fix: preserve original behavior - always call PolicyResolver

Remove early return when applied_policy_names is empty to preserve
original behavior where PolicyResolver.resolve_guardrails_for_context()
is always called. The resolver does its own independent matching and
inheritance resolution, which can apply guardrails from parent policies
even when child policies fail their conditions.

This ensures no guardrails are silently dropped due to the refactoring.

Addresses Greptile review feedback on behavioral change.
This commit is contained in:
Julio Quinteros Pro 2026-02-14 14:41:23 -03:00
parent 9e0af32d46
commit 0f0b7a3f50

View file

@ -1704,15 +1704,12 @@ def add_guardrails_from_policy_engine(
f"key_alias={context.key_alias}, model={context.model}, tags={context.tags}"
)
# Match and track policies
applied_policy_names, _ = _match_and_track_policies(
data, context, request_body_policies
)
if not applied_policy_names:
return
# Match and track policies (may be empty, but resolution still happens)
_match_and_track_policies(data, context, request_body_policies)
# Apply resolved guardrails to metadata
# Note: PolicyResolver does its own independent matching and inheritance resolution,
# so we always call it even if applied_policy_names is empty
_apply_resolved_guardrails_to_metadata(data, metadata_variable_name, context)