Skip to content
Merged
Changes from 1 commit
Commits
Show all changes
15 commits
Select commit Hold shift + click to select a range
da26d9d
fix(permissions): escalate repeated destructive-command denials to ma…
yiliang114 Oct 8, 2026
fa1c3a9
test(permissions): pin destructive escalation message and persisted s…
yiliang114 Oct 8, 2026
2add596
docs(auto-mode): count destructive blocks in the 3-block fallback bullet
yiliang114 Oct 8, 2026
fd7d48a
fix(permissions): keep the denial reason on the session-cap fallback …
yiliang114 Oct 8, 2026
43fef6f
docs(approval-mode): count destructive blocks in the loop-guard bullet
yiliang114 Oct 8, 2026
6953a30
fix(permissions): sanitize the destructive escalation banner reason
yiliang114 Oct 8, 2026
b65468e
fix(permissions): sanitize the destructive denial tool error
yiliang114 Oct 8, 2026
755ec95
Merge origin/main into fix/issue-13570-destructive-denial-escalation
yiliang114 Oct 8, 2026
e39649b
docs(auto-mode): note the destructive-block cap exception in failure …
yiliang114 Oct 8, 2026
e36d9fa
fix(permissions): bound the destructive guard's echoed fragment
yiliang114 Oct 8, 2026
9b6eab4
fix(permissions): qualify the destructive guard contract comments
yiliang114 Oct 9, 2026
d9632ba
fix(permissions): name the arm instead of a spatial pointer in the L5…
yiliang114 Oct 9, 2026
d50890f
fix(permissions): make the destructive-command escalation human-only
yiliang114 Oct 9, 2026
b072304
fix(acp): require human approval for destructive hook replacements
yiliang114 Oct 9, 2026
fddaab1
fix(permissions): deny human-only destructive escalation in headless …
yiliang114 Oct 9, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
docs(approval-mode): count destructive blocks in the loop-guard bullet
`docs/users/features/approval-mode.md` described the AUTO mode loop guard as
"three consecutive policy blocks" after which "the next call" falls back. Since
the destructive-command escalation, deterministic destructive-command blocks
also count towards that cap, and `shouldFallback` is evaluated on the
post-increment state, so the call that reaches the third block falls back on
that same call.

Mirrors the wording already delivered for the sibling bullet in
`docs/users/features/auto-mode.md`, keeping the two user docs consistent.

Co-authored-by: Qwen-Coder <[email protected]>
Patrol-Run: qwen-pr-closeout/jmuzbyw3ref
  • Loading branch information
yiliang114 and qwencoder committed Oct 8, 2026
commit 43fef6f2b6a94db97e5fd70e0fbfc1c16c643fb0
7 changes: 4 additions & 3 deletions docs/users/features/approval-mode.md
Original file line number Diff line number Diff line change
Expand Up @@ -269,9 +269,10 @@ settings.json. See [auto-mode.md](./auto-mode.md#configuring-hints).
- **Fail-closed**: when the classifier API is unreachable, the action is
blocked rather than allowed. After two consecutive unavailable calls,
the next tool call falls back to manual approval.
- **Loop guard**: after three consecutive policy blocks, the next call
also falls back to manual approval so the agent isn't stuck cycling on
a dead-end approach.
- **Loop guard**: after three consecutive blocks — classifier policy blocks
and deterministic destructive-command blocks both count — the call that
reaches the third block also falls back to manual approval so the agent
isn't stuck cycling on a dead-end approach.

### Example

Expand Down
Loading