hive-runtime, hive-agent: MCP permission only for kind other
A permission request counted as an MCP tool call whenever its title looked like `<server>_<tool>`, whatever its kind, and acp_permits allowed MCP calls before looking at the kind. So an `execute` request titled e.g. `hyperhive_x`, or a `fetch` without web_tools, was allowed. MCP tool calls come with kind `other` (opencode's toToolKind maps every tool it doesn't name, MCP tools included, to "other"). The runtime now sets PermissionAsk::mcp_server only for kind `other`, and acp_permits allows an MCP server's tool only under the `other` arm. Refs #4391
This commit is contained in:
parent
868fc789d1
commit
bed72ce280
3 changed files with 49 additions and 10 deletions
|
|
@ -34,9 +34,10 @@ pub struct PermissionAsk<'a> {
|
|||
/// The tool call's ACP `kind` (`read`, `edit`, `execute`, `fetch`, …;
|
||||
/// `other` when the agent gives none).
|
||||
pub kind: &'a str,
|
||||
/// The MCP server, of those handed to the session, whose tool this is:
|
||||
/// the tool call's title names it as `<server>_<tool>`,
|
||||
/// `<server>__<tool>` or `mcp__<server>__<tool>`.
|
||||
/// For a `kind` of `other`: the MCP server, of those handed to the
|
||||
/// session, whose tool this is — the tool call's title names it as
|
||||
/// `<server>_<tool>`, `<server>__<tool>` or `mcp__<server>__<tool>`.
|
||||
/// `None` for every other kind.
|
||||
pub mcp_server: Option<&'a str>,
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue