This commit is contained in:
@@ -0,0 +1,15 @@
|
|||||||
|
name: ci
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [main, develop]
|
||||||
|
pull_request:
|
||||||
|
branches: [main, develop]
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
test:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- uses: dtolnay/rust-toolchain@stable
|
||||||
|
- run: cargo test --all-features
|
||||||
|
- run: cargo build --release --features cli
|
||||||
@@ -38,6 +38,3 @@ predicates = "3.1"
|
|||||||
default = ["cli", "harness-claude"]
|
default = ["cli", "harness-claude"]
|
||||||
cli = ["dep:clap"]
|
cli = ["dep:clap"]
|
||||||
harness-claude = []
|
harness-claude = []
|
||||||
|
|
||||||
[lints]
|
|
||||||
workspace = true
|
|
||||||
|
|||||||
@@ -1,69 +1,37 @@
|
|||||||
# dirigent_fermata
|
# fermata
|
||||||
|
|
||||||
`𝄐 fermata` — a fast, harness-agnostic guard that blocks AI coding agents from reading, writing, or executing things they shouldn't.
|
`𝄐` — a fast, harness-agnostic policy gate for AI coding agents.
|
||||||
|
|
||||||
Reads `.botignore` (gitignore syntax) and an optional `botignore.toml` for advanced rules. Designed to be called from agent hooks, used as an MCP server (future), or consumed as a library.
|
Reads `.botignore` files (gitignore syntax) and an optional `botignore.toml`
|
||||||
|
to decide whether an agent's read / write / bash operation should proceed.
|
||||||
## Status
|
Designed to be called from agent hooks (Claude Code first; Codex and Gemini
|
||||||
|
planned).
|
||||||
v0.1 — first releasable slice:
|
|
||||||
- Library: `Op`, `Decision`, `Policy::check`, `Policy::check_command`, project-root walk-up, `.botignore` walker (via `ignore`), `botignore.toml` parsing, path identification heuristics.
|
|
||||||
- CLI: `fermata check <path>...`, `fermata hook --harness <name>`.
|
|
||||||
- Harness: Claude Code (PreToolUse) only.
|
|
||||||
|
|
||||||
Out of scope for v0.1: Codex, Gemini, MCP server, audit log, filesystem watcher.
|
|
||||||
|
|
||||||
## Install
|
## Install
|
||||||
|
|
||||||
From a published release (after `cargo publish`):
|
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cargo install dirigent_fermata
|
cargo install dirigent_fermata
|
||||||
```
|
```
|
||||||
|
|
||||||
From source (this monorepo):
|
## Usage
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cargo install --path crates/dirigent_fermata --features cli
|
fermata check --op read ./.env # exit 1 if blocked
|
||||||
|
fermata hook --harness claude < req.json
|
||||||
```
|
```
|
||||||
|
|
||||||
This installs the `fermata` binary into `~/.cargo/bin/`.
|
## About this repository
|
||||||
|
|
||||||
## Quick start
|
This is a downstream mirror. Fermata is developed inside the upstream
|
||||||
|
[Dirigent](https://git.g4b.org/dirigence/dirigent) monorepo and exported here
|
||||||
|
for distribution. Issues and pull requests are accepted on the `develop`
|
||||||
|
branch, but the canonical development branch is upstream.
|
||||||
|
|
||||||
```bash
|
## License
|
||||||
# As a CLI
|
|
||||||
fermata check --op read /path/to/.env
|
|
||||||
echo $? # 1 if blocked, 0 if allowed
|
|
||||||
|
|
||||||
# As a Claude Code hook
|
Licensed under either of
|
||||||
fermata hook --harness claude < hook_payload.json
|
|
||||||
```
|
|
||||||
|
|
||||||
## Configuration
|
- Apache License, Version 2.0 ([LICENSE-APACHE](LICENSE-APACHE))
|
||||||
|
- MIT License ([LICENSE-MIT](LICENSE-MIT))
|
||||||
|
|
||||||
`.botignore` (gitignore syntax, applies to read + write):
|
at your option.
|
||||||
```
|
|
||||||
.env
|
|
||||||
.env.*
|
|
||||||
secrets/**
|
|
||||||
```
|
|
||||||
|
|
||||||
`botignore.toml` (per-op rules):
|
|
||||||
```toml
|
|
||||||
[read]
|
|
||||||
patterns = [".env*", "secrets/**"]
|
|
||||||
|
|
||||||
[write]
|
|
||||||
patterns = ["vendor/**", "*.lock"]
|
|
||||||
|
|
||||||
[bash]
|
|
||||||
deny = ["rm -rf /", "git push --force*"]
|
|
||||||
ask = ["rm:*", "mv:*"]
|
|
||||||
allow_prefixes = ["make test", "git checkout:*"]
|
|
||||||
```
|
|
||||||
|
|
||||||
## See also
|
|
||||||
|
|
||||||
- `docs/tools/fermata.md` — Dirigent integration plan
|
|
||||||
- `docs/workpad/brainstorm/fermata.md` — full product spec
|
|
||||||
|
|||||||
Reference in New Issue
Block a user