Skip to content

Require general shell approval analysis - #1874

Merged
Aaronontheweb merged 1 commit into
devfrom
docs/generalize-shell-approval-policy
Aug 11, 2026
Merged

Require general shell approval analysis#1874
Aaronontheweb merged 1 commit into
devfrom
docs/generalize-shell-approval-policy

Conversation

@Aaronontheweb

Copy link
Copy Markdown
Collaborator

Summary

  • prohibit executable-specific parsing in Netclaw shell approval code
  • require general syntax, control-flow, value, path, and authority facts
  • keep unresolved input strict when ShellSyntaxTree lacks a general fact
  • preserve explicit safe-verb and hard-deny lists as policy data

This is a constitution-only change. No runtime code changed.

Prohibit executable-specific parsing in the Netclaw approval layer. Keep unresolved inputs strict when general shell facts are not available.
@Aaronontheweb
Aaronontheweb merged commit 64590e1 into dev Aug 11, 2026
18 checks passed
@Aaronontheweb
Aaronontheweb deleted the docs/generalize-shell-approval-policy branch August 11, 2026 16:09
@Aaronontheweb Aaronontheweb mentioned this pull request Aug 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant