Before you start
What happened? 发生了什么?
The built-in safety gate added for #6827 correctly refuses Get-Process node | Stop-Process -Force. But it also refuses a targeted stop when the PID is stored in a variable first, while allowing the identical command written inline.
| Command |
Gate |
Stop-Process -Id (Get-NetTCPConnection -LocalPort 3999 -State Listen).OwningProcess |
allowed, server stopped |
$p = (Get-NetTCPConnection -LocalPort 3999 -State Listen).OwningProcess; Stop-Process -Id $p |
refused |
Stop-Process -Id 26128 (literal) |
allowed |
Refusal message:
Built-in safety gate requires approval: unbounded process termination can kill this or another Codewhale npm session's Node launcher; stop the owned server by PID or port instead
This also blocks the usual owned-process pattern, which is what the message recommends:
$proc = Start-Process node server.js -PassThru; Start-Sleep 3; Stop-Process -Id $proc.Id
It matters more because a process started with Start-Process inside one tool call is gone by the next call (it appears to be contained to the call), so an agent can't start a server in one call and stop it by a literal PID in the next. Start and stop have to happen in the same command, which in practice means holding the PID in a variable.
Expected: Stop-Process -Id $var should be allowed when $var comes from Start-Process -PassThru or the same port lookup the gate already accepts inline, or at least behave consistently with the inline form.
Steps to reproduce 复现步骤
- In a normal PowerShell tab, start any Node server on port 3999 (
node server.js).
- In Codewhale (Full Access), ask it to run exactly:
Stop-Process -Id (Get-NetTCPConnection -LocalPort 3999 -State Listen).OwningProcess
→ runs; the server stops.
- Restart the server, then ask it to run exactly:
$p = (Get-NetTCPConnection -LocalPort 3999 -State Listen).OwningProcess; Stop-Process -Id $p
→ refused with the message above.
Codewhale version 版本
codewhale 0.10.1 (dev), built from source at af5fa5c
Where did it happen? 在哪里出现?
TUI (terminal interface)
Operating system 操作系统
Windows
How did you get Codewhale? 获取方式
Built from a git checkout
Provider and model 提供商和模型
deepseek / deepseek-v4-pro
Terminal and shell 终端
Windows Terminal + Windows PowerShell 5.1
codewhale doctor (optional)
Logs, screenshots, anything else (optional)
No response
Before you start
What happened? 发生了什么?
The built-in safety gate added for #6827 correctly refuses
Get-Process node | Stop-Process -Force. But it also refuses a targeted stop when the PID is stored in a variable first, while allowing the identical command written inline.Stop-Process -Id (Get-NetTCPConnection -LocalPort 3999 -State Listen).OwningProcess$p = (Get-NetTCPConnection -LocalPort 3999 -State Listen).OwningProcess; Stop-Process -Id $pStop-Process -Id 26128(literal)Refusal message:
This also blocks the usual owned-process pattern, which is what the message recommends:
It matters more because a process started with
Start-Processinside one tool call is gone by the next call (it appears to be contained to the call), so an agent can't start a server in one call and stop it by a literal PID in the next. Start and stop have to happen in the same command, which in practice means holding the PID in a variable.Expected:
Stop-Process -Id $varshould be allowed when$varcomes fromStart-Process -PassThruor the same port lookup the gate already accepts inline, or at least behave consistently with the inline form.Steps to reproduce 复现步骤
node server.js).Stop-Process -Id (Get-NetTCPConnection -LocalPort 3999 -State Listen).OwningProcess→ runs; the server stops.
$p = (Get-NetTCPConnection -LocalPort 3999 -State Listen).OwningProcess; Stop-Process -Id $p→ refused with the message above.
Codewhale version 版本
codewhale 0.10.1 (dev), built from source at af5fa5c
Where did it happen? 在哪里出现?
TUI (terminal interface)
Operating system 操作系统
Windows
How did you get Codewhale? 获取方式
Built from a git checkout
Provider and model 提供商和模型
deepseek / deepseek-v4-pro
Terminal and shell 终端
Windows Terminal + Windows PowerShell 5.1
codewhale doctor (optional)
Logs, screenshots, anything else (optional)
No response