diff --git a/packages/paperclip-runner/test/acpx-codex-package-contract.test.mjs b/packages/paperclip-runner/test/acpx-codex-package-contract.test.mjs index 024ad972c2..6f96a49e53 100644 --- a/packages/paperclip-runner/test/acpx-codex-package-contract.test.mjs +++ b/packages/paperclip-runner/test/acpx-codex-package-contract.test.mjs @@ -136,6 +136,13 @@ test("the Codex patch enforces isolated instructions, tools, and skills", () => } }); +test("the Codex patch keeps MCP tool approvals on the governed permission channel", () => { + assert.match( + codexPatch, + /!context\.isToolApproval && this\.shouldUseAcpElicitation\(params\)/, + ); +}); + test("the Claude patch removes ambient project and local configuration", () => { for (const token of [ "PAPERCLIP_ACPX_ISOLATED_CONTEXT", diff --git a/patches/@agentclientprotocol__codex-acp@1.6.2.patch b/patches/@agentclientprotocol__codex-acp@1.6.2.patch index f6a8c34bfe..e9355a2901 100644 --- a/patches/@agentclientprotocol__codex-acp@1.6.2.patch +++ b/patches/@agentclientprotocol__codex-acp@1.6.2.patch @@ -1,6 +1,15 @@ diff --git a/dist/index.js b/dist/index.js --- a/dist/index.js +++ b/dist/index.js +@@ -25341,7 +25341,7 @@ + async handleElicitation(params) { + try { + const context = this.createMcpElicitationContext(params); +- if (this.shouldUseAcpElicitation(params)) { ++ if (!context.isToolApproval && this.shouldUseAcpElicitation(params)) { + const response2 = await this.connection.request( + methods.client.elicitation.create, + this.buildElicitationRequest(params, context), @@ -25563,7 +25563,7 @@ toolCall: { toolCallId: context.correlatedCallId,