mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-10-11 03:38:07 +00:00
The first real skill-evolution run got past task binding, then the proposer session exited 1 with "Permission mode forced to default — CLAUDE_CODE_SUBPROCESS_ENV_SCRUB is set (allowed_non_write_users hardening)". On 2.1.214 the permission resolver unconditionally forces permission mode to "default" whenever CLAUDE_CODE_SUBPROCESS_ENV_SCRUB is set — `--permission-mode dontAsk`, settings `permissions.defaultMode`, and `autoAllowBashIfSandboxed` are all ignored for the mode decision. The proposer runs headless `-p --bare` where Bash is its only writable tool (it writes the candidate overlay); under forced "default" Bash was no longer auto-approved, so the session blocked. We cannot set ENV_SCRUB=0 (it scrubs the Anthropic auth token from the sandboxed proposer's Bash subprocesses). Instead, align with the forced mode: pre-approve the proposer's exact tool surface via settings `permissions.allow` (["Read","Grep","Glob","Bash"]) — under "default" a tool runs without a prompt iff it matches an allow rule — and stop requesting a non-default mode so no warning fires. ENV_SCRUB and the full sandbox filesystem/network lockdown are unchanged. The real-binary containment canary is updated to the new invocation (no --permission-mode) so the CI job is the authoritative empirical gate, and a fast unit assertion pins the new permissions.allow / absent defaultMode. Claude-Session: https://claude.ai/code/session_01Va5uu9Ar3e45QZ5xFsG4AZ Co-authored-by: Gergo Magyar <gergomagyar@icloud.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| conftest.py | ||
| test_ce_plugin_runtime.py | ||
| test_errors.py | ||
| test_evolve.py | ||
| test_mcp_bridge.py | ||
| test_oracle_assets.py | ||
| test_parse_run_id.py | ||
| test_process_control.py | ||
| test_promotion_apply.py | ||
| test_property_based.py | ||
| test_proposer_sandbox.py | ||
| test_runner_hardening.py | ||
| test_sanitized_graph.py | ||
| test_task_assets.py | ||
| test_tool_scripts.py | ||
| test_workflow_bench.py | ||
| test_workflow_bench_evolution.py | ||
| test_workflow_bench_sessions.py | ||