From e02b279785c5462effdb865fe1ab8ac3b66d45ef Mon Sep 17 00:00:00 2001 From: damocles Date: Wed, 27 May 2026 13:35:43 +0200 Subject: [PATCH 1/2] harness: add 6 missing manager tools to allow-list (unblocks #509) --- hive-ag3nt/src/mcp.rs | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/hive-ag3nt/src/mcp.rs b/hive-ag3nt/src/mcp.rs index 63593d97..a2548e4d 100644 --- a/hive-ag3nt/src/mcp.rs +++ b/hive-ag3nt/src/mcp.rs @@ -1765,6 +1765,19 @@ pub fn allowed_mcp_tools(flavor: Flavor) -> Vec { "restart", "update", "request_apply_commit", + // Tools added post-#444 / #235 / #467 / #472 / #474 / #478 that + // got missed in the allow-list when their `#[tool]` impls + // landed. Claude Code's permission gate refuses uninlisted + // tools in non-interactive `--print` mode with a "permissions + // not granted yet" error (hm1nd hit this trying to run the + // dedup pass for #509). Keep this block in lockstep with the + // `#[tool]` fns in the `ManagerServer` impl. + "request_update_meta_inputs", + "request_schedule_prompt", + "fire_schedule_now", + "cancel_schedule", + "edit_schedule", + "list_schedules", "ask", "answer", "get_logs", From c62c73e546443988689fea09220f0d6599cc4d92 Mon Sep 17 00:00:00 2001 From: damocles Date: Wed, 27 May 2026 13:47:35 +0200 Subject: [PATCH 2/2] harness: anchor 'update allow-list' reminder on both #[tool_router] impls (argus nit on #511) --- hive-ag3nt/src/mcp.rs | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/hive-ag3nt/src/mcp.rs b/hive-ag3nt/src/mcp.rs index a2548e4d..c77721bc 100644 --- a/hive-ag3nt/src/mcp.rs +++ b/hive-ag3nt/src/mcp.rs @@ -467,6 +467,12 @@ impl AgentServer { } } +// IMPORTANT: when adding a new `#[tool]` fn to this impl, also add +// its name to `allowed_mcp_tools(Flavor::Agent)` below. Claude +// Code's permission gate refuses uninlisted MCP tools in +// non-interactive `--print` mode with "permissions not granted yet" +// — same failure mode #511 cleaned up on the manager side. Keep the +// two lists in lockstep. #[tool_router] impl AgentServer { #[tool( @@ -1058,6 +1064,12 @@ impl ManagerServer { } } +// IMPORTANT: when adding a new `#[tool]` fn to this impl, also add +// its name to `allowed_mcp_tools(Flavor::Manager)` below. Claude +// Code's permission gate refuses uninlisted MCP tools in +// non-interactive `--print` mode with "permissions not granted yet" +// — exactly the failure mode PR #511 cleaned up. Keep the two lists +// in lockstep. #[tool_router] impl ManagerServer { #[tool(