feat(task): grant scoped JS kernel tools to in-process children
Resolve tools names at spawn against the parent invocation's live kernelTools capability, normalize them with the MCP name rules, and reject duplicates, normalized collisions, reserved host aliases and undefined descriptors with typed errors before any child session exists. The grant is a TRANSIENT in-process ChildSpec field plus child tool wrappers: no closure, descriptor or requested name reaches SpawnSpecV1, the JSONL session_init or a task record. Only non-curated in-process children of a live JS worker parent receive it; curated read-only agents, process/team children, non-JS parents and children whose own tool policy narrows the parent surface get typed tools_unavailable/curated_policy_denied with no spawn. Each wrapper validates its fenced descriptor tuple and identity, then calls the live parent capability by name, returning typed errors on the CHILD's tool-result channel. Workpool create accepts the same names: only plain-data names persist, and the grant is re-resolved afresh at every new worker spawn.
Y
YeonGyu-Kim committed
5fbcb0d7f0ac8d31f224cbb8a1e3d4372c9d1873
Parent: 879a8b7