Skip to content

Diagnose and surface silently refused ACP permissions - #879

Merged
realtonyyoung merged 2 commits into
mainfrom
claude-tyoung/ai2677-copilot-diag
Sep 11, 2026
Merged

realtonyyoung merged 2 commits into
mainfrom
claude-tyoung/ai2677-copilot-diag

Conversation

@realtonyyoung

Copy link
Copy Markdown
Collaborator

Closes #851 — AI-2677

What & why

Launching Copilot from the desktop app, a permission approved in the web UI resolved as cancelled, the tool returned "The user rejected this tool call", and the turn ended with nothing in the chat. AcpInteractionBridge.MapPermissionDecision is fail-closed: an affirmative outcome maps to allow only when its SelectedOptionId matches an option the agent offered; anything else is cancelled. The daemon logged neither the offered ids nor the received decision, so the mismatch was invisible, and a refused turn left the chat blank.

Two kcap-cli changes: the bridge now logs the offered options as optionId:kind pairs when a request is issued and the received (outcome, selectedOptionId, matched) when it resolves, so an id echoed back that matches nothing offered shows matched=false in the daemon log. And an ACP turn that ends after a permission is cancelled with no assistant output emits a system note ("The tool call was not permitted; the turn ended.") so the chat shows why it stopped.

Not in scope (cross-repo): the actual root cause is the kcap-server web UI permission card echoing back a different optionId than Copilot offered. This PR makes that failure diagnosable and stops the blank chat; the card itself is a separate kcap-server fix.

Where to look

The offered/received option ids are the one deliberately non-payload-free permission log — they are the diagnostic this exists for — logged narrowly (ids and kinds, never labels or tool args). The turn-end note keys on the ACP cancelled response shape, which covers both a genuine cancel and the fail-closed mismatch.

Verification

  • New bridge tests (offered ids logged; a non-matching selectedOptionId logs matched=false, reproducing the Copilot shape; a matching id logs matched=true) and runtime tests (cancelled + no assistant output emits the note; with assistant output or an allow, no note). TDD sanity check confirmed the runtime test fails without the emission.
  • ACP bridge + runtime suites green; daemon AOT publish clean.

The bridge already fails closed to `cancelled` when a decision's
optionId matches none offered; only the mismatch itself was invisible
in the log. The turn-end note is keyed on that same wire outcome, not
the raw decision, so it covers the fail-closed path too.
@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Diagnose ACP permission mismatches and surface silent refusals

🐞 Bug fix ✨ Enhancement 🧪 Tests 🕐 20-40 Minutes

Grey Divider

AI Description

• Log offered and returned ACP permission identifiers to expose option mismatches.
• Surface silent cancelled permission turns with a user-visible system note.
• Cover matching, mismatching, cancelled, allowed, and assistant-output paths with tests.
Diagram

sequenceDiagram
    actor User
    participant Agent as ACP Agent
    participant Runtime as Agent Runtime
    participant Bridge as ACP Bridge
    participant UI as Permission UI
    participant Log as Daemon Log
    Agent->>Runtime: Permission request
    Runtime->>Bridge: Route request
    Bridge->>Log: Offered IDs and kinds
    Bridge->>UI: Request decision
    UI-->>Bridge: Outcome and option ID
    Bridge->>Log: Match result
    Bridge-->>Runtime: Selected or cancelled
    Runtime-->>Agent: ACP response
    alt Cancelled without assistant output
        Runtime-->>User: Refusal system note
    end
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Fix only the permission UI
  • ➕ Corrects the known option ID echo mismatch at its source.
  • ➕ Avoids synthesizing fallback messaging for this specific defect.
  • ➖ Requires a separate repository change.
  • ➖ Leaves future malformed decisions undiagnosable in daemon logs.
  • ➖ Still permits blank turns after genuine cancellations from silent agents.
2. Map affirmative decisions without exact ID matching
  • ➕ Could allow an approved request despite a malformed echoed identifier.
  • ➕ May avoid cancellation for agents offering a single allow option.
  • ➖ Weakens the bridge's fail-closed security boundary.
  • ➖ Becomes ambiguous when multiple allow choices have different persistence semantics.
  • ➖ Could execute tools using a permission scope the user did not select.

Recommendation: Keep this PR's fail-closed mapping, narrow identifier logging, and conditional system note. Fixing the permission UI separately addresses the immediate root cause, while these changes provide safe defense-in-depth for genuine cancellations and future protocol mismatches.

Files changed (4) +319 / -16

Bug fix (2) +100 / -13
AcpInteractionBridge.csLog offered permission options and decision-match diagnostics +24/-5

Log offered permission options and decision-match diagnostics

• Logs offered option IDs and kinds, then records the received outcome, selected option ID, and whether it matched an offered option. Logging intentionally excludes labels, tool names, and arguments while preserving fail-closed permission mapping.

src/Capacitor.Cli.Daemon/Acp/AcpInteractionBridge.cs

AcpHostedAgentRuntime.csSurface cancelled permissions that leave turns silent +76/-8

Surface cancelled permissions that leave turns silent

• Tracks per-turn assistant output and cancelled permission responses across the runtime's concurrent paths. At turn completion, it emits an explanatory system note only when a cancelled permission produced no assistant text or thinking output.

src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs

Tests (2) +219 / -3
AcpInteractionBridgeTests.csVerify permission option and decision diagnostics +66/-3

Verify permission option and decision diagnostics

• Adds coverage for logging offered option IDs and kinds, unmatched returned IDs, and successful matches. It also confirms mismatched affirmative decisions continue to fail closed as cancelled.

test/Capacitor.Cli.Daemon.Tests.Unit/Acp/AcpInteractionBridgeTests.cs

AcpHostedAgentRuntimePermissionTests.csVerify silent permission refusal notes +153/-0

Verify silent permission refusal notes

• Adds runtime tests proving cancelled silent turns emit the explanatory note. Negative controls verify no note appears when the agent speaks or when permission is allowed.

test/Capacitor.Cli.Daemon.Tests.Unit/Services/AcpHostedAgentRuntimePermissionTests.cs

@qodo-code-review

qodo-code-review Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (2) 📘 Rule violations (0) 🔗 Cross-repo conflicts (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Hidden thinking leaves the chat blank 🐞 Bug ≡ Correctness
Description
EmitEnvelope sets _turnHadAssistantOutput for AssistantThinking, so the turn-end check treats
internal reasoning as a visible reply. ChatTabViewModel.Apply has no case for that event kind, so
a cancelled permission followed only by thinking still leaves the chat blank and suppresses the new
explanation.
Code

src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[R1854-1855]

+        if (envelope.Kind is AcpEventKind.AssistantText or AcpEventKind.AssistantThinking)
+            Volatile.Write(ref _turnHadAssistantOutput, 1);
Relevance

●●● Strong

This is a deterministic UI/runtime mismatch: thinking is counted as visible output but is not
rendered.

PR-#722
PR-#688

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The runtime explicitly treats thinking as assistant output, while the chat switch renders assistant
text and system notes but ignores thinking envelopes; therefore thinking-only output suppresses the
sole visible explanation.

src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[1353-1358]
src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[1845-1855]
src/Capacitor.App/ViewModels/ChatTabViewModel.cs[438-470]
src/Capacitor.Cli.Daemon/Acp/AcpEventTranslator.cs[82-87]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Assistant-thinking envelopes currently suppress the silent-permission-refusal note even though the chat does not render those envelopes, leaving the user with no visible explanation.

## Fix Focus Areas
- src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[1355-1358]
- src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[1852-1855]
- test/Capacitor.Cli.Daemon.Tests.Unit/Services/AcpHostedAgentRuntimePermissionTests.cs[360-394]

## Recommended Fix
Set the visibility flag only for assistant event kinds actually rendered in chat, currently `AssistantText`. Add a cancelled-permission test with thinking-only output and assert that the system note is still emitted.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools



Remediation recommended

2. Two test comments narrate assertions ✓ Resolved 📘 Rule violation ⚙ Maintainability
Description
RequestPermission_ResolvedOptionIdDoesNotMatchOffered_LogsOutcomeAndMismatch adds comments that
announce the cancelled assertion and then announce the log assertion immediately below. When either
assertion changes, those paraphrases become stale without conveying behavior that the test name and
expressions do not already show.
Code

test/Capacitor.Cli.Daemon.Tests.Unit/Acp/AcpInteractionBridgeTests.cs[706]

+        // The mapped ACP result still fails closed to cancelled...
Relevance

●●● Strong

Recent test-review precedents accept removing comments that merely paraphrase adjacent assertions.

PR-#688
PR-#718

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The rule explicitly rejects comments that restate what adjacent code clearly does. These comments
describe the cancelled-result assertion and diagnostic-log assertion immediately before those
checks.

Rule 2762993: Restrict comments to documenting non-obvious, behavior‑critical constraints
test/Capacitor.Cli.Daemon.Tests.Unit/Acp/AcpInteractionBridgeTests.cs[706-716]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Two comments in the mismatch test merely paraphrase the assertions that immediately follow them.

## Fix Focus Areas
- test/Capacitor.Cli.Daemon.Tests.Unit/Acp/AcpInteractionBridgeTests.cs[706-710]

## Recommended Fix
Remove the assertion-narration comments while retaining the descriptive test name and assertion expressions.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


3. Router comment relies on plan labels ✓ Resolved 📘 Rule violation ⚙ Maintainability
Description
RouteServerRequestCoreAsync describes its routing stages with unexplained r5–r8 coordinates
alongside Phase one and Phase two. A reader who has only this file cannot resolve those external
plan labels, so later routing changes can preserve stale review metadata instead of the actual
cancellation invariant.
Code

src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[R2776-2777]

+    /// RACED against the sweep's bookkeeping signal so a blocked foreign cancellation callback can
+    /// never strand the response or the entry's removal (r5–r8). Exactly one response per request is
Relevance

●●● Strong

The team accepts removing process identifiers and trimming comments that depend on external or stale
metadata.

PR-#425
PR-#876

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The changed comment contains external process coordinates rather than solely documenting current
behavior, and those coordinates are not explained within the file. This violates both the
prohibition on process-reference metadata and the requirement that comments be understandable from
the current file.

Rule 2897915: Avoid time-sensitive or process-reference metadata in code comments
Rule 2762993: Restrict comments to documenting non-obvious, behavior‑critical constraints
src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[2772-2778]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The routing comment depends on unexplained phase and requirement labels that are not meaningful from the current file alone.

## Fix Focus Areas
- src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[2772-2778]

## Recommended Fix
Rewrite the comment to describe the current locking, cancellation, and cleanup invariants directly, removing `Phase one`, `Phase two`, and `r5–r8` references.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


4. Late events mislabel the next turn 🐞 Bug ☼ Reliability
Description
_turnHadAssistantOutput and _turnPermissionCancelled are process-wide flags reset per admitted
turn, while EmitEnvelope and NotePermissionOutcome mutate them without checking the active turn
or incarnation. If a late update or swept permission response from the previous incarnation runs
after the next reset, it can suppress the next turn's refusal note or make that turn emit a note for
a permission it never requested.
Code

src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[R1321-1324]

+            // Reset THIS turn's silent-permission-refusal signal (see the finally block below) —
+            // a prior turn's cancelled permission or assistant text must never leak into this one.
+            Volatile.Write(ref _turnHadAssistantOutput, 0);
+            Volatile.Write(ref _turnPermissionCancelled, 0);
Relevance

●●● Strong

Recent concurrency and late-event race findings are consistently accepted when asynchronous state
can affect later turns.

PR-#616
PR-#727

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
Turn admission records an incarnation, but the two new fields carry none; notification aggregation
and permission completion run asynchronously and update those fields without consulting _inFlight
or the originating incarnation.

src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[1239-1258]
src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[1353-1358]
src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[1574-1614]
src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[1843-1855]
src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[2764-2768]
src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[2807-2815]
src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[2834-2842]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The new refusal and assistant-output flags are shared across the runtime and can be changed by asynchronous events that do not belong to the currently executing turn.

## Fix Focus Areas
- src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[1321-1324]
- src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[1852-1855]
- src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[2764-2768]
- src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[2834-2842]

## Recommended Fix
Store the refusal state in a per-turn tracker carrying the active incarnation or generation. Update it only when the emitting connection or permission route matches that tracker, and add tests where an old-incarnation interaction settles after a successor turn begins.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


View medium (2)
5. Agents can forge daemon log entries ✓ Resolved 🐞 Bug ⛨ Security
Description
FormatOptions copies agent-controlled option IDs and kinds into an information log without
escaping line breaks. RollingFileLoggerProvider writes the formatted text verbatim, so an option
containing CR/LF can inject fabricated timestamp-looking lines into the daemon log used to diagnose
permission decisions.
Code

src/Capacitor.Cli.Daemon/Acp/AcpInteractionBridge.cs[R830-831]

+    static string FormatOptions(IReadOnlyList<PermissionOptionDto> options) =>
+        "[" + string.Join(", ", options.Select(o => $"{o.OptionId}:{o.Kind ?? "?"}")) + "]";
Relevance

●● Moderate

Accepted log-sanitization precedents conflict with a recent rejection of sanitizing explicitly
untrusted diagnostic fields.

PR-#337
PR-#408
PR-#508

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The permission DTO imposes no validation on the agent-provided strings, FormatOptions interpolates
them directly, and the configured file logger writes the resulting message unchanged.

src/Capacitor.Cli.Core/Acp/AcpMessages.cs[243-254]
src/Capacitor.Cli.Daemon/Acp/AcpInteractionBridge.cs[304-320]
src/Capacitor.Cli.Daemon/Acp/AcpInteractionBridge.cs[827-831]
src/Capacitor.Cli.Daemon/Acp/AcpInteractionBridge.cs[846-850]
src/Capacitor.Cli.Daemon/RollingFileLoggerProvider.cs[32-40]
src/Capacitor.Cli.Daemon/RollingFileLoggerProvider.cs[87-97]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Permission option identifiers and kinds come from the agent and are persisted without escaping, allowing embedded line breaks to create forged daemon log entries.

## Fix Focus Areas
- src/Capacitor.Cli.Daemon/Acp/AcpInteractionBridge.cs[827-831]
- src/Capacitor.Cli.Daemon/Acp/AcpInteractionBridge.cs[846-850]
- src/Capacitor.Cli.Daemon/RollingFileLoggerProvider.cs[32-40]

## Recommended Fix
Encode option IDs, kinds, and selected IDs into a bounded single-line representation before logging, escaping CR, LF, and other control characters. Add tests with newline-bearing option fields and assert each diagnostic remains one physical log entry.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


6. A test heading duplicates nearby names ✓ Resolved 📘 Rule violation ⚙ Maintainability
Description
The comment at line 294 labels the following block as the no-blank-chat tests but records no
constraint or rationale. The three test names already identify the covered permission outcomes, so
adding or moving a case leaves a second organizational label to keep synchronized.
Code

test/Capacitor.Cli.Daemon.Tests.Unit/Services/AcpHostedAgentRuntimePermissionTests.cs[294]

+    // ── No blank chat after a cancelled permission with no assistant output ─────────────────────
Relevance

●● Moderate

Comment-minimization findings are often accepted, but section headings have also been retained for
test organization.

PR-#606
PR-#876

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The checklist requires changed comments to capture non-obvious, behavior-critical information rather
than duplicate nearby code structure. The heading only restates the subject already expressed by the
following test names.

Rule 2762993: Restrict comments to documenting non-obvious, behavior‑critical constraints
test/Capacitor.Cli.Daemon.Tests.Unit/Services/AcpHostedAgentRuntimePermissionTests.cs[294-323]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The added section heading merely summarizes test names and does not document a non-obvious behavioral constraint.

## Fix Focus Areas
- test/Capacitor.Cli.Daemon.Tests.Unit/Services/AcpHostedAgentRuntimePermissionTests.cs[294-294]

## Recommended Fix
Remove the section-heading comment and let the descriptive test names organize this group.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context sources
✅ Compliance rules (platform): 64 rules
✅ Cross-repo context — repo relationships
  Explored: repo: kurrent-io/kcap-server (sha: 01e241aa)
Review mode: ⚖️ Balanced: This changes permission handling and turn-state/concurrency-sensitive runtime behavior across bridge and routing paths, so it carries genuine behavioral risk but is not broad or defect-dense enough to warrant extended review.

Grey Divider

Tip of the day
💡 Did you know, you can switch off images and animations for a plain-text comment

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs Outdated
Comment thread test/Capacitor.Cli.Daemon.Tests.Unit/Acp/AcpInteractionBridgeTests.cs Outdated
Comment on lines +1854 to +1855
if (envelope.Kind is AcpEventKind.AssistantText or AcpEventKind.AssistantThinking)
Volatile.Write(ref _turnHadAssistantOutput, 1);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Action required

1. Hidden thinking leaves the chat blank 🐞 Bug ≡ Correctness

EmitEnvelope sets _turnHadAssistantOutput for AssistantThinking, so the turn-end check treats
internal reasoning as a visible reply. ChatTabViewModel.Apply has no case for that event kind, so
a cancelled permission followed only by thinking still leaves the chat blank and suppresses the new
explanation.
Agent Prompt
## Issue description
Assistant-thinking envelopes currently suppress the silent-permission-refusal note even though the chat does not render those envelopes, leaving the user with no visible explanation.

## Fix Focus Areas
- src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[1355-1358]
- src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[1852-1855]
- test/Capacitor.Cli.Daemon.Tests.Unit/Services/AcpHostedAgentRuntimePermissionTests.cs[360-394]

## Recommended Fix
Set the visibility flag only for assistant event kinds actually rendered in chat, currently `AssistantText`. Add a cancelled-permission test with thinking-only output and assert that the system note is still emitted.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

Comment on lines +1321 to +1324
// Reset THIS turn's silent-permission-refusal signal (see the finally block below) —
// a prior turn's cancelled permission or assistant text must never leak into this one.
Volatile.Write(ref _turnHadAssistantOutput, 0);
Volatile.Write(ref _turnPermissionCancelled, 0);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remediation recommended

4. Late events mislabel the next turn 🐞 Bug ☼ Reliability

_turnHadAssistantOutput and _turnPermissionCancelled are process-wide flags reset per admitted
turn, while EmitEnvelope and NotePermissionOutcome mutate them without checking the active turn
or incarnation. If a late update or swept permission response from the previous incarnation runs
after the next reset, it can suppress the next turn's refusal note or make that turn emit a note for
a permission it never requested.
Agent Prompt
## Issue description
The new refusal and assistant-output flags are shared across the runtime and can be changed by asynchronous events that do not belong to the currently executing turn.

## Fix Focus Areas
- src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[1321-1324]
- src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[1852-1855]
- src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[2764-2768]
- src/Capacitor.Cli.Daemon/Services/AcpHostedAgentRuntime.cs[2834-2842]

## Recommended Fix
Store the refusal state in a per-turn tracker carrying the active incarnation or generation. Update it only when the emitting connection or permission route matches that tracker, and add tests where an old-incarnation interaction settles after a successor turn begins.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

Comment thread src/Capacitor.Cli.Daemon/Acp/AcpInteractionBridge.cs Outdated
A transport drop declines the pending permission as cancelled and runs the turn-end finally, so the note is now emitted only for a turn that reached its stopReason. Agent-controlled option ids/kinds are stripped of control chars and capped before logging.
@realtonyyoung

Copy link
Copy Markdown
Collaborator Author

Ran a Codex review (codex exec review --base main). Two P2s, both fixed in ca628a6:

  • Teardown-cancellation could forge a refusal note. A transport drop declines the pending permission as cancelled and runs the turn-end finally, so the note could appear for a turn nobody refused. It now emits only for a turn that reached its stopReason (a completedNormally gate). New test: a transport drop before the stopReason emits no note.
  • Unsanitized agent-controlled option ids in the log. A newline in an optionId could inject a log line, or a huge value could flood the log. The ids and kinds are now stripped of control characters and capped before logging.

Qodo's three comment-convention notes are addressed in the same commit.

The root cause — the kcap-server permission card echoing the wrong optionId — remains a separate cross-repo fix; this PR makes it diagnosable and stops the blank chat.

@realtonyyoung
realtonyyoung merged commit b73d298 into main Sep 11, 2026
7 checks passed
@realtonyyoung
realtonyyoung deleted the claude-tyoung/ai2677-copilot-diag branch September 11, 2026 12:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Copilot permission approved in the web UI resolves as cancelled and leaves the agent idle

1 participant