Decide whether a coordinator may lift a headless worker's refusal (the trust boundary #68 defers)
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 25/100
- issue の種類
- 機能追加
- 明瞭さ
- 説明が足りない
- 活発さ
- 活発
- 技術スタック
- typescript
調査の方向性
Start with the refusal key resolution at index.ts:3203, liftRefusals at index.ts:3262, and the dialog-approval and headless checks at index.ts:4302 and index.ts:4333. Decide and document the trust-boundary policy, then add tests covering coordinator authorization, critical refusals, and attribution of both identities in decisions.jsonl. Done means the chosen constraints hold and the agent-on-behalf-of-user behavior is documented.
索引モデルが issue の本文から書いたものです。
説明
Split from #68 by your decision there: the mechanical half (narrowing the refusal key) is agent work on that issue, and this is the trust boundary it deliberately does not touch.
The gap. A headless worker cannot lift a refusal. liftRefusals (index.ts:3262) runs at exactly one call site, inside the dialog-approval handler (index.ts:4333), and that handler is only reachable when ctx.hasUI — index.ts:4302 collapses every headless hit into a block before any lift path. A refusal a coordinator considers wrong therefore stays for the whole session.
Why it is a design call and not a fix. Building the channel means answering who may lift a refusal taken on another agent's command, whether an agent may approve on a user's behalf, and whether a critical refusal is ever liftable. Those are the same questions the persistent-grant surface answers for a human, asked about a machine, and the answer decides how much of the prod-secrets posture moves.
Options as presented.
- A registered tool a coordinator may call, with headless coordinators rejected by construction, critical refusals permanently unliftable, and the hop recorded in
decisions.jsonlwith both identities. Cost: an agent-to-agent approval path exists at all. - Lift only with a human-issued token in the environment, so an unattended session still cannot lift. Cost: it is a human approval with extra steps in the common case.
- Leave it unliftable, documented with the reason. Cost: a wedged headless worker is restart-only.
Acceptance, whichever is chosen: the chosen constraints hold under test (a headless coordinator is rejected or accepted as specified; a critical refusal cannot be lifted by any path); every lift is attributable in the log with the lifting identity and the original refuser; the docs state what an agent may do on another agent's behalf.
Related: #68 (key narrowing), and the refusal store's key resolution at index.ts:3203.
- 主要言語
- TypeScript
- スター
- 0
- フォーク
- 1
- 平均マージ
- 2時間 10分
- マージ済み PR(30日)
- 64
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
STRML/omp-classifier のほかの issue
-
enhancement ready-for-human
難易度 4/5 3〜5日 初心者へのやさしさ 45/100
STRML/omp-classifier#116 · コメント 7 件 ·
メンテナーはふだん 1 日以内に返信
-
enhancement ready-for-human
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
STRML/omp-classifier#13 · コメント 6 件 ·
メンテナーはふだん 1 日以内に返信
STRML/omp-classifier の issue をすべて見る
似ている issue
-
Mend: dependency security vulnerability untriaged
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
opensearch-project/security-dashboards-plugin#2545 ·
メンテナーはふだん 1 日以内に返信
-
Add: Dream TR SDオープンcheck:passed streams:add
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
メンテナーはふだん 1 日以内に返信
-
doctor integrity sample scans soft-deleted pages on Postgres (batch path has no deleted_at filter)オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 72/100
SocialGouv/egapro#4672 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
area:agents area:tui bug
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
anthropics/claude-code#98358 ·
メンテナーはふだん 1 日以内に返信