Skip to content

Fix exclude tools docs #7117 - #28965

Open
samanyugoyal2010 wants to merge 2 commits into
google-gemini:mainfrom
samanyugoyal2010:cursor/fix-exclude-tools-docs-7117
Open

Fix exclude tools docs #7117#28965
samanyugoyal2010 wants to merge 2 commits into
google-gemini:mainfrom
samanyugoyal2010:cursor/fix-exclude-tools-docs-7117

Conversation

@samanyugoyal2010

Copy link
Copy Markdown

Summary

Details

Related Issues

How to Validate

Pre-Merge Checklist

  • Updated relevant documentation and README (if needed)
  • Added/updated tests (if needed)
  • Noted breaking changes (if any)
  • Validated on required platforms/methods:
    • MacOS
      • npm run
      • npx
      • Docker
      • Podman
      • Seatbelt
    • Windows
      • npm run
      • npx
      • Docker
    • Linux
      • npm run
      • npx
      • Docker

@samanyugoyal2010
samanyugoyal2010 requested review from a team as code owners August 22, 2026 19:17
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request addresses a long-standing ambiguity in how tool exclusions were handled. Previously, users could provide strings like 'run_shell_command(rm -rf)' in configuration files, which were not actually valid tool names. This change formalizes the handling of these entries by automatically converting them into proper Policy Engine deny rules, while simultaneously deprecating the old syntax and updating documentation to guide users toward the supported Policy Engine approach.

Highlights

  • Legacy Tool Exclusion Syntax: Deprecated the use of toolName(args) syntax in tools.exclude and excludeTools settings, as these were not valid tool names but rather command-level restrictions.
  • Policy Engine Integration: Implemented automatic conversion of legacy parenthesized exclusion entries into formal Policy Engine deny rules to ensure security restrictions are correctly applied.
  • Documentation Updates: Updated CLI and extension documentation to recommend the Policy Engine for command-level restrictions instead of the deprecated exclusion syntax.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@github-actions github-actions Bot added the size/l A large sized PR label Aug 22, 2026
@github-actions

Copy link
Copy Markdown

📊 PR Size: size/L

  • Lines changed: 434
  • Additions: +377
  • Deletions: -57
  • Files changed: 13

@google-cla

google-cla Bot commented Aug 22, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request deprecates the legacy parenthesized toolName(args) syntax in tools.exclude and extension excludeTools configurations, transitioning command-level restrictions to the Policy Engine. It introduces backward compatibility by automatically converting legacy parenthesized entries into Policy Engine deny rules, and updates the documentation, examples, and loaders accordingly. I have no feedback to provide as there are no review comments.

@gemini-cli gemini-cli Bot added the priority/p1 Important and should be addressed in the near term. label Aug 22, 2026
@samanyugoyal2010 samanyugoyal2010 changed the title Cursor/fix exclude tools docs 7117 Fix exclude tools docs #7117 Aug 22, 2026
samanyugoyal2010 and others added 2 commits August 22, 2026 19:38
Extension excludeTools entries are matched by exact tool name, so forms like
run_shell_command(rm -rf *) never exclude anything. Update docs and the
shipped example to use bare tool names, and point command-level blocking at
the policy engine.

Co-authored-by: samanyugoyal2010 <samanyugoyal2010@users.noreply.github.com>
tools.exclude and extension excludeTools compared whole tool names, so
entries like run_shell_command(rm) were silently ignored. Convert that
legacy form into Policy Engine deny rules with command-prefix matching,
warn that authors should migrate to policies/, and update shell and
enterprise docs that still taught the non-matching syntax.

Fixes google-gemini#28962. Also addresses the matching gap
reported in google-gemini#17728; command-level control remains the Policy Engine
path introduced by google-gemini#18508.

Co-authored-by: samanyugoyal2010 <samanyugoyal2010@users.noreply.github.com>
@cursor
cursor Bot force-pushed the cursor/fix-exclude-tools-docs-7117 branch from 9498dd0 to 6db1316 Compare August 22, 2026 19:39
@samanyugoyal2010

Copy link
Copy Markdown
Author

@dtedesco1-at-google can this PR Please be approved

@gemini-cli

gemini-cli Bot commented Aug 30, 2026

Copy link
Copy Markdown
Contributor

Hi there! Thank you for your interest in contributing to Gemini CLI.

To ensure we maintain high code quality and focus on our prioritized roadmap, we only guarantee review and consideration of pull requests for issues that are explicitly labeled as 'help wanted'.

This PR will be closed in 7 days if it remains without that designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority/p1 Important and should be addressed in the near term. size/l A large sized PR status/pr-nudge-sent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant