A Write(<path>) permission rule matches nothing. File permission checks
consult only Edit(<path>) rules, which already cover every file-editing
tool — Write, Edit and NotebookEdit alike. Claude Code now warns about
the dead shape at session start.
The Edit() rule directly above this one was doing the whole job, so the
grammars were never unprotected and nothing changes here but the
warning. Worth noting the general hazard though: a permission rule that
silently matches nothing is indistinguishable from one that works, which
is the same failure mode as the git prefix-pattern bypass.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Bash(awk *) traded a single permission prompt for an unbounded write
grant — awk writes files via print redirection, so the rule permitted
arbitrary filesystem writes under the guise of a text-processing tool.
Scripts that call awk internally are unaffected: permission rules match
the top-level command string only, so make targets and ci/test.sh keep
working. Only direct awk invocation now prompts. Shell glue needed more
than once belongs in a named make target that can be allowlisted for
what it actually does.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
tools/ts-wasm/build.sh compiles straight out of the working trees under
/var/mnt/data/projects/treesitter, so editing a grammar source or a
highlights query silently changes the wasm and native artefacts.
The divergence is invisible: treesitter is not itself a repo, so the
cross-repo status sweeps report it as "not a git repo" and never descend
into the ~49 sub-checkouts. A stray edit shows only in that one
checkout's git status, which nothing routinely reads, and survives until
someone re-clones.
Guards the plausible accident — hand-editing a grammar while chasing a
highlighting bug. It does not constrain Bash, so it is a guardrail
against silent divergence rather than a hard boundary.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Deny Bash(git add -A*), Bash(git add --all*), and Bash(git add .) so the
bulk-stage forms can't run; deny overrides the existing git add * allow. The
git-commit skill mandates specific-path staging, and a shared working tree
makes -A actively dangerous (it sweeps another agent's files into the commit).
Exact-match the bare dot rather than git add .* so git add .gitignore and
other dotfile paths still work.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The sidebar/dock filter fields (the shared ClideFilterBox) had no CLI
peer — a one-way, UI-only affordance that broke D-6 parity. Add the
drive+observe verb `clide ui filter <address> [<text>]`, routed entirely
through the kernel MessageBus pub/sub so a box reacts to a published
message identically whether the trigger was a UI keystroke or the CLI —
keeping extensions first-class (no dispatcher→widget wiring).
- ClideFilterBox gains an `address`; when set it listens on `filter.set`
for its address and republishes its value on `filter.state`. Null
address keeps the box a kernel-free UI widget.
- FilterStateCache (new kernel service) caches the latest `filter.state`
per address — the bus has no retention, so this backs the observe-half.
- ui.filter: with text → publishes `filter.set` (drive); without →
reads the cache (observe). Honest toolError when there is no live UI.
- Address every box: decisions/tickets/files/git/output/problems panes,
the four search boxes, and the pql search/query/markdown inputs.
Addresses are the ids from `clide pane list` (e.g. decisions.panel).
settings.json: allow the `clide` CLI + relevant skills.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Coverage parsing, lcov triage, and quick log scans use awk one-liners
constantly. Adding `Bash(awk *)` to the project allowlist removes
the permission prompt without weakening the deny rules.
Co-Authored-By: Claude <noreply@anthropic.com>
test / unit + widget + golden + a11y (push) Failing after 40s
test / integration_test (xvfb) (push) Has been skipped
test / bundle smoke (xvfb 5s) (push) Has been skipped
test / daemon subprocess + web WASM smoke (push) Has been skipped
PqlExtension contributes a sidebar tab (files, query, decisions,
tickets views) and a context-panel tab (backlinks + outlinks for
the active file, auto-refreshing on editor.active-changed).
ProblemsExtension contributes a sidebar tab aggregating pql.doctor
and decisions.sync diagnostics with actionable hints.
Both upgraded from stubs to 0.1.0.
Co-Authored-By: Claude <noreply@anthropic.com>
pql init --with-skill=yes installs .claude/skills/pql/SKILL.md
covering vault queries and the planning surface (decisions +
tickets). Lock file tracks version + SHA-256 for drift detection.
Bash(pql) and Bash(pql *) added to .claude/settings.json so
pql commands run without permission prompts.
Co-Authored-By: Claude <noreply@anthropic.com>
Go sidecar is retired (ADR 0005). The matching Claude-Code allow list
still permitted `go`, `golangci-lint`, `goreleaser`, `govulncheck`,
`npm` — none of which are used anymore. Narrow the allow list to the
commands that actually run in this project.
Co-Authored-By: Claude <noreply@anthropic.com>
Ports the patterns that crystallized during the short-lived claudian
plugin project (discarded in favour of this Flutter rebuild):
- ADRs 0001-0004 capture decisions that survive the host change —
CLI-first over MCP, Go for the sidecar, pql as a supporter tool
that becomes a clide-managed subsystem when present, and the
ignore-file strategy that wires all file-enumerating surfaces
through one knob in .pql/config.yaml.
- .claude/settings.json and the git-commit and skill-create skills
come over with naming updated for clide. The git-commit skill's
"no Conventional Commits" convention supersedes the Python-era
clide style under legacy/; the Keep-a-Changelog discipline and
the project.yaml-version-and-changelog-bumped-together rule
apply going forward.
- CHANGELOG.md starts fresh at the repo root to track the Flutter
rebuild. The Python changelog is preserved under legacy/.
.gitignore narrows from `.claude/` to just `.claude/settings.local.json`
so project-level config and skills travel with the repo.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>