Skip to content

Issue 297 guard dev server verdict - #303

Merged
slowdini merged 2 commits into
devfrom
issue-297-guard-dev-server-verdict
Sep 2, 2026
Merged

Issue 297 guard dev server verdict#303
slowdini merged 2 commits into
devfrom
issue-297-guard-dev-server-verdict

Conversation

@slowdini

@slowdini slowdini commented Sep 2, 2026

Copy link
Copy Markdown
Owner

Closes #297

classify_bash_with_policy returned only the first denial, so a command both
layers would block (e.g. npm run dev redirected outside the sandbox) reported
just the containment problem, and its actionable scratch hint sent the agent
to fix something that could never unblock the command. classify_bash_denials
now collects every applicable layer, and the arbiter renders one verdict that
names each blocking reason. Single-layer denials keep their exact historic
message; the two npm-install byte-pins (empty marker policy trips both the
package-install containment and the command policy) move to the combined
wording.
The packaged profile allowed install, CI, test, build, lint, and typecheck,
but not npm run dev — and framework/nextjs only activates on a next
dependency, so a plain Vite + React project (the pinned Weeknight fixture)
had no packaged way to start its own dev server during a guarded run. dev
and start are generic lifecycle script names, not Next.js-specific, so they
move into the language profile for npm, pnpm, Yarn, and Bun.
@slowdini
slowdini merged commit cdb3a6b into dev Sep 2, 2026
7 checks passed
@slowdini
slowdini deleted the issue-297-guard-dev-server-verdict branch September 2, 2026 00:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Guard: language/javascript blocks npm run dev, and the denial message sends the agent to fix the wrong thing

1 participant