Repository navigation
[Feat] Auto pauses a Session when calls can't be checked - #3337
Merged
Merged
Conversation
Contributor
|
No new code issues found. See task
Reviewed 43d26cd |
…; honor Auto off after a pause
This was referenced Sep 30, 2026
…en-unavailable # Conflicts: # apps/worker/src/sandbox-server/lib/harnesses/opencode-server/tool-approvals.ts # packages/cloud-agents/src/server/fast-agent/fast-agent-tool-approvals.ts # packages/types/src/integration-tool-approvals.ts
A batch of parallel calls pauses Auto when any of them cannot be checked, instead of asking about the batch.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related issue
Internal follow-up to #3116; no separate issue is linked.
Why this PR exists
What changed
When Auto is on but a call can't be assessed (the judgment model is unconfigured, failing, or timing out), each call used to become a card if the owner was present and a denial if they were away. During an outage that meant a click on every integration call, or unattended work quietly stalling.
Now the first call that can't be assessed pauses Auto for that Session:
auto_tool_approvals_suspended_at(a new nullable column, so N-1 safe). From then on its default tools ask the owner with a normal approval card instead of being assessed. If Auto is later turned off for the deployment, they run as they always have.pausedoutcome. The agent is told to stop and not retry, and later task calls in that Session ask the owner. An older worker that doesn't knowpausedfails closed.Notice copy (draft): "Automatic approvals aren't available right now, so I paused Auto for this session and stopped before running {tool} from {integration}. Reply when you're ready to continue, and I'll ask you before running tools."
How it was tested
pnpm lintandpnpm check-typespass.Checklist
[Fix],[Feat],[Improve],[Refactor],[Docs], or[Chore]followed by a user-facing descriptionpnpm lintandpnpm check-typespass locallypnpm changeset(not needed: Auto is a nightly-only experiment)Combined local smoke (2026-09-30)
All six Auto/approval PRs (#3332, #3334, #3335, #3337, #3338, #3339) were merged together locally and run on a local stack. It used a real web session with Auto on, Jev through OpenRouter, and a local MCP server whose tools only log (
list_files,delete_file,pay_invoice). The PRs merge cleanly into develop in any order, except #3332 and #3337: both add an export next to each other inpackages/types, and whichever lands second needs a trivial rebase. The combined build passes uncachedpnpm check-types,pnpm lint, and the approval suites (cloud-agents 131, sdk 23, worker 13, db 32).delete_fileauto-approved (authorization 0.97, highest risk level). Alist_fileswith no arguments now shows a card instead of failing the insert.list_fileswas assessed by Auto (auto-approved row).Not covered live: chat surfaces (Slack, Telegram, Discord) and the task (sandbox) path, because there's no local worker. Both are covered by unit tests.