docs(guardrails): document after-block continuation and PS over-blocks (#4236) - #4848
Merged
Merged
Conversation
…locks (#4236) README records that the dispatcher keeps running after a deny so a dual-blocked PowerShell sink prints both reasons, and documents the & $var two-positional write over-block and foreach { git } grouping rewrite. Stopping the chain at the first deny is declined. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…ter-block-readme-37e9 Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…to 0.39.3 The dispatcher keeps walking after exit 2 so a PowerShell fail-closed sink prints both block-no-verify and block-dangerous-git reasons. Stopping at the first deny is declined (#4236). Version sits above in-flight 0.39.2. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…ter-block-readme-37e9 # Conflicts: # plugins/guardrails/.claude-plugin/plugin.json # plugins/guardrails/CHANGELOG.md Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
The after-block continuation decision is kept; this Linux checkout cannot measure the PowerShell allow path. Point operators at RUN_GUARDS_PROFILE=1 on a Windows host. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
The purged-em-dash gate rejects that README line. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Release the after-block README as guardrails 0.40.0, one minor above main 0.39.2. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
4 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #4236
Summary
Document that the dispatcher keeps running after a deny, name the PowerShell over-blocks with the rewrite that already passes, and pin that a dual-blocked PowerShell sink prints both denials.
Fix
foreach { git … }(and other untokenizable{}/()grouping) into flatgit -C <path> …;statements; rewrite& $var script arg1 arg2as a quoted literal path or a flag-first call (& $sh -File …). Binding-to-literal relief remains guardrails:& $var script record dirblocked as a file write; block reason names the wrong cause #4234; grouping interrogation relief remains guardrails: read-only git inside {} blocked by two guards, with irrelevant commit guidance, Bash-lane advice, and no narrow lever #4235 / fix(guardrails): PowerShell read-only git grouping + ps-computed-positional (#4235) #4817 (open; this PR does not claim that relief).run-guards.test.shpinsInvoke-Command -ScriptBlock { git reset --hard }throughblock-no-verify+block-dangerous-gitand asserts bothblock_no_verify_enabledandblock_dangerous_git_enabledon stderr.Verification
PASS=311 FAIL=0, including
PS dual sink: block-no-verify reason is on stderrandPS dual sink: block-dangerous-git reason is on stderr too.Decision
Invoke-Command { git reset --hard }) is refused by bothblock-no-verifyandblock-dangerous-git. Ending the chain at the first deny would hide the second lever. The over-length ceiling (guardrails: Bash|PowerShell PreToolUse row takes 30+s on a ~70 KB command; its 60s timeout fails open #4528) remains the documented short-circuit.needs-human
RUN_GUARDS_PROFILE=1cost of the kept full chain on Git Bash PowerShell allow is unmeasured here.RUN_GUARDS_PROFILE=1on Windows Git Bash against the PowerShell allow path and compare to the README budget table.Related
& $var script record dirblocked as a file write; block reason names the wrong cause #4234 (computed-call literal binding).guardrails 0.39.3 (serialized above origin/main 0.38.13 and in-flight 0.39.2 on #4251).