{ "schemaVersion": 1, "id": "approval-desk", "title": "First desk: decide which gate applies", "label": "TEACHING DATA — DO NOT EXECUTE COMMAND STRINGS OR INSTALL AS AN EXTENSION", "domain": "The fictional Cedar Seed Library; no real inventory, devices, accounts, or permissions are changed.", "executionPolicy": "These JSON files are inert cases, not a shell script or OMP configuration. The private verifier calls actual OMP resolution/wrapper code with recording UI adapters and inert executors only. Bash strings are classification data and are never passed to BashTool.execute.", "host": "Current local custom OMP source; not an upstream compatibility promise.", "proofStatus": "Expected outcomes authored from source. Execution evidence exists only in the separately generated private report; this file does not claim a run.", "sources": { "approval": "packages/coding-agent/src/tools/approval.ts:104-233", "wrapper": "packages/coding-agent/src/extensibility/extensions/wrapper.ts:177-346", "bash": "packages/coding-agent/src/tools/bash.ts:264-300,553-579", "write": "packages/coding-agent/src/tools/write.ts:515-560,1104-1205", "xdev": "packages/coding-agent/src/tools/xdev.ts:406-474", "rpc": "packages/coding-agent/src/modes/rpc/rpc-mode.ts:545-579,645-693,771-950,953-975", "runner": "packages/coding-agent/src/extensibility/extensions/runner.ts:885-891", "fallback": "packages/coding-agent/src/tools/file-write-fallback.ts:3-88,218-226,402-467" }, "cases": [ { "id": "approval-always-ask-read", "title": "Mode always-ask meets read tier", "scenario": "approval", "given": { "tool": "seed_note", "approval": "read", "mode": "always-ask" }, "expected": { "resolved": { "policy": "allow", "tier": "read", "override": false, "source": "mode" } }, "why": "Modes compare capability tiers; always-ask still allows read-tier calls.", "sourceRefs": [ "approval" ] }, { "id": "approval-always-ask-write", "title": "Mode always-ask meets write tier", "scenario": "approval", "given": { "tool": "seed_note", "approval": "write", "mode": "always-ask" }, "expected": { "resolved": { "policy": "prompt", "tier": "write", "override": false, "source": "mode" } }, "why": "Modes compare capability tiers; always-ask still allows read-tier calls.", "sourceRefs": [ "approval" ] }, { "id": "approval-always-ask-exec", "title": "Mode always-ask meets exec tier", "scenario": "approval", "given": { "tool": "seed_note", "approval": "exec", "mode": "always-ask" }, "expected": { "resolved": { "policy": "prompt", "tier": "exec", "override": false, "source": "mode" } }, "why": "Modes compare capability tiers; always-ask still allows read-tier calls.", "sourceRefs": [ "approval" ] }, { "id": "approval-write-read", "title": "Mode write meets read tier", "scenario": "approval", "given": { "tool": "seed_note", "approval": "read", "mode": "write" }, "expected": { "resolved": { "policy": "allow", "tier": "read", "override": false, "source": "mode" } }, "why": "Modes compare capability tiers; always-ask still allows read-tier calls.", "sourceRefs": [ "approval" ] }, { "id": "approval-write-write", "title": "Mode write meets write tier", "scenario": "approval", "given": { "tool": "seed_note", "approval": "write", "mode": "write" }, "expected": { "resolved": { "policy": "allow", "tier": "write", "override": false, "source": "mode" } }, "why": "Modes compare capability tiers; always-ask still allows read-tier calls.", "sourceRefs": [ "approval" ] }, { "id": "approval-write-exec", "title": "Mode write meets exec tier", "scenario": "approval", "given": { "tool": "seed_note", "approval": "exec", "mode": "write" }, "expected": { "resolved": { "policy": "prompt", "tier": "exec", "override": false, "source": "mode" } }, "why": "Modes compare capability tiers; always-ask still allows read-tier calls.", "sourceRefs": [ "approval" ] }, { "id": "approval-yolo-read", "title": "Mode yolo meets read tier", "scenario": "approval", "given": { "tool": "seed_note", "approval": "read", "mode": "yolo" }, "expected": { "resolved": { "policy": "allow", "tier": "read", "override": false, "source": "mode" } }, "why": "Modes compare capability tiers; always-ask still allows read-tier calls.", "sourceRefs": [ "approval" ] }, { "id": "approval-yolo-write", "title": "Mode yolo meets write tier", "scenario": "approval", "given": { "tool": "seed_note", "approval": "write", "mode": "yolo" }, "expected": { "resolved": { "policy": "allow", "tier": "write", "override": false, "source": "mode" } }, "why": "Modes compare capability tiers; always-ask still allows read-tier calls.", "sourceRefs": [ "approval" ] }, { "id": "approval-yolo-exec", "title": "Mode yolo meets exec tier", "scenario": "approval", "given": { "tool": "seed_note", "approval": "exec", "mode": "yolo" }, "expected": { "resolved": { "policy": "allow", "tier": "exec", "override": false, "source": "mode" } }, "why": "Modes compare capability tiers; always-ask still allows read-tier calls.", "sourceRefs": [ "approval" ] }, { "id": "approval-undeclared-exec", "title": "An undeclared capability defaults to exec", "scenario": "approval", "given": { "tool": "seed_note", "mode": "write" }, "expected": { "resolved": { "policy": "prompt", "tier": "exec", "override": false, "source": "mode" } }, "why": "Omitting approval is not a read-only declaration.", "sourceRefs": [ "approval" ] }, { "id": "approval-tool-deny-wins", "title": "A tool-owned refusal survives user allow and yolo", "scenario": "approval", "given": { "tool": "seed_note", "approval": { "tier": "write", "policy": "deny", "reason": "Fictional desk is closed" }, "mode": "yolo", "userPolicies": { "seed_note": "allow" } }, "expected": { "resolved": { "policy": "deny", "tier": "write", "override": false, "source": "tool", "reason": "Fictional desk is closed" } }, "why": "Tool deny is checked first and the refusal names tool policy.", "sourceRefs": [ "approval" ] }, { "id": "approval-user-deny-wins", "title": "A user refusal survives tool allow and yolo", "scenario": "approval", "given": { "tool": "seed_note", "approval": { "tier": "read", "policy": "allow" }, "mode": "yolo", "userPolicies": { "seed_note": "deny" } }, "expected": { "resolved": { "policy": "deny", "tier": "read", "override": false, "source": "user", "policyKey": "seed_note" } }, "why": "Effective user deny is checked before tool allow.", "sourceRefs": [ "approval" ] }, { "id": "approval-explicit-tool-prompt", "title": "Explicit tool prompt is not an override-only heuristic", "scenario": "approval", "given": { "tool": "seed_note", "approval": { "tier": "exec", "policy": "prompt" }, "mode": "yolo", "userPolicies": { "seed_note": "allow" } }, "expected": { "resolved": { "policy": "prompt", "tier": "exec", "override": false, "source": "tool" } }, "why": "Yolo ignores override-only prompts, not an explicit tool prompt policy.", "sourceRefs": [ "approval" ] }, { "id": "approval-tool-allow-before-user-prompt", "title": "Tool allow precedes a non-deny user prompt", "scenario": "approval", "given": { "tool": "seed_note", "approval": { "tier": "write", "policy": "allow" }, "mode": "always-ask", "userPolicies": { "seed_note": "prompt" } }, "expected": { "resolved": { "policy": "allow", "tier": "write", "override": false, "source": "tool" } }, "why": "Do not summarize precedence as all user policy always wins: deny is special.", "sourceRefs": [ "approval" ] }, { "id": "approval-policy-key-fallback", "title": "An invalid device policy falls back to invoking write", "scenario": "approval", "given": { "tool": "write", "approval": { "tier": "exec", "policyKey": "seed_slot" }, "mode": "yolo", "userPolicies": { "seed_slot": "not-a-policy", "write": "deny" } }, "expected": { "resolved": { "policy": "deny", "tier": "exec", "override": false, "source": "user", "policyKey": "write" } }, "why": "Missing or invalid keyed policy falls back; the refusal names the effective