Skip to content

🛡️ fix: Let Background Subagents Run With HITL Enabled - #571

Merged
danny-avila merged 2 commits into
mainfrom
lia/background-subagent-hitl-deny
Sep 28, 2026
Merged

danny-avila merged 2 commits into
mainfrom
lia/background-subagent-hitl-deny

Conversation

@lia-by-librechat

@lia-by-librechat lia-by-librechat Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Allow HITL-enabled background subagents. Default to fail-closed deny for tools requesting approval, while backgroundPausePolicy: 'reject' preserves the former admission check.
  • Exclude ask_user_question, report denied tools to the parent, and fail unexpected interrupts clearly.
  • Isolate children from the parent's durable checkpoint with a task-private in-memory saver and distinct child thread. Fail closed on broken background PreToolUse and SubagentStart policies, including local programmatic inner tools.
  • Scope denial to detached children and descendants; explicit background deny does not break foreground HITL or cross-run resume.

Verification

  • Seven focused Jest suites: 420 passed.
  • npx tsc --noEmit, ESLint/import order on nine touched files, npm run build, and git diff --check: passed.

Scope

SDK Phase 0 only. Durable deferred approvals and LibreChat configuration/UI remain separate work.

@danny-avila

Copy link
Copy Markdown
Collaborator

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T12:42:19.911943Z fdcf8c3 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c557539d30

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/tools/subagent/SubagentExecutor.ts Outdated
Comment on lines +2695 to +2697
if (this.humanInTheLoop?.backgroundPausePolicy === 'deny') {
childGraph.humanInTheLoop = this.humanInTheLoop;
childGraph.eagerEventToolExecution = undefined;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Isolate background children from the parent checkpointer

When a real Run has HITL enabled, snapshotChildGraphFactory has already attached the parent's checkpointer (src/graphs/Graph.ts:5311-5313) before this override runs. Because the detached executor is configured with enabled: false, its invocation path then reuses the inherited parent thread_id instead of childThreadId (SubagentExecutor.ts:2816-2819). A default-policy background child therefore runs an independent graph against the same root checkpoint namespace as its parent, potentially loading/merging parent state and concurrently overwriting checkpoints used for parent resume or sibling tasks. Clear the inherited checkpointer for deny-policy children or assign each child a dedicated checkpoint thread/namespace.

Useful? React with 👍 / 👎.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Self-review follow-up pushed at exact head fdcf8c3615bf8c0702f719209e90f527f75fc351. Codex reviewed previous head c557539d305a736eabf3c8a39dd58ab8f2cac4b4.

Codex P1 fixed: a task-private saver and distinct child thread prevent reading the parent checkpoint. A real Run test reproduced that leak before the fix and passed afterward. My review also fixed fail-open background hook errors (direct/event tools, programmatic inner tools, and SubagentStart), unexpected interrupts being reported as successful tasks, and explicit background deny changing foreground HITL resume.

Local verification: 420 focused tests passed; TypeScript, touched-file ESLint/import order, SDK build, and whitespace checks passed. A maintainer must request a new Codex review for this exact head.

@danny-avila

Copy link
Copy Markdown
Collaborator

@codex review the latest head

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Can't wait for the next one!

Reviewed commit: fdcf8c3615

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@danny-avila
danny-avila merged commit fb81d4c into main Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants