Python: Isolate provider-owned state in agent tools - #8853
Roger Barreto (rogerbarreto) wants to merge 3 commits into
Conversation
Keep provider-owned state with its agent or client while retaining shared application state.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Nested delegation can still copy and mutate provider-owned state declared only by the parent, and the README references a nonexistent public class.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Isolates provider-owned continuation state during delegated agent-tool invocations while preserving application state.
Changes:
- Combines child agent and client service-state declarations.
- Adds Foundry declarations, tests, and documentation.
- Verifies sequential delegated-call isolation.
| File | Description |
|---|---|
python/packages/core/agent_framework/_agents.py |
Filters provider-owned delegated state. |
python/packages/core/tests/core/test_agents.py |
Tests state isolation and propagation. |
python/packages/core/AGENTS.md |
Documents the provider-state contract. |
python/packages/foundry/agent_framework_foundry/_agent.py |
Declares Foundry-owned state keys. |
python/packages/foundry/tests/foundry/test_foundry_agent.py |
Tests Foundry delegated isolation. |
python/packages/foundry/README.md |
Documents delegated session behavior. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
Code Coverage OverviewLanguages: Python Python / code-coverage/pythonThe overall line coverage in commit 32a3541 in the Show a line coverage summary of the most covered files.
Updated |
There was a problem hiding this comment.
MAF Automated Review — Iteration 1
Result: Findings reported
Scope: full PR (1 commit(s)): 79bd4f9412f0
Model: gpt-5.6-sol-fast
Overview
The PR combines agent- and client-declared service-state keys and filters them in both directions while preserving ordinary application state, with focused core and Foundry regression coverage. Fresh child sessions, merge exclusions, and Foundry's inherited declarations provide strong protection when parent and child use the same provider key. One residual gap remains for heterogeneous delegation: exclusions are derived only from the child, so a parent provider's protected key can still cross the boundary.
Reviewed the supplied pull-request change set across correctness, security/reliability, architecture, and failure behavior.
1 verified finding remained after source verification (1 medium) across 1 file. Details are attached to the affected lines below.
Affected areas: python/packages/core/agent_framework/_agents.py
Include the invoking agent and client declarations in delegated state filtering so providers with different keys retain their own state.


Motivation & Context
Agent tools should share application-owned state when requested while keeping provider-owned continuation state scoped to each delegated invocation.
Description & Review Guide
service_session_state_keysdeclarations when copying and merging delegated state. Carry parent declarations through private function-invocation metadata. Declare the Foundry client's service-owned keys alongside the existing agent declaration. Add sequential child-call and distinct parent/child declaration coverage and document the behavior.as_tool(propagate_session=True)continues to propagate ordinary application state while keeping service continuation handles local to their owning invocation. The behavior applies toRawFoundryAgent,FoundryAgent, andAgentconfigured with aRawFoundryAgentChatClient.Related Issue
N/A.
Contribution Checklist
breaking changelabel (or add "[BREAKING]" to the title prefix, before or after any language prefix) — a workflow keeps the label and title prefix in sync automatically.