test(harness): make permission-mode model evidence-based - #2542
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
The connector usage-limit notice is informational, not a review finding. This PR is being checked through the independent coordinator review path; no code action is requested from this notice. |
Chris0Jeky
left a comment
There was a problem hiding this comment.
Independent coordinator review of exact head 5998724: no CRITICAL/HIGH correctness, security, or data-loss finding. The change removes an unsupported auto assumption, anchors the remaining protected-mode model to #2395 and the repo refresh record, and adds a discriminating project acceptEdits control. AST, focused, full 28/28 self-test, and diff checks are green. Hosted checks remain the required gate.
Merging — and the red on the earlier head was never this PRReview: fresh-context, verdict SHIP. One MEDIUM and three INFOs, all tracked rather than blocking. This PR is T1, not control-plane: On the earlier red, recorded because it looked alarming and was not. The failing check was The actual failure was This PR cannot reach that code. It changes only Deliberately not filed as "known flake": it is distinct from the #2378/#2161 timeout cohort (those are Gate at the current head Tracked, not fixed here: the MEDIUM is that |
Summary
autois a protected project/local permission modeacceptEditscontrol while preserving the bypass, allow-rule, trust, and command-line precedence checksCloses #2537
Verification
headless-permission-contractcase — 1/1powershell -NoProfile -ExecutionPolicy Bypass -File scripts/git/Test-New-CodexIssueWorktree.ps1— 28/28git diff --check— passedBoundaries
Test-model and regression coverage only. No project settings, runtime permissions, or production behavior changed.