Repository navigation
feat(subagents): add resource, capability and model controls - #1086
Open
lyx2145181 wants to merge 6 commits into
Open
lyx2145181 wants to merge 6 commits into
lyx2145181 wants to merge 6 commits into
Conversation
Why: Subagents need resource selection before extension import, while approved late registrations must remain usable under SDK 1.0's hard tool allowlist. Safety: Resolve restricted resources before import and apply real project trust. Enforce a frozen, winner-specific policy for direct and nested execution. Handle queued readiness failures immediately and recheck cancellation before delegated prompts, including cancellation before listener setup. This is not a filesystem or extension-JavaScript sandbox. Compatibility: Preserve foreign YAML, unedited selections and legacy boolean clients. Keep v1 hard allowlists; restore v2 from its creation snapshot, not the current profile. Refresh non-resource scoped settings without persisting transient setters or widening resource and builtin permissions. Validation: Exported and checked this staged tree independently of the pending UI. Typecheck and ESLint passed. Isolated offline suite: 2339 passed; separately mocked plugin-update suite: 5 passed. No build, real provider request, MCP connection or deployment was run.
Why: Boolean switches cannot show or edit resource whitelists. Compact summaries and an on-demand picker keep the profile editor readable without changing its draft and Save workflow. Safety: Search, navigation and retry leave selections unchanged. The single tri-state bulk control selects the full enabled catalog as explicit paths, not future-enabled All, and preserves unknown or ambiguous entries. Share catalog matching, use native DOM contracts, clamp fixed positions to the visual viewport and avoid refocusing on responsive width changes. Keep built-in profiles read-only and distinguish explicit from automatic focus restoration. Validation: Exported and checked this staged tree independently. Typecheck and ESLint passed. Isolated offline suite: 2366 passed; separately mocked plugin-update suite: 5 passed. Post-fix browser acceptance stopped after two harness environment failures; no browser pass or physical keyboard/pinch-zoom verification is claimed. No real profile save, build or deployment was run.
Why: Direct SDK prompts bypass the wrapper's prompt and Stop lifecycle. Delegated runs must await completion and resume extension UI after Stop. Safety: Use wrapper admission, readiness and cancellation for create and resume. Reset extension UI cancellation before prompting without rebinding. Share MCP preparation with normal prompts. Compatibility: Keep v2 snapshots and legacy test-host fallbacks unchanged. Introduce no capability fields, profile APIs or host authorization changes. Validation: Exported and checked this staged tree independently. Typecheck, ESLint and whitespace checks passed. Isolated offline suite: 2367 passed; separately mocked plugin suite: 5 passed. Independent targeted tests: 41 passed. The lifecycle test also passed with pending v3 code; restoring the old runtime in a temporary copy reproduced an interrupted-UI Stop timeout. No browser validation, build, deployment or real provider/MCP request.
Why: Subagent roles need independent Code mode and MCP capabilities with explicit server selection, rather than inheriting a parent's loadout. Safety: Apply real scoped builtin switches and project trust. Check selected registration ownership before transport value resolution, and enforce actual-winner authorization for direct and nested tool calls. Use the child's frozen builtin selection for read-only MCP policy. Separate aggregate declaration from execution during SDK catalog lag; preserve explicit tool disablement without replaying an old active set. This is not a filesystem, network or extension-JavaScript sandbox. The roster observer depends on audited SDK 1.0 catalog-update timing. Compatibility: Default both capabilities off and preserve omitted fields from old clients. Freeze scoped server identities in v3 snapshots, not config or credentials. Keep v1/v2 authority unchanged without migration or capability promotion. Share existing factories, hosts and credential storage; include no UI changes. Validation: Exported and checked this staged tree independently. Typecheck, ESLint and whitespace checks passed with no warnings. Isolated offline suite: 2384 passed; separately mocked plugin suite: 5 passed. Independent capability, lifecycle and profile API tests: 22 passed. No browser validation, build, deployment or real provider/MCP request.
Why: Expose independent Code mode and MCP role capabilities without expanding the profile editor into a separate configuration panel. Safety: Reuse the Resources field, responsive cards and shared picker DOM policy. Read the masked files-only MCP overview; never change server configuration, enable servers or invoke Test or Sign-in. Keep built-in profiles read-only and preserve dormant scoped selections. Search, retry and stale responses do not change the draft. Compatibility: Use the existing profile draft and Save flow. Default legacy drafts off and preserve exact scoped names when copying. Add matching English, Simplified Chinese and Traditional Chinese strings. Leave backend authorization and snapshot behavior unchanged. Validation: Exported and checked this staged tree independently. Typecheck, ESLint and whitespace checks passed with no warnings. Isolated offline suite: 2395 passed; separately mocked plugin suite: 5 passed. Independent UI and shared resource-picker tests: 57 passed. Static, SSR and mocked checks are not browser or real keyboard acceptance. No browser validation, real profile save, build, deployment or real provider/MCP request.
Why: Parent-supplied model parameters should not silently replace a role's specified model, and reopening a setup-only child should not reset its recorded choice to the default. Behavior: Add a default-off profile switch for parent model overrides beside the model selector. With a specified role model and the switch off, ignore parent model parameters and continue using the role model without retry. Keep explicit choice and inheritance unchanged for roles without a model. Resume ignores attached model parameters and retains the child's current model, including manual changes. Cold restoration uses the active branch's recorded choice and fails if that model or configured auth is unavailable. Compatibility: Reuse profile frontmatter, the draft/Save flow and existing model lookup. Preserve omitted fields from old clients, copies and foreign frontmatter. Keep built-ins read-only and normal unsent-session defaults unchanged. Introduce no permission store, dependency or resource snapshot version. Roles relying on parent overrides must explicitly enable the new switch. Validation: Exported and checked this staged tree independently. Typecheck, ESLint and whitespace checks passed with no warnings. Isolated offline suite: 2426 passed; separately mocked plugin suite: 5 passed. Independent targeted review: 123 passed, with additional cold-restore checks. Real in-process provider fixtures verify one-shot role selection and a real Agent-to-controller resume retaining the manually selected child model. Manual model behavior was confirmed by the tester after preview restart. No real provider request or comprehensive browser acceptance was run by this validation; no production deployment was performed.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Give subagent profiles their own resource selections, Code mode/MCP capabilities, and model-override control, while keeping the existing profile editor and session lifecycle.
The goal is to make a role's configuration meaningful for the child it creates: select what it loads, explicitly opt into host capabilities, and keep its chosen model instead of silently inheriting a different parent loadout.
User-facing changes
Select skills and extensions per role
Opt into Code mode and selected MCP servers
Keep configured role and child models
Agent.modelparameter and use the role model—even if the ignored parameter names an unknown or ambiguous model. Do not reject the task merely to make the parent retry without that parameter.English, Simplified Chinese, and Traditional Chinese strings are included.
Technical adjustments
Resource loading and authorization
session_start/resource discovery: do not use early enumeration as the SDK's permanent allowlist. Enforce frozen builtin/extension authority using the actual registration winner for both direct calls and nestedtool_callexecution.Delegated-run lifecycle
AgentSessionWrapperadmission, readiness, prompt preparation, and cancellation, and await actual completion rather than a prompt acknowledgment.Native host capabilities
McpHost, project trust, scoped settings, and credential storage rather than introducing a parallel pipeline.models: false; tool search is a dependency, not a third profile setting. Respect native builtin disable/replacement rules.Model selection and editor reuse
Compatibility and limits
Validation
tsc --noEmit --incremental false.git diff --checkclean.npm testcovers both paths.Agent→ controller → child resume after a manual model change.Related open work and design choices
maindirectly and also includes the picker, late-tool policy, and independent host capabilities; it is not stacked on that proposal.ModelRuntimesharing remains a separate concern inherited from currentmain.modelon resume, retaining the existing child choice without making the parent retry. It does not implement model hot-swapping or change the handling of other resume options.These are related proposals, not prerequisites. The model behavior above is an explicit reviewable policy choice rather than an accidental silent override.
Review structure
This PR contains six existing logical commits; it does not rewrite or squash their history:
The model editor, resolver, persistence compatibility, and cold-restore fix form one complete final increment, so they are submitted together rather than as partially functioning layers. Unrelated font/sidebar/session-list customizations and personal planning files are excluded.