feat: analyze bundled permission grants - #429
Conversation
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
…ue-399-hook-surface Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
rng1995
left a comment
There was a problem hiding this comment.
[SkillSpector Review]
This draft is not yet code-reviewable for its stated BH3 permission-grant scope. PR #429 and dependency PR #404 currently point to the identical head commit (8cf3376), so the displayed 18k-line diff is entirely inherited BH1/BH2 work and there are no BH3-specific production or test changes to evaluate.
Before requesting re-review, please:
- Fast-forward/rebase this branch onto the final reviewed #404 head. #404 currently conflicts with
main, so resolve that dependency conflict first and propagate the resolved head here. - Add the BH3 implementation and its focused positive, negative, boundary, archive, ledger, scoring, output-format, and baseline regressions described in this PR.
- Isolate the stacked diff while #404 remains open—preferably by temporarily targeting #404's branch as this PR's base—so reviewers see only BH3 changes rather than re-reviewing the entire dependency.
- Align the documented Claude Code semantics snapshot: this PR description names 2.1.241, while the inherited README/design currently state 2.1.238.
No inline findings are attached because this head contains no #429-specific code. Please keep the PR in draft and ping for re-review after the BH3 delta is present and the dependency/base conflicts are resolved.
rng1995
left a comment
There was a problem hiding this comment.
Reviewed this head against #404. It is the exact same commit (8cf33768) and contains no permission-grant/BH3 implementation to review; the PR description also says production implementation has not started and depends on #404. I left the hook-flow findings on #404 to avoid duplicate inline threads. Please add the #429-specific implementation (and return this to draft until then), then re-request review.
rng1995
left a comment
There was a problem hiding this comment.
Requesting changes because this PR is marked ready for review but has no #429-specific implementation: its head is byte-for-byte identical to #404, and the PR description says production implementation has not started. Please return it to draft, add the permission-grant/BH3 delta after its dependency lands, and then re-request review. The hook-flow implementation findings remain on #404 to avoid duplicate threads.
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
|
Implementation checkpoint: the BH3 delta is now present and pushed through The existing changes-requested review targets old commit |
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
|
Powered by Codex: PR council review result. This is a triage signal, not a maintainer approval.
|
Signed-off-by: Narendran Raghavan <nraghavan@nvidia.com>
Signed-off-by: Narendran Raghavan <nraghavan@nvidia.com>
rng1995
left a comment
There was a problem hiding this comment.
[SkillSpector Review]
Re-review: the BH3 implementation is now present as an isolated permission-grant analyzer delta, the current-main conflict is resolved with the non-brittle README wording preserved, focused validation passed, and all required checks are green. Approved.
Pull request was converted to draft
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
bf5fd15 to
d2fcb8b
Compare
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Part of #399
Depends on #404 and contains that branch as an explicit merge parent. GitHub cannot select a fork-only head branch as this upstream PR base, so the displayed base remains
main; after #404 merges, this PR displayed diff collapses to the BH3-only delta below.Scope
This draft is the BH3-only follow-up for the project-settings portion of #399:
.claude/settings.jsonand.claude/settings.local.jsonsurfacespermissions.allow, root/homeadditionalDirectories, andpermissions.defaultModedeclarationsBH1/BH2 and shared analyzer wiring come from #404. The reviewable stacked delta is six files: 557 additions, 17 deletions.
Implementation
defaultMode: autois retained as LOW/ignored_by_surfaceon project/local settings, matching current documented behaviorrequires_settings_activationqualifierdisableAllHookstrustworthyVerification
bfef00f: 3,071 passed, 13 skipped, 38 deselected, 4 expected xfailsdisableAllHookssuppressed ordinary BH1/BH2 plugin-hook findings whileBash(*)still emitted only BH3, remained complete, scored 51/HIGH, recommendedDO_NOT_INSTALL, and exited 1requires_settings_activation--fail-on-incompleteexit contractorigin/main: both produced 30 passed, 2 skipped, 3 failed; the same two live-Codex model-resolution failures and graph/LLM telemetry expectation reproduce on mainautobehaviorDeliberate limits
The analyzer does not calculate
ask/denyprecedence, execute permission globs, emulate tool aliases, resolve marketplace policy, or claim final runtime activation. Live authenticated Claude/IDE/Desktop permission dispatch was not run because the local Claude environment is not authenticated.This PR remains draft for maintainer review.