Skip to content

Windows shell safety gate refuses Stop-Process when the PID is held in a variable, blocking the owned-process stop it recommends #6871

Description

@jayanthvee

Before you start

  • I searched existing issues and this is not a duplicate. 我已搜索过现有 issue。

What happened? 发生了什么?

The built-in safety gate added for #6827 correctly refuses Get-Process node | Stop-Process -Force. But it also refuses a targeted stop when the PID is stored in a variable first, while allowing the identical command written inline.

Command Gate
Stop-Process -Id (Get-NetTCPConnection -LocalPort 3999 -State Listen).OwningProcess allowed, server stopped
$p = (Get-NetTCPConnection -LocalPort 3999 -State Listen).OwningProcess; Stop-Process -Id $p refused
Stop-Process -Id 26128 (literal) allowed

Refusal message:

Built-in safety gate requires approval: unbounded process termination can kill this or another Codewhale npm session's Node launcher; stop the owned server by PID or port instead

This also blocks the usual owned-process pattern, which is what the message recommends:

$proc = Start-Process node server.js -PassThru; Start-Sleep 3; Stop-Process -Id $proc.Id

It matters more because a process started with Start-Process inside one tool call is gone by the next call (it appears to be contained to the call), so an agent can't start a server in one call and stop it by a literal PID in the next. Start and stop have to happen in the same command, which in practice means holding the PID in a variable.

Expected: Stop-Process -Id $var should be allowed when $var comes from Start-Process -PassThru or the same port lookup the gate already accepts inline, or at least behave consistently with the inline form.

Steps to reproduce 复现步骤

  1. In a normal PowerShell tab, start any Node server on port 3999 (node server.js).
  2. In Codewhale (Full Access), ask it to run exactly:
    Stop-Process -Id (Get-NetTCPConnection -LocalPort 3999 -State Listen).OwningProcess
    → runs; the server stops.
  3. Restart the server, then ask it to run exactly:
    $p = (Get-NetTCPConnection -LocalPort 3999 -State Listen).OwningProcess; Stop-Process -Id $p
    → refused with the message above.

Codewhale version 版本

codewhale 0.10.1 (dev), built from source at af5fa5c

Where did it happen? 在哪里出现?

TUI (terminal interface)

Operating system 操作系统

Windows

How did you get Codewhale? 获取方式

Built from a git checkout

Provider and model 提供商和模型

deepseek / deepseek-v4-pro

Terminal and shell 终端

Windows Terminal + Windows PowerShell 5.1

codewhale doctor (optional)


Logs, screenshots, anything else (optional)

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingsecuritySecurity, isolation, permissions, or trust-boundary worktoolsTool execution, tool schemas, tool UX, and built-in tool behaviorwindowsWindows-specific behaviour

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions