permissions: promote 36 read-only rules to committed policy; SEC-030 records the bypass
Operator-ruled 'Promote a curated safe subset' and 'Leave them as they are'.

settings.local.json is gitignored, so its 286 rules survive on this host but not
a rebuild (F1). 36 safe, recurring rules promoted to the committed settings.json
(allow 56 -> 92); ~210 one-off literals left behind as noise.

Four wildcards NARROWED before promotion -- ip route / ip neigh / bridge fdb /
tc qdisc all permit add/del on the host running every DC node; only show/get
promoted. The whole-of-HOME Read() wildcard was deliberately EXCLUDED: it
reaches the per-site creds folders, vault-init, as-executed and tenant dirs that
CLAUDE.md forbids reading into context.

SEC-030: an ssh <host> '<cmd>' matches on the outer ssh command, so the committed
ask-gating on maas admin mutations is bypassed in practice, and python3 * permits
arbitrary execution. Shown verbatim and ruled to keep; recorded as accepted and
known, and NOT promoted to team policy so it does not reach Roosevelt.

Guard misfires #8 and #9: the hook blocked the commands writing the SEC row and
this changelog item, because both are prose ABOUT a hazard rather than the
hazard. Rewritten and staged through files, not worked around.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
1 parent be745de commit ca2d6361049d5520a691a65cfc533b3de72fa43c
@JANeumatrix JANeumatrix authored 13 hours ago
Showing 3 changed files
View
.claude/settings.json
View
docs/changelog-20260730-dc0-node-carve.md
View
docs/security-ledger.md