A Write(<path>) permission rule matches nothing. File permission checks consult only Edit(<path>) rules, which already cover every file-editing tool — Write, Edit and NotebookEdit alike. Claude Code now warns about the dead shape at session start. The Edit() rule directly above this one was doing the whole job, so the grammars were never unprotected and nothing changes here but the warning. Worth noting the general hazard though: a permission rule that silently matches nothing is indistinguishable from one that works, which is the same failure mode as the git prefix-pattern bypass. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
69 lines
1.7 KiB
JSON
69 lines
1.7 KiB
JSON
{
|
|
"permissions": {
|
|
"allow": [
|
|
"Skill(pql)",
|
|
"Skill(clide)",
|
|
"Skill(whats-next)",
|
|
"Skill(git-commit)",
|
|
"Bash(git add *)",
|
|
"Bash(git commit *)",
|
|
"Bash(git status *)",
|
|
"Bash(git diff *)",
|
|
"Bash(git log *)",
|
|
"Bash(git show *)",
|
|
"Bash(git branch *)",
|
|
"Bash(git checkout *)",
|
|
"Bash(git switch *)",
|
|
"Bash(git merge *)",
|
|
"Bash(git rebase *)",
|
|
"Bash(git stash *)",
|
|
"Bash(git fetch *)",
|
|
"Bash(git pull *)",
|
|
"Bash(git push *)",
|
|
"Bash(git tag *)",
|
|
"Bash(git remote *)",
|
|
"Bash(git rev-parse *)",
|
|
"Bash(git symbolic-ref *)",
|
|
"Bash(git ls-remote *)",
|
|
"Bash(git config *)",
|
|
"Bash(git blame *)",
|
|
"Bash(git shortlog *)",
|
|
"Bash(git cherry-pick *)",
|
|
"Bash(dart *)",
|
|
"Bash(flutter *)",
|
|
"Bash(make *)",
|
|
"Bash(pql)",
|
|
"Bash(pql *)",
|
|
"Bash(clide)",
|
|
"Bash(clide *)"
|
|
],
|
|
"deny": [
|
|
"Edit(//var/mnt/data/projects/treesitter/**)",
|
|
"Bash(rm -rf /*)",
|
|
"Bash(rm -rf ~*)",
|
|
"Bash(rm -rf $HOME*)",
|
|
"Bash(sudo rm *)",
|
|
"Bash(sudo chmod *)",
|
|
"Bash(sudo chown *)",
|
|
"Bash(mkfs*)",
|
|
"Bash(mkfs.*)",
|
|
"Bash(dd if=*)",
|
|
"Bash(git push --force*)",
|
|
"Bash(git push -f*)",
|
|
"Bash(git push --force-with-lease*)",
|
|
"Bash(git reset --hard*)",
|
|
"Bash(git clean -fd*)",
|
|
"Bash(git clean -fdx*)",
|
|
"Bash(git clean -ffd*)",
|
|
"Bash(git branch -D *)",
|
|
"Bash(git checkout -- *)",
|
|
"Bash(git restore .*)",
|
|
"Bash(chmod -R 777 *)",
|
|
"Bash(chmod 777 *)",
|
|
"Bash(git add -A*)",
|
|
"Bash(git add --all*)",
|
|
"Bash(git add .)"
|
|
]
|
|
}
|
|
}
|