feat(#630): retire blanket rm deny + aipass doctor migration
Phase 2 of #630. The rm_gate hook + drone rm now own destructive-delete protection (cross-provider, path-aware, teaching), so the Claude-only blanket deny is redundant AND harmful (it short-circuits before the hook, suppressing the teaching message). - setup.sh: removed Bash(rm -rf*) + Bash(rm -r *) from git_deny (new installs) - bootstrap.py: removed Bash(rm -rf *) shipped via aipass init (project settings) - doctor_wire.reconcile_stale_deny(): aipass doctor WARNs on stale rules; --fix removes them (idempotent, preserves all else) — migration for existing installs (the 'aipass update should be trusted' goal) - .aipass/project_hooks.json template: added rm_gate (new projects get it) Tests: 8 reconcile + 432 aipass total, seedgo 99%. CHANGELOG W23.
This commit is contained in:
@@ -606,7 +606,6 @@ git_deny = [
|
||||
"Bash(git push -f *)",
|
||||
"Bash(git rebase*)",
|
||||
"Bash(git clean*)",
|
||||
"Bash(rm -rf*)",
|
||||
"Bash(git reset*)",
|
||||
"Bash(git merge*)",
|
||||
"Bash(git config*)",
|
||||
@@ -617,7 +616,6 @@ git_deny = [
|
||||
"Bash(git branch -D*)",
|
||||
"Bash(git stash drop*)",
|
||||
"Bash(git stash clear*)",
|
||||
"Bash(rm -r *)",
|
||||
"Bash(git checkout -b*)",
|
||||
"Bash(git switch -c*)",
|
||||
"Bash(git switch --create*)",
|
||||
|
||||
Reference in New Issue
Block a user