fix(monitors): fence persistent command authorization - #527
Conversation
Require current-session approval and sandbox configuration before persistent monitor commands can start or restart. Cover every reachable Session initializer with a distinct writer fence. Agent: iapp-factory-coordinator
Agent: iapp-factory-coordinator
|
[REVIEW] NO_GO — #527 @ 46fe0d1 — lens: correctness+security+gates, reviewer Trebius (1 of 1) Reviewed the complete diff from fetched base Commands and evidence:
Repository-declared gates:
Forge checks read by name:
Blocking findings:
No other concrete, currently reachable, in-scope P0/P1 correctness or security defect was found. Non-blocking follow-ups:
|
Agent: Trebius
|
[REMEDIATION] Trebius fixed the current-head Linux Bazel Clippy blocker in The monitor approval cwd helper now returns the already-typed |
|
[REVIEW] GO — #527 @ d32cdc9 — lens: correctness+security+gates, reviewer Trebius (1 of 1) Focused re-review
Declared repository setup and gates
Authoritative forge checks
Lane-chosen commands, not repository gates
Verdict |
Summary
Scope
Fresh successor for OPE2-00287. This selectively ports only the final current-fence behavior from terminal PR #489 plus the focused Session-initializer regression. It does not port the historical occurrence-lifecycle changes and does not mutate PR #489.
Evidence
Hosted Rust and Bazel checks are required before READY and remain pending at PR creation.
Task: OPE2-00287 / f4a9b60f-b202-4a0d-b7bc-bb6ac2f43099
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.