From 2e4fdc38a2ce9cfc6e247fc9400b49bab226dddf Mon Sep 17 00:00:00 2001 From: Levi Neely <141506390+lneely@users.noreply.github.com> Date: Thu, 16 Jul 2026 21:08:04 +0200 Subject: [PATCH] prompts: clarify tools-elevate does NOT run as root --- prompts/tools-elevate.md | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/prompts/tools-elevate.md b/prompts/tools-elevate.md index 375d9e9..32b24b5 100644 --- a/prompts/tools-elevate.md +++ b/prompts/tools-elevate.md @@ -1,17 +1,22 @@ # Elevation -Run a bash command outside the sandbox with user approval. +Run a bash command outside the sandbox as the **current user** (not root). The command escapes the Landlock filesystem sandbox but does NOT gain superuser privileges. -**Trigger condition**: a task requires privileges unavailable inside the sandbox — installing packages, writing to protected paths, managing services. +**What it does**: Removes sandbox filesystem restrictions so the command can access paths the sandbox normally blocks (e.g., `~/.config/`, `/usr/lib64/`, system directories). The command still runs as the logged-in user with that user's normal permissions. + +**What it does NOT do**: It does not run as root. It does not `sudo`. If the target operation requires root (e.g., `make install` to `/usr/`), the user must handle privilege escalation themselves outside of this mechanism. + +**Trigger condition**: a task requires filesystem access unavailable inside the sandbox — writing to paths outside the sandbox whitelist, reading protected config files, running commands that access restricted directories. **Calling convention**: ``` -execute_code: steps=[{code: "apt install -y ripgrep", elevated: true}] +execute_code: steps=[{code: "cp file.so /usr/lib64/qt6/plugins/kf6/ktexteditor/", elevated: true}] ``` **Constraints**: - Briefly explain what the command does and why it needs elevation before running it. - `elevated: true` is per-step — only apply to steps that need it. - Only bash is supported for elevated steps. +- Does NOT run as root. Cannot `apt install`, `make install` to system dirs, or anything else requiring superuser unless the user has passwordless sudo configured. - May not be available on all systems; if absent, the step fails with "elevation not available". - Blocks until the user approves or denies — this is expected, not an error.