Skip to content

docs: correct policy action names - #54331

Open
xiajiahang wants to merge 2 commits into
anomalyco:devfrom
xiajiahang:policy-action-docs
Open

xiajiahang wants to merge 2 commits into
anomalyco:devfrom
xiajiahang:policy-action-docs

Conversation

@xiajiahang

@xiajiahang xiajiahang commented Oct 10, 2026 •

Copy link
Copy Markdown

Issue for this PR

Closes #54214

Type of change

  • Bug fix
  • New feature
  • Refactor / code improvement
  • Documentation

What does this PR do?

The policy examples use permission, which the config schema rejects. Use tool.use in the policies, config, and permissions guides, and list the three supported policy actions. Explain integration.use resources with an MCP server and skill allowlist example.

How did you verify your code works?

  • Decoded all 20 policy examples from the three guides with ConfigPolicy.Info: all accepted. The original examples had 7 rejected statements.
  • packages/core: bun test test/config/policy.test.ts — 13 passed.
  • services/www: bun typecheck and bun run check:generated passed.
  • services/www: bun run build passed, including link validation.
  • Root bun run check: lint completed with 0 errors; typecheck blocked by missing @solidjs/start imports in the unchanged Console support package (the initial run also encountered this dependency issue in the stats app).

Screenshots / recordings

Not applicable; documentation content only.

Checklist

  • I have tested my changes locally
  • I have not included unrelated changes in this PR

@github-actions

Copy link
Copy Markdown
Contributor

The following comment was made by an LLM, it may be inaccurate:

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks right to me. I compared the docs against the code. ConfigPolicy.Info only accepts provider.use, tool.use and integration.use. The permission hard-deny hook in packages/core/src/config/plugin/policy.ts matches tool.use against <action>:<value>, and the last matching statement wins. That fits the corrected examples and the "allow only lifts an earlier deny" wording. No other "action": "permission" examples are left in the docs. This is docs-only, so there was nothing to run.

Public API: unchanged. This only updates the documentation of the existing config keys.

One small gap, not blocking: the actions table now lists integration.use, but the page never says what it controls or what its resources look like. In the code, integration.use statements remove MCP servers (mcp:<server>) and skills (skill:<id>). A short section with an example, like the existing Permissions section, would mean readers don't have to guess.

Related: #54100

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

config: experimental.policies silently drops "permission" action statements

1 participant