tools: pipe stdin JSON via heredoc for elevated calls

The elevation broker protocol doesn't support stdin piping.
When a promoted tool runs elevated, wrap the command as:
  cat <<'OLLIE_EOF' | /path/to/tool
  {json}
  OLLIE_EOF

This ensures elevated tools receive their JSON args.
This commit is contained in:
Levi Neely 2026-07-29 08:52:53 +02:00
parent 75b76b118e
commit 3b05b50b47
1 changed files with 3 additions and 1 deletions

View File

@ -306,7 +306,9 @@ func (e *Server) callPromotedTool(ctx context.Context, tool string, args json.Ra
e.wdMu.RLock()
workDir := e.cwd
e.wdMu.RUnlock()
result, err = e.executeElevated(ctx, code, workDir, 30)
// Broker protocol has no stdin support; pipe JSON via heredoc.
elevatedCode := fmt.Sprintf("cat <<'OLLIE_EOF' | %s\n%s\nOLLIE_EOF", code, stdinData)
result, err = e.executeElevated(ctx, elevatedCode, workDir, 30)
} else {
result, err = e.executeWithStdin(ctx, code, "bash", 30, "default", false, stdinData)
}