Conversation
…onsent Slice 1 of 3 for Gentleman-Programming#1305: prompt layer only. Adds one Safety rule that keeps session work inside the project root and registered same-clone worktrees, requires asking before any out-of-boundary read or write (naming the absolute target path), and scopes grants per-target and per-session, never blanket. Runtime fences follow the two open design questions in the issue thread (path-tool fence, bash fence).
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review. 📝 WalkthroughWalkthroughThe orchestrator safety guidance now limits session work to the project root or registered same-clone worktrees. It requires approval before reading or writing outside those locations and defines approval as applying only to the named target for that session. ChangesSession path boundary
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The orchestrator now requires target-specific approval before outside-root reads or writes. No actionable merge-blocking issue is evident in this prompt-only change. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
carlosmoradev
left a comment
There was a problem hiding this comment.
Clean and focused first slice.
Verified that the prompt addition stays well within the 8,192-byte budget with tests passing cleanly. The explicit clarification that in-project scripts referencing outside paths do not constitute standing consent is a great addition to prevent boundary leakage.
Looking forward to the runtime fences in slices 2 and 3.
|
Could we confirm the reads-vs-writes decision in #1305 before merging this slice? The new prompt rule already requires consent for both reads and writes outside the worktree, while the runtime scope is still an open question in the issue. Confirming that policy now would keep the prompt and the later fence aligned. |
|
Good question, and the alignment concern is the right one to raise. Two reasons this slice is safe to land before the Q1 decision:
The reads-vs-writes question itself stays open with @x4barin and the maintainers in #1305 (asked 2026-09-27; slices 2 and 3 follow the answer). If a maintainer prefers to hold this slice until Q1 resolves, that works too: it is one prompt line, trivial to rebase. My recommendation is to land it, because the current state (no rule at all) is weaker than every candidate policy, so the superset cannot make the boundary looser than today. |
Linked Issue
Part of #1305 (slice 1 of 3; the issue closes with the last slice, not here)
Design thread: the diagnosis and two-layer design are in the issue thread (2026-09-27). This PR is the prompt layer only; the runtime fences (slices 2 and 3) follow the two design questions still open with the reporter (reads-vs-writes scope, bash v1 coverage).
PR Type
Summary
sync.bashcase from the report).Changes
assets/orchestrator.mdTest Plan
node --experimental-strip-types --test tests/orchestrator-budget.test.ts— 34 pass (both 8192-byte budget tests included)Chain Context
mainScope
Contributor Checklist
status:approved(bug(harness) Agent left the current project directory (sibling project) without asking for permission #1305)Summary by CodeRabbit