What happens
On Linux, Codewhale 0.10.0 does not actually grant Full Access to agents. When the user sets the maximum permission posture, running sub-agents keep being checked by the Auto-Review guardian and denied (fail-closed after about 90 s), or they appear stuck. The user downgraded to 0.9.3, which works. (Reported by a user in the community chat; reproduced in code.)
Root causes found
- Sub-agents copied the permission posture when they were spawned, so switching to Full Access never reached agents that were already running.
- Every sub-agent call was judged as unattended background work, so the destructive-background safety rule blocked ordinary commands even under Full Access.
- A child agent's approval answer was only delivered while the main session was idle or itself waiting on an approval, so an approved agent could stay blocked.
Fix (in progress on wave/0.10.1-next)
- Agents read the session's live posture on every call; the spawn-time copies are deleted.
- Detached agents keep the destructive-background floor in every posture.
- Approval answers are routed straight to the waiting agent.
- The reviewer shows progress while it checks, and its failure message is clearer.
- In-workspace build deletes are no longer over-blocked. A second review found the classifier change too broad, and the repair for that is in progress.
Commits: d1655c4, 0526412, and a pending follow-up. Each change was adversarially reviewed.
Known limit
Full Access switched on at runtime cannot lift the Linux no-new-privileges flag, so sudo still fails inside the agent. Start with sandbox_mode = "danger-full-access" or CODEWHALE_NO_NEW_PRIVS=0.
Refs #6475, #6478.
What happens
On Linux, Codewhale 0.10.0 does not actually grant Full Access to agents. When the user sets the maximum permission posture, running sub-agents keep being checked by the Auto-Review guardian and denied (fail-closed after about 90 s), or they appear stuck. The user downgraded to 0.9.3, which works. (Reported by a user in the community chat; reproduced in code.)
Root causes found
Fix (in progress on
wave/0.10.1-next)Commits: d1655c4, 0526412, and a pending follow-up. Each change was adversarially reviewed.
Known limit
Full Access switched on at runtime cannot lift the Linux no-new-privileges flag, so
sudostill fails inside the agent. Start withsandbox_mode = "danger-full-access"orCODEWHALE_NO_NEW_PRIVS=0.Refs #6475, #6478.