Skip to content

fix(vscode_copilot): powershell/bash hook keys; record 2026-09-28 Windows evidence - #164

Merged
jothimani-rajendran merged 1 commit into
mainfrom
fix/copilot-windows-evidence
Sep 29, 2026
Merged

jothimani-rajendran merged 1 commit into
mainfrom
fix/copilot-windows-evidence

Conversation

@jothimani-rajendran

Copy link
Copy Markdown
Collaborator

What this changes

install for vscode_copilot now writes bash and powershell beside command and windows on every entry (idempotent; re-install upgrades an old entry in place; other vendors unchanged). Live on Windows, Copilot's CLI runtime ran the plain command in PowerShell and ignored windows, so the hook errored and every tool call was denied.

Also: a Write now carries its content to the policy (tool_input.file_text was read only for the memory tool), and Copilot's camelCase agentStop payload (no event name, stopReason) is claimed and parsed as a stop (it was read as a preToolUse).

The vscode_copilot row records the second live Windows capture (2026-09-28): snake_case tool payloads and tools seen, a witnessed deny, both agentStop and Stop firing at each turn end, and a Stop block answered with both dialects' keys.

Claim check

  • No capability claim is widened without a mechanism behind it
  • Any new/changed MATRIX row carries a verified record (version, date, method)
  • Payload shapes come from a primary source: a captured live run, Windows, 2026-09-28 (VS Code Copilot Chat agent mode, "Copilot CLI runtime", GPT-5 mini). Fixtures are sanitized placeholders.

Checks

  • pytest -q: 1894 passed, 4 skipped
  • ruff check . and ruff format --check . pass
  • Runtime path is still stdlib-only (tests/check_stdlib_only.py OK)
  • Commits are signed off (git commit -s)
  • examples/generate.py --check, tools/validate_vendor_config.py, docs figures and brand assets are current

Notes for the reviewer

  • fail_mode for pre_tool stays open. One hook error blocked every tool, but it was a single uncontrolled run, the error was a PowerShell parse failure (not a hook that ran and exited non-2), and it conflicts with the VS Code source reading behind open. Recorded as a note, not a claim; the two products may differ.
  • Which of top-level {decision, reason} or nested hookSpecificOutput Copilot reads at Stop is not isolated, so the Stop answer keeps the nested shape.
  • New parser tests fail on the old code (Write content, both Stop spellings); new install tests fail without the powershell/bash keys.
  • tools/literal_duplication.py reports permissionDecisionReason 3x; this is the same on main.

🤖 Generated with Claude Code


Generated by Claude Code

…8 Windows evidence

Copilot's CLI runtime on Windows ran the plain `command` in PowerShell and
ignored `windows`, so the hook errored and every tool call was denied. Each
installed entry now carries `bash` and `powershell` beside `command` and
`windows`.

Also read `file_text` as a Write's content, and parse the camelCase
`agentStop` payload (no event name, `stopReason`) as a stop.

Record the second live Windows capture on the vscode_copilot row. fail_mode
stays open: one hook error that blocked every tool is noted, not claimed.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
@jothimani-rajendran
jothimani-rajendran marked this pull request as ready for review September 29, 2026 01:51
@jothimani-rajendran
jothimani-rajendran merged commit cd9504e into main Sep 29, 2026
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants