Conversation
…e guard The planning-phase tool_call gate rejected xd://plannotator_submit_plan as a non-markdown path, making plan submission impossible. Allowlist exactly that device URI; all other device URIs, non-markdown writes, and the submit tool's file validation are unchanged. Closes backnotprop#1466.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
In Oh My Pi planning mode the agent must submit its plan by writing JSON to the
xd://plannotator_submit_plandevice URI, but the planning-phasetool_callgate validated every write/edit path withisPlanWritePathAllowed, which rejects the URI as a non-markdown path. Plan submission was impossible: the planning contract demands a call the guard blocks.This change allowlists exactly that device URI (derived from
PLAN_SUBMIT_TOOL, exact match only) in the gate. Everything else is unchanged: other device URIs such asxd://report_issuestay blocked, filesystem writes stay limited to in-cwd markdown, and the submit tool's own plan-file validation keeps rejecting device URIs as file paths.Testing:
bun test apps/pi-extension/tool-scope.test.ts(16 pass), fullbun run typecheckclean.Closes #1466.