{ "schemaVersion": 1, "id": "boundary-desk", "title": "Third desk: distinguish approval, UI capability, and host authority", "label": "TEACHING DATA — DO NOT EXECUTE COMMAND STRINGS OR INSTALL AS AN EXTENSION", "domain": "The fictional Cedar Seed Library; no real inventory, devices, accounts, or permissions are changed.", "executionPolicy": "These JSON files are inert cases, not a shell script or OMP configuration. The private verifier calls actual OMP resolution/wrapper code with recording UI adapters and inert executors only. Bash strings are classification data and are never passed to BashTool.execute.", "host": "Current local custom OMP source; not an upstream compatibility promise.", "proofStatus": "Expected outcomes authored from source. Execution evidence exists only in the separately generated private report; this file does not claim a run.", "sources": { "approval": "packages/coding-agent/src/tools/approval.ts:104-233", "wrapper": "packages/coding-agent/src/extensibility/extensions/wrapper.ts:177-346", "bash": "packages/coding-agent/src/tools/bash.ts:264-300,553-579", "write": "packages/coding-agent/src/tools/write.ts:515-560,1104-1205", "xdev": "packages/coding-agent/src/tools/xdev.ts:406-474", "rpc": "packages/coding-agent/src/modes/rpc/rpc-mode.ts:545-579,645-693,771-950,953-975", "runner": "packages/coding-agent/src/extensibility/extensions/runner.ts:885-891", "fallback": "packages/coding-agent/src/tools/file-write-fallback.ts:3-88,218-226,402-467" }, "cases": [ { "id": "boundary-approval-does-not-persist", "title": "A second call asks again after the first approval", "scenario": "wrapper", "given": { "approval": "exec", "args": { "action": "publish" }, "mode": "always-ask", "choices": [ "Approve", "Deny" ], "repeat": 2 }, "expected": { "outcome": "throw", "effects": 1, "prompts": 2, "toolCalls": 2, "input": { "action": "publish" }, "errorIncludes": "Tool call denied by user", "successfulCalls": 1 }, "why": "The same wrapped tool runs twice with unchanged settings; approving the first call does not authorize the second.", "sourceRefs": [ "wrapper", "approval" ] }, { "id": "boundary-auto-approve-mode", "title": "Execute-time autoApprove forces yolo despite configured always-ask", "scenario": "wrapper", "given": { "approval": "exec", "args": { "action": "publish" }, "mode": "always-ask", "autoApprove": true, "ui": false }, "expected": { "outcome": "return", "effects": 1, "prompts": 0, "toolCalls": 1, "input": { "action": "publish" } }, "why": "The wrapper chooses yolo from context.autoApprove before resolving the configured mode; no CLI parsing is claimed here.", "sourceRefs": [ "wrapper", "approval" ] }, { "id": "boundary-auto-approve-still-denied", "title": "Execute-time autoApprove does not remove an explicit user deny", "scenario": "wrapper", "given": { "approval": "exec", "args": { "action": "publish" }, "mode": "always-ask", "autoApprove": true, "ui": false, "userPolicies": { "seed_note": "deny" } }, "expected": { "outcome": "throw", "effects": 0, "prompts": 0, "toolCalls": 0, "errorIncludes": "blocked by user policy" }, "why": "The effective mode is yolo, but deny precedence remains in force.", "sourceRefs": [ "wrapper", "approval" ] }, { "id": "boundary-approve-one-call", "title": "Approve permits only this inert call", "scenario": "wrapper", "given": { "approval": "exec", "args": { "action": "publish" }, "mode": "always-ask", "choices": [ "Approve" ] }, "expected": { "outcome": "return", "effects": 1, "prompts": 1, "toolCalls": 1, "input": { "action": "publish" } }, "why": "A recording adapter selects Approve; no durable user setting or operator grant is written.", "sourceRefs": [ "wrapper", "approval" ] }, { "id": "boundary-deny-one-call", "title": "Deny stops execution", "scenario": "wrapper", "given": { "approval": "exec", "args": { "action": "publish" }, "mode": "always-ask", "choices": [ "Deny" ] }, "expected": { "outcome": "throw", "effects": 0, "prompts": 1, "toolCalls": 1, "errorIncludes": "Tool call denied by user" }, "why": "Only the exact response Approve authorizes the call.", "sourceRefs": [ "wrapper", "approval" ] }, { "id": "boundary-dismiss-one-call", "title": "A dismissed selection fails closed", "scenario": "wrapper", "given": { "approval": "exec", "args": { "action": "publish" }, "mode": "always-ask", "choices": [ null ] }, "expected": { "outcome": "throw", "effects": 0, "prompts": 1, "toolCalls": 1, "errorIncludes": "Tool call denied by user" }, "why": "JSON null stands for the recording adapter returning undefined.", "sourceRefs": [ "wrapper", "approval" ] }, { "id": "boundary-no-ui", "title": "A required prompt without a UI refuses", "scenario": "wrapper", "given": { "approval": "exec", "args": { "action": "publish" }, "mode": "always-ask", "ui": false }, "expected": { "outcome": "throw", "effects": 0, "prompts": 0, "toolCalls": 1, "errorIncludes": "requires approval but no interactive UI available" }, "why": "No-UI is a runner capability condition; it is not a synonym for RPC.", "sourceRefs": [ "wrapper", "approval" ] }, { "id": "boundary-deny-before-handler", "title": "A deny on original input cannot be rewritten away", "scenario": "wrapper", "given": { "approval": { "tier": "exec", "policy": "deny" }, "args": { "action": "blocked" }, "revise": { "action": "inspect" }, "mode": "yolo" }, "expected": { "outcome": "throw", "effects": 0, "prompts": 0, "toolCalls": 0, "errorIncludes": "blocked by tool policy" }, "why": "The wrapper consumes a loop marker, then original-input deny stops before emitting tool_call.", "sourceRefs": [ "wrapper", "approval" ] }, { "id": "boundary-rpc-approve", "title": "A synthetic RPC client answers the real select transport", "scenario": "wrapper", "given": { "approval": "exec", "args": { "action": "publish" }, "mode": "always-ask", "ui": "rpc", "choices": [ "Approve" ] }, "expected": { "outcome": "return", "effects": 1, "prompts": 1, "toolCalls": 1, "input": { "action": "publish" }, "rpcRequests": 1 }, "why": "The real requestRpcSelect and dispatchRpcControlFrame settle a queued response. Full runRpcMode and a physical client UI are not launched.", "sourceRefs": [ "wrapper", "approval" ] }, { "id": "boundary-rpc-cancel", "title": "RPC cancellation becomes undefined and refuses", "scenario": "wrapper", "given": { "approval": "exec", "args": { "action": "publish" }, "mode": "always-ask", "ui": "rpc", "choices": [ null ] }, "expected": { "outcome": "throw", "effects": 0, "prompts": 1, "toolCalls": 1, "errorIncludes": "Tool call denied by user", "rpcRequests": 1 }, "why": "The exported transport helper returns undefined for cancelled:true; the actual wrapper rejects it.", "sourceRefs": [ "wrapper", "approval" ] }, { "id": "boundary-provider-check-no-ui", "title": "Synthetic pending safety checks cannot be auto-acknowledged", "scenario": "wrapper", "given": { "approval": "read", "args": { "action": "inspect" }, "mode": "yolo", "autoApprove": true, "userPolicies": { "seed_note": "allow" }, "ui": false, "safetyCheck": true }, "expected": { "outcome": "throw", "effects": 0, "prompts": 0, "toolCalls": 1, "errorIncludes": "pending provider safety checks", "providerSafetyApproved": false }, "why": "Local metadata only: no provider request or desktop input. The wrapper still requires a prompt.", "sourceRefs": [ "wrapper", "approval" ] }, { "id": "boundary-provider-check-approved", "title": "A recording selection explicitly acknowledges synthetic checks", "scenario": "wrapper", "given": { "approval": "read", "args": { "action": "inspect" }, "mode": "yolo", "choices": [ "Approve" ], "safetyCheck": true }, "expected": { "outcome": "return", "effects": 1, "prompts": 1, "toolCalls": 1, "input": { "action": "inspect" }, "providerSafetyApproved": true, "promptIncludes": "Fictional seed shelf check" }, "why": "This proves only wrapper metadata transition to providerSafetyApproved=true, not provider or physical computer behavior.", "sourceRefs": [ "wrapper", "approval" ] }, { "id": "boundary-fallback-no-handler", "title": "A denied primitive does not magically become an operator grant", "scenario": "fallback", "given": { "code": "EACCES", "message": "Synthetic denied fictional seed note" }, "expected": { "outcome": "throw-same-error", "effects": 0, "primitiveAttempts": 1 }, "why": "The real writeFileWithFallback calls an injected inert writer once; with no registered fallback it rethrows the identical error. No privileged channel or success handler is installed.", "sourceRefs": [ "fallback" ] }, { "id": "boundary-fallback-code-precedence", "title": "A path mentioning EACCES is not itself permission denial", "scenario": "classify-error", "given": { "code": "ENOENT", "message": "ENOENT opening fictional/EACCES/card" }, "expected": { "permissionDenied": false, "effects": 0 }, "why": "The real permission-error classifier treats structured code as authoritative.", "sourceRefs": [ "fallback" ] }, { "id": "boundary-fallback-message", "title": "Unstructured transport-style permission text is classified", "scenario": "classify-error", "given": { "message": "EACCES: synthetic transport refusal" }, "expected": { "permissionDenied": true, "effects": 0 }, "why": "An Error without a structured code can be classified from its message; classification is not permission or a recovered write.", "sourceRefs": [ "fallback" ] } ], "sourceOnly": [ { "id": "rpc-construction", "claim": "runRpcMode constructs RpcExtensionUIContext, sets tool UI with hasUI=true, and supplies that UI to initializeExtensions. ExtensionRunner.hasUI compares the adapter with noOpUIContext. RPC can therefore answer ordinary selection approvals through its host transport.", "sourceRefs": [ "rpc", "runner" ], "notExecuted": "Full RPC process initialization and real stdin/stdout client" }, { "id": "rpc-not-a-tui", "claim": "RPC custom() returns undefined, raw terminal input and component factories are unsupported, and widget transport accepts string arrays. A UI-capable RPC adapter is not a physical TUI.", "sourceRefs": [ "rpc" ], "notExecuted": "Custom component rendering and physical terminal interaction" }, { "id": "fallback-is-not-grant", "claim": "Fallback registries route supported permission-denied byte writes or unlinks to separately supplied handlers. A host must independently obtain authority and perform a durable operation before reporting success; tool approval does not create an OS grant. Archive, SQLite, ACP bridge and formatter operations are not universally covered.", "sourceRefs": [ "fallback" ], "notExecuted": "Fallback handler registration, privileged broker, OS grant acquisition, privileged success, and delete operations" } ] }