Repository navigation
Vendor the ai-agent-subsystem at v0.11.9: a Gemini run under bypass can run every tool - #34
Merged
Merged
Conversation
…an run every tool The chart's subsystem.version and supportedVersions, the vendored controller's version notes, the minikube script's image digests read from the registry for the tag, and @re-cinq/agent-contracts ^0.11.9. v0.11.9 changed no CRD. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Lore is reviewing this PR — 4230b363-f7be-46f9-a58c-cae286dbed94. Submit a review that requests changes to have Lore push a fix for it. Comment |
There was a problem hiding this comment.
Lore review — Approved
Vendoring of ai-agent-subsystem v0.11.9 is complete and correct.
Must fix (0) · Consider (1) · Nits (0)
Reviewed by gemini-3-flash-preview, gemini-3.1-pro-preview
Submit a review that requests changes to have Lore push a fix for it. Comment @lore review to re-run the review.
Posted by floor, visit 34002fde-1ff2-446c-bb02-2a46b914912f.
| The images are not taken from upstream's `deploy/`: a tag's `deploy/` pins the digests of the release before it (at v0.11.6 it still pinned v0.11.3), so the digests are read from the registry for the tag itself. The digests in `scripts/setup-minikube-agents.sh` are the ones the v0.11.8 release published, checked by their image label. | ||
| The images are not taken from upstream's `deploy/`: a tag's `deploy/` pins the digests of the release before it (at v0.11.6 it still pinned v0.11.3), so the digests are read from the registry for the tag itself. The digests in `scripts/setup-minikube-agents.sh` are the ones the v0.11.9 release published, checked by their image label. | ||
|
|
||
| `npm run minikube-setup` installs this, and `npm run minikube-claude-auth` gives its agents a Claude credential. To move to a newer release, copy the new `deploy/crds/`, update the two image digests in the script, and bump `@re-cinq/agent-contracts`. |
There was a problem hiding this comment.
question: Were there no CRD changes upstream in v0.11.9?
Suggested change
| `npm run minikube-setup` installs this, and `npm run minikube-claude-auth` gives its agents a Claude credential. To move to a newer release, copy the new `deploy/crds/`, update the two image digests in the script, and bump `@re-cinq/agent-contracts`. | |
| The README instructions say to 'copy the new deploy/crds/', but the diff contains no changes to the CRDs. If upstream CRDs changed in v0.11.9, they need to be vendored here as well. |
gedaiu
added a commit
to re-cinq/lore
that referenced
this pull request
Oct 7, 2026
…try (#2609) ## Why A Gemini review pod on Otto (run 3c90397a) had `git -C /workspace/target diff ...` refused with "Tool execution denied by policy." Every AI station's pod should be able to run any tool or command; the test guard (`LORE_TEST_POLICY`) is meant to be the only refusal. The Gemini half of the fix ships in ai-agent-subsystem v0.11.9 (re-cinq/ai-agent-subsystem#268), which every bypass run now gets: it is live on the floor since re-cinq/floor#34. What's left here is Lore's own recipes. ## What Changed - `daily-digest` named no `skills_source`, so the floor served its own `/skills` and the pod never got the test guard. It now names `${LORE_SKILLS_URL}`. - The `disallowed_tools` lists are gone from the review and planning agents and the `code-review` default. Claude enforces them in every permission mode, so those pods couldn't run `sh`, `bash`, `go`, `make` or `npx` at all; the guard already blocks the test runs, installs and builds they were meant to stop. - Two pipeline-wide tests fail on any agent that skips Lore's registry or declares a deny list. The platform spec and `CLAUDE.md` describe this. An earlier commit shipped a Gemini policy file in Lore's hook bundle as a stopgap. With v0.11.9 live, the last commits remove it again. ## Testing - `vitest` on the assembly-lines suite and the mcp-server transport tests passes after rebasing onto main. - eslint on the changed files reports no errors. - The spec's links point at the new tests. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
ai-agent-subsystem v0.11.9 fixes Gemini runs under
permission_mode: bypass, which every floor agent gets by default.--yololeft gemini-cli's built-in rules in charge of whatever yolo didn't cover, so a headless run could havegit diffrefused withTool execution denied by policy.The release writes a policy that allows every tool in every approval mode and loads it with--policy(re-cinq/ai-agent-subsystem#268).What Changed
The same moves as the v0.11.8 vendor (#15):
subsystem.versionisv0.11.9, andv0.11.9joinssupportedVersions.scripts/setup-minikube-agents.shtakes the v0.11.9 digests, read from the registry for the tag. They match the subsystem's own pin PR (#270). This also replaces the old controller digest, which had a stray trailing2.@re-cinq/agent-contractsis^0.11.9.v0.11.9 changed no CRD and no contract type (
git diff v0.11.8 v0.11.9 -- deploy/crds packages/agent-contracts/srcis empty), so the CRDs are untouched.Testing
CI runs the chart and package checks. The digests were checked with
docker buildx imagetools inspect ghcr.io/re-cinq/{ai-agent-controller,ai-agent}:v0.11.9.🤖 Generated with Claude Code