Releases: OpenBox-AI/openbox-temporal-sdk-python
Release list
v2.0.0
v1.4.0
Changes
- Modules:
retryable_block.py→patch.py;retry_coordinator.py→patch_coordinator.py RetryableBlockRequest→PatchRequest;RetryableBlockControl→PatchControl;RetryableBlockCoordinator→PatchCoordinator;max_retryable_block_restarts→max_patch_restarts; base importhandle_retryable_block→handle_patch
v1.3.0
-
Retryable BLOCK workflow restart. A governance
BLOCKcarrying a validretry_plan(withnew_input) restarts the workflow via Continue-As-New using the replacement input. Event-agnostic (WorkflowStarted/Completed/Failed, SignalReceived, ActivityStarted/Completed, Handoff, hook evaluations, approval polling), bounded bymax_retryable_block_restarts(default 3, min 1) with a durable per-chain memo counter; exceeding the bound raises non-retryableGovernanceRetryLimitExceeded. Plain BLOCK, HALT, expired approvals, and malformed plans preserve existing behavior. -
Workflow input capture in
WorkflowStarted. The event now carries the Temporal workflow arguments in the genericactivity_inputfield (stored/displayed like activity input). Outer argument list preserved verbatim (workflow(a, b)→[a, b]; single list arg stays nested; no args →[]). Version-gated by patch markeropenbox-workflow-start-input-v1so histories predating the change replay their originalsend_governance_eventpayload unchanged. -
openbox-sdk-pythondependency raised to>=1.1.0, installed from PyPI. Retryable-BLOCK restart needshandle_retryable_blockfrom base SDK 1.1.0; now that it is published, the temporary local editable source is removed.
v1.2.1
v1.2.0
Changed
- Depends on
openbox-sdk-python>=0.2.0(import packageopenbox_core) — the shared
base SDK owning contracts, the always-strict gate, identity/signing, the evaluate
client, context runtime, CoreSpanDatawire serialization, generic instrumentation,
and the conformance kit. The0.2.0floor adds Redis/MongoDB/urllib3/urllib
instrumentation in the base runtime so no hook coverage is lost in the flip. - Hook governance is now owned entirely by the base runtime. The worker/plugin
build and own anopenbox_coreruntime and callinstall_instrumentation();
HTTP/DB/file/function hooks, payload shape, evaluation, and enforcement all live in
openbox_core. LangGraph and Temporal now emit one identical flat hook interface. request_signingnow shims overopenbox_core.identity. Signed request bytes are
UNCHANGED — gated byte-for-byte by a golden fixture generated from the pre-migration
signer (tests/test_base_sdk_signing_parity.py).Verdict,GuardrailsCheckResult, andWorkflowEventTypere-export the shared
contracts;GovernanceVerdictResponsesubclasses the sharedEvaluationResult
(same public surface, plusfallback_used/diagnostics/raw/approval_expiration_time).- Workflow lifecycle events route through shared
EventEnvelopefactories
(sandbox-safe pure contracts; wire payloads unchanged). - Activity execution binds the shared
ActivityContextwith a guaranteed
try/finally reset — governance context can no longer leak when an activity raises.
Behavior changes (regression-gated)
- Approval decision precedence: approval poll responses parse via the shared
ApprovalResult;actionnow outranksverdictwhen both are present
(previously verdict-first), and a response with NEITHER field stays PENDING
(previously implicit ALLOW). Pinned bytests/test_approval_action_precedence.py.
Known behavior differences in the core runtime
- Completed-hook semantics: core completed hooks never raise to the caller —
stop verdicts mark FUTURE execution blocked (abort/halt flags). Some legacy
completed hooks could raise after the operation ran (HTTP response hook, file
close); raising post-hoc cannot undo the operation, so the core model drops it
by design. - Fail-closed shaping: core maps started-hook evaluation failures under
on_api_error="fail_closed"(and started-hook contract errors, always) to a
non-retryableGovernanceHaltvia the adapter — same terminal effect as
legacy's HALT-shapedGovernanceBlockedError, different exception chain. - Redaction point for
activity_input: the coreActivityContextreceives
the post-redaction input (what actually ran); the legacy buffer stored the
pre-redaction value. Core hook payloads therefore never leak redacted fields.
Added
openbox.governance_state.TemporalGovernanceState— run-scoped state carrying the
Temporal effects that must survive past a base hook callback: signal BLOCK/HALT
verdicts that fail the next activity, HITL pending-approval retry markers, and the
completed-hook stop bridge (completed BLOCK skips the duplicate completed event;
completed HALT reaches the terminate path). Consumed on every activity exit path.openbox.core_adapter—TemporalFrameworkAdapter(maps base-SDK verdicts to
nativeApplicationErrortypes and the retry-based HITL loop; REQUIRE_APPROVAL marks
the pending-approval retry marker and degrades to a non-retryable block when HITL is
disabled/skipped; completed BLOCK/HALT records run-scoped stop state with the resolved
ActivityContext), andcreate_core_runtime(...)which builds and owns the base
runtime the worker/plugin install.core_activity_scopeis the sole hook-context
bridge (guaranteed try/finally reset + trace registration).- Redis, MongoDB, urllib3, and urllib governance now flow through the base runtime.
- Gates: workflow-sandbox import-safety, base-SDK conformance suite driven by the
Temporal adapter, public-API compatibility suite, and a deterministic
llm_completionhook-parity test (flat interface via the Temporal runtime, no live
OpenAI credentials).
Removed
WorkflowSpanProcessor,WorkflowSpanBuffer, and thesetup_opentelemetry_for_governance
entry point (public exports). Governance instrumentation is installed by the base
runtime; there is no Temporal-local OpenTelemetry setup to call.- Temporal-local hook modules
otel_setup,hook_governance,http_governance_hooks,
db_governance_hooks,file_governance_hooks,span_processor, and the dead
context_propagationhelper (its ContextVar-to-executor propagation lives in the base
runtime). Their payload-shape/instrumentation coverage moved to the base SDK suite. openbox.tracing.tracednow wrapsopenbox_core.instrumentation.function.governed;
create_spanremains a plain span helper.
Fixed (legacy file instrumentation — pre-existing upstream)
- Runtime RecursionError under file instrumentation: governance evaluation
itself opens files (httpx/ssl, package-metadata scans via importlib_metadata/
zipp) — governing those opens re-evaluated recursively until RecursionError.
traced_open now (1) passes through any open performed on a thread already
inside file-governance work (re-entrancy guard) and (2) bypasses
interpreter-owned trees (venv, stdlib, site-packages — sys.prefix/base_prefix- sysconfig paths): those reads are Python machinery, not application data
access. Application paths (./.env, data files, temp files) remain governed.
Same guard mirrored in the base SDK's file instrumentation.
- sysconfig paths): those reads are Python machinery, not application data
Fixed (HTTP hook payloads — pre-existing upstream)
- Mangled method on httpx spans: OTel's httpx instrumentation passes the
method as BYTES;str(b"POST")shippedhttp_method: "b'POST'"on every
httpx started span. Methods now decode bytes-safely at all client paths. - Credential leak in governance payloads: raw request/response headers
(authorization,cookie,set-cookie,x-api-key, …) were sent to Core
verbatim — live API keys landed in Core logs. All header dicts are now
redacted at the span-data builder choke point. Same redaction added to the
base SDK instrumentation. Rotate any API keys that appeared in payloads.
v1.1.2
Security
openbox_api_keyis no longer written to workflow history. Credentials are now captured on the governance activity instance instead of flowing throughsend_governance_eventinputs. Rotate your key after upgrade if your namespace was shared - old histories still contain it.
New
- W3C trace propagation through Temporal headers is on by default.
traceparentflows from caller → workflow → activity, so upstream spans finally stitch to workflow spans in your tracing backend. Opt out with
enable_trace_propagation=False.
Fixes
WorkflowFailedreporting can no longer shadow the real workflow exception when governance isfail_closedand the API is down.- Governance error routing now matches
ApplicationError.typeinstead of substring-matchingstr(e)- no more false halts when a user error message contains a governance keyword. - Race fix on the lazy
httpxclient inhook_governance- eliminates connection-pool leaks under concurrent activities. Replayerin plugin integration tests now receives the plugin, validating interceptor replay-safety.print()in plugin/worker init replaced with module loggers.temporalio >= 1.23.0version-pin comments corrected.
Compat
No breaking public-API changes. New parameter enable_trace_propagation (default True) on OpenBoxPlugin and create_openbox_worker().
Full changelog: https://github.com/OpenBox-AI/openbox-temporal-sdk-python/blob/main/CHANGELOG.md
v1.1.1
v1.1.1 (2026-04-07)
Features
- OpenBoxPlugin — Drop-in SimplePlugin integration for Temporal Workers. Single-line setup: plugins=[OpenBoxPlugin(openbox_url=..., openbox_api_key=...)]. Includes sandbox passthrough, interceptors, OTel instrumentation, and send_governance_event activity auto-registration. (#7)
Fixes
- HTTP body truncation — Enforce max_body_size (default 64KB) on HTTP request/response bodies in governance spans. Prevents large LLM responses from bloating governance API payloads. (#8)
- File I/O spans — Remove raw file content (data field) from file governance spans. Only bytes_read/bytes_written metadata is sent. (#8)
- error_type sanitization — Sanitize error.cause.error_type in WorkflowFailed payloads to prevent serialized error objects from being sent as the type string. (#8)
Refactoring
- Reduce cognitive complexity across 6 modules: activity_interceptor.py, workflow_interceptor.py, activities.py, db_governance_hooks.py, otel_setup.py, tracing.py, verdict_handler.py
- Remove useless f-strings, redundant exception clauses, merge nested if statements
- Extract shared helpers for DB governance (_run_governed_query_sync/async), traced decorator, and error chain extraction
Dependencies
- Bump temporalio>=1.23.0 (SimplePlugin support)
- Bump Pygments 2.19.2 → 2.20.0 (ReDoS fix, CVSS 1.9) (#9)
Full Changelog: v1.1.0...v1.1.1