Watch
0
0
Fork
You've already forked hyperhive
0

hive-runtime, hive-agent: MCP permission only for kind other

A permission request counted as an MCP tool call whenever its title
looked like `<server>_<tool>`, whatever its kind, and acp_permits
allowed MCP calls before looking at the kind. So an `execute` request
titled e.g. `hyperhive_x`, or a `fetch` without web_tools, was allowed.

MCP tool calls come with kind `other` (opencode's toToolKind maps every
tool it doesn't name, MCP tools included, to "other"). The runtime now
sets PermissionAsk::mcp_server only for kind `other`, and acp_permits
allows an MCP server's tool only under the `other` arm.

Refs #4391
This commit is contained in:
atlas 2026-09-29 22:14:06 +02:00 • committed by mara
commit bed72ce280
3 changed files with 49 additions and 10 deletions

View file

@ -34,9 +34,10 @@ pub struct PermissionAsk<'a> {
/// The tool call's ACP `kind` (`read`, `edit`, `execute`, `fetch`, …;
/// `other` when the agent gives none).
pub kind: &'a str,
/// The MCP server, of those handed to the session, whose tool this is:
/// the tool call's title names it as `<server>_<tool>`,
/// `<server>__<tool>` or `mcp__<server>__<tool>`.
/// For a `kind` of `other`: the MCP server, of those handed to the
/// session, whose tool this is — the tool call's title names it as
/// `<server>_<tool>`, `<server>__<tool>` or `mcp__<server>__<tool>`.
/// `None` for every other kind.
pub mcp_server: Option<&'a str>,
}