Skip to content

Vendor the ai-agent-subsystem at v0.11.9: a Gemini run under bypass can run every tool - #34

Merged
gedaiu merged 1 commit into
mainfrom
vendor-subsystem-v0.11.9
Oct 7, 2026
Merged

gedaiu merged 1 commit into
mainfrom
vendor-subsystem-v0.11.9

Conversation

@gedaiu

@gedaiu gedaiu commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Why

ai-agent-subsystem v0.11.9 fixes Gemini runs under permission_mode: bypass, which every floor agent gets by default. --yolo left gemini-cli's built-in rules in charge of whatever yolo didn't cover, so a headless run could have git diff refused with Tool execution denied by policy. The release writes a policy that allows every tool in every approval mode and loads it with --policy (re-cinq/ai-agent-subsystem#268).

What Changed

The same moves as the v0.11.8 vendor (#15):

  • subsystem.version is v0.11.9, and v0.11.9 joins supportedVersions.
  • The vendored controller notes and READMEs name v0.11.9.
  • scripts/setup-minikube-agents.sh takes the v0.11.9 digests, read from the registry for the tag. They match the subsystem's own pin PR (#270). This also replaces the old controller digest, which had a stray trailing 2.
  • @re-cinq/agent-contracts is ^0.11.9.

v0.11.9 changed no CRD and no contract type (git diff v0.11.8 v0.11.9 -- deploy/crds packages/agent-contracts/src is empty), so the CRDs are untouched.

Testing

CI runs the chart and package checks. The digests were checked with docker buildx imagetools inspect ghcr.io/re-cinq/{ai-agent-controller,ai-agent}:v0.11.9.

🤖 Generated with Claude Code

…an run every tool

The chart's subsystem.version and supportedVersions, the vendored controller's
version notes, the minikube script's image digests read from the registry for
the tag, and @re-cinq/agent-contracts ^0.11.9. v0.11.9 changed no CRD.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@lore-agent

lore-agent Bot commented Oct 7, 2026

Copy link
Copy Markdown

Lore is reviewing this PR — 4230b363-f7be-46f9-a58c-cae286dbed94.

Submit a review that requests changes to have Lore push a fix for it. Comment @lore review to re-run the review.

@lore-agent lore-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lore review — Approved

Vendoring of ai-agent-subsystem v0.11.9 is complete and correct.

Must fix (0) · Consider (1) · Nits (0)

Reviewed by gemini-3-flash-preview, gemini-3.1-pro-preview

Submit a review that requests changes to have Lore push a fix for it. Comment @lore review to re-run the review.

Posted by floor, visit 34002fde-1ff2-446c-bb02-2a46b914912f.

The images are not taken from upstream's `deploy/`: a tag's `deploy/` pins the digests of the release before it (at v0.11.6 it still pinned v0.11.3), so the digests are read from the registry for the tag itself. The digests in `scripts/setup-minikube-agents.sh` are the ones the v0.11.8 release published, checked by their image label.
The images are not taken from upstream's `deploy/`: a tag's `deploy/` pins the digests of the release before it (at v0.11.6 it still pinned v0.11.3), so the digests are read from the registry for the tag itself. The digests in `scripts/setup-minikube-agents.sh` are the ones the v0.11.9 release published, checked by their image label.

`npm run minikube-setup` installs this, and `npm run minikube-claude-auth` gives its agents a Claude credential. To move to a newer release, copy the new `deploy/crds/`, update the two image digests in the script, and bump `@re-cinq/agent-contracts`.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

question: Were there no CRD changes upstream in v0.11.9?

Suggested change
`npm run minikube-setup` installs this, and `npm run minikube-claude-auth` gives its agents a Claude credential. To move to a newer release, copy the new `deploy/crds/`, update the two image digests in the script, and bump `@re-cinq/agent-contracts`.
The README instructions say to 'copy the new deploy/crds/', but the diff contains no changes to the CRDs. If upstream CRDs changed in v0.11.9, they need to be vendored here as well.

@gedaiu
gedaiu merged commit 61c66cf into main Oct 7, 2026
15 checks passed
gedaiu added a commit to re-cinq/lore that referenced this pull request Oct 7, 2026
…try (#2609)

## Why

A Gemini review pod on Otto (run 3c90397a) had `git -C /workspace/target
diff ...` refused with "Tool execution denied by policy." Every AI
station's pod should be able to run any tool or command; the test guard
(`LORE_TEST_POLICY`) is meant to be the only refusal. The Gemini half of
the fix ships in ai-agent-subsystem v0.11.9
(re-cinq/ai-agent-subsystem#268), which every bypass run now gets: it is
live on the floor since re-cinq/floor#34. What's left here is Lore's own
recipes.

## What Changed

- `daily-digest` named no `skills_source`, so the floor served its own
`/skills` and the pod never got the test guard. It now names
`${LORE_SKILLS_URL}`.
- The `disallowed_tools` lists are gone from the review and planning
agents and the `code-review` default. Claude enforces them in every
permission mode, so those pods couldn't run `sh`, `bash`, `go`, `make`
or `npx` at all; the guard already blocks the test runs, installs and
builds they were meant to stop.
- Two pipeline-wide tests fail on any agent that skips Lore's registry
or declares a deny list. The platform spec and `CLAUDE.md` describe
this.

An earlier commit shipped a Gemini policy file in Lore's hook bundle as
a stopgap. With v0.11.9 live, the last commits remove it again.

## Testing

- `vitest` on the assembly-lines suite and the mcp-server transport
tests passes after rebasing onto main.
- eslint on the changed files reports no errors.
- The spec's links point at the new tests.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant