fix(subagent): inherit parent policy overrides in continuable children
A continuable background child (the default backgroundMode for both delegation tools) never received the parent session's explicit sandbox/approval overrides: materialization applied only child composition, so a danger-full-access parent produced workspace-write children whose every out-of-workspace operation raised an approval prompt. Move the one-shot driver's capture/append pair into the shared child-agent module (captureDelegatedPolicyOverrides / appendDelegatedPolicyOverrides) and call it from both paths: startContinuable captures before its first await, only fresh materialization appends the source-tagged events (after any fork seed), and a cold resume replays the persisted delegation events instead of re-capturing the parent. Adds the continuable inheritance unit suite, the ACP snapshot scenario subagent-continuable-inheritance (fails without the fix), the continuable policy-inheritance Agent Note, and the seam-level README contract, with bilingual counterparts. Fixes #1692
This commit is contained in:
@@ -47,6 +47,9 @@ const SESSION_TITLE_CONFIG = fileURLToPath(new URL('../session-title.cordis.yml'
|
||||
const SUBAGENT_DURABILITY_FAILURE_CONFIG = fileURLToPath(
|
||||
new URL('../subagent-durability-failure.cordis.yml', import.meta.url),
|
||||
)
|
||||
const SUBAGENT_CONTINUABLE_INHERITANCE_CONFIG = fileURLToPath(
|
||||
new URL('../subagent-continuable-inheritance.cordis.yml', import.meta.url),
|
||||
)
|
||||
const LSP_CONFIG = fileURLToPath(new URL('./lsp.cordis.yml', import.meta.url))
|
||||
const WEB_CONFIG = fileURLToPath(new URL('../web.cordis.yml', import.meta.url))
|
||||
const FS_SEARCH_CONFIG = fileURLToPath(new URL('./fs-search.cordis.yml', import.meta.url))
|
||||
@@ -315,6 +318,18 @@ const SCENARIOS: Scenario[] = [
|
||||
pinsChildToolSchemas: [1],
|
||||
configPath: SUBAGENT_DURABILITY_FAILURE_CONFIG,
|
||||
},
|
||||
// Authored policy-inheritance transcript: the root session is switched to
|
||||
// read-only at creation (the UI Access switch equivalent), and the
|
||||
// continuable background child's log carries that override as a
|
||||
// `sandbox/mode` `source: 'delegation'` event, so the child's runtime
|
||||
// context states the inherited policy instead of the deployment default.
|
||||
{
|
||||
name: 'subagent-continuable-inheritance',
|
||||
hasModelTurn: true,
|
||||
recorded: false,
|
||||
pinsChildToolSchemas: [1],
|
||||
configPath: SUBAGENT_CONTINUABLE_INHERITANCE_CONFIG,
|
||||
},
|
||||
// The in-process child is published before its first follow-up fails. The
|
||||
// foreground tool retains both that run-result failure and an independent
|
||||
// published-handle disposal failure.
|
||||
|
||||
Reference in New Issue
Block a user