Skip to content

feat(cli): continue run after rejecting a permission ask - #51968

Merged
jlongster merged 1 commit into
v2from
run-ask-continue
Sep 29, 2026
Merged

jlongster merged 1 commit into
v2from
run-ask-continue

Conversation

@jlongster

Copy link
Copy Markdown
Collaborator

Type of change

  • New feature

What does this PR do?

opencode run has nobody to approve permission asks. Today it rejects the ask, interrupts the session and exits 1. The model never gets to react.

Now, outside V1 compatibility mode, run rejects the ask with feedback (permission.reply with decision: "reject" and a message) and does not interrupt. Core already turns a reject-with-message into Permission.CorrectedError, so the tool fails with model-visible output and the model continues in the same turn. The run then ends normally, with an exit code that reflects the final outcome.

! permission requested: read (.env); auto-rejecting
✗ Read .env failed
Error: This non-interactive run cannot ask the user for permission, so the request was rejected. Continue without this action.
> build · …
<model's final answer>
  • --auto is unchanged: it approves once.
  • A deny rule is unchanged: the tool is blocked and the model continues.
  • V1 compatibility mode keeps reject + interrupt.

Core fix included: toSessionError had no case for Permission.CorrectedError, whose message is empty. Tools that wrap permission failures, like read ("Unable to read .env"), replaced the feedback with their generic message, so a rejection with feedback never reached the model. That also affects the TUI's reject-with-feedback. It now maps to permission.rejected with the feedback text, like BlockedError.

How did you verify your code works?

  • packages/cli: bun typecheck; bun test test/run is 11 pass / 0 fail.
  • packages/core: bun typecheck; bun test test/session-runner.test.ts test/permission.test.ts test/session-error.test.ts is 333 pass / 0 fail.
  • End to end with opencode-drive (server and CLI both from this branch, simulated LLM reading .env), checking whether the file's contents or the feedback reached the model:
    • allow → tool runs, exit 0
    • ask → rejected with feedback, model sees the feedback (not the secret) and continues, exit 0
    • deny → blocked, model continues, exit 0

Checklist

  • I have tested my changes locally
  • I have not included unrelated changes in this PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant