Skip to content

feat(chat): default scoped project conversations to workspace writes - #5555

Open
huangruiteng wants to merge 3 commits into
codex/native-private-agent-selection-20261004from
codex/native-project-write-grant-20261004
Open

huangruiteng wants to merge 3 commits into
codex/native-private-agent-selection-20261004from
codex/native-project-write-grant-20261004

Conversation

@huangruiteng

Copy link
Copy Markdown
Collaborator

Ordinary project Chat currently refuses requested file edits because both the Codex sandbox and conversational prompt are read-only. Default host-declared project workspaces and Codex project App bindings now support workspace_write, with an explicit read-only option. The existing typed context owner derives the actual host sandbox on start and exact-thread resume, without Task/Goal mode or manager authority.

Settings, persisted App readback and /status//help agree with the effective grant. --project-workspace-grant workspace_read restricts both local Chat and App binding creation/resume. Changing an App grant creates a new binding/Session and requires new Agent target authorization; old Sessions cannot gain permission or move audiences. Other executors and steward/attached-host permissions remain independently scoped. Material Lifecycle still requires its own explicit activation and project adapter.

Stacked on #5546 at e05382373f21e4660fdc8377af109264fa9ecc9f; the PR base isolates this increment and does not repeat its unmerged foundations. The base includes the current main 99839aeb8fed5fae38a5d319391cd050672a6508.

Validation on this head:

  • 178 focused Python cases and 14 native Core cases passed, including ordinary no-Goal write start/resume, explicit read-only, grant downgrade/replacement, App isolation and status without model work.
  • A real Codex host edited/read back a synthetic note under project AGENTS/skill instructions and preserved prior text without creating a Goal.
  • Packaged settings browser: default write binding, independent read-only second App, reload and persisted grant readback passed with a synthetic provider. This is not live Lark write-workflow evidence.
  • Core/dashboard typecheck, standard Chat bundle build, configured Mypy (19 sources), changed-file Ruff, semantic/registry IO census and exact 23-path premerge passed (5 direct checks, 19 selected checks). Quality policy is disabled; no fabricated qualification receipt or merge permission.
  • An exploratory whole-repository Ruff invocation failed with 606 findings; changed Python files pass. Chat build retains its existing chunk-size warning. Full repository pytest, Linux/release CI, installed live Lark writing, material intake/ranking, streaming media/permission callbacks and login recovery remain unqualified.

The existing IO census was regenerated for three shifted line references, without adding direct IO classifications. Shared project context/binding remains the permission owner; no provider-local Session authority, new runner or scheduler. Runtime/product/permission changes require maintainer review and are not self-merged.

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant