Skip to content

fix(agent): contain model deny rules and correlate workflow events - #49

Merged
elkaix merged 1 commit into
mainfrom
fix/subagent-deny-and-event-correlation
Aug 9, 2026
Merged

fix(agent): contain model deny rules and correlate workflow events#49
elkaix merged 1 commit into
mainfrom
fix/subagent-deny-and-event-correlation

Conversation

@elkaix

@elkaix elkaix commented Aug 9, 2026

Copy link
Copy Markdown
Contributor

Related Issue

No linked issue — the problem is explained below.

Problem

Two gaps in the subagent host:

  1. Model deny rules did not contain profile-sourced overrides. A deny rule such as Agent(model:x) or DynamicWorkflow(model:x) fires at approval only when the model appears in the tool arguments. A subagent model override coming from an agent profile, or re-resolved on resume/retry, never passes through approval — so it rode past the deny rule.
  2. Subagent lifecycle events could not be correlated without caching. Only the start event carried workflow identity, so a client that missed or dropped the spawn event could not attribute completion, failure, or suspension events to a workflow.

What changed

  • PermissionManager.deniesModelOverride re-checks model:-namespace deny rules at the spawn path, where every override lands. Only rules whose argument pattern targets the model: namespace are consulted, so a rule keyed on another subject (profile name, plan digest) is not re-interpreted against a model-only subject list. A denied override falls back to the parent agent's model instead of failing the spawn.
  • Subagent completion and failure events now carry workflowName, and suspension events carry both workflowRunId and workflowName (protocol types and zod schemas updated; all fields optional, so this is wire-compatible).

This fits the codebase because the spawn path (childModelConfig) is the single point every override flows through — one containment point instead of patching each override source.

Tests: 259 new lines in the subagent host suite covering both the deny containment (profile override, resume, retry, fallback) and the event field pass-through.

Checklist

  • I have read the CONTRIBUTING document.
  • I have linked a related issue, or explained the problem above.
  • I have added tests that prove my feature works.
  • Ran gen-changesets skill, or this PR needs no changeset.
  • Ran gen-docs skill, or this PR needs no doc update. (Internal permission/event plumbing; no user-facing docs affected.)

Model permission deny rules now also apply to subagent model overrides
coming from agent profiles and from resume or retry, not only to models
named in tool arguments; a denied override falls back to the parent
agent's model. Subagent lifecycle events carry the workflow name on
start, completion and failure, and suspension events carry both the
workflow run id and name, so clients can correlate every event without
caching the spawn event.
@coderabbitai

coderabbitai Bot commented Aug 9, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in: 6 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: f2fe1daa-e82d-4c30-befa-c1ba57384331

📥 Commits

Reviewing files that changed from the base of the PR and between 17967df and 6157e1e.

📒 Files selected for processing (6)
  • .changeset/subagent-model-deny-containment.md
  • .changeset/workflow-event-correlation.md
  • packages/agent-core/src/agent/permission/index.ts
  • packages/agent-core/src/session/subagent-host.ts
  • packages/agent-core/test/session/subagent-host.test.ts
  • packages/protocol/src/events.ts

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Aug 9, 2026

Copy link
Copy Markdown
pnpm dlx https://pkg.pr.new/@pythoughts/pythinker-code@6157e1e
npx https://pkg.pr.new/@pythoughts/pythinker-code@6157e1e

commit: 6157e1e

@elkaix

elkaix commented Aug 9, 2026

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 9, 2026

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@elkaix
elkaix merged commit f35061e into main Aug 9, 2026
12 checks passed
@elkaix
elkaix deleted the fix/subagent-deny-and-event-correlation branch August 9, 2026 18:41
elkaix pushed a commit that referenced this pull request Aug 9, 2026
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @pythoughts/pythinker-code@0.14.0

### Minor Changes

- [#51](#51)
[`c8cdcc7`](c8cdcc7)
- `/workflow save` accepts `--personal` to save into the home skills
directory, resolves the repository root when saving from a subdirectory
so the saved skill is discoverable, and persists the workflow size
guideline into the saved skill.

### Patch Changes

- [#46](#46)
[`bceff21`](bceff21)
- Fix `pythinker doctor` crashing on native installs, and report the
last recorded update outcome.

- [#49](#49)
[`f35061e`](f35061e)
- Model permission deny rules now also apply to subagent model overrides
coming from agent profiles and from resume or retry, not only to models
named in tool arguments; a denied override falls back to the parent
agent's model.

- [#46](#46)
[`bceff21`](bceff21)
- Stop reporting an update as installed when the executable did not
change; the version is checked after the installer finishes and a
mismatch is recorded as a failure with the reason.

- [#46](#46)
[`bceff21`](bceff21)
- Show download progress under the prompt while a Windows update
installs, instead of nothing until it finishes.

- [#46](#46)
[`bceff21`](bceff21)
- Fix automatic updates on Windows for npm, pnpm, and yarn installs,
which failed to start at all.

- [#50](#50)
[`38e3504`](38e3504)
- Record the origin of the prompt that entered Dynamic Workflow mode, so
a fan-out started by a scheduled job or hook is attributable in the
session records.

- [#49](#49)
[`f35061e`](f35061e)
- Subagent lifecycle events now carry the workflow name on start,
completion and failure, and suspension events carry both the workflow
run id and name, so clients can correlate every event without caching
the spawn event.
## pythinker-code@0.9.0

### Minor Changes

- [#48](#48)
[`17967df`](17967df)
- Combine permission mode, plan mode, and thinking effort into one
composer menu, and answer approval prompts with number keys.

- [#48](#48)
[`17967df`](17967df)
- Add a config hub page that shows models, providers, MCP servers, the
local config file, and extension settings in one place.

- [#48](#48)
[`17967df`](17967df)
- The extension UI now follows the editor color theme, including light,
dark, and high-contrast themes.

- [#48](#48)
[`17967df`](17967df)
- Add a status bar indicator, quick-fix code actions, terminal and
editor context menu entries, a getting-started walkthrough, and a
new-conversation keybinding.

### Patch Changes

- [#48](#48)
[`17967df`](17967df)
- Render long conversations with a virtualized list, fix control overlap
at narrow sidebar widths, and make sign-out work from the command
palette.

- Updated dependencies
[[`c8cdcc7`](c8cdcc7)]:
  - @pythoughts/pythinker-code-sdk@0.15.0
## @pythoughts/pythinker-code-sdk@0.15.0

### Minor Changes

- [#51](#51)
[`c8cdcc7`](c8cdcc7)
- The saved-workflow write helper now takes the working directory and
resolves the repository root itself, saved workflows can carry a size
guideline, and the workflow size guideline resolver is exported.

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant