prompts: elevation requires proven failure first

This commit is contained in:
Levi Neely 2026-07-17 16:04:40 +02:00
parent b0f187aafb
commit d3d350efbb
1 changed files with 6 additions and 2 deletions

View File

@ -6,7 +6,12 @@ Run a bash command outside the sandbox as the **current user** (not root). The c
**What it does NOT do**: It does not run as root. It does not `sudo`. If the target operation requires root (e.g., `make install` to `/usr/`), the user must handle privilege escalation themselves outside of this mechanism.
**Trigger condition**: a task requires filesystem access unavailable inside the sandbox — writing to paths outside the sandbox whitelist, reading protected config files, running commands that access restricted directories.
**Trigger condition**: a command has **already failed** with a permission denied error inside the sandbox, proving that elevation is necessary. Do NOT use elevation preemptively.
**Procedure**:
1. **Always try without elevation first.** Run the command normally inside the sandbox.
2. **Only if it fails** with a permission/access error (e.g., `Permission denied`, `No such file or directory` for a path outside the sandbox), retry with `elevated: true`.
3. Never assume elevation is needed based on the path alone — the sandbox whitelist may already cover it.
**Calling convention**:
```
@ -14,7 +19,6 @@ execute_code: steps=[{code: "cp file.so /usr/lib64/qt6/plugins/kf6/ktexteditor/"
```
**Constraints**:
- Briefly explain what the command does and why it needs elevation before running it.
- `elevated: true` is per-step — only apply to steps that need it.
- Only bash is supported for elevated steps.
- Does NOT run as root. Cannot `apt install`, `make install` to system dirs, or anything else requiring superuser unless the user has passwordless sudo configured.