Skip to content

fix(server): children start in full access; drop agent- and kit-set runtimeMode - #89

Merged
lukemaj merged 2 commits into
mainfrom
fix/88-spawn-thread-drop-runtime-mode
Oct 1, 2026
Merged

lukemaj merged 2 commits into
mainfrom
fix/88-spawn-thread-drop-runtime-mode

Conversation

@lukemaj

@lukemaj lukemaj commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

What: child threads always start in full-access; spawn_thread no longer takes runtimeMode, and the Prism role kit no longer has one.
Why: a child's approvals go only to the user and the planner cannot see or answer them, so a restricted child stalls unseen; copying the parent's mode would also make a read-only dispatcher's implementers read-only.
So what: ready for review; merging needs the user's approval.

Closes #88

Change

  • threads/tools.ts: removed runtimeMode from SpawnThreadInput; the role description no longer promises per-role permissions.
  • threads/handlers.ts: a child is created with DEFAULT_RUNTIME_MODE instead of kit ?? parent.
  • contracts/prism.ts: removed runtimeMode from role kits and kit patches. Saved settings carrying it still decode (the key is dropped).
  • Tests: the schema omits runtimeMode and a passed value is dropped (roles.test.ts); the child of an approval-required parent starts in full-access (childReportState.test.ts); old saved settings load (prism.test.ts).

Proof

  • vp test run src/mcp/toolkits/threads (apps/server): 41 passed.
  • vp test run src/prism.test.ts (packages/contracts): 9 passed.
  • tsc --noEmit apps/server and packages/contracts: exit 0.
  • Against the old code: the schema test fails (1 failed / 17 passed), and the child-mode test fails with expected 'approval-required' to be 'full-access'.

Elon record

  • Requirements and who asked: the user wants children never blocked on approvals they did not request, and implementers not limited by a restricted dispatcher; nobody asked for agents or kits to pick a child's mode.
  • Deleted: spawn_thread.runtimeMode, the role-kit runtimeMode (unused in the user's settings), and parent-mode inheritance for children.
  • Bottleneck: child approvals route only to the user, invisible to the planner.
  • Checked myself: handlers.ts was the only reader; no web or mobile code shows the kit field; the user's settings set no role mode; the thread toolkit has no approval tool or waiting-for-approval status.

Done by Claude Opus 5.5 in Claude Code (T3 Code).

🤖 Generated with Claude Code

An agent set approval-required on a background child on its own, so
every approval went to the user and the child sat blocked while the
parent reported it running. The child's mode now comes only from the
role kit, else the parent thread. A runtimeMode passed anyway is dropped.

Closes #88

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:S labels Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire 13.5 KiB 13.5 KiB +36 B (+0.3%) 15.1 KiB ✅
Codex Thread snapshot wire 7.1 KiB 7.1 KiB +2 B (+0.0%) 7.3 KiB ✅
Codex Live turn WebSocket wire 6.4 KiB 6.4 KiB +34 B (+0.5%) 7.8 KiB ✅
Codex Live turn WebSocket decoded 56.2 KiB 56.2 KiB +44 B (+0.1%) 66.4 KiB ✅
Codex Live turn messages 8 9 +1 (+12.5%) 21 ✅
Claude Total thread wire 13.5 KiB 13.5 KiB +2 B (+0.0%) 15.1 KiB ✅
Claude Thread snapshot wire 7.1 KiB 7.1 KiB +3 B (+0.0%) 7.3 KiB ✅
Claude Live turn WebSocket wire 6.5 KiB 6.4 KiB −1 B (−0.0%) 7.8 KiB ✅
Claude Live turn WebSocket decoded 57.0 KiB 57.0 KiB 0 B (0.0%) 66.4 KiB ✅
Claude Live turn messages 9 9 0 (0.0%) 21 ✅

Baseline: c0132ad · PR result: e1a54cd · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 113.9 KiB
  • Claude decoded thread snapshot: 114.6 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

…Mode

A child's approvals go to the user, never to the planner, and the planner
cannot see or answer them, so any restricted mode stalls a child unseen.
Copying the parent's mode was also wrong: a read-only dispatcher would
make its implementers read-only. Children now always start in T3's default
full-access mode, and the unused role-kit runtimeMode is removed. Saved
settings that still carry it load and drop the key.

Refs #88

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Child threads: always start in full access; drop agent- and kit-set runtimeMode

1 participant