From 8c9904a7c486a87ba810b07cf28c02e7ddb3bb12 Mon Sep 17 00:00:00 2001 From: Dai Ha Date: Sat, 15 Aug 2026 13:57:18 +0200 Subject: [PATCH] Record that the classifier still blocks the daemon kill A CLAUDE.md rule grants intent, not tool permission. Tried the redeploy right after writing the section and the classifier refused `kill`, so the section would have been misleading as written. States the honest split until a Bash permission rule exists: the lead builds and verifies, the operator runs the stop and start with `!`. --- CLAUDE.md | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/CLAUDE.md b/CLAUDE.md index 76723eb..a56e09e 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -231,8 +231,12 @@ Five things to get right, each of which has gone wrong here before: `bridged/bridged.out`, dated after the restart. An old daemon that never died looks identical from the outside. -If a step is refused by the command classifier, do not try to route around it. Say what you were -going to run and why, and ask the operator to run it with `!`. +**Known blocker.** The command classifier refuses `kill` on the daemon, so step 2 cannot run by +default however clearly this file grants permission — a `CLAUDE.md` rule does not widen tool +permissions. Until the operator adds a Bash permission rule for it, the honest sequence is: the lead +builds the jar and verifies it, then asks the operator to run the stop and start with `!`. Do not try +to route around the refusal by other means. Say what you were going to run and why, and let the +operator decide. ### The prompt is part of the product — update it with the code (mandatory)