Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .changeset/tool-approvals-subagents.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@roomote/cloud-agents': patch
---

Apply tool approval choices to integration calls that a session's subagents make, so those calls ask for approval like any other.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Original file line number Diff line number Diff line change
Expand Up @@ -1647,8 +1647,8 @@ export async function getFastAgentNativeToolRuntime(
automationLaunchCriteriaEnabled?: boolean;
brainEnabled?: boolean;
/**
* Per-tool approval rules in OpenCode config-permission shape, applied to the parent build agent
* and the helper subagents in the generated per-conversation config.
* Per-tool approval rules in OpenCode config-permission shape, applied to every agent in the
* generated per-conversation config, subagents included.
* Rules live in config rather than the session ruleset so a policy
* change never strands stale state in a persisted session: this file is
* rewritten every turn, and a policy change disposes the directory's
Expand Down Expand Up @@ -1701,10 +1701,15 @@ export async function getFastAgentNativeToolRuntime(
);
runtime.env.OPENCODE_EXPERIMENTAL_CODE_MODE = '1';
runtime.codeModeIntegrationsActive = true;
// Approval rules apply to the parent build agent and to the helper
// subagents. OpenCode merges this per-directory config over the shared
// server config, so a permission-only entry extends the existing advisor
// and judge definitions instead of replacing them.
// Approval rules apply to every agent: the top-level permission covers any
// subagent the model starts (including OpenCode's built-in ones), which
// would otherwise call integration tools under the default allow. Session
// calls are not gated at the proxy, so these native asks are the only
// gate. The build, advisor, and judge entries repeat the rules because an
// agent's own permission takes precedence over the top-level one. OpenCode
// merges this per-directory config over the shared server config, so a
// permission-only entry extends the existing advisor and judge definitions
// instead of replacing them.
const toolApprovalAgentEntries = options.toolApprovalPermission
? {
permission: options.toolApprovalPermission,
Expand All @@ -1713,6 +1718,7 @@ export async function getFastAgentNativeToolRuntime(
writeFileSync(
join(runtime.directory, 'opencode.json'),
JSON.stringify({
...toolApprovalAgentEntries,
// Keep the parent's fail-closed filter on its agent rather than on the
// session. OpenCode copies session deny rules into task-created child
// sessions, which would otherwise give advisor and judge the parent's
Expand Down
Loading