Skip to content

sdk: a caller's label requirement is met by any one pair, as in sam-node - #514

Merged
aojea merged 1 commit into
google:mainfrom
aojea:fix/sdk-required-labels-any-of
Sep 26, 2026
Merged

aojea merged 1 commit into
google:mainfrom
aojea:fix/sdk-required-labels-any-of

Conversation

@aojea

@aojea aojea commented Sep 26, 2026

Copy link
Copy Markdown
Collaborator

Fixes #508. Reported by @HosniBelfeki, with the proof from internal/node/labels_gate_test.go.

What was wrong

sam-node renders X-Sam-Required-Labels and call_remote_tool's required_labels as check if label(k1, v1) or label(k2, v2) (api.LabelCheck): a requirement of several pairs is met by any one of them. The JS and Python SDKs required every pair, so the same call succeeded through a sam-node and was refused by an SDK.

Change

  • sdk/js/src/mcp.ts requireLabels and sdk/python/src/agent_mesh/mcp_client.py require_labels apply the any-of rule sam-node applies; the refusal says the provider "carries none of the required labels". Unit tests carry the labels_gate_test.go matrix in both languages.
  • The operator's egress floor (egress.require_labels, api.LabelFloorCheck) is the conjunction and stays sam-node's alone; the SDKs have no floor.
  • sdk/README.md and the Native SDKs guide state the rule.

Interoperability test

TestNativeSDKsMesh gained a required-labels matrix run through all three implementations against control-plane-attested credentials. The sam-node and every SDK member attest the same labels (the policy grants region=*, team=*); the four cases of labels_gate_test.go are then run

  • from each SDK against the sam-node over /sam/mcp/1.0.0 (tools with required_labels), and
  • from the sam-node against each SDK agent through the egress proxy's X-Sam-Required-Labels, expecting 200 or 403.

With the previous predicates the SDK legs fail on "any-of requirement matches one key" while the Go leg passes; with this change all three agree.

The conformance runners take SAM_SDK_LABELS at enrollment and required_labels on tools/call for this.

Validation: npm test (66), pytest (79), TestNativeSDKsMesh, hack/verify-sdk-generated.sh, go vet.

sam-node renders X-Sam-Required-Labels and call_remote_tool's
required_labels as `check if label(k1, v1) or label(k2, v2)`
(api.LabelCheck), so a requirement of several pairs is met by any one of
them. The JS and Python SDKs required every pair, so the same call
succeeded through a sam-node and was refused by an SDK. The SDKs now
apply the any-of rule; the operator's egress floor stays the
conjunction and sam-node's alone.

TestNativeSDKsMesh runs the labels_gate_test.go matrix through all three
implementations against control-plane-attested credentials: each SDK
requiring labels of the sam-node over /sam/mcp/1.0.0, and the sam-node
requiring labels of each SDK agent through X-Sam-Required-Labels. With
the previous predicate the SDK legs fail on the "any-of requirement
matches one key" case while the Go leg passes.

Reported-by: Hosni Belfeki <https://github.com/HosniBelfeki>
Fixes google#508

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request implements caller-side label requirements for MCP sessions across the JavaScript and Python SDKs. It updates the label matching logic to support an 'any-of' requirement, where a set of label pairs is satisfied if at least one pair matches the provider's credential. The changes include updates to the command interfaces, protocol handling, and the addition of comprehensive integration tests in tests/integration/sdk_mesh_test.go to verify the label matching matrix across different implementations. I have no feedback to provide.

@aojea
aojea merged commit 5bb6c83 into google:main Sep 26, 2026
21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sdk: caller-side label requirements are all-of in the SDKs, any-of in sam-node

1 participant