Repository navigation
Conversation
`HostRules` holds a host's rules, either deny/ask/allow lists or OpenCode's
ordered last-match-wins list, read from disk once. Every `rtk hook <agent>`
processor and `rtk hook check` decide through `decide_for_host`: the verdict
of the typed command, the shared decision, and, on a host that judges the
command its hook hands back (OpenCode), no rewrite whose verdict differs.
This replaces `load_rules_for` and the OpenCode branch in
`check_command_for_agent`.
`rtk hook check --agent opencode` now gives the plugin's answer: it reported
a rewrite the plugin skips, e.g. `git status` under
`{"*": "deny", "git status": "allow"}`.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
📊 Automated PR Analysis
SummaryIntroduces Review Checklist
Analyzed automatically by wshm · This is an automated analysis, not a human review. |
`rtk discover` kept its own deny/ask/allow struct for Claude Code's rules. It now holds the same `HostRules` the hooks load, still read once per run, and `load_permission_rules` is private to `permissions` again. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #4349.
Summary
permissions::HostRulesholds a host's rules, read from disk once: deny/ask/allow lists, or OpenCode's ordered last-match-wins list.HostRules::load(host, agent)replacesload_rules_forand the OpenCode branch incheck_command_for_agent; each host's arm also says whether that host judges the command its hook hands back.rtk hook <agent>processor andrtk hook checkdecide throughdecision::decide_for_host: the verdict of the typed command, the shared decision, and, on a host that judges the final command (OpenCode), no rewrite whose verdict differs. The rules are loaded once and the typed verdict is computed once.rtk hook check --agent opencodenow gives the plugin's answer. It printedrtk git status(exit 0) wherertk hook opencodeanswers{}, e.g.git statusunder{"*": "deny", "git status": "allow"},git push origin mainunder{"git push *": "ask"}.rtk discoverjudges transcript commands through the sameHostRules(Claude Code's, still read once per run) instead of its own deny/ask/allow struct.When the skip applies,
hook checkprints the genericNo rewrite for: <cmd>; saying that the rewrite would change the verdict could be a follow-up.Test plan
cargo fmt --all && cargo clippy --all-targets && cargo test --all(4169 passed)rtk rewrite,rtk hook opencodeandrtk hook checkfor all 18 agents, over 3 settings layouts × 9 commands (783 runs per side). The only difference ishook check --agent opencodeongit statusunder the [OpenCode] RTK rewrite breaks existing Bash permission allowlists by addingrtkbefore permission evaluation #4195 policy.rtk discover --allon a synthetic transcript gives the same report as develop (its group labels vary run to run on develop too).hook checkvs the plugin over 7 policies × 6 commands, each host reading its own rule file and no other, delegates reading Claude Code's rules and rules-file agents none, Claude Code keeping its rewrite beside anopencode.json.🤖 Generated with Claude Code