Skip to content

feat: expand workspace trust controls and restore watch and session defaults - #334

Closed
elkaix wants to merge 6 commits into
mainfrom
fix/reconcile-2026-09-30
Closed

elkaix wants to merge 6 commits into
mainfrom
fix/reconcile-2026-09-30

Conversation

@elkaix

@elkaix elkaix commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Requirement or Bug

Restore pre-2.1 file/git behavior for symlinked workspaces, make workspace trust more transparent, and land a batch of session-behavior fixes (watch default, agent status, cron forks, completion budget).

Bug Reproduction Steps

N/A (behavior restore + features; see Code Changes).

Root Cause

The 2.1 trust-boundary hardening resolved every tool path through realpath and probed git repo config, which broke legitimate symlinked workspaces and slowed every git invocation. This is a fundamental fix: the broad gates are removed and the narrow guard that matters (blocking writes to env files, credentials, and SSH keys) is kept.

Code Changes

  • Reverts the trust-boundary hardening: file tools and background git no longer run symlink-realpath gates or repo-config probes; project-local local.toml loads without the trust prompt again. Writes that resolve to env files, credentials, or SSH keys are still blocked, and the tower commit-identity test coverage stays.
  • New PYTHINKER_CODE_TRUST_WORKSPACE=1 env var trusts the current workspace for headless runs without answering the trust prompt; untrust reports the effective state.
  • The workspace trust prompt now lists the MCP servers, extra directories, and project instruction sources that trusting would activate, with a typed disclosure service behind it; the SDK getWorkspaceTrustInfo result gains origin, gatedAdditionalDirs, additionalDirSources, warnings, and instructionSources.
  • Filesystem watch defaults back to on ([watch] enabled = false / PYTHINKER_CODE_WATCH=0 to disable).
  • setMode publishes permission mode on AgentStatusUpdated; the nudge only fires for clients with an updates panel; undo removes a turn's interruption reminder; forks clear inherited cron tasks with a one-shot notice; the default completion token cap is gone (set maxCompletionTokens in modelOverrides to cap output); usedContextTokens reads the tokenizer size.

Impact Scope

  • packages/agent-core-v2 (tools, trust, watch, nudge, permission mode, interruption reminder, cron, usage/traits), packages/agent-gateway (trust env, untrust report), packages/node-sdk (trust info shape), CLI (cli/v2 MCP warning), web (no functional change), docs (config-files.md, env-vars.md, mcp.md).
  • Tests: new/updated suites for the write guard, env trust, trust disclosure, nudge gate, permission status, reminder undo, cron fork notice, completion budget, and provider traits; full suite green locally (17,819 passed; one pre-existing flaky gateway transcript-contract test, S3 … mid.meta.agent, also fails on main without this branch).

Checklist

  • I have read the CONTRIBUTING document.
  • I have linked a related issue (external PRs: issue must have a maintainer's /approve). — No public issue; maintainer work.
  • I have added tests that prove my feature works.
  • Ran gen-changesets skill, or this PR needs no changeset. — 6 changesets included.
  • Ran gen-docs skill, or this PR needs no doc update. — config-files, env-vars, mcp docs updated.

elkaix and others added 6 commits September 30, 2026 19:18
Remove the symlink-realpath gates on file tools, the repo-config git
hardening probe, and the local.toml trust gating; project-local config
and git invocations return to plain resolution while the sensitive-file
write guard stays.
…pletion budget behavior

Watchers default back on, NotifyUser nudges respect the host update
panel, permission mode changes publish agent.status.updated, undo drops
its turn's interruption reminder, forks clear inherited cron tasks with
a notice, and the completion token cap is only sent when configured.
Headless runs can set the variable instead of answering the trust
prompt; the untrust route now reports the effective trust state.
The trust prompt and SDK trust info now disclose gated MCP servers with
their config origins, additional directory grants, and the project
instruction sources (AGENTS.md, skills, agent profiles) that load on
trust.
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Important

Review skipped

Too many files!

This PR contains 113 files, which is 13 over the limit of 100.

To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.

Upgrade to a paid plan to raise the limit.

⚙️ Run configuration

Configuration used: Repository: PyModel/pythinker-code/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 6531fadb-f461-4f9a-9577-07d1b0cfcf7a

📥 Commits

Reviewing files that changed from the base of the PR and between 5c5a205 and 41cbb9f.

📒 Files selected for processing (113)
  • .changeset/completion-cap-opt-in.md
  • .changeset/fork-cron-clear.md
  • .changeset/roll-back-trust-boundary-hardening.md
  • .changeset/status-and-undo-fixes.md
  • .changeset/trust-disclosure.md
  • .changeset/trust-workspace-env.md
  • .changeset/watch-default-on.md
  • README.md
  • apps/pythinker-code/src/cli/v2/run-v2-print.ts
  • apps/pythinker-code/src/feedback/codebase/scanner.ts
  • apps/pythinker-code/src/tui/components/dialogs/trust-prompt.ts
  • apps/pythinker-code/src/tui/pythinker-tui.ts
  • apps/pythinker-code/src/utils/git/git-args.ts
  • apps/pythinker-code/src/utils/git/git-status.ts
  • apps/pythinker-code/test/tui/components/dialogs/trust-prompt.test.ts
  • apps/pythinker-code/test/tui/pythinker-tui-startup.test.ts
  • apps/pythinker-code/test/tui/signal-handlers.test.ts
  • apps/pythinker-code/test/utils/git/git-status.test.ts
  • apps/vis/server/src/lib/agent-record-types.ts
  • docs/configuration/config-files.md
  • docs/configuration/env-vars.md
  • docs/customization/mcp.md
  • packages/agent-core-v2/docs/wire-manifest.d.ts
  • packages/agent-core-v2/src/agent/interruptionReminder/interruptionReminderService.ts
  • packages/agent-core-v2/src/agent/llmRequester/llmRequesterService.ts
  • packages/agent-core-v2/src/agent/permissionMode/permissionModeService.ts
  • packages/agent-core-v2/src/agent/permissionPolicy/policies/git-cwd-write-approve.ts
  • packages/agent-core-v2/src/agent/tools/edit/editTool.ts
  • packages/agent-core-v2/src/agent/tools/os/glob/globTool.ts
  • packages/agent-core-v2/src/agent/tools/os/grep/grepTool.ts
  • packages/agent-core-v2/src/agent/tools/os/read/readTool.ts
  • packages/agent-core-v2/src/agent/tools/os/write/writeTool.ts
  • packages/agent-core-v2/src/agent/tools/read-media-file/readMediaFileTool.ts
  • packages/agent-core-v2/src/agent/usage/usageEvents.ts
  • packages/agent-core-v2/src/app/agentProfileCatalog/agentProfileCatalog.ts
  • packages/agent-core-v2/src/app/config/configService.ts
  • packages/agent-core-v2/src/app/git/git.ts
  • packages/agent-core-v2/src/app/git/gitService.ts
  • packages/agent-core-v2/src/app/git/hardening.ts
  • packages/agent-core-v2/src/app/mcpRegistry/mcpRegistryService.ts
  • packages/agent-core-v2/src/app/projectLocalConfig/projectLocalConfig.ts
  • packages/agent-core-v2/src/features/cron/cronAgentRuntime.ts
  • packages/agent-core-v2/src/features/cron/cronOps.ts
  • packages/agent-core-v2/src/features/cron/cronService.ts
  • packages/agent-core-v2/src/features/goal/goalOps.ts
  • packages/agent-core-v2/src/features/goal/goalService.ts
  • packages/agent-core-v2/src/features/notify/notifyUserNudgeService.ts
  • packages/agent-core-v2/src/features/tower/protocol/git.ts
  • packages/agent-core-v2/src/human/llm-pythinker/provider.ts
  • packages/agent-core-v2/src/human/llm-pythinker/trait.ts
  • packages/agent-core-v2/src/human/llm/protocol/format.ts
  • packages/agent-core-v2/src/human/llm/requester/bases/anthropic/profile.ts
  • packages/agent-core-v2/src/human/llm/requester/bases/openai-responses/requester.ts
  • packages/agent-core-v2/src/human/llm/requester/bases/openai-responses/trait.ts
  • packages/agent-core-v2/src/human/llm/requester/bases/openai/requester.ts
  • packages/agent-core-v2/src/human/llm/requester/bases/openai/trait.ts
  • packages/agent-core-v2/src/human/test/llm/trait.test.ts
  • packages/agent-core-v2/src/human/test/utils/watch.test.ts
  • packages/agent-core-v2/src/human/utils/watch.ts
  • packages/agent-core-v2/src/index.ts
  • packages/agent-core-v2/src/llm-adapter/model/completion-budget.ts
  • packages/agent-core-v2/src/llm-adapter/model/model.types.ts
  • packages/agent-core-v2/src/llm-adapter/provider/provider-definition.ts
  • packages/agent-core-v2/src/persistence/backends/node-fs/projectLocalConfigService.ts
  • packages/agent-core-v2/src/program/program.ts
  • packages/agent-core-v2/src/session/agentLifecycle/forked.ts
  • packages/agent-core-v2/src/session/agentLifecycle/profile/gitContext.ts
