Skip to content

fix(code): avoid redundant Auto approval prompts - #4993

Merged
Mason Daugherty (mdrxy) merged 3 commits into
mainfrom
mdrxy/code/avoid-redundant-auto-approvals
Jul 23, 2026
Merged

fix(code): avoid redundant Auto approval prompts#4993
Mason Daugherty (mdrxy) merged 3 commits into
mainfrom
mdrxy/code/avoid-redundant-auto-approvals

Conversation

@mdrxy

Copy link
Copy Markdown
Member

Supersedes #4946
Supersedes #4947

Auto mode no longer interrupts users when an action is already covered by their explicit ask_user selection or when the agent is performing the built-in conversation-compaction operation.


Previously, Auto mode could ask users to approve an action immediately after they selected it in an ask_user prompt. It could also pause autonomous work to approve compact_conversation, even though compaction is an internal maintenance operation without an externally consequential effect.

The two cases now follow separate trust rules:

  • Server-created, same-turn receipts allow the authorization classifier to consider only the user's selected answer for the exact subsequent action. The receipt is bound to the LangGraph execution thread, the active turn, and the originating ask_user tool call, and is validated against the full checkpoint history so it survives conversation compaction. Only the latest ask_user exchange in the turn is admitted; model-authored questions, unselected choices, and prior answers are excluded. Invalid, stale, ambiguous, or overly broad consent continues through the normal approval path.
  • The trusted built-in compact_conversation operation is deterministically allowed without classifier or human review. The exemption is guarded by exact tool-object identity, not by name, so a caller-supplied tool with the same name cannot exploit it. At most one trusted compaction call is allowed per action batch; duplicates are denied without classifier review, and that denial is preserved across all fallback paths.
Test plan

Targeted Auto-mode, ask_user, agent-wiring, and Textual-adapter tests:

uv run --group test pytest tests/unit_tests/test_ask_user_middleware.py \
  tests/unit_tests/test_auto_mode.py \
  tests/unit_tests/tui/test_textual_adapter.py::TestExecuteTaskTextualTurnMarkers \
  tests/unit_tests/test_agent.py::test_cli_context_schema_fields_mirror_typed_dict \
  tests/unit_tests/test_agent.py::TestCreateCliAgentInterpreterWiring \
  --disable-socket --allow-unix-socket --benchmark-disable -q

Result: 135 passed.

Full package unit tests:

make test

Result: 10617 passed, 4 skipped, 6 pre-existing failures in TestLangsmithSecretRedaction (env-dependent, fail on clean origin/main).

Lint, format, type check, and commands catalog:

make lint

Result: All checks passed.

A real LangGraph interrupt/resume test (test_real_agent_resume_forwards_ask_user_receipt_to_classifier) verifies the full path: ask_user interrupt → checkpoint resume → receipt minting with real execution_info.thread_id → classifier sees same_turn_user_answers → action executes without a second HITL prompt.

A compiled-graph identity test (test_compiled_agent_preserves_canonical_compaction_tool_identity) verifies the canonical CLICompactionMiddleware tool object survives create_deep_agent's middleware merge into the compiled ToolNode, and that AutoModeHITLMiddleware._trusted_compaction_tool references that same object.

The 6 TestLangsmithSecretRedaction failures are pre-existing and env-dependent (real LangSmith credentials in the local environment); they fail identically on clean origin/main and are unrelated to this change.

@github-actions github-actions Bot added dcode Related to `deepagents-code` fix A bug fix (PATCH) internal User is a member of the `langchain-ai` GitHub organization size: XL 1000+ LOC labels Jul 23, 2026

@open-swe open-swe Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Open SWE Review: No issues found

Open SWE reviewed this PR and found no potential bugs to report.

Open in WebView Open SWE trace

…ndant-auto-approvals

# Conflicts:
#	libs/code/deepagents_code/_cli_context.py
#	libs/code/deepagents_code/tui/textual_adapter.py
@mdrxy
Mason Daugherty (mdrxy) merged commit 9975874 into main Jul 23, 2026
54 checks passed
@mdrxy
Mason Daugherty (mdrxy) deleted the mdrxy/code/avoid-redundant-auto-approvals branch July 23, 2026 13:37
Mason Daugherty (mdrxy) pushed a commit that referenced this pull request Jul 24, 2026
> [!CAUTION]
> Merging this PR will automatically publish to **PyPI** and create a
**GitHub release**.

For the full release process, see
[`.github/RELEASING.md`](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md).

