Skip to content

fix(subagents): prevent scoped tools from bypassing idle review - #247

Merged
Grivn merged 11 commits into
mainfrom
codex/fix-211-review-evidence-reuse
Sep 11, 2026
Merged

fix(subagents): prevent scoped tools from bypassing idle review#247
Grivn merged 11 commits into
mainfrom
codex/fix-211-review-evidence-reuse

Conversation

@Grivn

@Grivn Grivn commented Sep 11, 2026

Copy link
Copy Markdown
Collaborator

提交 PR 前请阅读贡献指南Contributing Guide开发和验证指南 / Development and Verification Guide
Before opening a PR, read the Contributing Guide, 贡献指南, and the Development and Verification Guide / 开发和验证指南.
PR 标题和提交信息必须使用 Conventional Commits(type(scope): subject),且不得包含 emoji。 / PR titles and commits must use Conventional Commits (type(scope): subject) and must not contain emoji.
本仓库接受 Bug 修复、兼容性适配、现有能力增强、性能或体验优化和维护类 PR。全新能力、Provider、持久化格式或安全边界变更必须先提 Issue 并获得维护者确认。 / This repository accepts bug fixes, compatibility work, improvements to existing capabilities, performance or UX optimization, and maintenance. New capabilities, Providers, persistence formats, or security-boundary changes require prior maintainer approval in an Issue.
外部贡献者的仅文档类 PR 不直接接受;请先提 Issue 讨论。维护者的发布说明与文档维护不受此限制。 / Documentation-only PRs from external contributors are not accepted directly; open an Issue first. Maintainer release notes and documentation maintenance are exempt.

摘要 / Summary

Idle review could execute an AOCI-style tool registered directly on its child Agent, bypassing DSH's inherited-tool filter even when complete overview evidence was already present. Attach a scoped execution guard before the child runs and explicitly reuse inherited evidence; bounded Document search and normal parent/manual tools remain available.

后台审查已继承完整概览时,仍可能通过直接注册在子 Agent 作用域中的工具重复读取。此修复在子 Agent 发布时安装执行限制,并明确复用继承证据,保留有界档案搜索和正常父会话 / 手动工具操作。

关联 Issue 或背景 / Related Issue or Context

Fixes #211.

The verified case is the current per-Agent plugin composition gap. The original Windows/AOCI profile and historical ~37K token usage were not reproduced; no token-saving measurement is claimed. Only the model choices and synthetic overview tool are fixtures.

涉及区域 / Affected Areas

  • Host 激活、Headless 或 bundle / Host activation, Headless, or bundle
  • 运行时记忆 / Runtime Memory
  • 项目档案 / Project Documents
  • 记忆空间或 Provider / Memory Spaces or Providers
  • 子 Agent 或 Agent 工作流 / Subagent or Agent workflow
  • Web UI 或对话交互 / Web UI or conversation interaction
  • 设置、存储或安全 / Settings, storage, or security
  • CLI、RPC、命令或工具 / CLI, RPC, commands, or tools
  • 安装、更新或发布 / Installation, update, or release
  • 测试、构建或文档 / Tests, build, or documentation
  • 其他(请说明)/ Other (explain below)

PR 类型 / PR Type

  • 面向用户的功能或行为变更 / User-facing feature or behavior change
  • Bug 修复 / Bug fix
  • 增强或优化 / Enhancement or optimization
  • 兼容性适配 / Compatibility change
  • 维护或重构 / Maintenance or refactor
  • 测试或构建 / Tests or build

最新代码确认 / Latest Codebase Confirmation

  • 我已基于最新 main 分支开发,或在提交前已 rebase 或合并最新 main。 / I developed from the latest main, or rebased or merged the latest main before submitting.

同步命令 / Sync command:

git fetch origin main confirmed base 1e19caf40f0bf37edf678c3d829f2398ab28792a; isolated worktree from latest main.

AI 编码披露 / AI Coding Disclosure

  • 完全 AI 编码:全部编程改动由 AI 产出,并由贡献者接受和审查。 / Fully AI-coded: AI produced all programming changes, which the contributor accepted and reviewed.
  • 部分 AI 辅助:AI 帮助编写或修改了部分内容。 / Partially AI-assisted: AI helped write or modify part of the change.
  • 未使用 AI 编码辅助。 / No AI coding assistance was used.

使用的 AI 模型 / AI model used:

GPT-6 Astra, max reasoning.

使用的编码 Agent 工具 / Coding Agent tool used:

Codex desktop with explicitly authorized collaborative agents.

仓库规范检查 / Repository Rules

  • 未修改 DSH 官方源码,未让 tsconfig 指向 DSH 源码 checkout,仅使用正式的 @deepseek-ai/* NPM 契约。 / I did not modify DSH source or point tsconfig at a DSH source checkout, and used only published @deepseek-ai/* NPM contracts.
  • Client 与 Host 边界仍以浏览器安全的 src/host/protocol.ts 为准,没有在两侧重复定义 wire DTO。 / The Client and Host boundary still uses browser-safe src/host/protocol.ts as the source for wire DTOs.
  • 持久化格式、RPC 权限、路径或凭据处理的变更包含兼容或拒绝路径、安全分析和相应测试。 / Changes to persistence formats, RPC authority, paths, or credentials include compatibility or rejection paths, security analysis, and tests.
  • 没有提交 token、密钥、私有记忆、未脱敏日志或生成的 lib/ 文件。 / I did not commit tokens, credentials, private memory, unredacted logs, or generated lib/ files.
  • 用户可见文案和长期文档已同步维护中文与英文版本,命令、配置键和路径保持一致。 / User-facing copy and long-lived documentation are synchronized in Chinese and English, with matching commands, configuration keys, and paths.
  • 会改变发布制品或其元数据的 PR 已添加 changeset;仅测试、CI 或站点文档变更可不添加。 / A PR that changes a published artifact or its metadata includes a changeset; test-only, CI-only, and site-documentation-only changes may omit one.
  • 新增和修改的代码、注释、文档、提交信息不含 emoji。 / New and modified code, comments, documentation, and commits contain no emoji.

兼容性与数据安全 / Compatibility and Data Safety

Uses published DSH APIs only: agent/created, agents.isOwnedBy, and agent.ctx.tools.guard. Real execution was verified on 0.1.5-rc.1; published 0.1.1-rc.1 and 0.1.2-rc.1 tarballs contain the required public contracts. Unsupported ownership/guard capability fails review explicitly. Both native and Code Mode paths preserve authorized tools and completion. The guard remains through child disposal; nested/concurrent starts and failing disposers are covered.

No storage format, RPC authority, credential, or Provider schema changes. Tests isolated DSH_HOME, MNEMON_DATA_DIR, and workspace; no personal data was used. Root-only patch changeset included. The measured artifact is 1,271,378 unpacked bytes; the bounded package cap moves from 1,270,000 to 1,275,000 for the Host guard. The browser fixture and real-host test accept both result protocols from #239.

本地验证 / Local Validation

执行的命令 / Commands run:

pnpm run verify
pnpm exec vitest run tests/review-evidence-host.spec.ts tests/review-tools.spec.ts tests/subagent.spec.ts
MNEMON_NATIVE_TEST_CLI=/opt/homebrew/bin/mnemon pnpm --filter dsh-mnemon-source-memory-spaces test -- tests/native-integration.spec.ts
pnpm run release:intent

结果摘要 / Result summary:

Final pnpm run verify passed: 935 Root and 323 plugin tests (seven opt-in skips), type checks, deterministic builds, Headless activation/restart/disable, package contents/public entries/lint. Targeted: 94 passed, including real native and worker-thread Code Mode dispatch before start returns. Real Native suite: 169 passed, one Windows-only skip. Both HTTP completion protocols also passed a fixed-fixture check. Release-intent coverage passed for dsh-mnemon. The initial package-cap failure was resolved by the documented measured cap adjustment; no failing checks remain.

用户可见变更证据 / Local Feature Evidence

Bilingual evidence and reproduction records source hashes, workload, counts, environment, and limits. Both real WebUI runs enable all three Strategy extensions.

Baseline: five inherited chunks, five parent reads, one executed redundant child read.

Baseline child read

Fixed: identical attempted read is denied; bounded Document search and skipped completion succeed.

Guarded review

A real Native CLI canary remains readable through WebUI; normal Forget returns zero items.

Native CLI continuity

证据 / Evidence:

@Grivn
Grivn merged commit 88f6dcc into main Sep 11, 2026
3 checks passed
@Grivn Grivn mentioned this pull request Sep 11, 2026
28 tasks
@Grivn
Grivn deleted the codex/fix-211-review-evidence-reuse branch September 11, 2026 14:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Idle review worker re-fetches the full AOCI overview already present in the inherited parent context (~37K redundant tokens)

1 participant