{"record":{"id":"3838b337d6038d5d","repo":"Hmbown/CodeWhale","slug":"tool-name-cannot-prove-a-bounded-file-target-or-read-only","errorCode":null,"errorMessage":"Tool {name} cannot prove a bounded file target or read-only execution while peers are writing in this shared checkout (blocking peers: {}). Use a bounded write tool, a proven read-only command, or bash with read_only=true for analysis under native enforcement. Executable work that needs writes requires worktree isolation. Disjoint write_roots alone do not constrain arbitrary code.","messagePattern":"Tool (.+?) cannot prove a bounded file target or read-only execution while peers are writing in this shared checkout \\(blocking peers: (.+?)\\)\\. Use a bounded write tool, a proven read-only command, or bash with read_only=true for analysis under native enforcement\\. Executable work that needs writes requires worktree isolation\\. Disjoint write_roots alone do not constrain arbitrary code\\.","errorType":"exception","errorClass":"anyhow::Error","httpStatus":null,"severity":"error","filePath":"crates/tui/src/tools/subagent/mod.rs","lineNumber":17639,"sourceCode":"                                        ToolCapability::WritesFiles\n                                            | ToolCapability::ExecutesCode\n                                            | ToolCapability::Network\n                                    )\n                                })))\n                }))\n        {\n            let manager = self.coordination_manager.read().await;\n            // Only a *contended* shared checkout needs this gate. The claim\n            // exists so concurrent children cannot overwrite each other; a lone\n            // writer has no peer to collide with, and blocking it there bought\n            // no safety while making a builder unable to run ordinary shell\n            // work in the workspace the operator actually watches — worktree\n            // isolation \"fixes\" that by writing somewhere they never see.\n            if manager.shared_write_claim(&self.owner_agent_id).is_some() {\n                let blocking_peers =\n                    manager.live_peer_shared_write_claim_owners(&self.owner_agent_id);\n                if !blocking_peers.is_empty() {\n                    return Err(anyhow!(\n                        \"Tool {name} cannot prove a bounded file target or read-only execution while peers are writing in this shared checkout (blocking peers: {}). Use a bounded write tool, a proven read-only command, or bash with read_only=true for analysis under native enforcement. Executable work that needs writes requires worktree isolation. Disjoint write_roots alone do not constrain arbitrary code.\",\n                        blocking_peers.join(\", \")\n                    ));\n                }\n            }\n        }\n        let context = self\n            .registry\n            .context()\n            .clone()\n            .with_owner_agent(self.owner_agent_id.clone(), self.owner_agent_name.clone());\n        let observed_paths = if scope_aware_write {\n            mutation_paths(name, &input)?\n        } else {\n            Vec::new()\n        };\n        let outcome = self\n            .registry","sourceCodeStart":17621,"sourceCodeEnd":17657,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/433685b2024e7bc4c99e1e2e326bcad39b4d9d65/crates/tui/src/tools/subagent/mod.rs#L17621-L17657","documentation":"While another agent holds a shared write claim in the same checkout, a tool call from this sub-agent could not prove it is either a bounded file write or a read-only execution, and live blocking peers exist. The library refuses unverifiable operations under concurrent shared writes because disjoint write_roots cannot constrain arbitrary code execution; work that writes must use worktree isolation.","triggerScenarios":"A peer sub-agent holds a live shared write claim (`live_peer_shared_write_claim_owners` non-empty) and this agent invokes a tool (typically bash without read_only=true) that neither mutates a bounded path nor passes the read-only command proof.","commonSituations":"Multiple agents sharing one workspace checkout where one is editing while another runs arbitrary shell; running build/test commands with extra args during a peer's write session; write_roots configured expecting isolation that the enforcer does not trust for unbounded tools.","solutions":["Use a bounded write tool (which takes a scoped claim) instead of arbitrary execution.","Re-run the command as a provable read-only command, or set `read_only: true` on the bash input for pure analysis.","Wait for blocking peers to release their shared write claims, then retry.","Move write-needing executable work into an isolated worktree and re-dispatch there."],"exampleFix":"// before\n{\"tool\":\"bash\",\"input\":{\"command\":\"cargo test foo -- --nocapture\"}}\n// after (analysis under native enforcement)\n{\"tool\":\"bash\",\"input\":{\"command\":\"cargo test foo -- --nocapture\",\"read_only\":true}}","handlingStrategy":"validation","validationCode":"if coordination.live_peer_shared_write_claim_owners(me).len() > 0\n    && !is_bounded_write(name)\n    && !is_provably_readonly(name, &input)\n{\n    // defer or isolate before calling\n}","typeGuard":"fn safe_under_shared_writes(name: &str, input: &Value) -> bool {\n    is_bounded_write_tool(name)\n        || input.get(\"read_only\").and_then(Value::as_bool).unwrap_or(false)\n        || codewhale_execpolicy::command_safety::is_readonly_command(\n            input.get(\"command\").and_then(Value::as_str).unwrap_or(\"\"))\n}","tryCatchPattern":"match result {\n    Err(e) if e.to_string().contains(\"blocking peers:\") => {\n        // wait for peer claims to clear or retry with read_only=true\n    }\n    other => other?,\n}","preventionTips":["Check shared write claims before invoking non-bounded tools in shared checkouts.","Prefer bounded write tools or read_only=true bash during concurrent sessions.","Use worktree isolation for executable work that writes.","Do not rely on disjoint write_roots to sandbox arbitrary code."],"tags":["rust","subagent","concurrency","write-coordination"],"backgroundTag":"permission-denied","analyzedSha":"433685b2024e7bc4c99e1e2e326bcad39b4d9d65","analyzedAt":"2026-09-15T12:24:24.634Z","contentChangedAt":"2026-09-15T12:24:24.634Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}