Skip to content

headless and --yolo cells cannot answer the approval floor, so rm -rf stalls a bench cell forever #1035

Description

@santoshkumarradha

What happens

internal/approval/floor.go's AlwaysAsks raises a card for rm -rf (and acts in the person's name) even under tools.approvalMode: allow / --yolo. That is the right law for a person at the keyboard. In a bench cell or any headless drive nobody can answer, so the turn waits on the card until the cell's ceiling cuts it. The 2026-09-14 PlanDB grid raised 99 such cards across 18 cells, 36 in one cell; the rig had to grow a tmux card-watcher that types 1 + Enter.

Replication a stranger can run

make build
AFORGE_HOME=/tmp/afy bin/aforge exec 'run: mkdir -p /tmp/afy-x && rm -rf /tmp/afy-x' --model deepseek/deepseek-v4.1-flash --max-turns 2 --token-budget 4000

With tools.approvalMode: allow in that home's config.json the command still waits on a card with no terminal to draw it on.

Acceptance, end to end first

The exec command above, with approvalMode: allow in the home, finishes without a card and calls.jsonl shows the tool ran; aforge chat --yolo in a tmux pane shows the same command run with a dim line naming what it did rather than a card. The floor stays in force wherever a person is at the door (provider.PersonAtTheDoor() false and the surface visible), pinned by a test in internal/approval.

This is a proposal: one door, approval floor under an unattended run, not an if/else on --yolo. The manual page on approvals must say what changes.


Drafted with CodeAF · reviewed and owned by the author

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:headlesscodeaf do and codeaf exec, runs with no screenarea:testsThe suite itself — flakes, harnesses, laws, CI redsbugSomething the code does that it should notsev:seriousWrong or missing behaviour a person meets in ordinary use

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions