Skip to content

v0.10.0

Latest

Choose a tag to compare

@github-actions github-actions released this 28 Sep 13:32
fa17df9

A run can deny tools outright, closing a gap AllowedTools alone can't reach,
and a prompt embedding a full diff no longer fails to exec on Linux.

Repository:

  • A new Disallower interface, separate from Permitter: a provider can
    grant an allowlist without being able to remove anything from it, or the
    reverse, and folding removal into PermissionArgs would force every
    existing implementer to change its signature for a capability some of
    them don't have.
  • Request.DisallowedTools names tools a scripted run must never use,
    regardless of what AllowedTools or PermissionMode otherwise grant. A
    tool that needs no permission is invisible to an allowlist; this is the
    field that closes it off directly. Set on a provider that isn't a
    Disallower, it is refused with ErrDisallowUnsupported before any
    process starts, the same way an unsupported turn limit or schema already
    is.
  • Driver.Provider() returns the wrapped agentic.Provider, so a caller
    can type-assert any capability — Disallower or one not yet invented —
    without holding onto its own concrete reference against the grain of the
    README's own usage example, which discards it after agentic.New, or
    submitting a Request just to read back the error.
  • Invocation gains Stdin []byte, piped to the child's standard input
    when non-nil; nil leaves it on the null device exactly as before, so
    this is a no-op for any provider that doesn't set it. Linux's execve(2)
    caps a single argv element at 128 KiB, and a prompt embedding a full diff
    routinely exceeds that on its own — the run used to fail at spawn with
    fork/exec ...: argument list too long before a single byte of the
    request was read. See ADR 0008.
  • Invocation.Args no longer carries the prompt for either dialect — an
    exported-behavior change. A caller that inspected StreamCommand's
    returned argv for the prompt text sees a different shape now. The known
    downstream consumer is agentic-toolkit, currently pinning this
    repository at v0.9.0.
  • Governed by gt 2.1.1 (up from 2.0.0): .github/workflows/ci-orchestration.yml
    gains a lydite coverage-baseline job, and the managed lydite-clearance
    workflow is renamed to gt-lydite-clearance.yml.

claudecode:

  • Implements Disallower, emitting --disallowedTools as one
    comma-joined argv element, the same shape --allowedTools already uses.
  • A bare * is accepted on the deny-list, unlike the allowlist: denying
    every tool is a coherent thing to ask for, where granting every tool
    under the guise of a restriction is refused.
  • --disallowedTools takes precedence over both the allowlist and the
    permission mode — a denied tool stays denied even under
    bypassPermissions.
  • The prompt travels on Invocation.Stdin instead of as the value of -p;
    -p itself stays in argv so claude still runs non-interactively.

codex:

  • Does not implement Disallower. Its nearest analogue,
    features.multi_agent, is a single switch over five tools at once, not
    a per-tool control, so a Disallower built on it could only honor a
    couple of hardcoded names and silently refuse the rest. A non-empty
    DisallowedTools is refused outright with ErrDisallowUnsupported,
    exactly like AllowedTools today.
  • The prompt travels on Invocation.Stdin instead of as the trailing
    positional argument to codex exec. It is dropped from argv entirely
    rather than replaced with -, since codex exec appends piped stdin as
    an extra <stdin> block rather than treating it as the prompt when a
    positional is also given.

agentictest:

  • Fake captures what was piped to its standard input, read back with the
    new Fake.Stdin(t), kept in its own file separate from the existing
    argv/env record so a prompt containing newlines or arg:/ENV-prefixed
    lines can't corrupt either.
  • A new IgnoreStdin field makes the fake never read its stdin, for
    testing a child that exits or stalls while the driver still has a
    payload left to write.

Full changelog: v0.9.1...v0.10.0