feat(sdk): wire workspace:/tools.fs: scope-compiler into preflight (#308) - #359
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
maintainability lens — FAILMaintainability Review — PR #359Blocker
The comment "fail closed — unreadable manifest treats every mount as unknown" describes the policy, but the author staring at Concerns
Notes
REVIEW_FAILED |
history lens — PASSBlockers: None under the three HISTORY criteria. Notes: The change follows commit The additions remain SDK-side and introduce no kernel vocabulary, provider adapters, replay mechanism, or gate-authority changes. They do not introduce a contradiction with RFC-0001 settled decisions #1, #5, or #13. The PR body explicitly defers worker-session enforcement and step-level composition; those omissions are not HISTORY blockers. Commit Concerns: In The older gate reference in REVIEW_PASSED |
structure lens — MISSING |
|
🎯 review-swarm: FAILED (M:fail H:pass S:missing) Lens transcripts posted as sibling comments above. |
) Consumes the scope-compiler and mount-registry from #329. Flow-header declarations compile against the nearest relayfile.mounts.json; preflight refuses with scope_syntax_invalid / mount_unknown / scope_ungrantable before any token is minted. Walker parity extended for the three new kinds. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> Session-Id: efeda5df-9b7c-48d4-b2ce-957f5bef0a82 Session-Id: efeda5df-9b7c-48d4-b2ce-957f5bef0a82
The scope-compiler wiring in this PR adds workspace and tools to FLOW_FIELDS; update the pinned expectation. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> Session-Id: efeda5df-9b7c-48d4-b2ce-957f5bef0a82 Session-Id: efeda5df-9b7c-48d4-b2ce-957f5bef0a82
4a2178f to
5c99a5c
Compare
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Want reviews to match your repository better? Bugbot Learning can learn team-specific rules from PR activity. A team admin can enable Learning in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 5c99a5c. Configure here.
| let mounts: MountRegistry | undefined; | ||
| if (options.projectSearchStart !== undefined) { | ||
| try { mounts = readMountRegistry(options.projectSearchStart); } | ||
| catch { mounts = {}; /* fail closed — unreadable manifest treats every mount as unknown */ } |
There was a problem hiding this comment.
Manifest errors reported as unknown mounts
Medium Severity
scopeDiagnostics catches every readMountRegistry failure and replaces it with an empty registry, so corrupt JSON, an invalid manifest, or a permission error all surface as mount_unknown. The registry already throws a path-specific reason, but that message is discarded and the grant is described as missing from the manifest.
Reviewed by Cursor Bugbot for commit 5c99a5c. Configure here.


Closes #308. Builds on #329's
scope-compiler+mount-registryfoundation, which was shipped unwired.What lands
FlowSpec.workspace?: string | string[]andFlowSpec.tools?.fs?: string | string[]— flow-header scope grants ("mount/path: readonly|readwrite|append")validate.tsaccepts the two new fields (closed vocabulary, strict scope-grant shape check)compile.tspreserves them in the CompiledFlowSpec, andtoKernelSpecdrops them (kernel dialect stays unchanged — grants are preflight-only)preflight.tscallscompileScopeswithreadMountRegistry(projectSearchStart); three closed refusal kinds surface at gate 1:scope_syntax_invalid— grant doesn't matchmount/path: modemount_unknown— mount name not present in the manifestscope_ungrantable— mount exists but cannot grant that path or modePREFLIGHT_FAILURE_KINDSextends with the three kinds; walker parity test adds scenarios so covenant 2's closed-vocabulary check still holdstests/scope-preflight.test.ts— 6 acceptance cases (accept, syntax refuse, mount_unknown, scope_ungrantable path, scope_ungrantable mode, tools.fs parity, absence)Deferred (follow-ups)
AgentOptions.workspacewidening (surface-side) — step-level grants sit alongside flow-header grants once we settle whether they compose or overridetools.mcpremains owned by that slice; this PR only touchestools.fsTest plan
scope-preflight.test.ts(6 cases) added totsconfig.tests.jsonNote
Medium Risk
Changes authorization preflight for filesystem scope grants and reads mount manifests from disk; incorrect behavior could block valid flows or miss bad grants before run.
Overview
Adds flow-header path-scoped grants via
workspaceandtools.fs("mount/path: readonly|readwrite|append"), validated invalidate.ts, preserved throughcompileSpec, and not lowered into the kernel dialect (preflight-only).Preflight now runs
compileScopesagainstrelayfile.mounts.jsonfromprojectSearchStart, surfacing three refusal kinds:scope_syntax_invalid,mount_unknown, andscope_ungrantable. Unreadable manifests fail closed (unknown mounts).Tests extend the closed refusal-kind walker and add
scope-preflight.test.ts(accept, syntax, mount, ungrantable path/mode,tools.fsparity, absence).Reviewed by Cursor Bugbot for commit 5c99a5c. Bugbot is set up for automated code reviews on this repo. Configure here.