docs: ACP agents run their own tools, and Grok has no Auto-accept edits - #13634
Conversation
ApprovabilityVerdict: Would Approve Macroscope's review found this PR approvable — The PR only revises two Markdown guides to document already-landed ACP and Grok permission behavior, with no executable or product-default changes. A separate unresolved High-severity ACP runtime-policy finding remains outside this documentation diff and should be handled by the repository's blocking correctness process. Not approved because:
Adjust the Minimum Blocking Severity for this repo — including turning it Off — in Settings. You can add or adjust custom eligibility rules. Learn more. |
Thread transfer impact✅ Thread transfer remains within every enforced ceiling.
Baseline: unavailable · PR result: Scenario and decoded snapshot size10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.
Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed. |
9d5cee1 to
f0ffbb4
Compare
4bef658 to
bd9cc73
Compare
Dismissing prior approval to re-evaluate f0ffbb4
f0ffbb4 to
e4d4675
Compare
bd9cc73 to
7cb3cd4
Compare
7cb3cd4 to
fc7e66b
Compare
Dismissing prior approval to re-evaluate e4d4675
| const mcpContext = acpMcpContext(threadId, self); | ||
| return { | ||
| cwd: input.runtimePolicy.cwd ?? process.cwd(), | ||
| runtimePolicy: input.runtimePolicy, |
There was a problem hiding this comment.
🟠 High Adapters/AcpAdapterV2.ts:1948
A restarted ACP runtime uses the original openSession policy instead of the later turn's policy, so a session opened in full-access remains in full-access after restarting for an approval-required turn. makeRuntimeInput should pass latestRuntimePolicy so launch-time permission enforcement matches the active turn.
| runtimePolicy: input.runtimePolicy, | |
| runtimePolicy: latestRuntimePolicy, |
🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
In file @apps/server/src/orchestration-v2/Adapters/AcpAdapterV2.ts around line 1948:
A restarted ACP runtime uses the original `openSession` policy instead of the later turn's policy, so a session opened in `full-access` remains in full-access after restarting for an `approval-required` turn. `makeRuntimeInput` should pass `latestRuntimePolicy` so launch-time permission enforcement matches the active turn.
The ACP Registry guide said T3 mediates agent file and terminal requests at the client boundary. Registry agents now run their own tools under their own mode, T3 answers their approval requests by the thread's permission mode, and only Devin's commands run in T3's terminals. The permission modes page now says Grok offers no Auto-accept edits and that a Grok thread already set to it runs in Supervised. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
e4d4675 to
180a033
Compare
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The ACP Registry guide said T3 mediates agent file and terminal requests at the client boundary. That stopped being true: registry agents run their own tools (#13623), the generic client fs guard is gone (#13633), and only Devin's commands run through T3's terminals. The permission-modes page also didn't say that Grok offers no Auto-accept edits (#13719).
Rewritten to match what landed after the spec-only reshape. There's no per-agent mode mapping, and the agent's own mode picker stays visible (#13724, which replaces #13629).
What changed
docs/user/providers-acp.md"Permissions and terminals" now explains:docs/user/permission-modes.md"Provider differences" says Grok offers no Auto-accept edits, and that a Grok thread already set to it runs in Supervised. It also links to the ACP section for registry agents.Verification
vp fmton both files. I checked each claim against the code:acpPermissionDispositioninAcpClientPolicy.tsfor how each mode answers,AcpRegistryAdapterV2for Devin's client terminals and for client fs being off,GrokProviderplusRuntimePolicyin fix(server): Grok no longer offers Auto-accept edits #13719 for Grok's modes and the Supervised fallback.Model: Claude Opus 5.5 (Claude Code)
🤖 Generated with Claude Code