key.", "sourceRefs": [ "approval" ] }, { "id": "approval-policy-key-specific", "title": "A valid device allow replaces invoking write deny", "scenario": "approval", "given": { "tool": "write", "approval": { "tier": "exec", "policyKey": "seed_slot" }, "mode": "always-ask", "userPolicies": { "seed_slot": " ALLOW ", "write": "deny" } }, "expected": { "resolved": { "policy": "allow", "tier": "exec", "override": false, "source": "user", "policyKey": "seed_slot" } }, "why": "write deny is a fallback, not an additional deny when the keyed policy is valid.", "sourceRefs": [ "approval" ] }, { "id": "bash-critical-before-allow", "title": "A selected allow cannot erase the critical heuristic", "scenario": "bash", "given": { "command": "chmod -R 700 /fictional-seed-library", "patterns": [ { "match": "chmod *", "approval": "allow" } ], "mode": "write", "userPolicies": { "bash": "allow" } }, "expected": { "resolved": { "policy": "prompt", "tier": "exec", "override": true, "source": "tool", "reason": "Critical pattern detected" } }, "why": "The critical heuristic runs after selected deny but before selected allow/prompt. Classification only; never execute this string.", "sourceRefs": [ "bash", "approval" ] }, { "id": "bash-critical-yolo", "title": "The same override-only critical prompt is skipped in yolo", "scenario": "bash", "given": { "command": "chmod -R 700 /fictional-seed-library", "patterns": [ { "match": "chmod *", "approval": "allow" } ], "mode": "yolo" }, "expected": { "resolved": { "policy": "allow", "tier": "exec", "override": false, "source": "mode" } }, "why": "This is a resolution observation, not a safety recommendation or permission to run a command.", "sourceRefs": [ "bash", "approval" ] }, { "id": "bash-selected-deny-before-critical", "title": "Selected deny survives critical classification and yolo", "scenario": "bash", "given": { "command": "chmod -R 700 /fictional-seed-library", "patterns": [ { "match": "chmod *", "approval": "deny" } ], "mode": "yolo" }, "expected": { "resolved": { "policy": "deny", "tier": "exec", "override": true, "source": "tool", "reason": "Blocked by bash pattern: chmod *" } }, "why": "A selected deny is returned before the heuristic.", "sourceRefs": [ "bash", "approval" ] }, { "id": "bash-first-applicable-rule", "title": "An earlier allow wins over a later matching deny", "scenario": "bash", "given": { "command": "printf seed-card", "patterns": [ { "match": "printf *", "approval": "allow" }, { "match": "*", "approval": "deny" } ], "mode": "always-ask" }, "expected": { "resolved": { "policy": "allow", "tier": "write", "override": false, "source": "tool" } }, "why": "Rules are first-applicable, not a global scan for any deny.", "sourceRefs": [ "bash", "approval" ] }, { "id": "bash-compound-deny-segment", "title": "Allow cannot vouch for a compound line; segment deny can match", "scenario": "bash", "given": { "command": "printf seed-card && printf closed", "patterns": [ { "match": "printf *", "approval": "allow" }, { "match": "printf closed", "approval": "deny" } ], "mode": "yolo" }, "expected": { "resolved": { "policy": "deny", "tier": "exec", "override": true, "source": "tool", "reason": "Blocked by bash pattern: printf closed" } }, "why": "Allow requires the whole non-compound command; deny/prompt can match any shell segment.", "sourceRefs": [ "bash", "approval" ] }, { "id": "bash-explicit-prompt-yolo", "title": "A noncritical pattern prompt persists in yolo", "scenario": "bash", "given": { "command": "printf seed-card", "patterns": [ { "match": "printf *", "approval": "prompt" } ], "mode": "yolo", "userPolicies": { "bash": "allow" } }, "expected": { "resolved": { "policy": "prompt", "tier": "exec", "override": false, "source": "tool", "reason": "Prompt required by bash pattern: printf *" } }, "why": "The explicit prompt policy survives where override-only critical prompting does not.", "sourceRefs": [ "bash", "approval" ] } ], "sourceOnly": [] }