{ "schemaVersion": 1, "id": "dispatch-desk", "title": "Second desk: follow an approval through dispatch", "label": "TEACHING DATA — DO NOT EXECUTE COMMAND STRINGS OR INSTALL AS AN EXTENSION", "domain": "The fictional Cedar Seed Library; no real inventory, devices, accounts, or permissions are changed.", "executionPolicy": "These JSON files are inert cases, not a shell script or OMP configuration. The private verifier calls actual OMP resolution/wrapper code with recording UI adapters and inert executors only. Bash strings are classification data and are never passed to BashTool.execute.", "host": "Current local custom OMP source; not an upstream compatibility promise.", "proofStatus": "Expected outcomes authored from source. Execution evidence exists only in the separately generated private report; this file does not claim a run.", "sources": { "approval": "packages/coding-agent/src/tools/approval.ts:104-233", "wrapper": "packages/coding-agent/src/extensibility/extensions/wrapper.ts:177-346", "bash": "packages/coding-agent/src/tools/bash.ts:264-300,553-579", "write": "packages/coding-agent/src/tools/write.ts:515-560,1104-1205", "xdev": "packages/coding-agent/src/tools/xdev.ts:406-474", "rpc": "packages/coding-agent/src/modes/rpc/rpc-mode.ts:545-579,645-693,771-950,953-975", "runner": "packages/coding-agent/src/extensibility/extensions/runner.ts:885-891", "fallback": "packages/coding-agent/src/tools/file-write-fallback.ts:3-88,218-226,402-467" }, "cases": [ { "id": "dispatch-inspect-no-ui", "title": "Mounted read inherits a read tier without asking", "scenario": "dispatch", "given": { "args": { "action": "inspect" }, "mode": "always-ask", "ui": false }, "expected": { "outcome": "return", "effects": 1, "prompts": 0, "toolCalls": 2, "input": { "action": "inspect" }, "tier": "read" }, "why": "The outer write evaluates the mounted function-valued approval; the real dispatcher reaches only the inert seed_slot tool.", "sourceRefs": [ "write", "xdev", "wrapper", "approval" ] }, { "id": "dispatch-reserve-once", "title": "One outer approval avoids a duplicate mode-tier prompt", "scenario": "dispatch", "given": { "args": { "action": "reserve" }, "mode": "always-ask", "choices": [ "Approve" ] }, "expected": { "outcome": "return", "effects": 1, "prompts": 1, "toolCalls": 2, "input": { "action": "reserve" }, "tier": "write" }, "why": "xdevApproved bypasses an unchanged inner mode-tier prompt, not all inner gates.", "sourceRefs": [ "write", "xdev", "wrapper", "approval" ] }, { "id": "dispatch-fallback-deny", "title": "No device policy means write deny blocks before dispatch", "scenario": "dispatch", "given": { "args": { "action": "inspect" }, "mode": "yolo", "userPolicies": { "write": "deny" } }, "expected": { "outcome": "throw", "effects": 0, "prompts": 0, "toolCalls": 0, "errorIncludes": "Tool \"write\" is blocked by user policy" }, "why": "The effective fallback deny short-circuits before any tool_call event.", "sourceRefs": [ "write", "xdev", "wrapper", "approval" ] }, { "id": "dispatch-specific-allow", "title": "Device allow replaces the invoking write fallback", "scenario": "dispatch", "given": { "args": { "action": "publish" }, "mode": "always-ask", "ui": false, "userPolicies": { "seed_slot": "allow", "write": "deny" } }, "expected": { "outcome": "return", "effects": 1, "prompts": 0, "toolCalls": 2, "input": { "action": "publish" }, "tier": "exec" }, "why": "The keyed policy wins over fallback, and both actual gates consult seed_slot.", "sourceRefs": [ "write", "xdev", "wrapper", "approval" ] }, { "id": "dispatch-explicit-prompt-twice", "title": "Explicit device prompt is not suppressed inside dispatch", "scenario": "dispatch", "given": { "args": { "action": "reserve" }, "mode": "yolo", "userPolicies": { "seed_slot": "prompt" }, "choices": [ "Approve", "Approve" ] }, "expected": { "outcome": "return", "effects": 1, "prompts": 2, "toolCalls": 2, "input": { "action": "reserve" }, "tier": "write" }, "why": "The current implementation can ask at both outer and inner gates for an explicit device prompt.", "sourceRefs": [ "write", "xdev", "wrapper", "approval" ] }, { "id": "dispatch-inner-tool-deny", "title": "Outer tier approval does not carry away inner tool deny", "scenario": "dispatch", "given": { "args": { "action": "blocked" }, "mode": "yolo" }, "expected": { "outcome": "error-result", "effects": 0, "prompts": 0, "toolCalls": 1, "errorIncludes": "blocked by tool policy", "tier": "exec" }, "why": "Write borrows the device tier, not its full policy; the decorated inner tool enforces its deny and dispatch returns isError.", "sourceRefs": [ "write", "xdev", "wrapper", "approval" ] }, { "id": "dispatch-rewrite-prompts", "title": "A handler raises the mounted action from read to exec", "scenario": "dispatch", "given": { "args": { "action": "inspect" }, "revise": { "action": "publish", "note": "Revised fictional card" }, "mode": "always-ask", "choices": [ "Approve" ] }, "expected": { "outcome": "return", "effects": 1, "prompts": 1, "toolCalls": 2, "input": { "action": "publish", "note": "Revised fictional card" }, "tier": "exec", "promptIncludes": "publish" }, "why": "The inner wrapper re-resolves revised input and invalidates xdevApproved bypass; reported dispatch tier follows the revised action.", "sourceRefs": [ "write", "xdev", "wrapper", "approval" ] }, { "id": "dispatch-rewrite-denies", "title": "A handler revision becomes tool-denied", "scenario": "dispatch", "given": { "args": { "action": "inspect" }, "revise": { "action": "blocked" }, "mode": "yolo" }, "expected": { "outcome": "error-result", "effects": 0, "prompts": 0, "toolCalls": 2, "errorIncludes": "blocked by tool policy", "tier": "exec" }, "why": "A passing original input is not permission for a newly denied action.", "sourceRefs": [ "write", "xdev", "wrapper", "approval" ] }, { "id": "dispatch-malformed-json", "title": "Invalid JSON never reaches the inert mounted executor", "scenario": "dispatch", "given": { "content": "{not-json", "mode": "yolo" }, "expected": { "outcome": "error-result", "effects": 0, "prompts": 0, "toolCalls": 1, "errorIncludes": "expects a JSON args object" }, "why": "Write uses exec tier for malformed payloads; dispatch then refuses the actual malformed content.", "sourceRefs": [ "write", "xdev", "wrapper", "approval" ] } ], "sourceOnly": [ { "id": "dispatch-not-a-new-authority", "claim": "xd:// is a dispatch address, not an operator grant. This fixture registers only one fictional in-process tool; no actual mounted remote device is reached.", "sourceRefs": [ "write", "xdev" ] } ] }