You're offline — showing cached data

MC-4351

[auto-review] _profile_for_thread() only injects the safe settings file when runtime
2026-06-13 08:49:41 SAST
Home Board MC-4351

[auto-review] _profile_for_thread() only injects the safe settings file when runtime

**Severity:** high **Location:** chat_runtime.py:47 **Flagged by:** codex **Issue:** _profile_for_thread() only injects the safe settings file when runtime_settings does not al...
State Done Next Action Closed Owner Luci Runtime Closed Age 16d ago
MC-4351
Ticket is done; runtime is closed. · profile claude_opus_1m_medium · cwd /home/lucienne/workspace/mission-control · uptime 16d 4h · last activity 16d 2h ago

Description

MC-4351
**Severity:** high **Location:** chat_runtime.py:47 **Flagged by:** codex **Issue:** _profile_for_thread() only injects the safe settings file when runtime_settings does not already contain settings_file, allowing a chat/runtime setting to launch claude with an arbitrary or default settings file. That can violate the Telegram lock by enabling another getUpdates poller and killing CCGram. **Suggested fix:** For cli='claude', force the approved worker/orchestrator settings file regardless of thread runtime_settings, and reject any unapproved settings_file override during thread/profile validation. --- Found by mc-auto-review on 2026-05-28 06:08 SAST. Repos reviewed: mission-control. auto-review-hash: 967014a673bc

Activity

done
Luci is working...
Live
No activity yet
Help