subagent: inherit parent sandbox/approval overrides in in-process children

Per-session policy overrides (sandbox/mode, approval/policy) never crossed
the delegation boundary: a spawn child of a read-only-switched parent ran
under the wider deployment default, and a fork child missed any switch made
after its seed boundary — delegation was a bypass channel for a user's
tightening.

The in-process driver now snapshots the delegating parent's override chain
and stamps it onto the child through the canonical write paths
(SandboxPolicyService.inheritOverride / ApprovalService.inheritOverride),
anchored inside the child's first turn via a one-shot agent/prompt-submit
listener: turn-enclosed (durable), ahead of the first request (an inherited
'never' reaches the child's first system prompt), and positioned after any
stale fork-seed switch so the ordinary last-event-wins fold resolves it.
Only overrides are copied — an unswitched parent stamps nothing and the
child follows the live deployment default; both services are consumed
opportunistically, so compositions without them delegate unchanged. Nesting
composes by construction (each stamp folds the already-stamped parent log).

Evidence: inheritance.spec.ts drives scripted-model children into the real
dsh-fs-sandbox fence through the real write tool (disk-state + denial-marker
assertions; spawn, stale-seed fork, grandchild, escalation fail-closed, and
no-stamp guards), inheritOverride contract tests in both service suites, and
the recorded subagent-sandbox-inheritance ACP snapshot (read-only preset →
delegate → child denied, replayed keylessly).

See .agents/notes/implemented/feature/2026-07-25-subagent-policy-inheritance.md.
This commit is contained in:
kingwl
2026-07-25 04:06:19 +08:00
parent 690c53dc03
commit 669771097d
29 changed files with 2168 additions and 7 deletions

View File

@@ -6,7 +6,7 @@ Each request must belong to an open agent turn. The service appends a paired `ap
Answerers are `approval/request` waterfall listeners. Return an outcome to answer for an owned agent or call `next()` to delegate. Agent-scoped listeners receive only that agent's requests; compose one terminal answerer per deployment because sibling listener order is not a policy priority mechanism. The ACP bridge is the shipped human answerer.
`ApprovalPolicy` is `'ask'` or `'never'`. The effective value is the last `approval/policy` event, falling back to config; `setApprovalPolicy()` is the write path. `'never'` rejects before interactive dispatch and is the only policy stated in the prompt. Switches produce at most one coalesced notice, attributed to the user when the override follows the last `request/header` and to operator/config otherwise.
`ApprovalPolicy` is `'ask'` or `'never'`. The effective value is the last `approval/policy` event, falling back to config; `setApprovalPolicy()` is the write path. `'never'` rejects before interactive dispatch and is the only policy stated in the prompt. Switches produce at most one coalesced notice, attributed to the user when the override follows the last `request/header` and to operator/config otherwise. `ctx.approval.inheritOverride(parent, child)` stamps a parent session's override (never the configured default) onto a child session through that write path — the in-process subagent driver calls it inside the child's first turn so a `'never'` parent cannot mint prompting children ([rationale](../../../.agents/notes/implemented/feature/2026-07-25-subagent-policy-inheritance.md)).
The tools pipeline routes `ask` decisions through this seam and fails closed when it is absent; the sandboxed bash tool also uses it for escalated retries. The ACP bridge is the shipped human answerer for calls it owns. Audit events remain log-only, so the model sees only the asking consumer's result. See the [approval-seam Agent Note](../../../.agents/notes/implemented/feature/2026-07-06-approval-seam.md) and [sandbox Agent Note](../../../.agents/notes/implemented/feature/2026-07-06-sandbox.md).

View File

@@ -326,6 +326,24 @@ export class ApprovalService extends Service {
return effectiveApprovalPolicy(session.events) ?? this.config.policy ?? 'ask'
}
/**
* Stamp the parent's approval-policy OVERRIDE onto a child session through
* the canonical write path — the delegation-inheritance step: a `'never'`
* (headless/CI) parent must not mint children that fall back to a prompting
* default. Only the override chain is copied: an unswitched parent stamps
* nothing, so the child keeps following the LIVE configured default. A
* child whose log (e.g. a fork seed) already folds to the inherited policy
* is left untouched. Callers must append inside an open child turn — a bare
* between-turn event is crash-tail garbage on reload.
* @param parent - the delegating session whose effective override is read.
* @param child - the child session the override is appended to.
*/
inheritOverride(parent: Session, child: Session): void {
const inherited = effectiveApprovalPolicy(parent.events)
if (inherited === undefined || effectiveApprovalPolicy(child.events) === inherited) return
setApprovalPolicy(child, inherited)
}
/**
* Dispatch the waterfall, contained and raced against the request signal.
* @param req - the borrowed public request.

View File

@@ -576,3 +576,46 @@ describe('approval policy (the approval/policy fold)', () => {
expect(afterDispose.injected).toEqual([])
})
})
describe('inheritOverride (parent → child stamping)', () => {
const policyEvents = (session: Session) => session.events.filter(e => e.type === 'approval/policy')
function bareSession(id: string): Session {
return new Session(SessionId(id))
}
it('stamps the parent LAST override onto the child through the canonical write path', async () => {
const ctx = await mounted()
const parent = bareSession('sess-appr-inherit-parent')
const child = bareSession('sess-appr-inherit-child')
setApprovalPolicy(parent, 'never')
ctx.approval.inheritOverride(parent, child)
const stamped = policyEvents(child)
expect(stamped).toHaveLength(1)
expect(stamped[0]?.data).toEqual({ policy: 'never' })
})
it('appends NOTHING when the parent never switched (the configured default must stay live)', async () => {
const ctx = await mounted()
const parent = bareSession('sess-appr-default-parent')
const child = bareSession('sess-appr-default-child')
ctx.approval.inheritOverride(parent, child)
expect(child.events).toHaveLength(0)
})
it('skips the append when the child already folds to the inherited policy (fork-seed dedup)', async () => {
const ctx = await mounted()
const parent = bareSession('sess-appr-dedup-parent')
const child = bareSession('sess-appr-dedup-child')
setApprovalPolicy(parent, 'never')
setApprovalPolicy(child, 'never')
ctx.approval.inheritOverride(parent, child)
expect(policyEvents(child)).toHaveLength(1)
})
})