Skip to content

Python: Isolate provider-owned state in agent tools - #8853

Draft
Roger Barreto (rogerbarreto) wants to merge 3 commits into
mainfrom
i800r539-session-state-isolation
Draft

Roger Barreto (rogerbarreto) wants to merge 3 commits into
mainfrom
i800r539-session-state-isolation

Conversation

@rogerbarreto

@rogerbarreto Roger Barreto (rogerbarreto) commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Motivation & Context

Agent tools should share application-owned state when requested while keeping provider-owned continuation state scoped to each delegated invocation.

Description & Review Guide

  • What are the major changes? Combine the parent and child agents' and clients' service_session_state_keys declarations when copying and merging delegated state. Carry parent declarations through private function-invocation metadata. Declare the Foundry client's service-owned keys alongside the existing agent declaration. Add sequential child-call and distinct parent/child declaration coverage and document the behavior.
  • What is the impact of these changes? as_tool(propagate_session=True) continues to propagate ordinary application state while keeping service continuation handles local to their owning invocation. The behavior applies to RawFoundryAgent, FoundryAgent, and Agent configured with a RawFoundryAgentChatClient.
  • What do you want reviewers to focus on? Bidirectional filtering, preservation of existing parent state, and consistent behavior across agent and client constructions. Local Windows/Python 3.11 checks cover both affected packages; the broader platform matrix is left to CI.

Related Issue

N/A.

Contribution Checklist

  • The code builds clean without any errors or warnings
  • All unit tests pass, and I have added new tests where possible
  • The PR follows the Contribution Guidelines
  • This PR is linked to an issue and there is no other open PR for this issue (see Related Issue above).
  • This is not a breaking change. If it is a breaking change, add the breaking change label (or add "[BREAKING]" to the title prefix, before or after any language prefix) — a workflow keeps the label and title prefix in sync automatically.

Keep provider-owned state with its agent or client while retaining shared application state.
Copilot AI balanced review requested due to automatic review settings September 29, 2026 15:37
@agent-framework-automation agent-framework-automation Bot added documentation Usage: [Issues, PRs], Target: documentation in the code base and learn docs python Usage: [Issues, PRs], Target: Python labels Sep 29, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Nested delegation can still copy and mutate provider-owned state declared only by the parent, and the README references a nonexistent public class.

Review effort: Balanced
Findings: 1 High severity · 1 Low severity

Open (2)
What changed in this PR

Isolates provider-owned continuation state during delegated agent-tool invocations while preserving application state.

Changes:

  • Combines child agent and client service-state declarations.
  • Adds Foundry declarations, tests, and documentation.
  • Verifies sequential delegated-call isolation.
File Description
python/​packages/​core/​agent_framework/​_agents.py Filters provider-owned delegated state.
python/​packages/​core/​tests/​core/​test_agents.py Tests state isolation and propagation.
python/​packages/​core/​AGENTS.md Documents the provider-state contract.
python/​packages/​foundry/​agent_framework_foundry/​_agent.py Declares Foundry-owned state keys.
python/​packages/​foundry/​tests/​foundry/​test_foundry_agent.py Tests Foundry delegated isolation.
python/​packages/​foundry/​README.md Documents delegated session behavior.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread python/packages/core/agent_framework/_agents.py
Comment thread python/packages/foundry/README.md Outdated
@github-code-quality

github-code-quality Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: Python

Python / code-coverage/python

The overall line coverage in commit 32a3541 in the i800r539-session-sta... branch is 92%. Line coverage data for the main branch is not yet available.

Show a line coverage summary of the most covered files.
File main i800r539-session-sta... 32a3541 +/-
packages/core/a...ework/_tools.py — 96% —
packages/core/a...ework/_types.py — 95% —
packages/core/a...work/_skills.py — 95% —
packages/openai..._chat_client.py — 94% —
packages/core/a.../_compaction.py — 94% —
packages/core/a...ork/_vectors.py — 93% —
packages/core/a...bservability.py — 93% —
packages/core/a...amework/_mcp.py — 92% —
packages/ag-ui/...i/_agent_run.py — 90% —
packages/core/a...ork/security.py — 89% —

Updated September 29, 2026 16:09 UTC

Comment thread python/packages/core/agent_framework/_agents.py Fixed

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

MAF Automated Review — Iteration 1

Result: Findings reported
Scope: full PR (1 commit(s)): 79bd4f9412f0
Model: gpt-5.6-sol-fast

Overview

The PR combines agent- and client-declared service-state keys and filters them in both directions while preserving ordinary application state, with focused core and Foundry regression coverage. Fresh child sessions, merge exclusions, and Foundry's inherited declarations provide strong protection when parent and child use the same provider key. One residual gap remains for heterogeneous delegation: exclusions are derived only from the child, so a parent provider's protected key can still cross the boundary.

Reviewed the supplied pull-request change set across correctness, security/reliability, architecture, and failure behavior.
1 verified finding remained after source verification (1 medium) across 1 file. Details are attached to the affected lines below.

Affected areas: python/packages/core/agent_framework/_agents.py

Comment thread python/packages/core/agent_framework/_agents.py
Include the invoking agent and client declarations in delegated state filtering so providers with different keys retain their own state.
Comment thread python/packages/core/agent_framework/_agents.py

This branch was successfully deployed

1 active deployment
github-app-auth — 32a3541e Deployed Sep 29, 2026 by rogerbarreto via add_label #24019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Usage: [Issues, PRs], Target: documentation in the code base and learn docs python Usage: [Issues, PRs], Target: Python

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants