Skip to content

fix(core): explicitly allow codebase_investigator and cli_help in read-only mode#21157

Merged
Adib234 merged 2 commits intomainfrom
adibakm/stop-ask-user-subagent
Mar 5, 2026
Merged

fix(core): explicitly allow codebase_investigator and cli_help in read-only mode#21157
Adib234 merged 2 commits intomainfrom
adibakm/stop-ask-user-subagent

Conversation

@Adib234
Copy link
Contributor

@Adib234 Adib234 commented Mar 4, 2026

Summary

Explicitly allow codebase_investigator and cli_help subagents in read-only.toml.

Details

Adding these tools to plan.toml (restricted to plan mode) causes AgentRegistry to skip its dynamic ALLOW rule for these local agents. This happens because AgentRegistry only adds dynamic rules if no static rules (TOML/Settings) exist for the tool.

Since the rule in plan.toml is restricted to modes = ["plan"], it does not apply in default mode, leading the policy engine to fall back to the system's defaultDecision: PolicyDecision.ASK_USER.

Adding them explicitly to read-only.toml ensures they are correctly allowed across all modes as they are safe, read-only tools.

Related Issues

Fixes #21158

How to Validate

  1. Verify packages/core/src/policy/policies/read-only.toml contains the new rules for codebase_investigator and cli_help.
  2. Run policy tests: npm test -w @google/gemini-cli-core -- src/policy/policy-engine.test.ts src/policy/workspace-policy.test.ts src/availability/policyCatalog.test.ts

Also manually verified in default and auto-edit that no permission is needed to run codebase_investigator and cli_help subagent

Pre-Merge Checklist

  • Updated relevant documentation and README (if needed)
  • Added/updated tests (if needed) - Validated with existing policy tests.
  • Noted breaking changes (if any)
  • Validated on required platforms/methods:
    • MacOS
      • npm run

@Adib234 Adib234 requested a review from a team as a code owner March 4, 2026 21:10
@gemini-cli
Copy link
Contributor

gemini-cli bot commented Mar 4, 2026

Hi there! Thank you for your contribution to Gemini CLI.

To improve our contribution process and better track changes, we now require all pull requests to be associated with an existing issue, as announced in our recent discussion and as detailed in our CONTRIBUTING.md.

This pull request is being closed because it is not currently linked to an issue. Once you have updated the description of this PR to link an issue (e.g., by adding Fixes #123 or Related to #123), it will be automatically reopened.

How to link an issue:
Add a keyword followed by the issue number (e.g., Fixes #123) in the description of your pull request. For more details on supported keywords and how linking works, please refer to the GitHub Documentation on linking pull requests to issues.

Thank you for your understanding and for being a part of our community!

@gemini-cli
Copy link
Contributor

gemini-cli bot commented Mar 4, 2026

Hi @Adib234, thank you so much for your contribution to Gemini CLI! We really appreciate the time and effort you've put into this.

We're making some updates to our contribution process to improve how we track and review changes. Please take a moment to review our recent discussion post: Improving Our Contribution Process & Introducing New Guidelines.

Key Update: Starting January 26, 2026, the Gemini CLI project will require all pull requests to be associated with an existing issue. Any pull requests not linked to an issue by that date will be automatically closed.

Thank you for your understanding and for being a part of our community!

@gemini-cli gemini-cli bot closed this Mar 4, 2026
@gemini-code-assist
Copy link
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request addresses a policy engine configuration issue to ensure that the codebase_investigator and cli_help tools are consistently allowed in all operational modes. By explicitly adding these read-only tools to the read-only.toml policy, it prevents unintended ASK_USER prompts that previously occurred due to how the AgentRegistry processed static versus dynamic policy rules.

Highlights

  • Policy Engine Configuration: Explicitly allowed the codebase_investigator and cli_help subagents within the read-only.toml policy file.
  • Rule Precedence Fix: Resolved an issue where dynamic ALLOW rules for these agents were skipped by AgentRegistry when static rules existed in plan.toml, leading to ASK_USER decisions in default mode.
Changelog
  • packages/core/src/policy/policies/read-only.toml
    • Added policy rules to explicitly allow codebase_investigator.
    • Added policy rules to explicitly allow cli_help.
Activity
  • Existing policy tests were used for validation.
  • The changes were validated on MacOS using npm run.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

Copy link
Contributor

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

The pull request correctly allows the codebase_investigator and cli_help tools in read-only mode by adding them to read-only.toml. This resolves an issue where they would otherwise require user confirmation. For improved maintainability, I've suggested consolidating the newly added policy rules into a single block, which aligns with the project's conventions.

Note: Security Review has been skipped due to the limited scope of the PR.

@Adib234 Adib234 self-assigned this Mar 4, 2026
@gemini-cli gemini-cli bot reopened this Mar 4, 2026
@gemini-cli
Copy link
Contributor

gemini-cli bot commented Mar 4, 2026

Thank you for linking an issue! This pull request has been automatically reopened.

@gemini-cli gemini-cli bot added the area/agent Issues related to Core Agent, Tools, Memory, Sub-Agents, Hooks, Agent Quality label Mar 4, 2026
@github-actions
Copy link

github-actions bot commented Mar 4, 2026

Size Change: -2 B (0%)

Total Size: 26 MB

ℹ️ View Unchanged
Filename Size Change
./bundle/gemini.js 25.5 MB -2 B (0%)
./bundle/node_modules/@google/gemini-cli-devtools/dist/client/main.js 221 kB 0 B
./bundle/node_modules/@google/gemini-cli-devtools/dist/src/_client-assets.js 227 kB 0 B
./bundle/node_modules/@google/gemini-cli-devtools/dist/src/index.js 11.5 kB 0 B
./bundle/node_modules/@google/gemini-cli-devtools/dist/src/types.js 132 B 0 B
./bundle/sandbox-macos-permissive-open.sb 890 B 0 B
./bundle/sandbox-macos-permissive-proxied.sb 1.31 kB 0 B
./bundle/sandbox-macos-restrictive-open.sb 3.36 kB 0 B
./bundle/sandbox-macos-restrictive-proxied.sb 3.56 kB 0 B
./bundle/sandbox-macos-strict-open.sb 4.82 kB 0 B
./bundle/sandbox-macos-strict-proxied.sb 5.02 kB 0 B

compressed-size-action

@Adib234 Adib234 added this pull request to the merge queue Mar 5, 2026
Merged via the queue into main with commit 173376b Mar 5, 2026
27 checks passed
@Adib234 Adib234 deleted the adibakm/stop-ask-user-subagent branch March 5, 2026 13:32
@Adib234
Copy link
Contributor Author

Adib234 commented Mar 5, 2026

/patch preview

1 similar comment
@galz10
Copy link
Collaborator

galz10 commented Mar 5, 2026

/patch preview

@github-actions
Copy link

github-actions bot commented Mar 5, 2026

Patch workflow(s) dispatched successfully!

📋 Details:

  • Channels: preview
  • Commit: 173376ba67600499bccd57dbc79b94f7706c9db3
  • Workflows Created: 1

🔗 Track Progress:

github-actions bot pushed a commit that referenced this pull request Mar 5, 2026
@github-actions
Copy link

github-actions bot commented Mar 5, 2026

🚀 Patch PR Created!

📋 Patch Details:

📝 Next Steps:

  1. Review and approve the hotfix PR: #21300
  2. Once merged, the patch release will automatically trigger
  3. You'll receive updates here when the release completes

🔗 Track Progress:

@github-actions
Copy link

github-actions bot commented Mar 5, 2026

🚀 Patch Release Started!

📋 Release Details:

  • Environment: prod
  • Channel: preview → publishing to npm tag preview
  • Version: v0.33.0-preview.1
  • Hotfix PR: Merged ✅
  • Release Branch: release/v0.33.0-preview.1-pr-21157

⏳ Status: The patch release is now running. You'll receive another update when it completes.

🔗 Track Progress:

@github-actions
Copy link

github-actions bot commented Mar 5, 2026

Patch Release Complete!

📦 Release Details:

🎉 Status: Your patch has been successfully released and published to npm!

📝 What's Available:

🔗 Links:

struckoff pushed a commit to struckoff/gemini-cli that referenced this pull request Mar 6, 2026
kunal-10-cloud pushed a commit to kunal-10-cloud/gemini-cli that referenced this pull request Mar 12, 2026
liamhelmer pushed a commit to badal-io/gemini-cli that referenced this pull request Mar 12, 2026
yashodipmore pushed a commit to yashodipmore/geemi-cli that referenced this pull request Mar 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/agent Issues related to Core Agent, Tools, Memory, Sub-Agents, Hooks, Agent Quality

Projects

None yet

Development

Successfully merging this pull request may close these issues.

codebase_investigator requires permission to run

3 participants