  • packages/agent-core-v2/src/session/agentLifecycle/profile/profiles.ts
  • packages/agent-core-v2/src/session/subagent/subagentService.ts
  • packages/agent-core-v2/src/tool/path-access.ts
  • packages/agent-core-v2/src/tool/realpath-access.ts
  • packages/agent-core-v2/src/workspace/workspaceDirs/workspaceDirsService.ts
  • packages/agent-core-v2/src/workspace/workspaceTrust/trustDisclosure.ts
  • packages/agent-core-v2/src/workspace/workspaceTrust/trustDisclosureService.ts
  • packages/agent-core-v2/src/workspace/workspaceTrust/workspaceTrustService.ts
  • packages/agent-core-v2/test/agent/fullCompaction/fullCompaction.test.ts
  • packages/agent-core-v2/test/agent/loop/loop.test.ts
  • packages/agent-core-v2/test/agent/media/tools/read-media.test.ts
  • packages/agent-core-v2/test/agent/permissionMode/permissionMode.test.ts
  • packages/agent-core-v2/test/agent/permissionPolicy/permissionPolicyService.test.ts
  • packages/agent-core-v2/test/app/edit/tools/edit.test.ts
  • packages/agent-core-v2/test/app/git/gitService.test.ts
  • packages/agent-core-v2/test/app/git/hardening.test.ts
  • packages/agent-core-v2/test/app/mcpManagement/mcpManagement.test.ts
  • packages/agent-core-v2/test/app/mcpRegistry/mcpRegistry.test.ts
  • packages/agent-core-v2/test/app/workspaceAliases/workspaceAliasesService.test.ts
  • packages/agent-core-v2/test/features/cron/sessionCron.test.ts
  • packages/agent-core-v2/test/features/dynamic_workflow/dynamic_workflow.test.ts
  • packages/agent-core-v2/test/features/notify/notifyUserNudgeService.test.ts
  • packages/agent-core-v2/test/features/plan/plan.test.ts
  • packages/agent-core-v2/test/features/tower/store.test.ts
  • packages/agent-core-v2/test/llm-adapter/model/completionBudget.test.ts
  • packages/agent-core-v2/test/llm-adapter/protocol/protocolAdapterRegistry.test.ts
  • packages/agent-core-v2/test/os/backends/node-local/tools/glob.test.ts
  • packages/agent-core-v2/test/os/backends/node-local/tools/grep.test.ts
  • packages/agent-core-v2/test/os/backends/node-local/tools/read.test.ts
  • packages/agent-core-v2/test/os/backends/node-local/tools/write.test.ts
  • packages/agent-core-v2/test/persistence/backends/node-fs/projectLocalConfigService.test.ts
  • packages/agent-core-v2/test/session/agentLifecycle/profile/gitContext.test.ts
  • packages/agent-core-v2/test/tool/path-access.test.ts
  • packages/agent-core-v2/test/tool/realpath-access.test.ts
  • packages/agent-core-v2/test/tools/fixtures/fake-exec.ts
  • packages/agent-core-v2/test/workspace/workspaceAgentProfileLoader/agentProfileLoader.test.ts
  • packages/agent-core-v2/test/workspace/workspaceDirs/workspaceDirs.test.ts
  • packages/agent-core-v2/test/workspace/workspaceFs/fsService.test.ts
  • packages/agent-core-v2/test/workspace/workspaceTrust/workspaceTrust.test.ts
  • packages/agent-gateway/src/routes/workspaces.ts
  • packages/agent-gateway/test/sessions.test.ts
  • packages/agent-gateway/test/v2Sessions.test.ts
  • packages/agent-gateway/test/workspaces.test.ts
  • packages/node-sdk/src/sdk-rpc-client-v2.ts
  • packages/node-sdk/src/types.ts
  • packages/node-sdk/test/sdk-rpc-client-v2.test.ts

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • Review on demand using usage pricing
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 1, 2026

Copy link
Copy Markdown
pnpm dlx https://pkg.pr.new/@pymodel/pythinker-code@41cbb9f
npx https://pkg.pr.new/@pymodel/pythinker-code@41cbb9f

commit: 41cbb9f

@elkaix

elkaix commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by the split stack, each under 100 changed files: #335 (trust-boundary rollback, 45 files) → #336 (watch/status/undo/cron/completion behavior, 47) → #337 (trust disclosure + env var, 25). Identical content, tree-verified against this branch's tested tip; the stray README-only commit is excluded. Branch kept for reference.

@elkaix elkaix closed this Oct 1, 2026
@elkaix
elkaix deleted the fix/reconcile-2026-09-30 branch October 1, 2026 16:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant