Conversation
_finalize_tool_call_data looked the tool up in the global registry, so a tool that was not exposed to the model could still be executed. Resolve against the tools passed to the turn instead. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
The default six tools were hardcoded, so they could not be disabled. Add [tools] enabled as an allowlist (defaulting to the current six) that is merged with [tools] extra and --extra-tools by a shared resolve_tools() helper, replacing the duplicated logic in the TUI and headless entry points. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
borko1945
force-pushed
the
feat/configurable-tool-allowlist
branch
from
September 21, 2026 21:35
e011d72 to
005fb32
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This is inspired by Deepseek harness mini mode - where the model has only bash as a tool. Models are pretty good with bash as this is part of their training. The model is more focused and dramatically reduces the initial context.
I am using it and so far so good.
The six built-in tools were hardcoded in
DEFAULT_TOOLS, so there was no way to turn any of them off —[tools] extracould only ever add tools. This adds[tools] enabledas an allowlist, which makes it possible to run a leaner Kon (for example bash-only) without touching the code.Changes
[tools] enabled— the built-in tools exposed to the agent, defaulting to the current six, so behaviour is unchanged out of the box.resolve_tools()— one helper that mergesenabled+extra+--extra-toolsand reports unknown names, replacing the duplicated (and slightly divergent) logic inui/app.pyandheadless.py.turn.pyfix —_finalize_tool_call_data()resolved tool calls against the global registry, so a tool that was not exposed to the model could still be executed if the model named it. It now resolves against the turn's active tools. This is a prerequisite for the allowlist to actually hold.DEFAULT_TOOLS/EXTRA_TOOLSconstants;tools_by_nameis the single registry and the defaults live inconfig.py+defaults/config.toml, matching how every other default is handled.Example:
Notes
enabledinherit the shipped default, so existing users see the same six tools plus theirextra. Verified against a real pre-existing config.config_versionbump / migration needed — the key has a default and absence is handled, so no user config gets rewritten.EXTRA_TOOLSpreviously doubled as the "is this a valid name?" check; validation is nowtools_by_name, so unknown names inenabledare reported too. The warning text changed fromunknown extra tooltounknown toolaccordingly (one test line updated).DEFAULT_TOOLS/EXTRA_TOOLSfromkon.tools.__all__is technically a public-API change — happy to keep them as aliases if you'd prefer.all_tools, and decide whether it belongs inenabledorextra.Testing
ruff format,ruff check,pyright(0 errors) andpytest(806 passed, 1 skipped) all clean. Newtests/test_tools_config.pycovers the default set, trimming to bash-only, extending viaextra/CLI, and unknown-name reporting;test_disabled_tool_is_not_executablecovers theturn.pyfix.AI usage
The change was coded by Opus 4.8 under my command