🪬 fix: Enforce Tool Approval Policy on Headless Agent Runs - #16467
Conversation
|
Review handoff for exact pushed head |
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Codex Review: Didn't find any major issues. 🚀 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Summary
An enabled
endpoints.agents.toolApprovalpolicy was installed only when the run caller supported interactive pause/resume. The two API-key Chat Completions and Responses endpoints do not implement that lifecycle, so they never registered the policy'sPreToolUsehooks. In particular, an administrator's harddenyanddontAskrules did not reach tools invoked by those endpoints.Build the same policy hooks for every run with an enabled policy. Keep the
humanInTheLoopswitch and durable checkpointer exclusive to interactive callers. The SDK blocks adenybefore tool execution and, without a resume surface, also blocksaskrather than emitting an unresolved interrupt. Explicit allows and theenabled: falseopt-out retain their configured behavior. The same run-wide hook follows lazy subagent MCP alias discovery and registered programmatic approval hooks.Reported by Chengzhi Yi (@Tardfyou). Related to the Agents API compatibility track.
Mechanism
No new handler, authorization model, transport, or configuration option is introduced. This does not make the API-key endpoints capable of obtaining human approval.
Verification
dontAskallow/deny, default ask, disabled policy, registered programmatic hooks, and lazy MCP alias healing under both interactive and headless runs.packages/apitypecheck, package build, policy suites, touched-file lint/imports, and static checks run locally. Endpoint controller suites run against the rebuilt package.Risk / Rollout
Deployments with tool approval already enabled may now see previously unreviewed headless tools blocked. That is the intentional fail-closed behavior; operators can explicitly allow trusted tools or disable the endpoint policy. The default-off configuration is unchanged. Canary is a separate branch and does not receive this dev PR automatically; include it in the next release only after a canary integration decision.