## Evidence and limitations

A permission explanation is useful only when its evidence reaches the claimed boundary\.&#32;This part combines source reading\,&#32;two runs of existing focused tests\,&#32;a separate private scenario report executed by Main\,&#32;and an isolated installed\-CLI configuration observation\.&#32;Those are four distinguishable evidence sources\,&#32;not one end\-to\-end product test\.

### Source snapshot and exact anchors

The new permissions source snapshot is dated&#32;**30 August 2026**\.&#32;Older Memory\,&#32;Tan\,&#32;Extension\,&#32;and Continuity reports retain their original dates and qualifications\.&#32;A shared version string does not establish identical custom APIs or behavior across installations\.

| Subject | Supplied source anchors |
| --- | ---: |
| Declaration and loop contracts | `packages/agent/src/types.ts`&#32;—&#32;`ToolTier`\,&#32;`ToolApprovalDecision`\,&#32;`ToolApproval`\,&#32;`AgentLoopConfig.beforeToolCall` |
| Resolution and provenance | `packages/coding-agent/src/tools/approval.ts`&#32;—&#32;`normalizeDecision`\,&#32;`normalizePolicy`\,&#32;`resolveToolTier`\,&#32;`resolveApproval`\,&#32;`requiresApproval`\,&#32;`denyError` |
| Per\-call gate and forwarding | `packages/coding-agent/src/extensibility/extensions/wrapper.ts`&#32;—&#32;`ExtensionToolWrapper.execute`\,&#32;`approvalArgs`\,&#32;`computerSafetyChecks` |
| Runner\/UI and handler behavior | `packages/coding-agent/src/extensibility/extensions/runner.ts`&#32;—&#32;`initialize`\,&#32;`hasUI`\,&#32;`emitToolCall`\,&#32;marker methods\,&#32;preview waiter\,&#32;`invokeNativeTool` |
| Approval event and UI types | `packages/coding-agent/src/extensibility/extensions/types.ts`&#32;—&#32;`ToolApprovalRequestedEvent`\,&#32;`ToolApprovalResolvedEvent`\,&#32;`ExtensionUIContext` |
| Shell classification | `packages/coding-agent/src/tools/bash.ts`&#32;—&#32;`BashTool.approval`\,&#32;ordered\-rule helpers\,&#32;`CRITICAL_BASH_PATTERNS` |
| Path\/device classification | `packages/coding-agent/src/tools/write.ts`&#32;—&#32;`WriteTool.approval`\,&#32;`execute`\;&#32;`tools/xdev.ts`&#32;—&#32;`resolveXdevTool`\,&#32;`parseDeviceArgs`\,&#32;`dispatchXdevTool`\;&#32;`tools/path-utils.ts`&#32;—&#32;`pathTargetsSsh`\,&#32;`resolveFileWriteApprovalTier` |
| Nonuniform read effects | `packages/coding-agent/src/tools/read.ts`&#32;—&#32;`ReadTool`\;&#32;`tools/grep.ts`&#32;—&#32;`GrepTool`\;&#32;`tools/hub/index.ts`&#32;—&#32;`hubApproval`\,&#32;`HubTool.execute`\;&#32;`tools/manage-skill.ts`&#32;—&#32;`ManageSkillTool`\;&#32;`tools/eval.ts`&#32;—&#32;`EvalTool` |
| Configuration and launch | `packages/coding-agent/src/config/settings.ts`&#32;—&#32;`Settings`\;&#32;`config/settings-schema.ts`&#32;— approval settings\;&#32;`commands/config.ts`&#32;—&#32;`Config.run`\;&#32;`cli/args.ts`&#32;—&#32;`parseArgs`\;&#32;`cli/flag-tables.ts`&#32;— approval setters\;&#32;`main.ts`&#32;—&#32;`runRootCommand`\,&#32;`buildSessionOptions`\;&#32;`sdk.ts`&#32;— session\/context construction |
| Protocol and print hosts | `packages/coding-agent/src/modes/rpc/rpc-mode.ts`&#32;—&#32;`runRpcMode`\,&#32;select\/control helpers\;&#32;`modes/acp/acp-agent.ts`&#32;—&#32;`createAcpExtensionUiContext`\,&#32;`#configureExtensions`\;&#32;`modes/runtime-init.ts`&#32;—&#32;`initializeExtensions`\;&#32;`modes/print-mode.ts`&#32;—&#32;`runPrintMode`\;&#32;`modes/controllers/extension-ui-controller.ts`&#32;—&#32;`ExtensionUiController` |
| Child construction | `packages/coding-agent/src/task/executor.ts`&#32;—&#32;`createSubagentSettings`\,&#32;`runSubprocess`\;&#32;`modes/controllers/tan-command-controller.ts`&#32;—&#32;`TanCommandController.start` |
| Later OS\/host seam | `packages/coding-agent/src/tools/file-write-fallback.ts`&#32;— write\/delete fallback helpers and error classifier\;&#32;`tools/path-utils.ts`&#32;—&#32;`resolveSyscallTarget` |

Paths abbreviated within a table cell retain that cell’s&#32;`packages/coding-agent/src/`&#32;prefix\.&#32;The fixtures supply line references for selected anchors\:&#32;approval lines 104–233\;&#32;wrapper lines 177–346\;&#32;bash lines 264–300 and 553–579\;&#32;write lines 515–560 and 1104–1205\;&#32;xdev lines 406–474\.&#32;These are supplied snapshot references\,&#32;not newly measured line numbers\.

Implementation takes precedence over broad comments\.&#32;In particular\,&#32;a comment calling coordination operations read\-only cannot override&#32;`hubApproval()`&#32;assigning read tier to cancellation and messaging\.&#32;A stale UI comment cannot override RPC adapter construction\.

