Repository navigation
A run can deny tools outright, closing a gap AllowedTools alone can't reach,
and a prompt embedding a full diff no longer fails to exec on Linux.
Repository:
- A new
Disallowerinterface, separate fromPermitter: a provider can
grant an allowlist without being able to remove anything from it, or the
reverse, and folding removal intoPermissionArgswould force every
existing implementer to change its signature for a capability some of
them don't have. Request.DisallowedToolsnames tools a scripted run must never use,
regardless of whatAllowedToolsorPermissionModeotherwise grant. A
tool that needs no permission is invisible to an allowlist; this is the
field that closes it off directly. Set on a provider that isn't a
Disallower, it is refused withErrDisallowUnsupportedbefore any
process starts, the same way an unsupported turn limit or schema already
is.Driver.Provider()returns the wrappedagentic.Provider, so a caller
can type-assert any capability —Disalloweror one not yet invented —
without holding onto its own concrete reference against the grain of the
README's own usage example, which discards it afteragentic.New, or
submitting aRequestjust to read back the error.InvocationgainsStdin []byte, piped to the child's standard input
when non-nil;nilleaves it on the null device exactly as before, so
this is a no-op for any provider that doesn't set it. Linux'sexecve(2)
caps a single argv element at 128 KiB, and a prompt embedding a full diff
routinely exceeds that on its own — the run used to fail at spawn with
fork/exec ...: argument list too longbefore a single byte of the
request was read. See ADR 0008.Invocation.Argsno longer carries the prompt for either dialect — an
exported-behavior change. A caller that inspectedStreamCommand's
returned argv for the prompt text sees a different shape now. The known
downstream consumer isagentic-toolkit, currently pinning this
repository at v0.9.0.- Governed by
gt2.1.1 (up from 2.0.0):.github/workflows/ci-orchestration.yml
gains a lydite coverage-baseline job, and the managed lydite-clearance
workflow is renamed togt-lydite-clearance.yml.
claudecode:
- Implements
Disallower, emitting--disallowedToolsas one
comma-joined argv element, the same shape--allowedToolsalready uses. - A bare
*is accepted on the deny-list, unlike the allowlist: denying
every tool is a coherent thing to ask for, where granting every tool
under the guise of a restriction is refused. --disallowedToolstakes precedence over both the allowlist and the
permission mode — a denied tool stays denied even under
bypassPermissions.- The prompt travels on
Invocation.Stdininstead of as the value of-p;
-pitself stays in argv soclaudestill runs non-interactively.
codex:
- Does not implement
Disallower. Its nearest analogue,
features.multi_agent, is a single switch over five tools at once, not
a per-tool control, so aDisallowerbuilt on it could only honor a
couple of hardcoded names and silently refuse the rest. A non-empty
DisallowedToolsis refused outright withErrDisallowUnsupported,
exactly likeAllowedToolstoday. - The prompt travels on
Invocation.Stdininstead of as the trailing
positional argument tocodex exec. It is dropped from argv entirely
rather than replaced with-, sincecodex execappends piped stdin as
an extra<stdin>block rather than treating it as the prompt when a
positional is also given.
agentictest:
Fakecaptures what was piped to its standard input, read back with the
newFake.Stdin(t), kept in its own file separate from the existing
argv/env record so a prompt containing newlines orarg:/ENV-prefixed
lines can't corrupt either.- A new
IgnoreStdinfield makes the fake never read its stdin, for
testing a child that exits or stalls while the driver still has a
payload left to write.
Full changelog: v0.9.1...v0.10.0