Add verified task permissions and active-turn steering - #1
Conversation
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Fix writable-root and sandbox-policy validation, and document update_thread_permissions.
Review effort: Lite
Findings: None
What changed in this PR
Adds verified per-task permissions, active-turn steering, MCP reload support, and related tests while preserving safe defaults.
Changes:
- Adds sandbox, approval, model, and reasoning-policy verification.
- Adds idle-task permission updates and active-turn steering.
- Adds reload CLI support and comprehensive test coverage.
| File | Summary |
|---|---|
tests/test_reload.py |
Tests reload behavior. |
tests/test_permissions.py |
Tests permission validation and receipts. |
tests/test_mcp.py |
Tests MCP tools and steering. |
tests/test_creation_profile.py |
Tests creation profiles. |
tests/test_bridge.py |
Tests active-turn steering. |
tests/conftest.py |
Extends the fake App Server. |
src/codex_thread_bridge/server.py |
Exposes new MCP tools. |
src/codex_thread_bridge/rpc.py |
Supports nullable RPC parameters. |
src/codex_thread_bridge/reload.py |
Adds the MCP reload command. |
src/codex_thread_bridge/bridge.py |
Implements policy validation, updates, and steering. |
README.md |
Documents permissions, steering, and reload. |
pyproject.toml |
Registers the reload executable. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Thanks for this PR. Added the review fixes, legacy replay compatibility, and interruption tests. Simplified the README and added official App Server references. Follow-up work is tracked in #2 and #3. All 119 tests, lint, type checks, and build pass. @genzorr Please let me know if that works as expected for you and I'll merge it. |
|
@saidelike Yes, this works as expected for me. |
Tasks created through the bridge could not request verified per-task execution policies, and the existing messaging tool could only start a new turn on an idle task. This PR adds explicit task permissions and active-turn steering while preserving the default read-only, approval-
nevercreation behavior.create_threadaccepts a complete sandbox policy and optionalon-requestapproval with App Server Auto-review. It verifies the effective sandbox, approval policy, model, and reasoning effort before dispatching an initial prompt; omitted model and effort retain configured defaults.update_thread_permissionsapplies a complete policy to an explicitly identified idle task throughthread/settings/update. It checks the expected task identity, records before/after settings, verifies the effective policy and preserved identity, and does not start a turn. Ordinary follow-up messages carry no settings overrides.steer_threadusesturn/steerwith an exact active-turn ID. It appends a message to that turn without resuming the task or changing model, effort, cwd, or permissions. Mutation receipts retain stable request IDs so uncertain outcomes can be inspected without blind redispatch.codex-thread-bridge-reloadrequests an MCP refresh from the configured App Server after a default-noy/Nconfirmation. An accepted response reports a queued refresh, not completion in every loaded task. Non-directory writable roots are rejected before permission changes.Validation
ty check src,git diff --check, anduv buildpassed.steer_threadand reportedsteerActiveTurn: true. In a live two-task test,turn/steeraccepted the current turn ID, the target history contained both user messages in that same turn, and the target followed the steered instruction after its running command finished.The App Server has no atomic idle compare-and-set, so another controller can race a permission update. An accepted steering receipt confirms dispatch, not processing; retained receipts prevent blind retries, not exactly-once server execution.