CB-559: drop .claude/settings.local.json from the default parity overlay #29

Closed
agent wants to merge 0 commits from worker/parity-overlay-settings-5fb711-1 into main
Member

The parity overlay default copied .claude/settings.local.json (alongside the env files) from primary to worker worktree. That file pre-approves tools a worker must never hold and enables MCP servers by name. Its grants are currently INERT because GitWorktrees.isolateToolSurface neutralizes every worktree's .mcp.json to an empty server map, so defence in depth. An operator who explicitly lists it in parityOverlay: keeps it; only the default changes.

Tests: added parityOverlayDefaultsToEnvFilesOnly and parityOverlayExplicitListIsPreservedVerbatim (BridgedConfigTest), updated worktreeAcquireRunsParityOverlayWithProfileDefaults (WorktreeSessionManagerTest).

mvn clean install: Tests run: 637, Failures: 0, Errors: 0.

The parity overlay default copied `.claude/settings.local.json` (alongside the env files) from primary to worker worktree. That file pre-approves tools a worker must never hold and enables MCP servers by name. Its grants are currently INERT because GitWorktrees.isolateToolSurface neutralizes every worktree's .mcp.json to an empty server map, so defence in depth. An operator who explicitly lists it in `parityOverlay:` keeps it; only the default changes. Tests: added parityOverlayDefaultsToEnvFilesOnly and parityOverlayExplicitListIsPreservedVerbatim (BridgedConfigTest), updated worktreeAcquireRunsParityOverlayWithProfileDefaults (WorktreeSessionManagerTest). mvn clean install: Tests run: 637, Failures: 0, Errors: 0.
agent added 1 commit 2026-08-14 20:57:35 +02:00
CB-559: drop .claude/settings.local.json from the default parity overlay
CI / build (pull_request) Successful in 54s
CI / contract (pull_request) Successful in 1m7s
b414a74c26
Owner

Closing as landed. Verified with git cherry main <branch>: every commit's content is present in main. The branch tip is not an ancestor only because the commit was rebased before merge, so the SHA differs while the patch is identical. No code is lost. Verified 2026-08-15.

Closing as **landed**. Verified with `git cherry main <branch>`: every commit's content is present in `main`. The branch tip is not an ancestor only because the commit was rebased before merge, so the SHA differs while the patch is identical. No code is lost. Verified 2026-08-15.
ltms closed this pull request 2026-08-15 07:11:07 +02:00
Some checks are pending
CI / build (pull_request) Successful in 54s
CI / contract (pull_request) Successful in 1m7s

Pull request closed

Sign in to join this conversation.