@@ -1602,16 +1602,9 @@ describe("createPermissionGate", () => {
16021602 // callTargetsRestricted to judge, so the gate's auto-allow `!restricted`
16031603 // guard is intentionally vacuous for them. Path restriction is enforced
16041604 // where paths are actually touched: inside the target worker, whose own
1605- // gate binds restriction judgments to its process cwd. This pins that
1606- // decision: a fleet call aimed at a restricted-worktree worker still
1607- // auto-allows in auto mode, exactly like spawn_agent/wait_agents.
1608- test ( "auto mode auto-allows agentId-targeted fleet calls regardless of target worktree" , async ( ) => {
1605+ // gate binds restriction judgments to its process cwd.
1606+ test ( "auto mode auto-allows agentId-targeted fleet calls even when every path is treated as restricted" , async ( ) => {
16091607 let asked = 0 ;
1610- // A registered worktree standing in for the restricted target worktree.
1611- // Restriction is live in this gate — the session-state control write
1612- // below still asks — so the fleet auto-allows prove worktree-independence
1613- // instead of assuming it.
1614- const worktree = mkdtempSync ( join ( tmpdir ( ) , "corbits-restricted-wt-" ) ) ;
16151608 const gate = createPermissionGate ( {
16161609 approvals : [ ] ,
16171610 requestApproval : async ( ) => {
@@ -1622,8 +1615,6 @@ describe("createPermissionGate", () => {
16221615 skipPermissions : false ,
16231616 reactorGated : false ,
16241617 auto : true ,
1625- cwd : worktree ,
1626- rootsProvider : ( ) => [ realpathSync ( worktree ) ] ,
16271618 } ) ;
16281619 const calls : ToolCall [ ] = [
16291620 { id : "c" , name : "close_agent" , arguments : { target : "worker-1" } } ,
@@ -1649,18 +1640,17 @@ describe("createPermissionGate", () => {
16491640 expect ( verdict . allowed ) . toBe ( true ) ;
16501641 }
16511642 expect ( asked ) . toBe ( 0 ) ;
1652- // Control: restriction is live in this gate — a session-state write
1653- // through the same gate still asks (and is denied here).
1654- const control = await gate . evaluate ( {
1643+ // Same-gate in-bounds write: this fixture is not a restricted worktree.
1644+ const inBounds = await gate . evaluate ( {
16551645 id : "c" ,
16561646 name : "write_file" ,
1657- arguments : { path : ".agent-state/run.json " } ,
1647+ arguments : { path : "notes.md " } ,
16581648 } ) ;
1659- expect ( control . allowed ) . toBe ( false ) ;
1660- expect ( asked ) . toBe ( 1 ) ;
1649+ expect ( inBounds . allowed ) . toBe ( true ) ;
1650+ expect ( asked ) . toBe ( 0 ) ;
16611651 // The carve-out is intentional, not an oversight: even an isRestricted
1662- // that reports everything restricted (the target worktree is restricted)
1663- // does not flag these calls — they carry agent ids, not paths.
1652+ // that reports everything restricted does not flag these calls — they
1653+ // carry agent ids, not paths.
16641654 const alwaysRestricted = ( ) => true ;
16651655 for ( const call of calls ) {
16661656 expect ( callTargetsRestricted ( call , alwaysRestricted ) ) . toBe ( false ) ;
0 commit comments