fix(agentic): allow local tool paths outside workspace root#778
Merged
bobleer merged 1 commit intoMay 19, 2026
Merged
Conversation
Local desktop sessions no longer hard-reject file/shell paths that resolve outside the opened workspace (e.g. /tmp for PR bodies). Remote SSH workspaces still enforce containment. Optional path_policy roots are unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
resolve_workspace_tool_path).path_policyroots (write_roots, etc.) are unchanged and still enforced viaenforce_path_operation.Motivation
Local agents already have host-level access via Bash; blocking
/tmp/...and similar paths on Read/Write/Edit only forced the same work through Shell with worse UX and misleading tool errors.Test plan
cargo test -p bitfun-core path_resolutionWriteto/tmp/pr_body.mdsucceeds