Skip to content

fix: tighten semantic dynamic choice safeguards - #73

Merged
nicobailon merged 7 commits into
mainfrom
fix/jev-semantic-followups
Sep 21, 2026
Merged

nicobailon merged 7 commits into
mainfrom
fix/jev-semantic-followups

Conversation

@nicobailon

@nicobailon nicobailon commented Sep 21, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • classify exact and comma-qualified visible Yes/No menus as dynamic-terminal-confirmation while keeping ordinary supported menus under dynamic-terminal-choice
  • fail closed for other whole-word Yes/No-leading pairs instead of downgrading them to generic choices
  • stop both later and already-pending dynamic choices after stop_automation
  • keep one-time approval identity stable when only elapsed/quiet time buckets change

Safety and scope

  • permission identity remains code-owned and uses the trusted global deny > ask > allow policy
  • terminal/session/operation changes still invalidate approval
  • exact input binding, secret/lifecycle exclusions, ownership/freshness checks, fixed actions, launch policy, and the one-dynamic-attempt session limit remain unchanged
  • supported layouts remain deliberately bounded; this is not general unattended CLI operation or a command sandbox
  • ask is the recommended default for both dynamic operation kinds unless a narrower trusted rule is intentional

Validation

  • focused semantic/observation/monitor matrix: 257 tests passed before the policy follow-up
  • confirmation-policy regression matrix: 72 tests passed
  • targeted independent review of updated policy delta: no P0/P1/P2 findings, merge verdict OK
  • full test suite
  • TypeScript typecheck
  • package dry run
  • diff hygiene

Follow-up to #72.

@nicobailon
nicobailon merged commit 06b9da3 into main Sep 21, 2026
2 checks passed
@nicobailon
nicobailon deleted the fix/jev-semantic-followups branch September 21, 2026 20:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant