Fix exclude tools docs #7117 - #28965
Conversation
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request addresses a long-standing ambiguity in how tool exclusions were handled. Previously, users could provide strings like 'run_shell_command(rm -rf)' in configuration files, which were not actually valid tool names. This change formalizes the handling of these entries by automatically converting them into proper Policy Engine deny rules, while simultaneously deprecating the old syntax and updating documentation to guide users toward the supported Policy Engine approach. Highlights
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. Footnotes
|
|
📊 PR Size: size/L
|
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
There was a problem hiding this comment.
Code Review
This pull request deprecates the legacy parenthesized toolName(args) syntax in tools.exclude and extension excludeTools configurations, transitioning command-level restrictions to the Policy Engine. It introduces backward compatibility by automatically converting legacy parenthesized entries into Policy Engine deny rules, and updates the documentation, examples, and loaders accordingly. I have no feedback to provide as there are no review comments.
Extension excludeTools entries are matched by exact tool name, so forms like run_shell_command(rm -rf *) never exclude anything. Update docs and the shipped example to use bare tool names, and point command-level blocking at the policy engine. Co-authored-by: samanyugoyal2010 <samanyugoyal2010@users.noreply.github.com>
tools.exclude and extension excludeTools compared whole tool names, so entries like run_shell_command(rm) were silently ignored. Convert that legacy form into Policy Engine deny rules with command-prefix matching, warn that authors should migrate to policies/, and update shell and enterprise docs that still taught the non-matching syntax. Fixes google-gemini#28962. Also addresses the matching gap reported in google-gemini#17728; command-level control remains the Policy Engine path introduced by google-gemini#18508. Co-authored-by: samanyugoyal2010 <samanyugoyal2010@users.noreply.github.com>
9498dd0 to
6db1316
Compare
|
@dtedesco1-at-google can this PR Please be approved |
|
Hi there! Thank you for your interest in contributing to Gemini CLI. To ensure we maintain high code quality and focus on our prioritized roadmap, we only guarantee review and consideration of pull requests for issues that are explicitly labeled as 'help wanted'. This PR will be closed in 7 days if it remains without that designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding. |
Summary
Details
Related Issues
How to Validate
Pre-Merge Checklist