Files
ISEP/docs/permissions-allow.json
claude-code fef35ed03a 出貨鏈三站上 main:release-ship 前置①改看 tag 的樹、release-check 可指定版本、信標開場報「打了 tag 沒 release」(inkstone/ISEP#67)
- hooks/lib/release_chain.py:問 Gitea 的判準一份三處用(匿名讀,D20)
- scripts/release-ship:前置①比「要建的那個 tag 的樹」裡的 plugin.json,不比工作樹/最新 tag
  (總管 09-07 在 v0.23.0 被擋的情境現在放行);note 從 Gitea compare 生,從 plugin 快取跑也行;
  覆核改跑 release-check <那個 tag>
- scripts/release-check [vX.Y.Z]:指定版本;v0.19/0.20/0.21 依裁決標「不補」不再黃字;補法印正本絕對路徑
- hooks/lib/beacon_report.py ④:最新 tag 沒 release/main 定版沒打 tag ⇒ 一行缺站+補法;都在安靜;
  只快取「都在」6 小時
- 測試:test-release-ship 14、test-release-check 14、信標 26→33;docs:TESTING A37/A38、盤點表、README 60 支腳本、
  白名單加 release-ship/release-check 形狀、mistakes 一條
- 沒改 plugin.json 版本號(待總管定版)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0178ef1fGw3XeZtpN7LaZrm4
2026-09-07 05:52:41 +00:00

46 lines
4.0 KiB
JSON
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
{
"_what": "Claude Code 權限白名單(permissions.allow)的唯一清單——本機與雲端都從這裡讀,不各養一份(inkstone/ISEP#130",
"_why": [
"leo 09-07 親手把四個 Gitea 正門工具(ticketmainlinegate-okgitea-pr-merge)加進本機 InkStoneCo/.claude/settings.jsonauto mode 的分類器才不擋。",
"雲端 session 沒有那四條,同樣的動作照樣被擋(09-04 progress-guard run logpermission_denials=6)。",
"薄殼 repoGitHub)要 D20 開閘才推得動 ⇒ 白名單住 ISEP`scripts/settings-allow-sync` 開工時寫進那台機器的 ~/.claude/settings.json。",
"以後加規則只改這個檔、出一版,雲端下一趟就有。",
"inkstone/ISEP#13709-07 雲端對 stage 的三種寫入(`npx wrangler secret put``stage-deploy-artifacts.py`curl POST 到 arcrun-yuga3bse)全被分類器擋——複合指令與任意 curl 對不上任何一條前綴。收成 `scripts/stage`secretapi 兩個子命令,只寫 stage、值只從環境變數名讀)四種形狀,外加 Arcrun 自己那支 `scripts/stage-deploy-artifacts.py`(它已寫死只認 youlin 帳號 ID、不收 --account--token)從 Arcrun repo 根目錄的相對形狀。不放 `Bash(npx *)``Bash(wrangler *)``Bash(curl *)`。",
"inkstone/ISEP#67SessionStart 信標印的補法是 `python3 <plugin root>/scripts/release-ship vX.Y.Z`——那一行在雲端要是被分類器擋,出路就走不通(閘的價值是「擋下來+給一條走得通的路」)。release-ship 只 POST 一件事(建 releasetag 與 release 名寫死從 Gitea 讀);release-check 純讀。"
],
"_rules": [
"開頭的 `~` 由 settings-allow-sync 換成那台機器的家目錄(本機 /Users/…、雲端 /root),其餘一字不改。",
"只放「正門工具」:每一條都要說得出它是哪支腳本的哪種呼叫形狀。不放 Bash(python3 *) 這種整類放行。",
"同一支工具幾種呼叫形狀就幾條(快取路徑/$CLAUDE_PLUGIN_ROOT/相對路徑)——權限規則是逐條完全比對,形狀差一個字就落在規則之外(scripts/gate-ok 檔頭記過這一課)。",
"別的 repo 的正門工具也可以進來(例 Arcrun 的 `scripts/stage-deploy-artifacts.py`),條件一樣:那支腳本自己把「只打哪台」寫死在程式裡,本清單放的是它從那個 repo 根目錄跑的相對形狀。"
],
"allow": [
"Bash(python3 ~/.claude/plugins/cache/inkstone/isep/*/scripts/ticket *)",
"Bash(python3 \"$CLAUDE_PLUGIN_ROOT/scripts/ticket\" *)",
"Bash(python3 \"$CLAUDE_PLUGIN_ROOT\"/scripts/ticket *)",
"Bash(python3 scripts/ticket *)",
"Bash(python3 ~/.claude/plugins/cache/inkstone/isep/*/scripts/mainline *)",
"Bash(python3 \"$CLAUDE_PLUGIN_ROOT/scripts/mainline\" *)",
"Bash(python3 \"$CLAUDE_PLUGIN_ROOT\"/scripts/mainline *)",
"Bash(python3 scripts/mainline *)",
"Bash(bash ~/.claude/plugins/cache/inkstone/isep/*/scripts/gate-ok *)",
"Bash(bash \"$CLAUDE_PLUGIN_ROOT/scripts/gate-ok\" *)",
"Bash(bash \"$CLAUDE_PLUGIN_ROOT\"/scripts/gate-ok *)",
"Bash(bash scripts/gate-ok *)",
"Bash(bash scripts/gitea-pr-merge.sh *)",
"Bash(python3 ~/.claude/plugins/cache/inkstone/isep/*/scripts/stage *)",
"Bash(python3 \"$CLAUDE_PLUGIN_ROOT/scripts/stage\" *)",
"Bash(python3 \"$CLAUDE_PLUGIN_ROOT\"/scripts/stage *)",
"Bash(python3 scripts/stage *)",
"Bash(python3 scripts/stage-deploy-artifacts.py *)",
"Bash(python3 ~/.claude/plugins/cache/inkstone/isep/*/scripts/release-ship *)",
"Bash(python3 \"$CLAUDE_PLUGIN_ROOT/scripts/release-ship\" *)",
"Bash(python3 \"$CLAUDE_PLUGIN_ROOT\"/scripts/release-ship *)",
"Bash(python3 scripts/release-ship *)",
"Bash(python3 ~/.claude/plugins/cache/inkstone/isep/*/scripts/release-check *)",
"Bash(python3 \"$CLAUDE_PLUGIN_ROOT/scripts/release-check\" *)",
"Bash(python3 \"$CLAUDE_PLUGIN_ROOT\"/scripts/release-check *)",
"Bash(python3 scripts/release-check *)"
]
}