From 92a8f48d702538a09730fcfed381a76f658a02c9 Mon Sep 17 00:00:00 2001 From: kirillk Date: Mon, 6 Apr 2026 10:31:34 -0400 Subject: [PATCH] fix(cli): preserve inherited restrictions across multi-hop sub-agent chains --- packages/opencode/src/tool/task.ts | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/packages/opencode/src/tool/task.ts b/packages/opencode/src/tool/task.ts index a8ab57cad04..c9bc00d43b8 100644 --- a/packages/opencode/src/tool/task.ts +++ b/packages/opencode/src/tool/task.ts @@ -65,8 +65,17 @@ export const TaskTool = Tool.define("task", async (ctx) => { // kilocode_change start — inherit edit and bash restrictions from the calling agent so // sub-agents cannot perform actions the parent agent is not allowed to perform. + // We merge the static agent definition with the current session's accumulated permissions + // so that restrictions survive multi-hop chains (plan → general → explore). + // Agent.get() gives the base definition; session.permission carries restrictions that + // were themselves inherited from a grandparent, so both sources are needed. const caller = await Agent.get(ctx.agent) - const inherited = caller?.permission.filter((r) => r.permission === "edit" || r.permission === "bash") ?? [] + const callerSession = await Session.get(ctx.sessionID) + const callerRules = PermissionNext.merge( + caller?.permission ?? [], + callerSession.permission ?? [], + ) + const inherited = callerRules.filter((r) => r.permission === "edit" || r.permission === "bash") // kilocode_change end const session = await iife(async () => {