diff --git a/plugins/disk-hygiene/.claude-plugin/plugin.json b/plugins/disk-hygiene/.claude-plugin/plugin.json index 4dce0c0fc8..11e4efce7d 100644 --- a/plugins/disk-hygiene/.claude-plugin/plugin.json +++ b/plugins/disk-hygiene/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json", "name": "disk-hygiene", - "version": "0.35.0", + "version": "0.35.1", "description": "Context-aware disk hygiene for arbitrary directory trees: inventories orphaned and temporary artifacts, classifies evidence into review tiers, and offers exact-path cleanup only after a fresh safety preview and explicit per-tier approval. The target is read-only by default; OS-managed paths, links and mount points, VCS-tracked content without the complete checkout evidence bundle, changed entries, and live-handle uncertainty fail closed.", "author": { "name": "Melodic Software", diff --git a/plugins/disk-hygiene/CHANGELOG.md b/plugins/disk-hygiene/CHANGELOG.md index 25374f7249..eb0e227d41 100644 --- a/plugins/disk-hygiene/CHANGELOG.md +++ b/plugins/disk-hygiene/CHANGELOG.md @@ -3,6 +3,16 @@ All notable changes to the `disk-hygiene` plugin are documented here. Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); this plugin uses semantic versioning. +## [0.35.1] - 2026-09-30 + +### Changed + +- **`safety-model.md` records how the `apply --execute` ask behaves under `bypassPermissions`** + ([#5609](https://github.com/melodic-software/claude-code-plugins/issues/5609)). A four-part + verification record states which modes were probed (headless default, `--bg` default, headless + `bypassPermissions`), which were not (interactive `bypassPermissions`, auto mode, the Windows + PowerShell tool), and what the official docs and upstream issues say. + ## [0.35.0] - 2026-09-30 ### Added diff --git a/plugins/disk-hygiene/skills/clean/reference/safety-model.md b/plugins/disk-hygiene/skills/clean/reference/safety-model.md index 81bfb54968..7f7b6828f0 100644 --- a/plugins/disk-hygiene/skills/clean/reference/safety-model.md +++ b/plugins/disk-hygiene/skills/clean/reference/safety-model.md @@ -639,6 +639,27 @@ semantics. The README states each surface in one table. The launch shape is asse `hooks/run-python-hook.test.sh` and `test_hygiene.py`, the no-interpreter posture by the former, and both are verified as step 1 of `/disk-hygiene:setup check`. +**Claim:** the guard's PreToolUse `ask` on `hygiene.py apply --execute` held in the three modes +probed. Headless default mode denied the call, `--bg` default mode parked at the permission prompt, +and headless `--permission-mode bypassPermissions` listed the call in `permission_denials`; in each +the target survived. Not probed: an interactive `bypassPermissions` session (where a person could +answer the prompt), auto mode against this guard, and the Windows PowerShell tool. **Basis:** the +probe table in and + +(Claude Code 2.1.285, Linux/WSL2, Bash tool, fresh scratch target). The official docs do not name a +hook `ask` under `bypassPermissions`: says +"Allow rules have no effect in `bypassPermissions`", and its "Actions no mode auto-approves" list +names "Tools matched by an explicit ask rule" and critical-path `rm` and `rmdir`, not a hook `ask`; + lists `permissionDecision` as allow/deny/ask/defer with no +statement about permission modes. Upstream +[anthropics/claude-code#37420](https://github.com/anthropics/claude-code/issues/37420) (a hook `ask` +resets bypass mode; closed as not planned 2026-04-20) and +[#79356](https://github.com/anthropics/claude-code/issues/79356) (a hook `ask` and `permissions.ask` +not enforced on the PowerShell tool in default mode; closed as not planned 2026-09-21) leave the +behavior undocumented. **As of:** 2026-09-30, both doc pages fetched that day. **Recheck:** a +Claude Code changelog entry that names PreToolUse `ask` or `bypassPermissions`, a change to the +"Actions no mode auto-approves" list, or the outcome of the unprobed-mode probes tracked in #5609. + A depth-limited scan records every directory it declined to enter in `truncated_paths`. Truncated directories have no captured descendant set, so the preview blocks them (and anything beneath them) as `truncated-not-inventoried`; they are coverage gaps, never candidates.