Conversation
Remove the symlink-realpath gates on file tools, the repo-config git hardening probe, and the local.toml trust gating; project-local config and git invocations return to plain resolution while the sensitive-file write guard stays.
…pletion budget behavior Watchers default back on, NotifyUser nudges respect the host update panel, permission mode changes publish agent.status.updated, undo drops its turn's interruption reminder, forks clear inherited cron tasks with a notice, and the completion token cap is only sent when configured.
Headless runs can set the variable instead of answering the trust prompt; the untrust route now reports the effective trust state.
The trust prompt and SDK trust info now disclose gated MCP servers with their config origins, additional directory grants, and the project instruction sources (AGENTS.md, skills, agent profiles) that load on trust.
|
Important Review skippedToo many files! This PR contains 113 files, which is 13 over the limit of 100. To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch. Upgrade to a paid plan to raise the limit. ⚙️ Run configurationConfiguration used: Repository: PyModel/pythinker-code/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (113)
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
commit: |
|
Superseded by the split stack, each under 100 changed files: #335 (trust-boundary rollback, 45 files) → #336 (watch/status/undo/cron/completion behavior, 47) → #337 (trust disclosure + env var, 25). Identical content, tree-verified against this branch's tested tip; the stray README-only commit is excluded. Branch kept for reference. |
Requirement or Bug
Restore pre-2.1 file/git behavior for symlinked workspaces, make workspace trust more transparent, and land a batch of session-behavior fixes (watch default, agent status, cron forks, completion budget).
Bug Reproduction Steps
N/A (behavior restore + features; see Code Changes).
Root Cause
The 2.1 trust-boundary hardening resolved every tool path through realpath and probed git repo config, which broke legitimate symlinked workspaces and slowed every git invocation. This is a fundamental fix: the broad gates are removed and the narrow guard that matters (blocking writes to env files, credentials, and SSH keys) is kept.
Code Changes
local.tomlloads without the trust prompt again. Writes that resolve to env files, credentials, or SSH keys are still blocked, and the tower commit-identity test coverage stays.PYTHINKER_CODE_TRUST_WORKSPACE=1env var trusts the current workspace for headless runs without answering the trust prompt; untrust reports the effective state.getWorkspaceTrustInforesult gainsorigin,gatedAdditionalDirs,additionalDirSources,warnings, andinstructionSources.[watch] enabled = false/PYTHINKER_CODE_WATCH=0to disable).setModepublishes permission mode onAgentStatusUpdated; the nudge only fires for clients with an updates panel; undo removes a turn's interruption reminder; forks clear inherited cron tasks with a one-shot notice; the default completion token cap is gone (setmaxCompletionTokensin modelOverrides to cap output);usedContextTokensreads the tokenizer size.Impact Scope
packages/agent-core-v2(tools, trust, watch, nudge, permission mode, interruption reminder, cron, usage/traits),packages/agent-gateway(trust env, untrust report),packages/node-sdk(trust info shape), CLI (cli/v2MCP warning), web (no functional change), docs (config-files.md,env-vars.md,mcp.md).S3 … mid.meta.agent, also fails onmainwithout this branch).Checklist
/approve). — No public issue; maintainer work.gen-changesetsskill, or this PR needs no changeset. — 6 changesets included.gen-docsskill, or this PR needs no doc update. — config-files, env-vars, mcp docs updated.