Skip to content

Commit 24b4b15

Browse files
committed
test(permissions): drop restricted-worktree theater from the fleet carve-out pin
The previous fixture registered cwd as a root, which is the in-bounds pattern, and the session-state write control already lives in its own test. The alwaysRestricted classify loop is the real pin.
1 parent 0378949 commit 24b4b15

1 file changed

Lines changed: 9 additions & 19 deletions

File tree

‎src/permission/permission.test.ts‎

Lines changed: 9 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -1602,16 +1602,9 @@ describe("createPermissionGate", () => {
16021602
// callTargetsRestricted to judge, so the gate's auto-allow `!restricted`
16031603
// guard is intentionally vacuous for them. Path restriction is enforced
16041604
// where paths are actually touched: inside the target worker, whose own
1605-
// gate binds restriction judgments to its process cwd. This pins that
1606-
// decision: a fleet call aimed at a restricted-worktree worker still
1607-
// auto-allows in auto mode, exactly like spawn_agent/wait_agents.
1608-
test("auto mode auto-allows agentId-targeted fleet calls regardless of target worktree", async () => {
1605+
// gate binds restriction judgments to its process cwd.
1606+
test("auto mode auto-allows agentId-targeted fleet calls even when every path is treated as restricted", async () => {
16091607
let asked = 0;
1610-
// A registered worktree standing in for the restricted target worktree.
1611-
// Restriction is live in this gate — the session-state control write
1612-
// below still asks — so the fleet auto-allows prove worktree-independence
1613-
// instead of assuming it.
1614-
const worktree = mkdtempSync(join(tmpdir(), "corbits-restricted-wt-"));
16151608
const gate = createPermissionGate({
16161609
approvals: [],
16171610
requestApproval: async () => {
@@ -1622,8 +1615,6 @@ describe("createPermissionGate", () => {
16221615
skipPermissions: false,
16231616
reactorGated: false,
16241617
auto: true,
1625-
cwd: worktree,
1626-
rootsProvider: () => [realpathSync(worktree)],
16271618
});
16281619
const calls: ToolCall[] = [
16291620
{ id: "c", name: "close_agent", arguments: { target: "worker-1" } },
@@ -1649,18 +1640,17 @@ describe("createPermissionGate", () => {
16491640
expect(verdict.allowed).toBe(true);
16501641
}
16511642
expect(asked).toBe(0);
1652-
// Control: restriction is live in this gate — a session-state write
1653-
// through the same gate still asks (and is denied here).
1654-
const control = await gate.evaluate({
1643+
// Same-gate in-bounds write: this fixture is not a restricted worktree.
1644+
const inBounds = await gate.evaluate({
16551645
id: "c",
16561646
name: "write_file",
1657-
arguments: { path: ".agent-state/run.json" },
1647+
arguments: { path: "notes.md" },
16581648
});
1659-
expect(control.allowed).toBe(false);
1660-
expect(asked).toBe(1);
1649+
expect(inBounds.allowed).toBe(true);
1650+
expect(asked).toBe(0);
16611651
// The carve-out is intentional, not an oversight: even an isRestricted
1662-
// that reports everything restricted (the target worktree is restricted)
1663-
// does not flag these calls — they carry agent ids, not paths.
1652+
// that reports everything restricted does not flag these calls — they
1653+
// carry agent ids, not paths.
16641654
const alwaysRestricted = () => true;
16651655
for (const call of calls) {
16661656
expect(callTargetsRestricted(call, alwaysRestricted)).toBe(false);

0 commit comments

Comments
 (0)