Skip to content

[Fix] Tool approvals apply to calls made by subagents - #3334

Merged
daniel-lxs merged 2 commits into
developfrom
fix/tool-approvals-subagents
Sep 30, 2026
Merged

daniel-lxs merged 2 commits into
developfrom
fix/tool-approvals-subagents

Conversation

@daniel-lxs

@daniel-lxs daniel-lxs commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Related issue

Internal follow-up to #3001 and #3084; no separate issue is linked.

Why this PR exists

  • A maintainer explicitly invited this PR in the linked issue or discussion
  • I am a maintainer / this is internal Roomote work

What changed

In a Session, per-tool approval rules (Ask first, Reject, and Auto's assessment) were written only for the parent agent and the advisor and judge helpers. An integration tool called by any other subagent the model started ran under OpenCode's default allow: no approval card, no Auto assessment, no audit row. Session calls aren't gated again at the integration proxy, so nothing else caught them.

The generated per-conversation OpenCode config now also carries the approval rules at the top level, so every agent inherits them, OpenCode's built-in subagents included. The existing per-agent entries stay because an agent's own permission takes precedence over the top-level one. Asks from subagent sessions already reach the Session's approval bridge, so they show up as normal cards.

Tasks are unaffected: task calls are also gated at the integration proxy.

How it was tested

  • Fast native tool bridge tests pass (36). The updated test asserts the top-level rules, and it fails on the previous code.
  • pnpm lint and the cloud-agents type check pass.
  • Live on a local stack with a local MCP server whose delete_file is set to Ask first. Before the fix, a subagent deleted the file with no card and no audit row. After the fix, the same subagent call showed an approval card and waited. "Allow once" ran the call, and the approval row was consumed.

Checklist

  • The PR title follows the repo convention: [Fix], [Feat], [Improve], [Refactor], [Docs], or [Chore] followed by a user-facing description
  • This PR is small and scoped to one change
  • pnpm lint and pnpm check-types pass locally
  • I added tests or included a clear manual validation note above
  • I removed secrets, tokens, private keys, and customer data from code, logs, and screenshots
  • If this change should appear in the changelog, I ran pnpm changeset

Combined local smoke (2026-09-30)

All six Auto/approval PRs (#3332, #3334, #3335, #3337, #3338, #3339) were merged together locally and run on a local stack. It used a real web session with Auto on, Jev through OpenRouter, and a local MCP server whose tools only log (list_files, delete_file, pay_invoice). The PRs merge cleanly into develop in any order, except #3332 and #3337: both add an export next to each other in packages/types, and whichever lands second needs a trivial rebase. The combined build passes uncached pnpm check-types, pnpm lint, and the approval suites (cloud-agents 131, sdk 23, worker 13, db 32).

# Scenario PR Result
S1 "Delete old-notes.txt": the delete runs with no card #3335, #3338 Pass. delete_file auto-approved (authorization 0.97, highest risk level). A list_files with no arguments now shows a card instead of failing the insert.
S2 "Pay invoice INV-11 for $120": asks, even though requested #3335, #3339 Pass. A card on the first attempt (it used to be auto-rejected as "away" in a new session), and the call never ran.
S3 A subagent calls an Ask first tool #3334 Pass. A card appeared and the call ran after Allow once. The subagent's list_files was assessed by Auto (auto-approved row).
S4 Flagged call while the owner is away #3332, #3339 Pass. Auto-rejected about 19 seconds after the message (presence recheck). The agent said "When you're back, ask again", with no mention of the transcript.
S5 Judgment model unavailable #3337 Pass. Two calls failed together, both were rejected, one notice was posted, and the session was marked paused. After "ok, continue", both got plain cards and ran once allowed.
S6 Auto turned off after a pause #3337 Pass. The next call ran with no card (new turn; the mid-turn path is covered by a unit test).
S7 "Delete draft-1, draft-2 and draft-3": all run #3335 Pass. Three deletes auto-approved (authorization 0.92 to 0.96), no cards.

Not covered live: chat surfaces (Slack, Telegram, Discord) and the task (sandbox) path, because there's no local worker. Both are covered by unit tests.

@roomote-community

roomote-community Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

No code issues found. See task

Reviewed 8afdc7a

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant