OMP Workbook

Read the source. Follow the evidence.

Evidence and limitations

A permission explanation is useful only when its evidence reaches the claimed boundary. This part combines source reading, two runs of existing focused tests, a separate private scenario report executed by Main, and an isolated installed-CLI configuration observation. Those are four distinguishable evidence sources, not one end-to-end product test.

Source snapshot and exact anchors

The new permissions source snapshot is dated 30 August 2026. Older Memory, Tan, Extension, and Continuity reports retain their original dates and qualifications. A shared version string does not establish identical custom APIs or behavior across installations.

SubjectSupplied source anchors
Declaration and loop contractspackages/agent/src/types.ts — ToolTier, ToolApprovalDecision, ToolApproval, AgentLoopConfig.beforeToolCall
Resolution and provenancepackages/coding-agent/src/tools/approval.ts — normalizeDecision, normalizePolicy, resolveToolTier, resolveApproval, requiresApproval, denyError
Per-call gate and forwardingpackages/coding-agent/src/extensibility/extensions/wrapper.ts — ExtensionToolWrapper.execute, approvalArgs, computerSafetyChecks
Runner/UI and handler behaviorpackages/coding-agent/src/extensibility/extensions/runner.ts — initialize, hasUI, emitToolCall, marker methods, preview waiter, invokeNativeTool
Approval event and UI typespackages/coding-agent/src/extensibility/extensions/types.ts — ToolApprovalRequestedEvent, ToolApprovalResolvedEvent, ExtensionUIContext
Shell classificationpackages/coding-agent/src/tools/bash.ts — BashTool.approval, ordered-rule helpers, CRITICAL_BASH_PATTERNS
Path/device classificationpackages/coding-agent/src/tools/write.ts — WriteTool.approval, execute; tools/xdev.ts — resolveXdevTool, parseDeviceArgs, dispatchXdevTool; tools/path-utils.ts — pathTargetsSsh, resolveFileWriteApprovalTier
Nonuniform read effectspackages/coding-agent/src/tools/read.ts — ReadTool; tools/grep.ts — GrepTool; tools/hub/index.ts — hubApproval, HubTool.execute; tools/manage-skill.ts — ManageSkillTool; tools/eval.ts — EvalTool
Configuration and launchpackages/coding-agent/src/config/settings.ts — Settings; config/settings-schema.ts — approval settings; commands/config.ts — Config.run; cli/args.ts — parseArgs; cli/flag-tables.ts — approval setters; main.ts — runRootCommand, buildSessionOptions; sdk.ts — session/context construction
Protocol and print hostspackages/coding-agent/src/modes/rpc/rpc-mode.ts — runRpcMode, select/control helpers; modes/acp/acp-agent.ts — createAcpExtensionUiContext, #configureExtensions; modes/runtime-init.ts — initializeExtensions; modes/print-mode.ts — runPrintMode; modes/controllers/extension-ui-controller.ts — ExtensionUiController
Child constructionpackages/coding-agent/src/task/executor.ts — createSubagentSettings, runSubprocess; modes/controllers/tan-command-controller.ts — TanCommandController.start
Later OS/host seampackages/coding-agent/src/tools/file-write-fallback.ts — write/delete fallback helpers and error classifier; tools/path-utils.ts — resolveSyscallTarget

Paths abbreviated within a table cell retain that cell’s packages/coding-agent/src/ prefix. The fixtures supply line references for selected anchors: approval lines 104–233; wrapper lines 177–346; bash lines 264–300 and 553–579; write lines 515–560 and 1104–1205; xdev lines 406–474. These are supplied snapshot references, not newly measured line numbers.

Implementation takes precedence over broad comments. In particular, a comment calling coordination operations read-only cannot override hubApproval() assigning read tier to cancellation and messaging. A stale UI comment cannot override RPC adapter construction.

Recorded evidence: existing focused tests

proof/existing-tests.json records 96 passes, zero failures, 230 assertions across four files:

  • packages/coding-agent/test/tools/approval.test.ts;
  • packages/coding-agent/test/tools/approval-mode.test.ts;
  • packages/coding-agent/test/tools/ssh-url-approval-gate.test.ts;
  • packages/coding-agent/test/tools/file-write-fallback.test.ts.

proof/additional-tests.json records a separate run of 105 passes, zero failures, 362 assertions across two files:

  • packages/coding-agent/test/write-xdev-dispatch.test.ts;
  • packages/coding-agent/test/extensions-runner.test.ts.

These are 201 passing existing tests in two runs. They are not one newly rerun aggregate of earlier workbook suites. The existing tests include actual local tool and file contracts as well as injected seams; they should not all be described as inert classification cases. SSH-shaped calls in the dedicated gate tests are rejected before connection. File-permission fixtures do not supply a real elevated broker.

Recorded evidence: the separate private scenario report

After Main’s execution, proof/report.json reports passed: true: 46 executed cases, 46 passes, zero failures, four separately labeled source-only items, ten inert tool executions, and one injected denied-primitive attempt. The launcher reports exit code zero and no timeout.

Public fixtureExecuted casesMeaning of the executed route
source-workbooks/permissions/site/examples/approval-desk/cases.json22Actual resolver calls, including actual BashTool declarations; no bash execution.
source-workbooks/permissions/site/examples/dispatch-desk/cases.json9Actual write/device dispatch and wrappers around a fictional in-memory executor.
source-workbooks/permissions/site/examples/boundary-desk/cases.json15Wrapper responses, RPC helpers, synthetic safety metadata, and a denied primitive/error classifier.

The report captures the exact fixture bytes and their supplied hashes. The public fixtures still describe authored expected outcomes; reading their expected fields is not itself execution evidence. The separate report is what records the completed checks.

The earlier proof/report-contract.json label READY_TO_RUN_NOT_EXECUTED_BY_AUTHOR is historical preparation state. The completed report supersedes it for these 46 named cases only. It does not turn its four source-only items into executed scenarios.

The private runner did not launch a provider, real shell command, SSH route, real remote device, auth store, privileged broker, or desktop input operation. Its tool counters mean in-memory ledger appends. Its denied writer throws before placing bytes. Full runRpcMode() initialization, actual runner UI construction, and a real client display were not exercised by this scenario harness.

Recorded evidence: installed configuration CLI

proof/cli-config-proof.json records the installed omp/18.0.7 set/get JSON roundtrip in an owned named profile and empty temporary cwd. It establishes the shown output objects and saved YAML, not effective policy in a live session. The combined launch-flag behavior is source-backed; the injected autoApprove cases verify the wrapper half separately.

No personal settings, credentials, private memory, hidden reasoning, or unrelated session material is needed for the public practice route. Private runner contents and generated private reports are not additional downloadable workbook exercises.

What remains unproved

No supplied result establishes physical keyboard behavior, every TUI/ACP/RPC capability, actual provider tool delivery, remote SSH permission, durable privileged writing, a full OS sandbox, or blanket cross-process enforcement. Source hashes identify bytes; they do not prove that every branch in a file executed.

The selected pack does not provide the complete live session inheritance/revival implementation or a reader’s current child context. Configuration inspection does not fill that gap. Likewise, a nested replacement’s tier report does not make every returned argument field a final-input record.

The finished manuscript and its editorial connections add explanations, not new runtime results. Conversion, catalog generation, browser behavior, preservation of existing routes, and publication require the owning publisher’s separate verification; no such action is asserted here.

Final paper checkpoint: assign these claims to their evidence: the mode matrix, two prompts for an explicit device policy, Tan’s initial helper mode, the JSON config getter shape, and a working physical approval dialog. Worked answer: recorded resolver cases; recorded dispatch case; supplied source construction; isolated CLI report; not established by this evidence. That last answer is a successful boundary judgment, not an incomplete lesson.

Tool permissions and approvals · Source chapter: permissions/evidence-and-limitations. Original evidence remains scoped to its recorded snapshot.

Read this chapter as Markdown

Your lesson ticks

A self-reported reading checklist, not proof of real OMP behavior. Only these ticks are saved in this browser. Reading a milestone does not resume, fork, reset or export a session.

Chapters I have worked through
Start here 1
Sessions, resets, and reviewable history 19
Memory and reusable knowledge 14
Tangent work and live control 17
Tool permissions and approvals 15
Extensions inside those boundaries 23
Connections and next steps 8
0 of 97 checked

Checklist saving needs JavaScript and available browser storage.