### Recorded evidence\:&#32;existing focused tests

`proof/existing-tests.json`&#32;records&#32;**96 passes\,&#32;zero failures\,&#32;230 assertions across four files**\:

- `packages/coding-agent/test/tools/approval.test.ts`\;
- `packages/coding-agent/test/tools/approval-mode.test.ts`\;
- `packages/coding-agent/test/tools/ssh-url-approval-gate.test.ts`\;
- `packages/coding-agent/test/tools/file-write-fallback.test.ts`\.

`proof/additional-tests.json`&#32;records a&#32;**separate run of 105 passes\,&#32;zero failures\,&#32;362 assertions across two files**\:

- `packages/coding-agent/test/write-xdev-dispatch.test.ts`\;
- `packages/coding-agent/test/extensions-runner.test.ts`\.

These are&#32;**201 passing existing tests in two runs**\.&#32;They are not one newly rerun aggregate of earlier workbook suites\.&#32;The existing tests include actual local tool and file contracts as well as injected seams\;&#32;they should not all be described as inert classification cases\.&#32;SSH\-shaped calls in the dedicated gate tests are rejected before connection\.&#32;File\-permission fixtures do not supply a real elevated broker\.

### Recorded evidence\:&#32;the separate private scenario report

After Main’s execution\,&#32;`proof/report.json`&#32;reports&#32;`passed: true`\:&#32;**46 executed cases\,&#32;46 passes\,&#32;zero failures**\,&#32;four separately labeled source\-only items\,&#32;ten inert tool executions\,&#32;and one injected denied\-primitive attempt\.&#32;The launcher reports exit code zero and no timeout\.

| Public fixture | Executed cases | Meaning of the executed route |
| --- | ---: | --- |
| `source-workbooks/permissions/site/examples/approval-desk/cases.json` | 22 | Actual resolver calls\,&#32;including actual BashTool declarations\;&#32;no bash execution\. |
| `source-workbooks/permissions/site/examples/dispatch-desk/cases.json` | 9 | Actual write\/device dispatch and wrappers around a fictional in\-memory executor\. |
| `source-workbooks/permissions/site/examples/boundary-desk/cases.json` | 15 | Wrapper responses\,&#32;RPC helpers\,&#32;synthetic safety metadata\,&#32;and a denied primitive\/error classifier\. |

The report captures the exact fixture bytes and their supplied hashes\.&#32;The public fixtures still describe authored expected outcomes\;&#32;reading their&#32;`expected`&#32;fields is not itself execution evidence\.&#32;The separate report is what records the completed checks\.

The earlier&#32;`proof/report-contract.json`&#32;label&#32;`READY_TO_RUN_NOT_EXECUTED_BY_AUTHOR`&#32;is historical preparation state\.&#32;The completed report supersedes it for these 46 named cases only\.&#32;It does not turn its four source\-only items into executed scenarios\.

The private runner did not launch a provider\,&#32;real shell command\,&#32;SSH route\,&#32;real remote device\,&#32;auth store\,&#32;privileged broker\,&#32;or desktop input operation\.&#32;Its tool counters mean in\-memory ledger appends\.&#32;Its denied writer throws before placing bytes\.&#32;Full&#32;`runRpcMode()`&#32;initialization\,&#32;actual runner UI construction\,&#32;and a real client display were not exercised by this scenario harness\.

### Recorded evidence\:&#32;installed configuration CLI

`proof/cli-config-proof.json`&#32;records the installed&#32;`omp/18.0.7`&#32;set\/get JSON roundtrip in an owned named profile and empty temporary cwd\.&#32;It establishes the shown output objects and saved YAML\,&#32;not effective policy in a live session\.&#32;The combined launch\-flag behavior is source\-backed\;&#32;the injected autoApprove cases verify the wrapper half separately\.

No personal settings\,&#32;credentials\,&#32;private memory\,&#32;hidden reasoning\,&#32;or unrelated session material is needed for the public practice route\.&#32;Private runner contents and generated private reports are not additional downloadable workbook exercises\.

### What remains unproved

No supplied result establishes physical keyboard behavior\,&#32;every TUI\/ACP\/RPC capability\,&#32;actual provider tool delivery\,&#32;remote SSH permission\,&#32;durable privileged writing\,&#32;a full OS sandbox\,&#32;or blanket cross\-process enforcement\.&#32;Source hashes identify bytes\;&#32;they do not prove that every branch in a file executed\.

The selected pack does not provide the complete live session inheritance\/revival implementation or a reader’s current child context\.&#32;Configuration inspection does not fill that gap\.&#32;Likewise\,&#32;a nested replacement’s tier report does not make every returned argument field a final\-input record\.

The finished manuscript and its editorial connections add explanations\,&#32;not new runtime results\.&#32;Conversion\,&#32;catalog generation\,&#32;browser behavior\,&#32;preservation of existing routes\,&#32;and publication require the owning publisher’s separate verification\;&#32;no such action is asserted here\.

**Final paper checkpoint\:**&#32;assign these claims to their evidence\:&#32;the mode matrix\,&#32;two prompts for an explicit device policy\,&#32;Tan’s initial helper mode\,&#32;the JSON config getter shape\,&#32;and a working physical approval dialog\.&#32;**Worked answer\:**&#32;recorded resolver cases\;&#32;recorded dispatch case\;&#32;supplied source construction\;&#32;isolated CLI report\;&#32;not established by this evidence\.&#32;That last answer is a successful boundary judgment\,&#32;not an incomplete lesson\.
