From 024f3e044bfd89ee226afc604fffac1c2005f7ec Mon Sep 17 00:00:00 2001 From: kshitij <82637225+kshitijk4poor@users.noreply.github.com> Date: Sun, 2 Aug 2026 19:45:15 +0530 Subject: [PATCH] docs(approval): _get_approval_config returns the live cache sub-dict Review follow-up on the #76194 salvage: the readonly swap makes this function leak the live config-cache 'approvals' sub-dict to callers. All current callers are read-only (audited); the docstring now carries the do-not-mutate contract for future ones. --- tools/approval.py | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/tools/approval.py b/tools/approval.py index 321eeed554..44fff7ace5 100644 --- a/tools/approval.py +++ b/tools/approval.py @@ -2601,7 +2601,11 @@ def _normalize_approval_mode(mode) -> str: def _get_approval_config() -> dict: - """Read the approvals config block. Returns a dict with 'mode', 'timeout', etc.""" + """Read the approvals config block. Returns a dict with 'mode', 'timeout', etc. + + Returns the LIVE config-cache sub-dict (load_config_readonly contract) — + callers must not mutate it or any nested structure. + """ try: from hermes_cli.config import load_config_readonly config = load_config_readonly()