Skip to content

test(server): replay denied Claude writes through V2 - #10452

Closed
CouchRiv wants to merge 429 commits into
pingdotgg:t3code/codex-turn-mappingfrom
CouchRiv:test/v2-claude-write-denial
Closed

CouchRiv wants to merge 429 commits into
pingdotgg:t3code/codex-turn-mappingfrom
CouchRiv:test/v2-claude-write-denial

Conversation

@CouchRiv

@CouchRiv CouchRiv commented Sep 7, 2026 •

Copy link
Copy Markdown

What Changed

Add a recorded Claude Write denial to the V2 orchestrator replay suite, completing the claude-v2/approvals-denied fixture TODO in #2829. The scenario checks a declined file-change approval, a failed write item, and a completed turn with Claude's final response.

Why

The recorded Claude fixtures contained allowed permission responses but no denied response. This capture uses workspace-write with on-request approval so Write is exposed and reaches the permission callback.

The recorder forwards the scenario's permission decision and uses the installed Claude executable, since this workspace excludes the SDK's bundled binaries. Replay accepts the partial stream messages the recorder already emits; output paths use the platform path service.

Captured with Claude Agent SDK 0.3.260, Claude Code 2.1.263 and claude-sonnet-4-6. The target file was not created. Workspace paths and opaque thinking signatures are redacted.

Rebased and revalidated on V2 89459e38: the denial and existing approval scenarios pass (10 focused tests), and the recording config, Claude, contract and integration replay suites pass 88 tests with one gated live-recording test skipped. queued_cancelled_while_active/codex fails independently of this change. A separate protocol check completes for deny and fails at permission.response:Write when allow is substituted. Server typecheck and targeted lint/format checks pass.

Windows replay validation included #10451's fixture-loading fix. That independent fix is not included in this diff.

Checklist

  • This PR is small and focused
  • I explained what changed and why

Implemented with GPT-6 via Codex desktop; rebased and revalidated with Claude Opus 5 in Claude Code.

@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Sep 7, 2026
@macroscopeapp

macroscopeapp Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Would Approve

Macroscope's review found this PR approvable — The PR adds a Claude denied-write replay fixture and supporting recorder behavior entirely within scripts and testkit code. It does not alter production request handling, product defaults, schemas, deployment, or static-analysis configuration.

Not approved because:

  • Monthly spending limit reached (workspace setting). Approvability relies on correctness review in order to determine eligibility

Review your spending limits in Billing settings. You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarminge force-pushed the t3code/codex-turn-mapping branch 3 times, most recently from efd9994 to 6102d00 Compare September 8, 2026 06:23
@CouchRiv
CouchRiv force-pushed the test/v2-claude-write-denial branch from 950e6f3 to a203c87 Compare September 8, 2026 18:13
@juliusmarminge
juliusmarminge force-pushed the t3code/codex-turn-mapping branch from 8187b17 to ada72ce Compare September 9, 2026 06:39
juliusmarminge and others added 22 commits September 10, 2026 12:14
A renderer performance trace showed the minimap strips as a standing
source of main-thread frame work: each strip transitioned
background-color (paint) and width (layout), and both fire constantly —
scrolling or streaming flips a band of in-view states at once, and the
hover fisheye animates several widths at a time — so any interaction
kept a 60fps style/layout/paint pipeline running.

The strip now animates only compositor-friendly properties: width tiers
are scale-x on a fixed-width box, and the in-view highlight is a bright
overlay faded with opacity. The scroll handler also skips no-op
data-in-view attribute writes, which previously re-dirtied style state
for every strip on every scroll tick.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Follow-ups from the main merge:

- Migration numbering: main's 035_ProjectionThreadTitleRegeneration is
  released and keeps its id; this branch's unreleased v2 migrations shift
  to 036-044 instead (a released migration can never be renumbered).
- thread.metadata.update accepts regenerateTitle: true arms an in-flight
  titleRegeneration marker on the thread payload (requestId + startedAt),
  a landing title or explicit false clears it. The marker projects onto
  thread shells and through the client-runtime shell model, so the
  sidebar's Regenerating state works unchanged.
- New ThreadTitleRegenerationService worker reacts to armed markers on
  the live domain-event stream (so ws, MCP, and mobile dispatches all
  behave the same): builds a newest-first conversation digest from the
  v2 projection (8k-char budget, retained attachments — ported from the
  v1 reactor), generates via TextGeneration, and lands the title with a
  follow-up metadata update. Failures clear the marker and log.
- The server advertises threadTitleRegeneration again, and the client
  updateThreadMetadata dispatches regenerateTitle-only updates.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The turn item materialized when a queued run is promoted was emitted
with inputIntent "turn_start", but the deterministic replay driver (and
the recorded queued_turn fixtures) expect "queued_turn" — the mismatch
stalled replay before the queued run could start, leaving run 1 waiting
and run 2 queued forever in all five queued_turn fixtures.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Effect service conventions: ThreadManagementThreadNotSendableError
carried an Archived/NoSteerableRun reason union and switched on
reason._tag inside the message getter. Modelled as two error classes
(ThreadManagementThreadArchivedError, ThreadManagementNoSteerableRunError);
both still map to the MCP thread_not_sendable failure code.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Prevent the title row from shifting when output is revealed
- Preserve panel and compact button sizing
- Schema.UnknownFromJsonString -> Schema.fromJsonString(Schema.Unknown)
- SchemaIssue.InvalidValue single-argument form in checkpointDiff
- McpServerClient requires protocolVersion

