Skip to content

Add verified task permissions and active-turn steering - #1

Merged
saidelike merged 9 commits into
saidelike:mainfrom
genzorr:feat/explicit-task-permissions
Sep 22, 2026
Merged

saidelike merged 9 commits into
saidelike:mainfrom
genzorr:feat/explicit-task-permissions

Conversation

@genzorr

@genzorr genzorr commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Tasks created through the bridge could not request verified per-task execution policies, and the existing messaging tool could only start a new turn on an idle task. This PR adds explicit task permissions and active-turn steering while preserving the default read-only, approval-never creation behavior.

  • create_thread accepts a complete sandbox policy and optional on-request approval with App Server Auto-review. It verifies the effective sandbox, approval policy, model, and reasoning effort before dispatching an initial prompt; omitted model and effort retain configured defaults.
  • update_thread_permissions applies a complete policy to an explicitly identified idle task through thread/settings/update. It checks the expected task identity, records before/after settings, verifies the effective policy and preserved identity, and does not start a turn. Ordinary follow-up messages carry no settings overrides.
  • steer_thread uses turn/steer with an exact active-turn ID. It appends a message to that turn without resuming the task or changing model, effort, cwd, or permissions. Mutation receipts retain stable request IDs so uncertain outcomes can be inspected without blind redispatch.
  • codex-thread-bridge-reload requests an MCP refresh from the configured App Server after a default-no y/N confirmation. An accepted response reports a queued refresh, not completion in every loaded task. Non-directory writable roots are rejected before permission changes.

Validation

  • 108 tests passed on Linux using fake App Servers and temporary Git repositories; Ruff, ty check src, git diff --check, and uv build passed.
  • After MCP reload on Codex Desktop 0.154.0, the bridge exposed steer_thread and reported steerActiveTurn: true. In a live two-task test, turn/steer accepted the current turn ID, the target history contained both user messages in that same turn, and the target followed the steered instruction after its running command finished.
  • A previous Linux permission probe returned the requested creation settings but exposed invalid socket/device writable roots; this PR rejects those roots. A corrected end-to-end permission execution probe, live existing-task permission update, and actual Auto-review escalation remain unverified.

The App Server has no atomic idle compare-and-set, so another controller can race a permission update. An accepted steering receipt confirms dispatch, not processing; retained receipts prevent blind retries, not exactly-once server execution.

@genzorr
genzorr marked this pull request as ready for review September 10, 2026 10:19
@genzorr genzorr changed the title Add explicit per-task execution permissions with verified receipts Add verified task permissions and active-turn steering Sep 14, 2026
@saidelike
saidelike requested a lite review from Copilot September 20, 2026 04:15

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Fix writable-root and sandbox-policy validation, and document update_thread_permissions.

Review effort: Lite
Findings: None

What changed in this PR

Adds verified per-task permissions, active-turn steering, MCP reload support, and related tests while preserving safe defaults.

Changes:

  • Adds sandbox, approval, model, and reasoning-policy verification.
  • Adds idle-task permission updates and active-turn steering.
  • Adds reload CLI support and comprehensive test coverage.
File Summary
tests/​test_reload.py Tests reload behavior.
tests/​test_permissions.py Tests permission validation and receipts.
tests/​test_mcp.py Tests MCP tools and steering.
tests/​test_creation_profile.py Tests creation profiles.
tests/​test_bridge.py Tests active-turn steering.
tests/​conftest.py Extends the fake App Server.
src/​codex_thread_bridge/​server.py Exposes new MCP tools.
src/​codex_thread_bridge/​rpc.py Supports nullable RPC parameters.
src/​codex_thread_bridge/​reload.py Adds the MCP reload command.
src/​codex_thread_bridge/​bridge.py Implements policy validation, updates, and steering.
README.md Documents permissions, steering, and reload.
pyproject.toml Registers the reload executable.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@saidelike saidelike self-assigned this Sep 20, 2026
@saidelike saidelike added the enhancement New feature or request label Sep 20, 2026
@saidelike

Copy link
Copy Markdown
Owner

Thanks for this PR.

Added the review fixes, legacy replay compatibility, and interruption tests. Simplified the README and added official App Server references. Follow-up work is tracked in #2 and #3. All 119 tests, lint, type checks, and build pass.

@genzorr Please let me know if that works as expected for you and I'll merge it.

@genzorr

genzorr commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor Author

@saidelike Yes, this works as expected for me.
Separately, after opening this PR I added support for named permission profiles and configurable defaults in my fork. That isn’t a blocker for this PR. If it fits your direction, I can rebase it onto the merged upstream main and submit it as a separate follow-up PR.

@saidelike
saidelike merged commit 76a4810 into saidelike:main Sep 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants