Repository navigation
fix(cli): run subagents under the parent session's tool permissions - #13313
lakshya-dhariwal wants to merge 13 commits into
Conversation
The subagent executor replaced the session's TOOL_PERMISSIONS state with allow-all for the duration of the run, discarding every user-configured exclude/ask policy. Remove the override so subagents inherit the parent session's policies, and plumb the onToolPermissionRequest callback through ToolRunContext so ask-tier tool calls inside a subagent surface the same approval dialog as top-level tool calls. Fixes continuedev#13289
|
All contributors have signed the CLA ✍️ ✅ |
|
I have read the CLA Document and I hereby sign the CLA |
|
Heads up on jetbrains-tests: it fails during environment setup with "tar: Child returned status 1 / tar: Error is not recoverable" while unpacking, before any tests actually run. Same failure on two runs in a row, so it looks like an infra flake rather than something in this diff, which only touches extensions/cli. Could a maintainer re-run the job when you get a chance? |
Added permissionSnapshot property to StreamCallbacks interface.
|
Thanks for the review. I pushed changes for all three points:
The changes are in src/stream, src/tools and src/subagent, with tests in the existing executor and subagent test files plus a new streamChatResponse.permissions.test.ts. |
|
CI note: the CLI lint and test jobs pass on all OS and Node versions. The remaining failures look like infra: jetbrains-tests (tar unpack error before tests run), vscode-get-test-file-matrix, and the macOS and Windows VSIX builds (cancelled after 10m). Could a maintainer re-run those jobs when you get a chance? |
Description
Fixes #13289.
When the main agent spawns a subagent,
executeSubAgentreplaced the wholeTOOL_PERMISSIONSstate with{ tool: "*", permission: "allow" }for the duration of the run, discarding every user-configuredexclude/askpolicy (Bash, Write, Edit, etc.).This change removes the allow-all override (and the matching restore), so a subagent runs under the parent session's policies:
allowflows through,excludestays blocked by policy. It also plumbs the TUI'sonToolPermissionRequestcallback throughexecuteStreamedToolCalls->executeToolCall->ToolRunContext->executeSubAgent, soask-tier tool calls inside a subagent surface the same approval dialog as top-level tool calls (the TODO that was left inexecutor.ts).Headless behavior is unchanged:
asktools are not offered to the model in headless mode, same as the main agent.One edge case to flag: if one batch spawns several subagents in parallel and two hit an
askprompt at the same time, the dialog shows one request at a time. Rare in practice; happy to add explicit queueing if you want it.AI Code Review
@continue-reviewChecklist
Screen recording or screenshot
Not a UI change; behavior is covered by the tests below.
Tests
src/subagent/executor.test.ts: the session's permission state is untouched during and after a subagent run, andonToolPermissionRequestis forwarded to the subagent's stream callbacks.src/tools/subagent.test.ts:runforwards the callback from the tool run context.vitest run src/permissions src/stream src/tools(238 tests passing),tsc --noEmit, andeslinton the touched files.