Repository navigation
Conversation
- 权限预设:allow 收敛为 WebSearch,ask 精简并补齐 publish,deny 补齐 rm 变体、 refspec 强推、凭据导出命令与 gh/gcloud/git-credentials 路径 - 沙箱预设:新增 credentials(envVars/files 按 name/path 去重追加), excludedCommands 由 git * 细化为联网类 git 子命令及 gh/aws/gcloud/kubectl 等 - 常用选项新增 CLAUDE_CODE_SUBPROCESS_ENV_SCRUB,默认关闭,同步用户手册 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
推荐权限预设不再整体拒绝 Read(//etc/**),仅拒绝 shadow、gshadow 与 SSH 主机私钥, 避免沙箱内 git status 无法读取 /etc/gitconfig;推荐沙箱预设改为 git * 统一在沙箱外执行。 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- 权限预设:allow 清空为 [],ask 收敛到 11 条、deny 收敛到 34 条, 与 dotfiles 的 permissions 段逐条一致,移除项目自造的加固项 - 沙箱预设:credentials 补 ANTHROPIC_API_KEY、OPENAI_API_KEY, 移除 CLOUDSDK_PROXY_PASSWORD 与 ~/.npmrc - 沙箱预设:excludedCommands 由 git * 细化为 6 个联网类 git 子命令, 不再排除 aws/gcloud/kubectl/helm/ssh/scp - 沙箱预设:network 新增 allowedDomains,不再注入 allowUnixSockets - 同步 ProfileEditor 测试断言与 config-system 规则说明 Co-Authored-By: Claude Code <noreply@anthropic.com>
- 权限预设镜像 dotfiles 后 ask 只剩 11 条,与宽松模式的 43 条硬编码清单 零交集,开关触发时无可移动规则,已成空转 - 删除开关 UI、说明 Tooltip、清单常量与 helper 函数、中英 i18n 及测试用例 Co-Authored-By: Claude Code <noreply@anthropic.com>
- 顶层 effortLevel 是 schema 规范字段,Claude Code 的 /effort 会写入;编辑器此前 只读写 env.CLAUDE_CODE_EFFORT_LEVEL,配置卡片却按 env -> 供应商 -> 顶层回退, 于是卡片有值而编辑器显示「未设置」,保存后残留的顶层键还继续遮蔽新值 - 编辑器改为按同一顺序读取,并在写回 env 时清掉同义顶层键(选「未设置」同样清理) - 新增两条回归用例(显示与迁移、清空两层),config-system 规则补充两层存储约束 Co-Authored-By: Claude Code <noreply@anthropic.com>
- ask 移出 Read(**/.env)、Read(**/.env.*),收敛为 9 条发布类规则 - deny 新增 .env / .env.* 的读写拒绝,并以 ! 前缀 carve-out 放行 .env.example - 注释标注 ! 规则的顺序约束,避免调整时静默失效 Co-Authored-By: Claude Code <noreply@anthropic.com>
按 env、供应商默认、顶层设置的顺序判断值来源,避免固化时漏掉供应商努力级别。单字段编辑与批量操作统一清理同义顶层键,并补充更换供应商后的固化和恢复回归测试。
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
配置编辑器的推荐权限与沙箱预设对齐维护者 dotfiles,并修复努力级别显示、编辑与批量固化时两层设置不一致的问题。
Evidence
effortLevel: xhigh、供应商默认为max时,固化后更换供应商会回退到xhigh;恢复默认也会重新读到旧顶层值。两条回归用例在修复前均失败。After: 固化后仍显示并保存
max,恢复默认后两层覆盖均清理;编辑器与供应商默认操作的 88 个相关测试通过。make verify通过:Rust 格式、IPC 绑定、文档、前后端 lint、前端类型检查与构建、Rust 测试及全部 940 个前端测试。首次运行的本地 socket 权限失败在放开沙箱限制后通过。Merge Danger
Door: two-way
代码可以回退,无数据库或 IPC 契约变更。用户加载并保存推荐权限规则后,原规则会被替换;已有设置文件需通过配置备份或重新编辑恢复。
Blast Radius: 配置编辑器
影响推荐权限与沙箱配置、努力级别及其供应商默认操作。沙箱预设按追加合并保留已有条目;权限推荐预设不再默认放行原有命令。未验证真实 Claude Code 会话中的执行效果或桌面截图。