$ the-wire · showcase
Enterprise permission defaults get teeth as Codex, Gemini CLI and Goose ship fixes
By RepoJournal · Filed · About Agentic Coding · Composed from the cited sources · methodology
Claude Code closes two holes where plugins could loosen organization-wide security settings, while Codex, Gemini CLI and Goose each ship an operational fix worth knowing about before your next run.
sec-default: a settings deny rule holds over an allow or ask from a plugin the person installed anthropics/claude-code
A deny rule from your settings now wins over an allow or ask verdict returned by a plugin you installed, and organizations can opt out in managed settings. If you run Claude Code with a security default seated, a third-party mod can no longer switch off the permission rule that was meant to hold.
sec-default: the system prompt's sections continue past the user tier anthropics/claude-code
Where an organization seats sec-default, your installed plugins no longer shape the system prompt's sections: prompt.compose now continues past the user tier like every other prompt-shaping event. Expect org-managed prompt composition to stop being silently rewritten by local plugin state.
fix(cli): propagate resolved folder trust state in headless mode (#29031) google-gemini/gemini-cli
useFolderTrust in headless mode used to report onTrustChange(true) to AppContainer even when isTrusted was false, leaving the hook's own state warning about an untrusted folder while consumers believed it was trusted. The resolved trust state now propagates, so untrusted workspaces stay untrusted in headless runs.
fix(acp): bridge PromptResponse.usage and emit usage_update notifications (#29389) google-gemini/gemini-cli
Gemini CLI in ACP mode now fills PromptResponse.usage and emits sessionUpdate: 'usage_update' notifications, capturing cachedContentTokenCount and thoughtsTokenCount from usageMetadata. The upshot for anyone billing off ACP clients: severe token overestimation, roughly 3x, goes away, and existing consumers of _meta.quota keep working.
fix(bedrock): report max_tokens truncation and flush tool calls aaif-goose/goose
The Bedrock converse stream path never read stopReason, so a response cut off by the output token limit looked like a normal end of turn: the CLI truncation warning never rendered, ACP reported end_turn, and a tool call truncated mid-arguments was dropped silently. Goose now reports truncation and flushes the partial tool call the way the Anthropic provider already does.
fix(core): honor Stop issued while a turn is still being prepared (#14634) cline/cline
A Stop issued between runTurn() entry and the agent run start, during session persistence, git metadata refresh or credential sync, was silently dropped: the turn ran to completion while the sidecar and webview already showed it stopped. In the desktop app that surfaced as edit and revert failing with "Wait for all turns in this workspace to finish before rest"; the abort is now honored.
fix(canvas): respect scoped runtime clients and workspace capabilities OpenHands/OpenHands
Canvas no longer shows host-workspace controls that cannot work on Docker or isolated agent-server backends, and service calls carry conversation identity instead of failing with a Docker 400 or running unscoped. If you run OpenHands behind an isolated backend, the workspace controls you see now match what the backend can actually do.
Remove randomized greetings from TUI session headers openai/codex
Codex's TUI drops the randomized startup greeting phrases and shared greeting state from session headers and the empty-state animation, and raw headers now consistently carry model: and directory: fields. Scripted sessions parsing headers get a stable shape, and one less piece of nondeterminism.