Skip to content

Python: Fix input mutation in SerializationMixin.from_dict - #7901

Merged
Eduard van Valkenburg (eavanvalkenburg) merged 1 commit into
microsoft:mainfrom
Namraa310806:fix/serialization-input-mutation
Aug 27, 2026
Merged

Python: Fix input mutation in SerializationMixin.from_dict#7901
Eduard van Valkenburg (eavanvalkenburg) merged 1 commit into
microsoft:mainfrom
Namraa310806:fix/serialization-input-mutation

Conversation

@Namraa310806

Copy link
Copy Markdown
Contributor

Motivation & Context

SerializationMixin.from_dict() can unexpectedly mutate nested dictionaries in the caller-provided input when dictionary-shaped dependencies are merged during deserialization.

The method creates a shallow copy of the input dictionary, so nested dictionaries remain shared with the original input. The subsequent in-place .update() operations therefore modify the caller's input.

This can cause unexpected state to persist when the same serialized specification is reused across multiple from_dict() calls. In particular, dependency data injected during one reconstruction can leak into subsequent reconstructions.

This change fixes that behavior while preserving the existing dictionary dependency merge semantics and dependency precedence.

Description & Review Guide

  • What are the major changes?

    • Replaced the two in-place dictionary .update() operations in SerializationMixin.from_dict() with non-mutating dictionary merges.
    • Added regression tests covering both dictionary dependency merge paths.
    • Added coverage to verify that repeated from_dict() calls using the same input do not leak dependency state.
    • Added coverage to verify that existing dependency override/merge behavior is preserved.
  • What is the impact of these changes?

    • The caller-provided input dictionary is no longer modified by dictionary dependency merging.
    • Existing dictionary merge behavior remains unchanged, including dependency values overriding conflicting keys.
    • No public API or serialization format is changed.
    • This is a focused bug fix with no intended impact on unrelated serialization or dependency-injection behavior.
  • What do you want reviewers to focus on?

    • Whether the non-mutating dictionary merge is the appropriate way to preserve the existing dependency merge semantics.
    • Whether the regression tests adequately cover both dependency merge paths and prevent cross-call state leakage.

Related Issue

Fixes #7899

Contribution Checklist

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@agent-framework-automation agent-framework-automation Bot added the python Usage: [Issues, PRs], Target: Python label Aug 27, 2026
@github-actions github-actions Bot changed the title Fix input mutation in SerializationMixin.from_dict Python: Fix input mutation in SerializationMixin.from_dict Aug 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Python Test Coverage

Python Test Coverage Report •
FileStmtsMissCoverMissing
packages/core/agent_framework
   _serialization.py1761193%356–357, 562, 637, 640, 683–684, 688–689, 691, 693
TOTAL48227448390% 

Python Unit Test Overview

Tests Skipped Failures Errors Time
9764 36 💤 0 ❌ 0 🔥 2m 41s ⏱️

Mohammed Sanaullah (sanaullahmohammed) pushed a commit to sanaullahmohammed/NexusOps that referenced this pull request Sep 3, 2026
Updated
[Microsoft.Agents.AI](https://github.com/microsoft/agent-framework) from
1.19.0 to 1.20.0.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Agents.AI's
releases](https://github.com/microsoft/agent-framework/releases)._

## 1.20.0

## What's Changed
* .NET: Bump AWSSDK.Extensions.Bedrock.MEAI from 4.0.6.10 to 4.0.101.8
by @​dependabot[bot] in
microsoft/agent-framework#7829
* .NET: Stabilize Foundry recovery tests by @​rogerbarreto in
microsoft/agent-framework#7817
* .NET: fix: preserve Responses logprobs field by @​he-yufeng in
microsoft/agent-framework#5860
* .NET: Honor cancellation for Foundry-hosted workflow responses by
@​rogerbarreto with @​Copilot in
microsoft/agent-framework#7842
* .NET: Use Responses API for hosted web search in AG-UI by
@​rogerbarreto with @​Copilot in
microsoft/agent-framework#7843
* .NET: Bump Aspire.Hosting from 13.1.0 to 13.5.2 by @​dependabot[bot]
in microsoft/agent-framework#7826
* .NET: Suppress false positive Zip Slip alert by @​SergeyMenshykh in
microsoft/agent-framework#7858
* .NET: added Mem0Sharp integration for in-memory storage in agent
samples. by @​jihadkhawaja in
microsoft/agent-framework#7792
* .NET: Annotate DevUI aggregator static-analysis false positives by
@​SergeyMenshykh in
microsoft/agent-framework#7864
* .NET: Rename CommunityToolkit.VectorData.CosmosNoSql to AzureCosmosDB
by @​adamsitnik in
microsoft/agent-framework#7878
* .NET: chore: upgrades aspnet openapi dependency by @​baywet in
microsoft/agent-framework#7870
* .NET: Simplify A2A function tool samples by @​SergeyMenshykh in
microsoft/agent-framework#7861
* .NET: Bump Azure.AI.AgentServer.Invocations from 1.0.0-beta.5 to
1.0.0-beta.6 by @​dependabot[bot] in
microsoft/agent-framework#7886
* .NET: docs: updates the contributing information for CFS users by
@​baywet in microsoft/agent-framework#7869
* Bump CommunityToolkit.VectorData.InMemory from 1.0.0 to 1.0.1 by
@​dependabot[bot] in
microsoft/agent-framework#7888
* .NET: Remove retired OpenAI Assistants integration tests by
@​rogerbarreto in microsoft/agent-framework#7896
* .NET: Simplify A2A client-server sample by @​SergeyMenshykh in
microsoft/agent-framework#7891
* Bump Dapr.AI.Microsoft.Extensions from 1.18.4 to 1.18.5 by
@​dependabot[bot] in
microsoft/agent-framework#7889
* .NET: docs/workflow fileinput sample dotnet by @​baywet in
microsoft/agent-framework#7913
* .NET: Add timeout for wait-for-first-completion by @​westey-m in
microsoft/agent-framework#7911
* .NET: Fix duplicate Foundry AgentHost port binding by @​rogerbarreto
in microsoft/agent-framework#7932
* .NET: tests: removes dependency on fluent assersion because of
licensing concerns by @​baywet in
microsoft/agent-framework#7938
* .NET: docs(decisions): resolve duplicate ADR sequence numbers (0016,
0021, 0024) by @​jluocsa in
microsoft/agent-framework#6046
* .NET: Bump Azure.Core from 1.61.0 to 1.62.0 by @​dependabot[bot] in
microsoft/agent-framework#7954
* .NET: Improve Cosmos DB Emulator startup reliability by @​TheovanKraay
in microsoft/agent-framework#3932
* .NET: add public API analyzers by @​baywet in
microsoft/agent-framework#7935
* .NET: Update version for 1.20.0 release by @​SergeyMenshykh in
microsoft/agent-framework#7972

## New Contributors
* @​madanmishra1223 made their first contribution in
microsoft/agent-framework#7705
* @​YashvantHange made their first contribution in
microsoft/agent-framework#7850
* @​jihadkhawaja made their first contribution in
microsoft/agent-framework#7792
* @​adamsitnik made their first contribution in
microsoft/agent-framework#7878
* @​baywet made their first contribution in
microsoft/agent-framework#7870
* @​Namraa310806 made their first contribution in
microsoft/agent-framework#7901
* @​Sweetteabittersugar made their first contribution in
microsoft/agent-framework#7903
* @​shoemoney made their first contribution in
microsoft/agent-framework#7837
* @​jluocsa made their first contribution in
microsoft/agent-framework#6046

**Full Changelog**:
microsoft/agent-framework@dotnet-1.19.0...dotnet-1.20.0

Commits viewable in [compare
view](microsoft/agent-framework@dotnet-1.19.0...dotnet-1.20.0).
</details>

Updated
[Microsoft.Agents.AI.OpenAI](https://github.com/microsoft/agent-framework)
from 1.19.0 to 1.20.0.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Agents.AI.OpenAI's
releases](https://github.com/microsoft/agent-framework/releases)._

## 1.20.0

## What's Changed
* .NET: Bump AWSSDK.Extensions.Bedrock.MEAI from 4.0.6.10 to 4.0.101.8
by @​dependabot[bot] in
microsoft/agent-framework#7829
* .NET: Stabilize Foundry recovery tests by @​rogerbarreto in
microsoft/agent-framework#7817
* .NET: fix: preserve Responses logprobs field by @​he-yufeng in
microsoft/agent-framework#5860
* .NET: Honor cancellation for Foundry-hosted workflow responses by
@​rogerbarreto with @​Copilot in
microsoft/agent-framework#7842
* .NET: Use Responses API for hosted web search in AG-UI by
@​rogerbarreto with @​Copilot in
microsoft/agent-framework#7843
* .NET: Bump Aspire.Hosting from 13.1.0 to 13.5.2 by @​dependabot[bot]
in microsoft/agent-framework#7826
* .NET: Suppress false positive Zip Slip alert by @​SergeyMenshykh in
microsoft/agent-framework#7858
* .NET: added Mem0Sharp integration for in-memory storage in agent
samples. by @​jihadkhawaja in
microsoft/agent-framework#7792
* .NET: Annotate DevUI aggregator static-analysis false positives by
@​SergeyMenshykh in
microsoft/agent-framework#7864
* .NET: Rename CommunityToolkit.VectorData.CosmosNoSql to AzureCosmosDB
by @​adamsitnik in
microsoft/agent-framework#7878
* .NET: chore: upgrades aspnet openapi dependency by @​baywet in
microsoft/agent-framework#7870
* .NET: Simplify A2A function tool samples by @​SergeyMenshykh in
microsoft/agent-framework#7861
* .NET: Bump Azure.AI.AgentServer.Invocations from 1.0.0-beta.5 to
1.0.0-beta.6 by @​dependabot[bot] in
microsoft/agent-framework#7886
* .NET: docs: updates the contributing information for CFS users by
@​baywet in microsoft/agent-framework#7869
* Bump CommunityToolkit.VectorData.InMemory from 1.0.0 to 1.0.1 by
@​dependabot[bot] in
microsoft/agent-framework#7888
* .NET: Remove retired OpenAI Assistants integration tests by
@​rogerbarreto in microsoft/agent-framework#7896
* .NET: Simplify A2A client-server sample by @​SergeyMenshykh in
microsoft/agent-framework#7891
* Bump Dapr.AI.Microsoft.Extensions from 1.18.4 to 1.18.5 by
@​dependabot[bot] in
microsoft/agent-framework#7889
* .NET: docs/workflow fileinput sample dotnet by @​baywet in
microsoft/agent-framework#7913
* .NET: Add timeout for wait-for-first-completion by @​westey-m in
microsoft/agent-framework#7911
* .NET: Fix duplicate Foundry AgentHost port binding by @​rogerbarreto
in microsoft/agent-framework#7932
* .NET: tests: removes dependency on fluent assersion because of
licensing concerns by @​baywet in
microsoft/agent-framework#7938
* .NET: docs(decisions): resolve duplicate ADR sequence numbers (0016,
0021, 0024) by @​jluocsa in
microsoft/agent-framework#6046
* .NET: Bump Azure.Core from 1.61.0 to 1.62.0 by @​dependabot[bot] in
microsoft/agent-framework#7954
* .NET: Improve Cosmos DB Emulator startup reliability by @​TheovanKraay
in microsoft/agent-framework#3932
* .NET: add public API analyzers by @​baywet in
microsoft/agent-framework#7935
* .NET: Update version for 1.20.0 release by @​SergeyMenshykh in
microsoft/agent-framework#7972

## New Contributors
* @​madanmishra1223 made their first contribution in
microsoft/agent-framework#7705
* @​YashvantHange made their first contribution in
microsoft/agent-framework#7850
* @​jihadkhawaja made their first contribution in
microsoft/agent-framework#7792
* @​adamsitnik made their first contribution in
microsoft/agent-framework#7878
* @​baywet made their first contribution in
microsoft/agent-framework#7870
* @​Namraa310806 made their first contribution in
microsoft/agent-framework#7901
* @​Sweetteabittersugar made their first contribution in
microsoft/agent-framework#7903
* @​shoemoney made their first contribution in
microsoft/agent-framework#7837
* @​jluocsa made their first contribution in
microsoft/agent-framework#6046

**Full Changelog**:
microsoft/agent-framework@dotnet-1.19.0...dotnet-1.20.0

Commits viewable in [compare
view](microsoft/agent-framework@dotnet-1.19.0...dotnet-1.20.0).
</details>

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

python Usage: [Issues, PRs], Target: Python

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Python: [Bug]: SerializationMixin.from_dict() mutates caller input when merging dictionary dependencies

3 participants