fix(guard): redirect only commands a task covers - #198
Merged
AbysmalBiscuit merged 2 commits intoSep 27, 2026
Merged
Conversation
A task claimed every typed command sharing its signature, which stops at the first flag. `test-doc` (`cargo test --doc --workspace`) claimed `cargo test -p X --test Y`, and `build` and `check` claimed every crate-scoped build and check, so agents could not run one crate. A bare word after `--` also dropped the signature, leaving `lint` unguarded. A typed command now redirects to a task only when each word it adds before `--` appears in the task's run, and its words after `--` equal the task's as a group. A task with nothing or a template past its signature keeps prefix matching. App launches keep prefix matching. Closes #195 Co-authored-by: Claude <noreply@anthropic.com>
Tasks tied on signature length fell through to name order, so `cargo build` named `build` over `build-release` only because it sorts first. Tasks with a `release` name ahead of the plain build would take it instead. Ties now go to the task whose run the typed command leaves the fewest words out of, before the app hint and name order are consulted. Co-authored-by: Claude <noreply@anthropic.com>
AbysmalBiscuit
deleted the
195-fix-guard-match-cargo-commands-by-their
branch
September 27, 2026 19:55
AbysmalBiscuit
added a commit
that referenced
this pull request
Sep 27, 2026
🤖 I have created a release *beep* *boop* --- ## [0.14.7](v0.14.6...v0.14.7) (2026-09-27) ### Features * **brief:** add a rules section ([#160](#160)) ([7ba41e2](7ba41e2)) * **brief:** list tasks by app and trim the brief ([#162](#162)) ([d991929](d991929)) * **command:** model permission changes ([#174](#174)) ([4aea742](4aea742)) * **config:** describe task args and variables ([#159](#159)) ([34e0076](34e0076)) * **docm:** treeless clones and per-library excludes ([#157](#157)) ([a4f4410](a4f4410)) * **forge:** support GitLab and Forgejo alongside GitHub ([#183](#183)) ([1926908](1926908)) * **harness:** claim bounded shell write sets ([#158](#158)) ([a72acf1](a72acf1)) * **hook:** parse Cursor and Antigravity payloads with pabal 0.2 ([#191](#191)) ([00e2918](00e2918)) * **hooks:** add before_worktree_remove ([#140](#140)) ([1ea3aed](1ea3aed)) * **issue:** add dashboard chart aggregation modes ([#144](#144)) ([61ad36a](61ad36a)) * **issue:** label the y-axis of dashboard charts ([#143](#143)) ([99e7b29](99e7b29)) * **issues:** create issues from enforced templates ([#185](#185)) ([3a38874](3a38874)) * **issue:** take the summary from the tracker ([#138](#138)) ([30425fb](30425fb)) * **rules:** add rules add, edit and remove ([#150](#150)) ([7052dd4](7052dd4)) * **rules:** honor repo-rules-agent.toml in query ([#151](#151)) ([e7a1d1f](e7a1d1f)) * **template:** render templates on demand ([#165](#165)) ([2da3c36](2da3c36)) * **templates:** add variable descriptions ([#152](#152)) ([918f594](918f594)) ### Bug Fixes * **command:** end the fresh-path exemption on placement ([#125](#125)) ([40ae328](40ae328)) * **common:** keep live blocks from climbing over output ([#141](#141)) ([2e2b919](2e2b919)) * **git:** fail fast when ssh needs a prompt ([#142](#142)) ([8fe7ae3](8fe7ae3)) * **guard:** note each unresolved command once ([#200](#200)) ([2bcd2fa](2bcd2fa)) * **guard:** redirect only commands a task covers ([#198](#198)) ([f6c0488](f6c0488)) * **hooks:** keep enforcement on past a broken layer ([#190](#190)) ([8846a35](8846a35)) * **issue:** allow setup --slug without an issue id ([#127](#127)) ([7c28ba7](7c28ba7)) * **issue:** dashboard spinners, x labels and status colors ([#149](#149)) ([b35e2ed](b35e2ed)) * **issue:** hold worktrees past their merged PR ([#189](#189)) ([a27a28b](a27a28b)) * **issue:** make status, info, end and MCP agree ([#193](#193)) ([cd9b46a](cd9b46a)) * **issue:** report ambiguous branch PRs in review finish ([#192](#192)) ([ff2cf62](ff2cf62)) * **locks:** free every root on release --all ([#199](#199)) ([d55ba01](d55ba01)) * **tasks:** refuse a blank required arg ([#173](#173)) ([d1b32b3](d1b32b3)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TL;DR (human written)
Closes #195
Agent summary
The command guard redirected crate-scoped cargo commands to whole-workspace tasks.
cargo test -p X --test Ywas denied as thetest-doctask, andcargo build -p Xandcargo check -p Xasbuildandcheck, so agents could not run one crate. Rawcargo clippy ... -- -D warningswent through unguarded, because the barewarningsafter--leftlintwith no signature.A typed command now redirects to a task only when it asks for nothing the task does not do: every word it adds before
--appears in the task'srun, and its words after--equal the task's as a group. A task with nothing or a template past its signature keeps prefix matching, sorun = ["vite"]and templated runs behave as before. App launches keep prefix matching, since a stricter match there would let unregistered servers start.Tasks tied on signature length now go to the one whose
runthe typed command leaves the fewest words out of, socargo buildnamesbuildoverbuild-releaseon the words rather than on name order.tests/harness_guard.rsdrives both sets of commands from the issue throughdevkit hook pre-tool-useagainst this repo's task shapes. The existing guard tests pass unchanged.A bare
cargo teststill redirects totest-doc: the matcher cannot tell--doc, which narrows what runs, from--locked, which does not. Fixing that needs a per-task key naming words the typed command must carry, left for its own issue.🤖 Generated with Claude Opus 5.5 via Claude Code