diff --git a/docs/gateway/sandbox-vs-tool-policy-vs-elevated.md b/docs/gateway/sandbox-vs-tool-policy-vs-elevated.md index c0e5a1e68..40b30d43d 100644 --- a/docs/gateway/sandbox-vs-tool-policy-vs-elevated.md +++ b/docs/gateway/sandbox-vs-tool-policy-vs-elevated.md @@ -79,8 +79,6 @@ Available groups: - `group:sessions`: `sessions_list`, `sessions_history`, `sessions_send`, `sessions_spawn`, `session_status` - `group:memory`: `memory_search`, `memory_get` -Legacy shorthand: `memory` expands to `group:memory`. - ## Elevated: exec-only “run on host” Elevated does **not** grant extra tools; it only affects `exec`. diff --git a/docs/multi-agent-sandbox-tools.md b/docs/multi-agent-sandbox-tools.md index 2431f824c..7f1195a0f 100644 --- a/docs/multi-agent-sandbox-tools.md +++ b/docs/multi-agent-sandbox-tools.md @@ -182,8 +182,6 @@ Sandbox tool policy supports `group:*` entries that expand to multiple concrete - `group:sessions`: `sessions_list`, `sessions_history`, `sessions_send`, `sessions_spawn`, `session_status` - `group:memory`: `memory_search`, `memory_get` -Legacy shorthand: `memory` expands to `group:memory`. - ### Elevated Mode `tools.elevated` is the global baseline (sender-based allowlist). `agents.list[].tools.elevated` can further restrict elevated for specific agents (both must allow). diff --git a/src/agents/sandbox-explain.test.ts b/src/agents/sandbox-explain.test.ts index d2d99f946..5ebef3fb1 100644 --- a/src/agents/sandbox-explain.test.ts +++ b/src/agents/sandbox-explain.test.ts @@ -65,7 +65,7 @@ describe("sandbox explain helpers", () => { ]); }); - it("supports legacy 'memory' shorthand and deny wins after expansion", () => { + it("denies still win after group expansion", () => { const cfg: ClawdbotConfig = { agents: { defaults: { @@ -75,7 +75,7 @@ describe("sandbox explain helpers", () => { tools: { sandbox: { tools: { - allow: ["memory"], + allow: ["group:memory"], deny: ["memory_get"], }, }, diff --git a/src/agents/sandbox.ts b/src/agents/sandbox.ts index 5ca68ed61..3bf96c6e3 100644 --- a/src/agents/sandbox.ts +++ b/src/agents/sandbox.ts @@ -269,9 +269,6 @@ function expandToolGroupEntry(entry: string): string[] { if (!raw) return []; const lower = raw.toLowerCase(); - // Back-compat shorthand: "memory" => "group:memory" - if (lower === "memory") return TOOL_GROUPS["group:memory"]; - const group = TOOL_GROUPS[lower]; if (group) return group; return [raw];