4 months ago
d9f0be7AgentControl.spawn never bounded the number of children a session could create, and the role schema's maxDepth/canSpawnChildren fields were defined but never read. A runaway or jailbroken root session could fork-bomb unbounded concurrent child sessions (each holding a binding + MCP loads), and any regression of the sessionKind==="agent" recursion guard had no backstop. Add two defense-in-depth caps enforced before any spawn work: - MAX_SPAWN_DEPTH, derived from the role definitions (no role permits a child to spawn, so depth is bounded to 1), rejecting recursive sub-delegation. - MAX_ACTIVE_CHILDREN_PER_PARENT (16), counting live non-closed child bindings. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Parent28b9854