prompts: elevation requires proven failure first
This commit is contained in:
parent
72185c5752
commit
89dba79dc1
|
|
@ -6,7 +6,12 @@ Run a bash command outside the sandbox as the **current user** (not root). The c
|
|||
|
||||
**What it does NOT do**: It does not run as root. It does not `sudo`. If the target operation requires root (e.g., `make install` to `/usr/`), the user must handle privilege escalation themselves outside of this mechanism.
|
||||
|
||||
**Trigger condition**: a task requires filesystem access unavailable inside the sandbox — writing to paths outside the sandbox whitelist, reading protected config files, running commands that access restricted directories.
|
||||
**Trigger condition**: a command has **already failed** with a permission denied error inside the sandbox, proving that elevation is necessary. Do NOT use elevation preemptively.
|
||||
|
||||
**Procedure**:
|
||||
1. **Always try without elevation first.** Run the command normally inside the sandbox.
|
||||
2. **Only if it fails** with a permission/access error (e.g., `Permission denied`, `No such file or directory` for a path outside the sandbox), retry with `elevated: true`.
|
||||
3. Never assume elevation is needed based on the path alone — the sandbox whitelist may already cover it.
|
||||
|
||||
**Calling convention**:
|
||||
```
|
||||
|
|
@ -14,7 +19,6 @@ execute_code: steps=[{code: "cp file.so /usr/lib64/qt6/plugins/kf6/ktexteditor/"
|
|||
```
|
||||
|
||||
**Constraints**:
|
||||
- Briefly explain what the command does and why it needs elevation before running it.
|
||||
- `elevated: true` is per-step — only apply to steps that need it.
|
||||
- Only bash is supported for elevated steps.
|
||||
- Does NOT run as root. Cannot `apt install`, `make install` to system dirs, or anything else requiring superuser unless the user has passwordless sudo configured.
|
||||
|
|
|
|||
Reference in New Issue