harness: say which settings file the exemption means
The exemption is Claude Code's permission list, not "settings files". khosra will have its own configuration and none of it is exempt: the engine's settings live in the site root and the engine validates them, while scripts/budgets.env and everything else under scripts/ and .claude/ stays gated. Verified by touching budgets.env and watching the coupling gate fail.
This commit is contained in:
+5
-2
@@ -76,8 +76,11 @@ if [ -d .git ] && command -v git >/dev/null 2>&1; then
|
||||
pass "templates/theme-contract coupling"
|
||||
fi
|
||||
|
||||
# settings.json is permissions, not mechanism — HARNESS.md calls it a convenience, so a tweak there
|
||||
# owes no explanation. Everything else under .claude/ changes how the machine behaves.
|
||||
# One exemption, and it is about the agent tooling rather than this project: .claude/settings.json is
|
||||
# Claude Code's own permission list, which HARNESS.md calls a convenience, so editing it explains
|
||||
# nothing about khosra. khosra's own configuration is not exempt from anything — the engine's settings
|
||||
# live in the site root (content-model.md) and the engine validates them itself. Everything else under
|
||||
# .claude/, and all of scripts/ including budgets.env, changes how the machine behaves and is gated.
|
||||
harnesschanged=$(echo "$changed" | grep -E '^(CLAUDE\.md$|scripts/|\.claude/)' | grep -v '^\.claude/settings\.json$' || true)
|
||||
if [ -n "$harnesschanged" ] && ! echo "$changed" | grep -qx 'HARNESS.md'; then
|
||||
bad "the harness changed (CLAUDE.md, scripts/ or .claude/) but HARNESS.md did not — the guide to the machine is part of the machine"
|
||||
|
||||
Reference in New Issue
Block a user