fix(subagent): inherit parent policy overrides in continuable children

A continuable background child (the default backgroundMode for both
delegation tools) never received the parent session's explicit
sandbox/approval overrides: materialization applied only child
composition, so a danger-full-access parent produced workspace-write
children whose every out-of-workspace operation raised an approval
prompt.

Move the one-shot driver's capture/append pair into the shared
child-agent module (captureDelegatedPolicyOverrides /
appendDelegatedPolicyOverrides) and call it from both paths:
startContinuable captures before its first await, only fresh
materialization appends the source-tagged events (after any fork seed),
and a cold resume replays the persisted delegation events instead of
re-capturing the parent.

Adds the continuable inheritance unit suite, the ACP snapshot scenario
subagent-continuable-inheritance (fails without the fix), the
continuable policy-inheritance Agent Note, and the seam-level README
contract, with bilingual counterparts.

Fixes #1692
This commit is contained in:
Hypatia May
2026-08-10 12:16:19 +08:00
parent abaf8f5061
commit 64e0fbfd6d
36 changed files with 1106 additions and 61 deletions
+15
View File
@@ -47,6 +47,9 @@ const SESSION_TITLE_CONFIG = fileURLToPath(new URL('../session-title.cordis.yml'
const SUBAGENT_DURABILITY_FAILURE_CONFIG = fileURLToPath(
new URL('../subagent-durability-failure.cordis.yml', import.meta.url),
)
const SUBAGENT_CONTINUABLE_INHERITANCE_CONFIG = fileURLToPath(
new URL('../subagent-continuable-inheritance.cordis.yml', import.meta.url),
)
const LSP_CONFIG = fileURLToPath(new URL('./lsp.cordis.yml', import.meta.url))
const WEB_CONFIG = fileURLToPath(new URL('../web.cordis.yml', import.meta.url))
const FS_SEARCH_CONFIG = fileURLToPath(new URL('./fs-search.cordis.yml', import.meta.url))
@@ -315,6 +318,18 @@ const SCENARIOS: Scenario[] = [
pinsChildToolSchemas: [1],
configPath: SUBAGENT_DURABILITY_FAILURE_CONFIG,
},
// Authored policy-inheritance transcript: the root session is switched to
// read-only at creation (the UI Access switch equivalent), and the
// continuable background child's log carries that override as a
// `sandbox/mode` `source: 'delegation'` event, so the child's runtime
// context states the inherited policy instead of the deployment default.
{
name: 'subagent-continuable-inheritance',
hasModelTurn: true,
recorded: false,
pinsChildToolSchemas: [1],
configPath: SUBAGENT_CONTINUABLE_INHERITANCE_CONFIG,
},
// The in-process child is published before its first follow-up fails. The
// foreground tool retains both that run-result failure and an independent
// published-handle disposal failure.