fix(policy): align file targets across approval checks - #6751
Merged
Merged
Conversation
Recovered the partial five-path Claude WIP from the stopped approval-and-path-policy-gates lane, with ownership handed over in the local support note. Preserve this checkpoint before further integration and repair. UNVERIFIED recovery checkpoint: no qualifying tests, npm test, or check:web were run for this work. Only git diff --check passed. Not ready to push or merge.
…ath-policy-gates Signed-off-by: Hunter B <hmbown@gmail.com>
Reuse the file tool alias vocabulary across typed rules, execution preflight, repository holds and deletion review. Keep restrictive rules effective for parent-component paths without widening allow matches, and refuse write calls without a resolvable target. Validation: 19 focused Rust tests passed (10 execpolicy + 9 TUI), 0 failed or ignored; the selected Linux-only case remains for hosted CI. npm test 636 passed, 0 failed; check:web passed after replacing checkout-external dependency links rejected by Turbopack. Source was unchanged for that web-only retry. Formatting, whitespace and independent source reviews passed. Signed-off-by: Hunter B <hmbown@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No-Issue: verified file-policy consistency findings
File tools accepted path aliases that policy checks did not consistently resolve. This change reuses the existing alias vocabulary in typed policy evaluation, execution preflight, repository holds and deletion review, so those checks inspect the same file targets as the executor. Conflicting aliases remain subject to the executor's existing refusal; calls that would write without a resolvable target are blocked before execution.
Restrictive typed rules remain effective when a target contains parent components. Allow matches keep their existing strict boundary. The implementation preserves the intended Full Access posture while still enforcing explicit deny rules and repository holds.
Validation on the final six-file source tree:
npm test: 636 passed, 0 failed (68 + 16 + 50 + 502).npm run check:web: passed, including the production web build.The first web build rejected checkout-external dependency links; a retry using checkout-local dependencies passed with unchanged source. No Rust tests were repeated for that setup correction. Hosted CI remains required before merge. No provider call, deployment or release evidence is claimed.