feat(deepagents): implement file system permissions for fs middleware tools (#492)
### Summary - Adds a FilesystemPermission class and a permissions parameter to createDeepAgent and SubAgent that controls which filesystem operations each agent is allowed to perform - Rules are evaluated first-match-wins with a permissive default; mode: "deny" blocks the operation before any backend call - Permissions are closed over at tool-creation time — no runtime config threading, no ToolPolicy in langchain-core - ls, glob, and grep enforce permissions in two passes: the base path check throws early; results are post-filtered to strip entries the caller can't read - Subagents receive the parent agent's permissions by default; setting permissions on a SubAgent is a full replacement, not a merge - FilesystemPermission, FilesystemPermissionOptions, FilesystemOperation, and PermissionMode are exported from the top-level package entry point ### Tests - permissions/types.test.ts — FilesystemPermission construction, validation (rejects relative paths, .., ~), defaults - permissions/enforce.test.ts — validatePath, globMatch (wildcards, brace expansion, dotfiles), decidePathAccess (first-match-wins, operation mismatch, multiple ops/paths) - middleware/fs.permissions.test.ts — each fs tool (read, write, edit, ls, glob, grep) with allow/deny rules and mock backends; verifies backend is never called on a denied path; verifies execute is unaffected - permissions/agent.permissions.test.ts — CreateDeepAgentParams.permissions type and default; wiring to createFilesystemMiddleware - middleware/subagents.permissions.test.ts — SubAgent.permissions type; ?? resolution (inherit vs override vs own deny); createFilesystemMiddleware behavior for each resolved-permissions case --------- Co-authored-by: Hunter Lovell <40191806+hntrl@users.noreply.github.com>
C
Colin Francis committed
43cd121133562abf0dee76c6db01f2bde0eb3fd3
Parent: 883581c
Committed by GitHub <noreply@github.com>
on 4/28/2026, 9:13:00 PM