Skip to content

docs(guardrails): document after-block continuation and PS over-blocks (#4236) - #4848

Merged
cursor[bot] merged 7 commits into
mainfrom
cursor/4236-guards-after-block-readme-37e9
Sep 28, 2026
Merged

cursor[bot] merged 7 commits into
mainfrom
cursor/4236-guards-after-block-readme-37e9

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Closes #4236

Summary

Document that the dispatcher keeps running after a deny, name the PowerShell over-blocks with the rewrite that already passes, and pin that a dual-blocked PowerShell sink prints both denials.

Fix

Verification

cd plugins/guardrails/hooks
bash run-guards.test.sh

PASS=311 FAIL=0, including PS dual sink: block-no-verify reason is on stderr and PS dual sink: block-dangerous-git reason is on stderr too.

Decision

needs-human

  • Claim: Windows RUN_GUARDS_PROFILE=1 cost of the kept full chain on Git Bash PowerShell allow is unmeasured here.
  • Basis: This environment is Linux CI. The issue's Windows profile numbers cannot be reproduced on this host.
  • As of: 2026-09-28
  • Recheck: run RUN_GUARDS_PROFILE=1 on Windows Git Bash against the PowerShell allow path and compare to the README budget table.

Related

guardrails 0.39.3 (serialized above origin/main 0.38.13 and in-flight 0.39.2 on #4251).

Open in Web Open in Cursor 

cursoragent and others added 6 commits September 28, 2026 03:19
…locks (#4236)

README records that the dispatcher keeps running after a deny so a
dual-blocked PowerShell sink prints both reasons, and documents the
& $var two-positional write over-block and foreach { git } grouping
rewrite. Stopping the chain at the first deny is declined.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…ter-block-readme-37e9

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…to 0.39.3

The dispatcher keeps walking after exit 2 so a PowerShell fail-closed
sink prints both block-no-verify and block-dangerous-git reasons.
Stopping at the first deny is declined (#4236). Version sits above
in-flight 0.39.2.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…ter-block-readme-37e9

# Conflicts:
#	plugins/guardrails/.claude-plugin/plugin.json
#	plugins/guardrails/CHANGELOG.md

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
The after-block continuation decision is kept; this Linux checkout cannot
measure the PowerShell allow path. Point operators at RUN_GUARDS_PROFILE=1
on a Windows host.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
The purged-em-dash gate rejects that README line.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
@cursor
cursor Bot marked this pull request as ready for review September 28, 2026 03:42
Release the after-block README as guardrails 0.40.0, one minor above main 0.39.2.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
@cursor
cursor Bot merged commit 121f387 into main Sep 28, 2026
19 checks passed
@cursor
cursor Bot deleted the cursor/4236-guards-after-block-readme-37e9 branch September 28, 2026 04:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

guardrails: all guards run after a block, and the README does not document the PowerShell over-blocks

2 participants