---

_Release notes preview: keep this section in sync with the package
`CHANGELOG.md`. The published GitHub release body is extracted from the
merged `CHANGELOG.md` by `release.yml`, not from this PR description._

---


##
[0.1.46](deepagents-code==0.1.45...deepagents-code==0.1.46)
(2026-07-24)

### Highlights

- Auto mode is now generally available.
[#4957](#4957)
- Added configurable Auto goal-criteria acceptance.
[#4940](#4940)
- Improved Auto behavior by authorizing actions from active goal/rubric
directives, avoiding redundant approval prompts, showing the enable
notice only on first global enable, deduplicating classifier-unavailable
transcript spam, logging underlying classifier failures, and reporting
classifier timeout budgets.
[#5017](#5017)
[#4993](#4993)
[#5012](#5012)
[#5013](#5013)
[#5011](#5011)
[#5025](#5025)
- Added Hooks v2 capability snapshots and session transcripts, and
hardened Hooks v2 command execution.
[#4916](#4916)
[#4918](#4918)
[#4917](#4917)
- Raised the agent recursion limit to 2000 and made it configurable.
[#4994](#4994)

### Improvements and fixes

- Let the rubric grader inspect working-directory files, show rubric
grader defaults, and improved `/rubric` help and empty-state messaging.
[#4835](#4835)
[#4966](#4966)
[#5015](#5015)
- Unified goal activation signaling.
[#4980](#4980)
- Made Version, Model, and CWD copyable in the Debug Console.
[#4975](#4975)
- Improved `config get` output when a key is missing.
[#4976](#4976)
- Aborted YOLO launch on `Ctrl+C`/`Ctrl+D` and made the YOLO warning
friendlier for new users.
[#4953](#4953)
[#4950](#4950)
- Updated LangSmith handling: secret redaction is disabled by default,
`/trace` now flags empty env overrides that shadow the LangSmith key,
and the default US endpoint is no longer treated as a custom target.
[#4970](#4970)
[#4996](#4996)
[#5022](#5022)
- Injected OpenAI `prompt_cache_key` for any OpenAI-provider endpoint.
[#4995](#4995)
- Improved tool and schema presentation: finished calls stay on the live
tool-group line, first-party tool schemas now include field
descriptions, and `web_search`/`fetch_url` tool descriptions were
trimmed. [#4927](#4927)
[#5019](#5019)
[#5016](#5016)
- Omitted `plugins/` and `conversation_history/` from the `/agent`
picker. [#4991](#4991)
- Made selector modal backdrop dimming consistent.
[#4990](#4990)
- Restored the `"Server log preserved at:"` notice on exit.
[#4999](#4999)
- Used the SDK pin as the effective editable version.
[#4949](#4949)

_End release notes preview._

---

> [!NOTE]
> A **New Contributors** section is appended to the GitHub release notes
automatically at publish time (see [Release
Pipeline](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md#release-pipeline),
step 2).

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: langchain-oss-automated-triage[bot] <248757908+langchain-oss-automated-triage[bot]@users.noreply.github.com>
Marcelo5444 pushed a commit to Marcelo5444/deepagents that referenced this pull request Jul 30, 2026
Supersedes langchain-ai#4946
Supersedes langchain-ai#4947

Auto mode no longer interrupts users when an action is already covered
by their explicit `ask_user` selection or when the agent is performing
the built-in conversation-compaction operation.

---

Previously, Auto mode could ask users to approve an action immediately
after they selected it in an `ask_user` prompt. It could also pause
autonomous work to approve `compact_conversation`, even though
compaction is an internal maintenance operation without an externally
consequential effect.

The two cases now follow separate trust rules:
- Server-created, same-turn receipts allow the authorization classifier
to consider only the user's selected answer for the exact subsequent
action. The receipt is bound to the LangGraph execution thread, the
active turn, and the originating `ask_user` tool call, and is validated
against the full checkpoint history so it survives conversation
compaction. Only the latest `ask_user` exchange in the turn is admitted;
model-authored questions, unselected choices, and prior answers are
excluded. Invalid, stale, ambiguous, or overly broad consent continues
through the normal approval path.
- The trusted built-in `compact_conversation` operation is
deterministically allowed without classifier or human review. The
exemption is guarded by exact tool-object identity, not by name, so a
caller-supplied tool with the same name cannot exploit it. At most one
trusted compaction call is allowed per action batch; duplicates are
denied without classifier review, and that denial is preserved across
all fallback paths.

<details>
<summary>Test plan</summary>

Targeted Auto-mode, ask_user, agent-wiring, and Textual-adapter tests:

```
uv run --group test pytest tests/unit_tests/test_ask_user_middleware.py \
  tests/unit_tests/test_auto_mode.py \
  tests/unit_tests/tui/test_textual_adapter.py::TestExecuteTaskTextualTurnMarkers \
  tests/unit_tests/test_agent.py::test_cli_context_schema_fields_mirror_typed_dict \
  tests/unit_tests/test_agent.py::TestCreateCliAgentInterpreterWiring \
  --disable-socket --allow-unix-socket --benchmark-disable -q
```
Result: 135 passed.

Full package unit tests:

```
make test
```
Result: 10617 passed, 4 skipped, 6 pre-existing failures in
`TestLangsmithSecretRedaction` (env-dependent, fail on clean
`origin/main`).

Lint, format, type check, and commands catalog:

```
make lint
```
Result: All checks passed.

A real LangGraph interrupt/resume test
(`test_real_agent_resume_forwards_ask_user_receipt_to_classifier`)
verifies the full path: `ask_user` interrupt → checkpoint resume →
receipt minting with real `execution_info.thread_id` → classifier sees
`same_turn_user_answers` → action executes without a second HITL prompt.

A compiled-graph identity test
(`test_compiled_agent_preserves_canonical_compaction_tool_identity`)
verifies the canonical `CLICompactionMiddleware` tool object survives
`create_deep_agent`'s middleware merge into the compiled `ToolNode`, and
that `AutoModeHITLMiddleware._trusted_compaction_tool` references that
same object.

The 6 `TestLangsmithSecretRedaction` failures are pre-existing and
env-dependent (real LangSmith credentials in the local environment);
they fail identically on clean `origin/main` and are unrelated to this
change.

</details>
Marcelo5444 pushed a commit to Marcelo5444/deepagents that referenced this pull request Jul 30, 2026
> [!CAUTION]
> Merging this PR will automatically publish to **PyPI** and create a
**GitHub release**.

For the full release process, see
[`.github/RELEASING.md`](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md).

---

_Release notes preview: keep this section in sync with the package
`CHANGELOG.md`. The published GitHub release body is extracted from the
merged `CHANGELOG.md` by `release.yml`, not from this PR description._

---


##
[0.1.46](langchain-ai/deepagents@deepagents-code==0.1.45...deepagents-code==0.1.46)
(2026-07-24)

### Highlights

- Auto mode is now generally available.
[langchain-ai#4957](langchain-ai#4957)
- Added configurable Auto goal-criteria acceptance.
[langchain-ai#4940](langchain-ai#4940)
- Improved Auto behavior by authorizing actions from active goal/rubric
directives, avoiding redundant approval prompts, showing the enable
notice only on first global enable, deduplicating classifier-unavailable
transcript spam, logging underlying classifier failures, and reporting
classifier timeout budgets.
[langchain-ai#5017](langchain-ai#5017)
[langchain-ai#4993](langchain-ai#4993)
[langchain-ai#5012](langchain-ai#5012)
[langchain-ai#5013](langchain-ai#5013)
[langchain-ai#5011](langchain-ai#5011)
[langchain-ai#5025](langchain-ai#5025)
- Added Hooks v2 capability snapshots and session transcripts, and
hardened Hooks v2 command execution.
[langchain-ai#4916](langchain-ai#4916)
[langchain-ai#4918](langchain-ai#4918)
[langchain-ai#4917](langchain-ai#4917)
- Raised the agent recursion limit to 2000 and made it configurable.
[langchain-ai#4994](langchain-ai#4994)

### Improvements and fixes

- Let the rubric grader inspect working-directory files, show rubric
grader defaults, and improved `/rubric` help and empty-state messaging.
[langchain-ai#4835](langchain-ai#4835)
[langchain-ai#4966](langchain-ai#4966)
[langchain-ai#5015](langchain-ai#5015)
- Unified goal activation signaling.
[langchain-ai#4980](langchain-ai#4980)
- Made Version, Model, and CWD copyable in the Debug Console.
[langchain-ai#4975](langchain-ai#4975)
- Improved `config get` output when a key is missing.
[langchain-ai#4976](langchain-ai#4976)
- Aborted YOLO launch on `Ctrl+C`/`Ctrl+D` and made the YOLO warning
friendlier for new users.
[langchain-ai#4953](langchain-ai#4953)
[langchain-ai#4950](langchain-ai#4950)
- Updated LangSmith handling: secret redaction is disabled by default,
`/trace` now flags empty env overrides that shadow the LangSmith key,
and the default US endpoint is no longer treated as a custom target.
[langchain-ai#4970](langchain-ai#4970)
[langchain-ai#4996](langchain-ai#4996)
[langchain-ai#5022](langchain-ai#5022)
- Injected OpenAI `prompt_cache_key` for any OpenAI-provider endpoint.
[langchain-ai#4995](langchain-ai#4995)
- Improved tool and schema presentation: finished calls stay on the live
tool-group line, first-party tool schemas now include field
descriptions, and `web_search`/`fetch_url` tool descriptions were
trimmed. [langchain-ai#4927](langchain-ai#4927)
[langchain-ai#5019](langchain-ai#5019)
[langchain-ai#5016](langchain-ai#5016)
- Omitted `plugins/` and `conversation_history/` from the `/agent`
picker. [langchain-ai#4991](langchain-ai#4991)
- Made selector modal backdrop dimming consistent.
[langchain-ai#4990](langchain-ai#4990)
- Restored the `"Server log preserved at:"` notice on exit.
[langchain-ai#4999](langchain-ai#4999)
- Used the SDK pin as the effective editable version.
[langchain-ai#4949](langchain-ai#4949)

_End release notes preview._

---

> [!NOTE]
> A **New Contributors** section is appended to the GitHub release notes
automatically at publish time (see [Release
Pipeline](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md#release-pipeline),
step 2).

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: langchain-oss-automated-triage[bot] <248757908+langchain-oss-automated-triage[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dcode Related to `deepagents-code` fix A bug fix (PATCH) internal User is a member of the `langchain-ai` GitHub organization size: XL 1000+ LOC

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant