fix(agent): contain model deny rules and correlate workflow events - #49
Conversation
Model permission deny rules now also apply to subagent model overrides coming from agent profiles and from resume or retry, not only to models named in tool arguments; a denied override falls back to the parent agent's model. Subagent lifecycle events carry the workflow name on start, completion and failure, and suspension events carry both the workflow run id and name, so clients can correlate every event without caching the spawn event.
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 6 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (6)
Comment |
commit: |
|
@coderabbitai review |
|
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @pythoughts/pythinker-code@0.14.0 ### Minor Changes - [#51](#51) [`c8cdcc7`](c8cdcc7) - `/workflow save` accepts `--personal` to save into the home skills directory, resolves the repository root when saving from a subdirectory so the saved skill is discoverable, and persists the workflow size guideline into the saved skill. ### Patch Changes - [#46](#46) [`bceff21`](bceff21) - Fix `pythinker doctor` crashing on native installs, and report the last recorded update outcome. - [#49](#49) [`f35061e`](f35061e) - Model permission deny rules now also apply to subagent model overrides coming from agent profiles and from resume or retry, not only to models named in tool arguments; a denied override falls back to the parent agent's model. - [#46](#46) [`bceff21`](bceff21) - Stop reporting an update as installed when the executable did not change; the version is checked after the installer finishes and a mismatch is recorded as a failure with the reason. - [#46](#46) [`bceff21`](bceff21) - Show download progress under the prompt while a Windows update installs, instead of nothing until it finishes. - [#46](#46) [`bceff21`](bceff21) - Fix automatic updates on Windows for npm, pnpm, and yarn installs, which failed to start at all. - [#50](#50) [`38e3504`](38e3504) - Record the origin of the prompt that entered Dynamic Workflow mode, so a fan-out started by a scheduled job or hook is attributable in the session records. - [#49](#49) [`f35061e`](f35061e) - Subagent lifecycle events now carry the workflow name on start, completion and failure, and suspension events carry both the workflow run id and name, so clients can correlate every event without caching the spawn event. ## pythinker-code@0.9.0 ### Minor Changes - [#48](#48) [`17967df`](17967df) - Combine permission mode, plan mode, and thinking effort into one composer menu, and answer approval prompts with number keys. - [#48](#48) [`17967df`](17967df) - Add a config hub page that shows models, providers, MCP servers, the local config file, and extension settings in one place. - [#48](#48) [`17967df`](17967df) - The extension UI now follows the editor color theme, including light, dark, and high-contrast themes. - [#48](#48) [`17967df`](17967df) - Add a status bar indicator, quick-fix code actions, terminal and editor context menu entries, a getting-started walkthrough, and a new-conversation keybinding. ### Patch Changes - [#48](#48) [`17967df`](17967df) - Render long conversations with a virtualized list, fix control overlap at narrow sidebar widths, and make sign-out work from the command palette. - Updated dependencies [[`c8cdcc7`](c8cdcc7)]: - @pythoughts/pythinker-code-sdk@0.15.0 ## @pythoughts/pythinker-code-sdk@0.15.0 ### Minor Changes - [#51](#51) [`c8cdcc7`](c8cdcc7) - The saved-workflow write helper now takes the working directory and resolves the repository root itself, saved workflows can carry a size guideline, and the workflow size guideline resolver is exported. Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Related Issue
No linked issue — the problem is explained below.
Problem
Two gaps in the subagent host:
Agent(model:x)orDynamicWorkflow(model:x)fires at approval only when the model appears in the tool arguments. A subagent model override coming from an agent profile, or re-resolved on resume/retry, never passes through approval — so it rode past the deny rule.What changed
PermissionManager.deniesModelOverridere-checksmodel:-namespace deny rules at the spawn path, where every override lands. Only rules whose argument pattern targets themodel:namespace are consulted, so a rule keyed on another subject (profile name, plan digest) is not re-interpreted against a model-only subject list. A denied override falls back to the parent agent's model instead of failing the spawn.workflowName, and suspension events carry bothworkflowRunIdandworkflowName(protocol types and zod schemas updated; all fields optional, so this is wire-compatible).This fits the codebase because the spawn path (
childModelConfig) is the single point every override flows through — one containment point instead of patching each override source.Tests: 259 new lines in the subagent host suite covering both the deny containment (profile override, resume, retry, fallback) and the event field pass-through.
Checklist
gen-changesetsskill, or this PR needs no changeset.gen-docsskill, or this PR needs no doc update. (Internal permission/event plumbing; no user-facing docs affected.)