Skip to content

Commit b050d20

Browse files
elkaixTest User
andauthored
fix: roll back workspace trust-boundary hardening (#335)
## Requirement or Bug Restore pre-2.1 file/git behavior for symlinked workspaces while keeping the narrow write guard. ## Bug Reproduction Steps N/A (behavior restore). ## Root Cause The 2.1 trust-boundary hardening resolved every tool path through realpath and probed git repo config, which broke legitimate symlinked workspaces and slowed every git invocation. Fundamental fix: the broad gates are removed; the guard that matters (blocking writes that resolve to env files, credentials, or SSH keys) is kept. ## Code Changes - File tools and background git no longer run symlink-realpath gates or repo-config probes; project-local `local.toml` loads without the trust prompt again. - The tower commit-identity test coverage stays. ## Impact Scope - `packages/agent-core-v2` (read/glob/grep/edit/write/read-media tools, path access, git protocol, workspace dirs, project-local config), CLI docs untouched in this slice. - Tests: write-guard, path-access, and tower suites updated; full suite green locally. ## Checklist - [x] I have read the [CONTRIBUTING](https://github.com/PyModel/pythinker-code/blob/main/CONTRIBUTING.md) document. - [x] I have linked a related issue (external PRs: issue must have a maintainer's `/approve`). — No public issue; maintainer work. - [x] I have added tests that prove my feature works. - [x] Ran `gen-changesets` skill, or this PR needs no changeset. - [x] Ran `gen-docs` skill, or this PR needs no doc update. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Behavior Changes** * Project-local configuration loads without a trust prompt, and configured additional directories are loaded regardless of workspace trust. * File and Git operations no longer apply extra symlink-path checks or repository-configuration probes. Writes targeting environment files, credentials, and SSH keys remain blocked. * **Bug Fixes** * Git context collection continues through process execution and reports timeouts and command failures while preserving available repository information. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Test User <test@example.test>
1 parent 5c5a205 commit b050d20

281 files changed

Lines changed: 2103 additions & 2606 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"@pymodel/pythinker-code": patch
3+
---
4+
5+
Stop sending a default completion token cap to models; set maxCompletionTokens in modelOverrides to cap output again.

‎.changeset/fork-cron-clear.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"@pymodel/pythinker-code": patch
3+
---
4+
5+
Forked sessions no longer inherit the source session's scheduled tasks; the source keeps them and the fork notes the clearing.
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"@pymodel/pythinker-code": patch
3+
---
4+
5+
Stop restricting file tools and background git through symlink-realpath gates and repo-config probes; project-local `local.toml` loads without the trust prompt again. Writes to paths that resolve to env files, credentials, or SSH keys are still blocked.
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"@pymodel/pythinker-code": patch
3+
---
4+
5+
Publish permission mode changes on agent status updates, stop NotifyUser nudges in clients without an updates panel, and drop the interruption reminder when its turn is undone.

‎.changeset/trust-disclosure.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"@pymodel/pythinker-code": minor
3+
---
4+
5+
The workspace trust prompt now lists the MCP servers, extra directories, and project instruction sources that trusting would activate.

‎.changeset/trust-workspace-env.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"@pymodel/pythinker-code": minor
3+
---
4+
5+
Add PYTHINKER_CODE_TRUST_WORKSPACE=1 to trust the current workspace for headless runs without answering the trust prompt.

‎.changeset/watch-default-on.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"@pymodel/pythinker-code": patch
3+
---
4+
5+
Watch config, skills, and AGENTS.md files for changes again by default; set `[watch] enabled = false` or PYTHINKER_CODE_WATCH=0 to keep them off.

‎apps/desktop/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@
2020
"@types/node": "^26.1.2",
2121
"@types/semver": "^7.7.0",
2222
"builder-util-runtime": "9.7.0",
23-
"electron": "43.4.0",
23+
"electron": "43.5.0",
2424
"electron-builder": "26.15.3",
2525
"electron-updater": "6.8.9",
2626
"semver": "^7.7.4",
Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
11
{
2-
"sourceHash": "04602432b100c73fa465235500caccbe13e6af08198ab1c90198cdc5bd19fd1c",
2+
"sourceHash": "0b9e0a931397c88206a0e22886da74780ce0c4a27202e3f6f9f81cd32777b557",
33
"sourceFileCount": 496
44
}

apps/pythinker-code/dist-web/assets/CodeBlockNode-uERC4D15.js renamed to apps/pythinker-code/dist-web/assets/CodeBlockNode-BscDteEG.js

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)