Commit Graph

12 Commits

Author SHA1 Message Date
roboomp a0b7ca6708 docs: clarify bash.patterns gates bash tool only, not eval
bash.patterns only feeds the bash tool's approval decision. The eval
tool declares the exec tier and can spawn a shell via subprocess, so a
deny rule there does nothing for the same command run through eval;
under yolo the exec call resolves to allow. Note the scope and point at
tools.approval.eval as the lever that closes the path in
bash-tool-runtime.md, approval-mode.md, and settings.md.

Fixes #8838
2026-08-19 08:46:21 +00:00
can1357 ebd5e3f86f chore: update stale docs 2026-08-03 16:39:23 +02:00
can1357 7c3b24ddf2 feat: implemented cross-platform window discovery and targeting capabilities
- Added window discovery, targeting, and frame validation for macOS, Windows, and Linux platforms.
- Updated computer tool and protocol definitions to support listing and targeting specific application windows.
- Refactored native computer tool exposure to function-only representation across models.
- Updated documentation and test suites to reflect window-scoped computer control capabilities.
2026-08-02 17:35:29 +02:00
usr-bin-roygbiv b9504f65e7 feat: add native Codex computer use 2026-07-24 01:40:04 +00:00
roboomp 88c883c64a docs(coding-agent): documented acp approval mode
Added ACP-specific approval-mode guidance covering config inheritance, yolo launch flags, client permission handling, and headless prompt behavior.

Fixes #2900
2026-06-17 18:47:53 +00:00
can1357 d5b3c78132 chore: update docs 2026-06-17 04:37:39 +02:00
can1357 1dba122c53 chore: updated docs 2026-05-31 04:36:14 +02:00
can1357 535f7cfa89 fix(coding-agent/tools): reworked yolo approval resolution to honor user tool policies
- In `resolveApproval`, yolo mode now returns the user policy directly (`allow`/`prompt`/`deny`) and ignores tool `override` prompts.
- Updated approval-mode and approval unit tests to match the new behavior for critical bash patterns under yolo and auto-approve.
- Updated docs and settings metadata to describe yolo as user-policy-driven rather than override-driven.
2026-05-27 00:21:33 +02:00
can1357 e4a16451ec feat(coding-agent): added coding-agent approval types and mode options
- Added `ToolTier`, `ToolApproval`, and `ToolApprovalDecision` types and exported approval APIs.
- Updated approval-mode options from `auto|prompt|custom` to `always-ask|write|yolo` and defaulted mode to `yolo`.
- Changed approval resolution to apply per-tool decisions first, then mode-tier limits, with legacy-mode migration.
- Assigned read/write/exec `approval` and approval-detail prompts across built-in, custom, extension, and MCP tools.
2026-05-26 21:52:16 +02:00
oldschoola f5273eee6f fix(coding-agent): address PR #1378 review findings
- Decouple the per-tool approval gate from extension presence. ExtensionRunner
  and the ExtensionToolWrapper that hosts the gate are now constructed
  unconditionally in createAgentSession. Previously the runner was only built
  when extensionsResult.extensions.length > 0, so the entire approval system
  silently disappeared for sessions with no extensions loaded — any
  tools.approvalMode: prompt|custom setting was a no-op without feedback.
  Today this hole was masked by createAutoresearchExtension always being
  pushed inline; the unconditional construction makes the safety invariant
  explicit, and a new regression test in approval-mode.test.ts pins it.

- Extend CRITICAL_BASH_PATTERNS to cover remote-fetch-then-execute shapes
  that the original `bash <(curl …)` regex missed:
  - `source <(curl …)` / `. <(curl …)` (anchored at command boundary so
    `find . -name foo` doesn't false-positive)
  - `eval "$(curl …)"` / `eval $(curl …)` / `eval `curl …``
  Also adds `chmod -R` symbolic-mode forms (`u+x`, `u+rwx,o+w …`) targeting
  filesystem root, and `tee` / `tee -a` writes to /etc/{passwd,shadow,sudoers}
  (the standard way to write root-owned files without redirect). Benign
  forms (`source ./local.sh`, `chmod -R u+x ./build`, `tee /var/log/app.log`,
  `eval "$VAR"`) are pinned negative in the test suite.

- Extend formatApprovalPrompt with payload previews for the destructive tools
  that previously rendered as bare `Allow tool: <name>`: eval (language +
  first cell's code), task (agent + first task's id + assignment), ast_edit
  (first op's pattern / replacement / paths), browser (action + tab + url +
  code), and write content (alongside path). For `task` in particular this
  closes the gap that docs/approval-mode.md's "parent's approval covers the
  subagent" claim was waving at — the prompt now actually shows what's being
  delegated.

- Tighten isMcpToolName: drop the fallback `|| toolName.includes("__")` so
  an extension tool legally named `my__feature` or `pkg__util__do` is no
  longer falsely labelled `Origin: MCP server tool` in the approval prompt.
  Strict `mcp__` prefix only.

- Revert the cargo-cult `{ autoApprove: true } as AgentToolContext` insertions
  in agent-session-python-cleanup.test.ts and sdk-move-cwd.test.ts. The tests
  create sessions without passing settings, so the wrapper falls through to
  approvalMode "auto" automatically; the explicit flag was unnecessary and
  the `as AgentToolContext` cast hid that autoApprove lives on
  CustomToolContext, not AgentToolContext.

- Document in commands/launch.ts the dual --auto-approve declaration (oclif
  Flags for --help, manual parseArgs for runtime) so a future rename catches
  both call sites.

- Promote the subagent caveat in docs/approval-mode.md to a callout near the
  top: anything `task` is asked to do runs unattended once the parent task
  call is approved.

Verification:
- bun test packages/coding-agent/test/tools/approval.test.ts → 75 pass / 0 fail
  (was 57; +18 cases covering new remote-exec patterns, chmod symbolic, tee
  /etc, isMcp negative, and eval/task/ast_edit/browser/write payload previews)
- bun test packages/coding-agent/test/tools/approval-mode.test.ts → 7 pass /
  0 fail (was 7; +1 case asserting extensionRunner is always constructed)
- bun tsc --noEmit -p packages/coding-agent → clean
- bun x biome check . → clean
- Windows EBUSY tempdir-cleanup noise in agent-session-python-cleanup and
  sdk-move-cwd is pre-existing on this branch (already documented in the
  PR body) and absent on Linux CI.
2026-05-26 20:53:35 +02:00
oldschoola 384f429461 fix(coding-agent): tighten approval edge cases and rewrite mode docs
- approval: user 'tool: deny' now wins over critical-pattern override
  (the override only tightens allow->prompt; it must never re-arm a denied tool).
- approval: rename hindsight policy keys to match registered tool names
  (recall/retain/reflect, not hindsight_recall/hindsight_retain).
- approval: head+tail truncation for bash/ssh command prompts so a
  destructive suffix buried after a long benign preamble stays visible.
- task/executor: force tools.approvalMode='auto' in createSubagentSettings
  so subagents (which have no UI) cannot deadlock on per-tool prompts;
  the parent's approval of the task call is the authorization.
- docs/approval-mode: rewrite so every example surfaces tools.approvalMode
  and explains that tools.approval is ignored outside 'custom' mode.
2026-05-26 20:53:35 +02:00
oldschoola 4d26453a0b feat(coding-agent): restore per-tool approval policies with safer defaults
Re-introduces the per-tool approval system from luzidd's commit 39124f3 (which
is no longer reachable from main) and improves it before re-landing.

What's restored:
- ApprovalPolicy (allow/deny/prompt) plus DEFAULT_APPROVAL_POLICIES.
- ACTION_EXCEPTIONS registry (LSP read-only, bash critical patterns).
- getApprovalPolicy() six-level resolution order.
- ExtensionToolWrapper.execute() gate before extension handlers.
- --auto-approve / --yolo CLI flag and tools.approval.<tool> user config.
- docs/approval-mode.md user guide.

What's improved over the original:
- Replaced unchecked 'as any' casts with typed unknown narrowing helpers.
- Validate userConfig values: invalid strings, numbers, etc. fall through to
  the built-in default instead of being silently honoured (typo no longer
  locks a tool out or grants implicit approval).
- Expanded CRITICAL_BASH_PATTERNS: chmod -R /, chown -R /, bash <(curl ...),
  writes to /etc/passwd|shadow|sudoers, shutdown/reboot/halt/init 0,
  kill -9 1, nc -e / nc -c reverse shells. Pattern shapes require a
  command-position boundary so 'npm run reboot-tests' and 'echo "shutdown the
  queue"' don't false-positive.
- Added DEBUG_READONLY_ACTIONS exception so DAP inspection actions (threads,
  stack_trace, variables, scopes, read_memory, …) auto-allow while
  execution-side actions (launch, attach, continue, evaluate, write_memory,
  set_breakpoint, …) still prompt.
- formatApprovalPrompt: labels mcp__<server>__<tool> calls as MCP server
  tools, surfaces ssh host + command, recognises the modern § hashline header
  for edit, and truncates >240-char fields so a heredoc-sized body cannot
  blow out the confirmation dialog.
- Test suite grown from 40 to 57 cases — new coverage for invalid user
  config, the extended critical-bash patterns, benign-keyword negatives,
  debug exceptions, MCP/ssh prompt formatting, and command truncation.

Verification:
- bun test packages/coding-agent/test/tools/approval.test.ts -> 57 pass
- bun x biome check . -> clean
- bun run check:ts across all 9 workspaces -> clean
2026-05-26 20:53:33 +02:00