summaryrefslogtreecommitdiff
path: root/constrain/vr-only-guard.sh
diff options
context:
space:
mode:
Diffstat (limited to 'constrain/vr-only-guard.sh')
-rwxr-xr-xconstrain/vr-only-guard.sh19
1 files changed, 0 insertions, 19 deletions
diff --git a/constrain/vr-only-guard.sh b/constrain/vr-only-guard.sh
deleted file mode 100755
index 0de698f..0000000
--- a/constrain/vr-only-guard.sh
+++ /dev/null
@@ -1,19 +0,0 @@
-#!/bin/sh
-# Claude Code PreToolUse hook (matcher: Bash): deny shell commands that read
-# files without going through vr. A guardrail, not a jail — it catches the
-# common readers at command position, not every conceivable bypass.
-cmd=$(jq -r '.tool_input.command // empty')
-
-readers='cat|head|tail|less|more|sed|awk|cut|rg|grep|egrep|fgrep|find|fd|strings|xxd|hexdump|od|tac|nl'
-pattern='(^|[;&|(`]|\$\()[[:space:]]*('$readers')([[:space:]]|$)'
-
-if printf '%s' "$cmd" | grep -qE "$pattern"; then
- echo "blocked: read/search files only through vr (run 'vr -doc' for usage)" >&2
- exit 2
-fi
-vcs='jj[[:space:]]+(file[[:space:]]+show|diff)|git[[:space:]]+(show|diff|grep|cat-file|blame|log)'
-if printf '%s' "$cmd" | grep -qE "(^|[;&|(\`])[[:space:]]*($vcs)"; then
- echo "blocked: use 'vr read -r REV FILE' / 'vr grep -r REV' instead of raw jj/git reads" >&2
- exit 2
-fi
-exit 0