fix(vscode_copilot): powershell/bash hook keys; record 2026-09-28 Windows evidence - #164
Merged
Merged
Conversation
…8 Windows evidence Copilot's CLI runtime on Windows ran the plain `command` in PowerShell and ignored `windows`, so the hook errored and every tool call was denied. Each installed entry now carries `bash` and `powershell` beside `command` and `windows`. Also read `file_text` as a Write's content, and parse the camelCase `agentStop` payload (no event name, `stopReason`) as a stop. Record the second live Windows capture on the vscode_copilot row. fail_mode stays open: one hook error that blocked every tool is noted, not claimed. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this changes
installforvscode_copilotnow writesbashandpowershellbesidecommandandwindowson every entry (idempotent; re-install upgrades an old entry in place; other vendors unchanged). Live on Windows, Copilot's CLI runtime ran the plaincommandin PowerShell and ignoredwindows, so the hook errored and every tool call was denied.Also: a
Writenow carries its content to the policy (tool_input.file_textwas read only for the memory tool), and Copilot's camelCaseagentStoppayload (no event name,stopReason) is claimed and parsed as a stop (it was read as apreToolUse).The
vscode_copilotrow records the second live Windows capture (2026-09-28): snake_case tool payloads and tools seen, a witnessed deny, bothagentStopandStopfiring at each turn end, and a Stop block answered with both dialects' keys.Claim check
MATRIXrow carries averifiedrecord (version, date, method)Checks
pytest -q: 1894 passed, 4 skippedruff check .andruff format --check .passtests/check_stdlib_only.pyOK)git commit -s)examples/generate.py --check,tools/validate_vendor_config.py, docs figures and brand assets are currentNotes for the reviewer
fail_modeforpre_toolstaysopen. One hook error blocked every tool, but it was a single uncontrolled run, the error was a PowerShell parse failure (not a hook that ran and exited non-2), and it conflicts with the VS Code source reading behindopen. Recorded as a note, not a claim; the two products may differ.{decision, reason}or nestedhookSpecificOutputCopilot reads at Stop is not isolated, so the Stop answer keeps the nested shape.powershell/bashkeys.tools/literal_duplication.pyreportspermissionDecisionReason3x; this is the same on main.🤖 Generated with Claude Code
Generated by Claude Code