Repository navigation
Pin which repository surfaces Claude runs still load - #2073
Merged
Merged
Conversation
ppXD
force-pushed
the
fix/publish-agent-work-from-a-clean-repository
branch
from
October 6, 2026 16:30
81250ad to
0fa166e
Compare
ppXD
changed the base branch from
fix/publish-agent-work-from-a-clean-repository
to
main
October 6, 2026 16:30
ppXD
force-pushed
the
fix/pin-which-repository-surfaces-claude-runs-load
branch
from
October 6, 2026 16:30
f2e44f9 to
b9613a4
Compare
The settings pin (--setting-sources user, with the workspace added back as an --add-dir) was documented as loading .claude/rules and as leaving a subdirectory's CLAUDE.md no route. Against Claude 2.1.263 only rules without a paths: frontmatter load from an added directory, and an --add-dir naming a subdirectory does load its memory in place. The sealed-egress note also claimed the runner writes no settings.json, which is false for an acceptance-bearing run's Stop hook; the CLI layers --settings over that file, so the hook still runs. A non-root arm now pins that: an acceptance-bearing Allowlist run's own Stop hook must leave its marker, with --settings on the argv. The E2E only checked that each repository's CLAUDE.md reached the model, so nothing would catch a CLI release that starts loading what the pin drops or stops loading what it keeps. Each Claude arm now plants both sides. .claude/CLAUDE.md, an unscoped rule and an in-repository @import must be in the first request. A skill, a command, an agent, CLAUDE.local.md, a paths:-scoped rule, sub/CLAUDE.md and a repository output style must reach no request, run none of their commands and stay off the init line, after the scripted model has read sub/notes.txt, invoked the skill and the command and delegated to the agent. The scoped rule and sub/CLAUDE.md attach only once that Read happens, so each repository's sub/notes.txt must come back to the model as a tool result. The scripted model gains named Claude tool calls, and refuses with a 400 any call the request does not offer, so a renamed tool fails the run at once. The Codex arm pins that a repository skill's openai.yaml MCP dependency is never started. Dropping --setting-sources (with the hijacking env left out so the run still reaches its broker) fails every drop assertion in the single-repo arms, and in the multi-repo arm the skill, command, agent, CLAUDE.local.md, scoped-rule and sub/CLAUDE.md ones: 2.1.263 reads no settings from a repository below a multi-repo cwd, so that arm's settings checks guard a later CLI. Dropping the add-dir memory switch fails every kept one.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ClaudeCodeHarnessdoc comments on what the--setting-sources userpin keeps under Claude 2.1.263:.claude/rulesfiles without apaths:frontmatter load from an--add-dir.--add-dirnaming a subdirectory loads that subdirectory's memory in place.--settingsflag is applied on top of the in-loop Stop hook'ssettings.jsonin the config home; it does not replace it.RepositoryConfigE2ETests:CLAUDE.md, the in-repo file it@-imports,.claude/CLAUDE.md, and a rule withoutpaths:.initline: a skill, a command, an agent,CLAUDE.local.md, apaths:-scoped rule,sub/CLAUDE.mdand a repository output style.sub/notes.txtto come back as a tool result, because the scoped rule andsub/CLAUDE.mdattach only after that Read.ScriptedModelUpstreamrefuses with a 400 any call the request does not offer, so a renamed CLI tool fails the run at once.--settings {"skipWebFetchPreflight":true}, must still run the platform's own Stop hook.ProductionSpecnow applies the executor's egress step, which is a no-op for Full egress.agents/openai.yamlMCP dependency is never started.Test plan
RepositoryConfigE2ETestsarms, the Standard single-repo arm and the new Stop-hook arm (7/7)app.txtfails both Claude arms on the new fixture checkTaskcall fails in 2 s withAPI Error: 400 The CLI offered no Task tool…settings.jsonof{}fails the new arm on its markerdotnet build CodeSpace.sln: 0 errors[repo-config-e2e] ran non-root claude-code own-stop-hook sealed-egress Standard uid=1654 confined=True