Skip to content

fix(policy): align file targets across approval checks - #6751

Merged
Hmbown merged 3 commits into
mainfrom
fix/bh-approval-and-path-policy-gates
Sep 29, 2026
Merged

Hmbown merged 3 commits into
mainfrom
fix/bh-approval-and-path-policy-gates

Conversation

@Hmbown

@Hmbown Hmbown commented Sep 29, 2026

Copy link
Copy Markdown
Owner

No-Issue: verified file-policy consistency findings

File tools accepted path aliases that policy checks did not consistently resolve. This change reuses the existing alias vocabulary in typed policy evaluation, execution preflight, repository holds and deletion review, so those checks inspect the same file targets as the executor. Conflicting aliases remain subject to the executor's existing refusal; calls that would write without a resolvable target are blocked before execution.

Restrictive typed rules remain effective when a target contains parent components. Allow matches keep their existing strict boundary. The implementation preserves the intended Full Access posture while still enforcing explicit deny rules and repository holds.

Validation on the final six-file source tree:

  • 19 focused Rust tests passed: 10 execpolicy and 9 TUI, 0 failed or ignored. The selected Linux-only case is reserved for hosted CI.
  • Coverage includes accepted aliases across the file tools, missing write targets, repository holds, deletion review, and real Engine fixture calls whose denied targets retain their original bytes.
  • npm test: 636 passed, 0 failed (68 + 16 + 50 + 502).
  • npm run check:web: passed, including the production web build.
  • Formatting, whitespace checks and independent source reviews passed.

The first web build rejected checkout-external dependency links; a retry using checkout-local dependencies passed with unchanged source. No Rust tests were repeated for that setup correction. Hosted CI remains required before merge. No provider call, deployment or release evidence is claimed.

Recovered the partial five-path Claude WIP from the stopped approval-and-path-policy-gates lane, with ownership handed over in the local support note. Preserve this checkpoint before further integration and repair.

UNVERIFIED recovery checkpoint: no qualifying tests, npm test, or check:web were run for this work. Only git diff --check passed. Not ready to push or merge.
…ath-policy-gates

Signed-off-by: Hunter B <hmbown@gmail.com>
Reuse the file tool alias vocabulary across typed rules, execution preflight, repository holds and deletion review. Keep restrictive rules effective for parent-component paths without widening allow matches, and refuse write calls without a resolvable target.

Validation: 19 focused Rust tests passed (10 execpolicy + 9 TUI), 0 failed or ignored; the selected Linux-only case remains for hosted CI. npm test 636 passed, 0 failed; check:web passed after replacing checkout-external dependency links rejected by Turbopack. Source was unchanged for that web-only retry. Formatting, whitespace and independent source reviews passed.
Signed-off-by: Hunter B <hmbown@gmail.com>
Copilot AI balanced review requested due to automatic review settings September 29, 2026 11:52

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@Hmbown
Hmbown merged commit 8b2aef7 into main Sep 29, 2026
35 checks passed
@Hmbown
Hmbown deleted the fix/bh-approval-and-path-policy-gates branch September 29, 2026 16:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants