[Fix] Tool approvals apply to calls made by subagents - #3334
Merged
Merged
Conversation
Contributor
This was referenced Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related issue
Internal follow-up to #3001 and #3084; no separate issue is linked.
Why this PR exists
What changed
In a Session, per-tool approval rules (Ask first, Reject, and Auto's assessment) were written only for the parent agent and the advisor and judge helpers. An integration tool called by any other subagent the model started ran under OpenCode's default allow: no approval card, no Auto assessment, no audit row. Session calls aren't gated again at the integration proxy, so nothing else caught them.
The generated per-conversation OpenCode config now also carries the approval rules at the top level, so every agent inherits them, OpenCode's built-in subagents included. The existing per-agent entries stay because an agent's own permission takes precedence over the top-level one. Asks from subagent sessions already reach the Session's approval bridge, so they show up as normal cards.
Tasks are unaffected: task calls are also gated at the integration proxy.
How it was tested
pnpm lintand the cloud-agents type check pass.delete_fileis set to Ask first. Before the fix, a subagent deleted the file with no card and no audit row. After the fix, the same subagent call showed an approval card and waited. "Allow once" ran the call, and the approval row was consumed.Checklist
[Fix],[Feat],[Improve],[Refactor],[Docs], or[Chore]followed by a user-facing descriptionpnpm lintandpnpm check-typespass locallypnpm changesetCombined local smoke (2026-09-30)
All six Auto/approval PRs (#3332, #3334, #3335, #3337, #3338, #3339) were merged together locally and run on a local stack. It used a real web session with Auto on, Jev through OpenRouter, and a local MCP server whose tools only log (
list_files,delete_file,pay_invoice). The PRs merge cleanly into develop in any order, except #3332 and #3337: both add an export next to each other inpackages/types, and whichever lands second needs a trivial rebase. The combined build passes uncachedpnpm check-types,pnpm lint, and the approval suites (cloud-agents 131, sdk 23, worker 13, db 32).delete_fileauto-approved (authorization 0.97, highest risk level). Alist_fileswith no arguments now shows a card instead of failing the insert.list_fileswas assessed by Auto (auto-approved row).Not covered live: chat surfaces (Slack, Telegram, Discord) and the task (sandbox) path, because there's no local worker. Both are covered by unit tests.