Evidence and limitations
A permission explanation is useful only when its evidence reaches the claimed boundary. This part combines source reading, two runs of existing focused tests, a separate private scenario report executed by Main, and an isolated installed-CLI configuration observation. Those are four distinguishable evidence sources, not one end-to-end product test.
Source snapshot and exact anchors
The new permissions source snapshot is dated 30 August 2026. Older Memory, Tan, Extension, and Continuity reports retain their original dates and qualifications. A shared version string does not establish identical custom APIs or behavior across installations.
| Subject | Supplied source anchors |
|---|---|
| Declaration and loop contracts | packages/agent/src/types.ts — ToolTier, ToolApprovalDecision, ToolApproval, AgentLoopConfig.beforeToolCall |
| Resolution and provenance | packages/coding-agent/src/tools/approval.ts — normalizeDecision, normalizePolicy, resolveToolTier, resolveApproval, requiresApproval, denyError |
| Per-call gate and forwarding | packages/coding-agent/src/extensibility/extensions/wrapper.ts — ExtensionToolWrapper.execute, approvalArgs, computerSafetyChecks |
| Runner/UI and handler behavior | packages/coding-agent/src/extensibility/extensions/runner.ts — initialize, hasUI, emitToolCall, marker methods, preview waiter, invokeNativeTool |
| Approval event and UI types | packages/coding-agent/src/extensibility/extensions/types.ts — ToolApprovalRequestedEvent, ToolApprovalResolvedEvent, ExtensionUIContext |
| Shell classification | packages/coding-agent/src/tools/bash.ts — BashTool.approval, ordered-rule helpers, CRITICAL_BASH_PATTERNS |
| Path/device classification | packages/coding-agent/src/tools/write.ts — WriteTool.approval, execute; tools/xdev.ts — resolveXdevTool, parseDeviceArgs, dispatchXdevTool; tools/path-utils.ts — pathTargetsSsh, resolveFileWriteApprovalTier |
| Nonuniform read effects | packages/coding-agent/src/tools/read.ts — ReadTool; tools/grep.ts — GrepTool; tools/hub/index.ts — hubApproval, HubTool.execute; tools/manage-skill.ts — ManageSkillTool; tools/eval.ts — EvalTool |
| Configuration and launch | packages/coding-agent/src/config/settings.ts — Settings; config/settings-schema.ts — approval settings; commands/config.ts — Config.run; cli/args.ts — parseArgs; cli/flag-tables.ts — approval setters; main.ts — runRootCommand, buildSessionOptions; sdk.ts — session/context construction |
| Protocol and print hosts | packages/coding-agent/src/modes/rpc/rpc-mode.ts — runRpcMode, select/control helpers; modes/acp/acp-agent.ts — createAcpExtensionUiContext, #configureExtensions; modes/runtime-init.ts — initializeExtensions; modes/print-mode.ts — runPrintMode; modes/controllers/extension-ui-controller.ts — ExtensionUiController |
| Child construction | packages/coding-agent/src/task/executor.ts — createSubagentSettings, runSubprocess; modes/controllers/tan-command-controller.ts — TanCommandController.start |
| Later OS/host seam | packages/coding-agent/src/tools/file-write-fallback.ts — write/delete fallback helpers and error classifier; tools/path-utils.ts — resolveSyscallTarget |
Paths abbreviated within a table cell retain that cell’s packages/coding-agent/src/ prefix. The fixtures supply line references for selected anchors: approval lines 104–233; wrapper lines 177–346; bash lines 264–300 and 553–579; write lines 515–560 and 1104–1205; xdev lines 406–474. These are supplied snapshot references, not newly measured line numbers.
Implementation takes precedence over broad comments. In particular, a comment calling coordination operations read-only cannot override hubApproval() assigning read tier to cancellation and messaging. A stale UI comment cannot override RPC adapter construction.
Recorded evidence: existing focused tests
proof/existing-tests.json records 96 passes, zero failures, 230 assertions across four files:
packages/coding-agent/test/tools/approval.test.ts;packages/coding-agent/test/tools/approval-mode.test.ts;packages/coding-agent/test/tools/ssh-url-approval-gate.test.ts;packages/coding-agent/test/tools/file-write-fallback.test.ts.
proof/additional-tests.json records a separate run of 105 passes, zero failures, 362 assertions across two files:
packages/coding-agent/test/write-xdev-dispatch.test.ts;packages/coding-agent/test/extensions-runner.test.ts.
These are 201 passing existing tests in two runs. They are not one newly rerun aggregate of earlier workbook suites. The existing tests include actual local tool and file contracts as well as injected seams; they should not all be described as inert classification cases. SSH-shaped calls in the dedicated gate tests are rejected before connection. File-permission fixtures do not supply a real elevated broker.
Recorded evidence: the separate private scenario report
After Main’s execution, proof/report.json reports passed: true: 46 executed cases, 46 passes, zero failures, four separately labeled source-only items, ten inert tool executions, and one injected denied-primitive attempt. The launcher reports exit code zero and no timeout.
| Public fixture | Executed cases | Meaning of the executed route |
|---|---|---|
source-workbooks/permissions/site/examples/approval-desk/cases.json | 22 | Actual resolver calls, including actual BashTool declarations; no bash execution. |
source-workbooks/permissions/site/examples/dispatch-desk/cases.json | 9 | Actual write/device dispatch and wrappers around a fictional in-memory executor. |
source-workbooks/permissions/site/examples/boundary-desk/cases.json | 15 | Wrapper responses, RPC helpers, synthetic safety metadata, and a denied primitive/error classifier. |
The report captures the exact fixture bytes and their supplied hashes. The public fixtures still describe authored expected outcomes; reading their expected fields is not itself execution evidence. The separate report is what records the completed checks.
The earlier proof/report-contract.json label READY_TO_RUN_NOT_EXECUTED_BY_AUTHOR is historical preparation state. The completed report supersedes it for these 46 named cases only. It does not turn its four source-only items into executed scenarios.
The private runner did not launch a provider, real shell command, SSH route, real remote device, auth store, privileged broker, or desktop input operation. Its tool counters mean in-memory ledger appends. Its denied writer throws before placing bytes. Full runRpcMode() initialization, actual runner UI construction, and a real client display were not exercised by this scenario harness.
Recorded evidence: installed configuration CLI
proof/cli-config-proof.json records the installed omp/18.0.7 set/get JSON roundtrip in an owned named profile and empty temporary cwd. It establishes the shown output objects and saved YAML, not effective policy in a live session. The combined launch-flag behavior is source-backed; the injected autoApprove cases verify the wrapper half separately.
No personal settings, credentials, private memory, hidden reasoning, or unrelated session material is needed for the public practice route. Private runner contents and generated private reports are not additional downloadable workbook exercises.
What remains unproved
No supplied result establishes physical keyboard behavior, every TUI/ACP/RPC capability, actual provider tool delivery, remote SSH permission, durable privileged writing, a full OS sandbox, or blanket cross-process enforcement. Source hashes identify bytes; they do not prove that every branch in a file executed.
The selected pack does not provide the complete live session inheritance/revival implementation or a reader’s current child context. Configuration inspection does not fill that gap. Likewise, a nested replacement’s tier report does not make every returned argument field a final-input record.
The finished manuscript and its editorial connections add explanations, not new runtime results. Conversion, catalog generation, browser behavior, preservation of existing routes, and publication require the owning publisher’s separate verification; no such action is asserted here.
Final paper checkpoint: assign these claims to their evidence: the mode matrix, two prompts for an explicit device policy, Tan’s initial helper mode, the JSON config getter shape, and a working physical approval dialog. Worked answer: recorded resolver cases; recorded dispatch case; supplied source construction; isolated CLI report; not established by this evidence. That last answer is a successful boundary judgment, not an incomplete lesson.
Tool permissions and approvals · Source chapter: permissions/evidence-and-limitations. Original evidence remains scoped to its recorded snapshot.