Skip to content

Restrict report handoffs and Feed curation to server-authorized tools - #43

Open
srctl wants to merge 2 commits into
codex/run-capability-policy-review-basefrom
codex/run-capability-policy-production
Open

srctl wants to merge 2 commits into
codex/run-capability-policy-review-basefrom
codex/run-capability-policy-production

Conversation

@srctl

@srctl srctl commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Automatically delivered delegation reports and Feed source text could invoke ordinary agent tools, including payments and the shared signed-in desktop. Apply an immutable server-side capability policy to both tool catalogs and dispatch: handoff turns get isolated threads with no dynamic tools; internal Feed editor runs get only Feed read/publication. Restricted runs disable native shell, desktop/browser tools, apps, image generation, web search, network access, and approval escalation. Payment, desktop, and Feed publication sinks also check persisted run purpose.

Feed curation continues from server-collected candidates. Automatic email retrieval and independent research require dedicated read-only tools; unavailable access must be reported accurately. Existing current-main personal Feed publication behavior is preserved.

Validation: the full pinned Node 24.15.0 / pnpm 9.15.0 check passed, including 419 web tests, 7 docs tests, lint, type checks, builds, and production auth/mobile smoke tests. Adversarial app-server tests forge calls absent from the catalog and verify server rejection; sink checks cover payments and desktop access. The v0.1.48 release workflow passed and published its archive, installer, and checksums.

This PR is for reviewing the already-landed fix. Main contains d1eaa68 and release commit ef94a39. The base branch is a snapshot of pre-fix main (cc44d86), so the PR shows the complete deployed change without reverting main. Merging this PR updates only that review snapshot. Deployed v0.1.48 to roost-dev.exe.xyz through the packaged updater. Live health reports status=ok/version=0.1.48; Roost, desktop, and noVNC services are active. Both SQLite databases pass integrity checks, maintenance is off, the operation lock is cleared, and all existing table counts match the immediate rollback backup except the expected new startup worker lease. The installed server bundle contains the capability guard. The rollback backup is retained.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant