Skip to content

fix(server): preserve Claude Auto permission fallback - #15698

Open
ashx-j wants to merge 4 commits into
pingdotgg:mainfrom
ashx-j:fix/issue-15650-claude-auto-followup
Open

ashx-j wants to merge 4 commits into
pingdotgg:mainfrom
ashx-j:fix/issue-15650-claude-auto-followup

Conversation

@ashx-j

@ashx-j ashx-j commented Oct 4, 2026 •

Copy link
Copy Markdown

Claude can silently start an unsupported Auto session in Manual. T3 then tried to restore Auto before follow-up turns, causing setPermissionMode to fail for delegated children and manually selected threads.

Records the first permission mode reported by each live Claude process and preserves its initial Auto-to-Manual fallback. Later mode changes still trigger restoration, including after EnterPlanMode. Supported Auto sessions continue to restore Auto, and replacement processes start with fresh state. This uses the provider's reported behavior rather than a model allowlist.

Fixes #15650.

validation after updating to current main on october 11:

  • all 231 claude adapter tests pass, including the four auto-fallback cases.
  • scoped typecheck of the adapter and its tests passes, as do targeted lint and formatting.
  • the merge retains current main's serialized sdk message handling. no live provider session was launched.

replaces #15692, whose original source fork was deleted.

initial implementation by gpt-6.1-sol through codex. updated by gpt-6-astra through codex in t3 code.


gpt 6 astra writing on behalf of ash.

@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Oct 4, 2026
@macroscopeapp

macroscopeapp Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at 93d9b3b

Macroscope's review found this PR approvable — This is a small, well-tested server bug fix that preserves Claude's initial permission fallback during reused sessions without changing product defaults or adding new capability. Supported Auto sessions and existing permission restoration behavior remain covered and unchanged.

You can add or adjust custom eligibility rules. Learn more.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Path: .coderabbit.config.ts
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 4417d43a-de0f-4ec3-8c08-ee6b7c01ffd3

📥 Commits

Reviewing files that changed from the base of the PR and between 312d72c and 93d9b3b.


📒 Files selected for processing (2)
  • apps/server/src/orchestration-v2/Adapters/ClaudeAdapterV2.test.ts
  • apps/server/src/orchestration-v2/Adapters/ClaudeAdapterV2.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.



📝 Walkthrough

Walkthrough

The Claude adapter records the first permission mode reported by a live query. When reusing a query opened in auto that first reported default, it restores default. Parameterized tests cover initial init and status frames and later permission-mode changes.

Changes

Claude Auto Permission Mode

Layer / File(s) Summary
Track and restore the initial mode
apps/server/src/orchestration-v2/Adapters/ClaudeAdapterV2.ts, apps/server/src/orchestration-v2/Adapters/ClaudeAdapterV2.test.ts
The adapter captures the first permission mode reported in an init or status frame. On live-query reuse, it restores default if the query opened in auto but first reported default; otherwise, it restores the opening mode. Parameterized tests cover initial frames, later reports, query reuse, and an unsupported Auto-mode update.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Bug fix · Severity of issue fixed: Medium

Suggested reviewers: juliusmarminge


Merge Risk | ⚪ Minimal · up to 93d9b

Merge Risk: ⚪ Minimal · up to 93d9b

The Auto permission fallback change is ready to merge after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 93d9b

The change preserves an initially reported Manual fallback instead of retrying unsupported Auto permissions. No new permission bypass was identified, but provider-side failure behavior and concurrent permission transitions remain incompletely validated.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The changed decision affects subsequent prompted turns on a reused live process opened in Auto that initially reported default, including work performed through that process's existing tools and delegated agents. It does not select additional tools, credentials or bypass-permission settings.

Trust Boundaries and Controls

  • observed — Prompt content is offered only after query selection and permission restoration. Ordinary reuse requires matching native thread, model identity and effective policy, including tool allowlists, approval configuration and MCP overrides. Tool requests are denied without an active turn. These existing controls remain separate from the new provider-reported fallback field.

Resilience and Maintainability Implications

  • observed — Continuation turns bypass restoration because they replay already-produced output rather than send another prompt; this behavior is unchanged from the base. Failed replacement opens clear obsolete process-scoped background state, and successful replacements start with fresh permission observations.

Pre-merge checks | Passed 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check Passed The title clearly and concisely describes the main change: preserving Claude Auto permission fallback in the server.
Description check Passed The description explains the problem, the implementation, the linked issue, and focused verification results. It does not use the required section headings and does not explicitly document maintainer …
Linked Issues check Passed Issue #15650 requires delegated Claude follow-up turns to succeed when the provider rejects inherited Auto. The PR records the first permission mode reported by each live process and preserves an init…
Out of Scope Changes check Passed The changes are limited to Claude live-query permission-mode state and focused adapter tests. The test harness changes verify the fallback, restoration, and process-state behavior. These changes direc…

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@juliusmarminge juliusmarminge added the macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews label Oct 11, 2026 — with ChatGPT Codex Connector
macroscopeapp[bot]
macroscopeapp Bot previously approved these changes Oct 11, 2026
@macroscopeapp
macroscopeapp Bot dismissed their stale review October 11, 2026 07:24

Dismissing prior approval to re-evaluate 93d9b3b

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews size:S 10-29 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Follow-up to a finished delegated Claude subagent fails with set_permission_mode control_request_failed when runtime mode is auto

2 participants