests fail without the source change. Reverting only
agent_assembly/core/assembly.pyand re-running the four new test functions gives
18 failed, 3 passed: the 16 matrix cells and thetwo
sdk-onlybehavioural tests go red, while the three non-sdk-onlycontrols stay green — whichis the discrimination the controls exist to provide.
Linux behavioural verification
The defect does not reproduce on macOS:
connect_runtime_client()returnsNonethere, so_register_agent_with_gatewaytakes its early warn-and-return path and the changed guard is neverreached. All runs below are in
python:3.12-slimwith nothing listening on the gateway port, on thereleased
0.0.1rc7wheel (so the native extension is the real one), with this commit's four-linesemantic change applied to the installed
core/assembly.py. Each replacement was asserted uniquebefore writing, and the patched file was re-read to confirm the old guard is gone.
Preconditions were printed in every run and were identical throughout —
native_core_available=True,connect_runtime_client=OBJECT— so only the code under test differs:modeenforcement_modesdk-onlyRAISED ConfigurationError: ... gateway gRPC endpoint is unreachable for registrationsdk-onlyOK network_mode=sdk-only registered=False, preceded by the AAASM-4547 warningautoRAISED ConfigurationErrorsdk-onlyenforceRAISED ConfigurationErrorproxyRAISED ConfigurationErrorA→B is the fix. C, D and E are the controls that show it is scoped to one cell.
Lint / types
ruff check .— all checks passed.ruff format --check .— 204 files already formatted.mypy agent_assembly— 5 errors, allagent_assembly._coreimport-not-foundplus missinggrpcstubs, i.e. the native extension not being built in the local venv. Unmodifiedmainproduces the same 5 under the same interpreter.
core/assembly.pyalone type-checks clean.Local caveat, stated rather than hidden:
uv syncfor thetestgroup could not complete againstthe configured registry on this workstation, so the suite was run with an interpreter from a sibling
checkout of this repo rather than a freshly locked env. CI runs the canonical environment.
Scope
Consumers are not unblocked by this change alone. The 16 Python examples in
ai-agent-assembly/examplesalso monkey-patch the private_register_adapters, whose return shapebecame a 2-tuple in rc.7, so with this fix applied their smoke test moves from the registration
error to
not enough values to unpack (expected 2, got 0). Verified in the same container, andtracked separately — it is a stale mock of a private helper, not an SDK contract, and the examples'
assertions do not change.
Closes AAASM-6155
External evidence is text only, per this workstation's data-handling policy.