agentrust-trace 0.11.0
Breaking
TraceAGTAdapterandTraceSandboxAdapterrequireenforcement_mode. They used to default toenforce, which signed a claim that a policy was evaluated when nothing evaluated it. Callers pass the mode their runtime ran under, ordeclaredwhen no engine evaluated the policy (#416, #419; diagnosis and first fix by @solloek369-arch in #417).- Signatures accept only canonical unpadded base64url, so one signature has one spelling. A padded or non-canonical signature that used to decode is refused (#418).
Added
verify_record()reports whether the objects a record cites resolve (#374).- Verifiers declare
accepted_profiles, andVerificationResultrecords the profile it verified under (#347, for #116). - The reproducibility claim and its re-execution appraisal in the schema and models, with 21 signed vectors (#364, #370).
condition-appraisalis a registeredreferencesrelation (#389).- MCP Server Provenance v2 binds behavioral hints (#409).
intent_bridgebinds a successor observation by digest (#340).provenance.verify_record()takesnowto replay a freshness decision (#411).
Fixed
- Schema patterns follow ECMA-262, so a trailing
\n,\r, U+2028 or U+2029 no longer passessubjector URI checks (#388). The Pydantic models share the same patterns (#412). - A malformed signature is reported as malformed, not missing (#390).
- Revocation bundles with no RFC 8785 form are
unverified_for_revocationrather than an exception (#386). - Non-ASCII challenge nonces raise the documented
ValueError(#383). - The AGT adapter no longer stamps
appraisal.status: affirmingon every record (#336), and both adapters checkiatbefore signing (#343). - The v0.3 draft schema refused neither a private
cnf.jwknor an RSA key with no key material (#372, #311). - Input validation across
content_marking,provenance,intent_bridge,revocation, the sandbox adapter andsign.verify_record()freshness bounds (#239, #282, #284, #287, #288, #290, #300, #305, #318, #322, #333, #334, #335, #339, #387, #410). - The PyPI description named
TrustRecord.sign(),record.anchor()andrecord.verify(), none of which exist. It now showssign_recordandverify_record(#309).
Full list in CHANGELOG.md.