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Required for follow-up requests by the 2025-06-18 MCP HTTP transport
that effect beta.103 enforces.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The thread-panel mapping change replaced the compact className on the
Run and Add controls with the isPanel conditional and dropped the
non-panel icon-compact classes that the responsive test asserts.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Ports the deleted v1 ProviderCommandReactor title coverage onto the v2
service: marker arming/clearing via thread.metadata.update, superseded
requestId no-ops, digest-driven regeneration, the "New thread" and
unchanged-title fallbacks, generation failure, and missing initial
messages, plus unit tests for formatThreadTitleContext.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Hoist inline Schema compiles to module scope, drop unused
imports/vars, stabilize react-markdown component identities via a
module-scope factory, remove useless spreads, and use data-derived
keys for release-note bullets. No behavior changes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The codex resume test was the only replay scenario without a
runtimePolicyOverride, so its checkpoint scope cwd fell back to
process.cwd() and baseline capture ran real git over the entire
checkout. Locally the capture short-circuits on checkpoint refs left
behind by earlier runs; on a fresh CI checkout it is a cold multi-second
capture that outlives the scenario wait budget, failing await_thread_idle
while the run is still mid-checkpoint. Point the fixture's turn/start
frames at the <workspace> placeholder and checkpoint a throwaway git
workspace like every other replay test.

Scenario waits are also wall-clock-bounded now: the iteration budget
counts event-loop turns, which burn at full speed while git/fixture IO
is in flight, so exhaustion additionally requires a 60s real-time
deadline to pass.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…r's scope (pingdotgg#5406)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
- Keep the git action control disabled when the branch is up to date
- Omit open PR menu entries and remove their link-opening behavior
- Update logic tests for the new states
…sPinned

Main owns migration numbering: 036_ProjectionThreadsPinned landed on main,
so the v2 migrations shift from 036-044 to 037-045. Release path runs all
of main's migrations first, then the v2 stack.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge and others added 14 commits September 10, 2026 16:08
…gg#9897)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
…ingdotgg#8464)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
…gg#9907)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
…otgg#9905)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
…gg#9928)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
…dotgg#9920)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
…ngdotgg#10051)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
@CouchRiv
CouchRiv force-pushed the test/v2-claude-write-denial branch from a203c87 to d0baed9 Compare September 11, 2026 19:06
@juliusmarminge
juliusmarminge force-pushed the t3code/codex-turn-mapping branch 4 times, most recently from e03e376 to e39429e Compare September 12, 2026 08:17
saphid pushed a commit to saphid/t3code that referenced this pull request Sep 14, 2026
Add a sanitized real Claude Agent SDK recording of a denied Write under
workspace-write + on-request approval, and replay it through the actual
OrchestratorV2 path. The projection records a declined runtime request and
a failed file_change item while the root run still completes, and a control
test proves substituting an allow decision fails at the recorded
permission.response:Write frame. Recordings now resolve an installed
claude executable when one is on PATH, falling back to the SDK's own
discovery.

Transcript provenance: claude-agent-sdk 0.3.260, Claude Code 2.1.263,
claude-sonnet-4-6. Workspace paths sanitized to the canonical replay
workspace; thinking signatures redacted. Adapted from pingdotgg#10452.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
saphid pushed a commit to saphid/t3code that referenced this pull request Sep 14, 2026
Add a sanitized real Claude Agent SDK recording of a denied Write under
workspace-write + on-request approval, and replay it through the actual
OrchestratorV2 path. The projection records a declined runtime request and
a failed file_change item while the root run still completes, and a control
test proves substituting an allow decision fails at the recorded
permission.response:Write frame. Recordings now resolve an installed
claude executable when one is on PATH, falling back to the SDK's own
discovery.

Transcript provenance: claude-agent-sdk 0.3.260, Claude Code 2.1.263,
claude-sonnet-4-6. Workspace paths sanitized to the canonical replay
workspace; thinking signatures redacted. Adapted from pingdotgg#10452.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@juliusmarminge
juliusmarminge force-pushed the t3code/codex-turn-mapping branch 2 times, most recently from 600a8a5 to d8c75ec Compare September 15, 2026 00:23
saphid pushed a commit to saphid/t3code that referenced this pull request Sep 15, 2026
Add a sanitized real Claude Agent SDK recording of a denied Write under
workspace-write + on-request approval, and replay it through the actual
OrchestratorV2 path. The projection records a declined runtime request and
a failed file_change item while the root run still completes, and a control
test proves substituting an allow decision fails at the recorded
permission.response:Write frame. Recordings now resolve an installed
claude executable when one is on PATH, falling back to the SDK's own
discovery.

Transcript provenance: claude-agent-sdk 0.3.260, Claude Code 2.1.263,
claude-sonnet-4-6. Workspace paths sanitized to the canonical replay
workspace; thinking signatures redacted. Adapted from pingdotgg#10452.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@juliusmarminge
juliusmarminge force-pushed the t3code/codex-turn-mapping branch 2 times, most recently from 463d0c6 to e10a1e2 Compare September 15, 2026 06:28
juliusmarminge pushed a commit to saphid/t3code that referenced this pull request Sep 15, 2026
Add a sanitized real Claude Agent SDK recording of a denied Write under
workspace-write + on-request approval, and replay it through the actual
OrchestratorV2 path. The projection records a declined runtime request and
a failed file_change item while the root run still completes, and a control
test proves substituting an allow decision fails at the recorded
permission.response:Write frame. Recordings now resolve an installed
claude executable when one is on PATH, falling back to the SDK's own
discovery.

Transcript provenance: claude-agent-sdk 0.3.260, Claude Code 2.1.263,
claude-sonnet-4-6. Workspace paths sanitized to the canonical replay
workspace; thinking signatures redacted. Adapted from pingdotgg#10452.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@juliusmarminge

Copy link
Copy Markdown
Member

Stale duplicate of #11597 — same denied-write replay fixture re-based onto the current branch. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L 100-499 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants