Skip to content

Pre-approve crit + tailscale serve remote-review pattern - #41

Merged
technicalpickles merged 3 commits into
mainfrom
fix-crit-tailscale-classifier
Sep 15, 2026
Merged

technicalpickles merged 3 commits into
mainfrom
fix-crit-tailscale-classifier

Conversation

@technicalpickles

Copy link
Copy Markdown
Owner

Summary

  • Adds ~/.crit to sandbox allowWrite so crit's session lock writes don't hit EPERM.
  • Adds a crit stack pre-approving crit --public-url:* and tailscale serve:*, so the documented Tailscale remote-review recipe (loopback host + --public-url + --allow-unauthenticated-network + tailscale serve) doesn't need a fresh auto-mode confirmation every session.

This resurrects work from taskwarrior task 766057bb (UUID 766057bb-e506-4a30-a157-31c4091ee289), which was marked completed on 2026-09-01 but the actual commits (b45730e, 6de6bb5) were stranded on an unmerged branch and never reached main. Cherry-picked here with a conflict resolved in claude/roles/base.jsonc against the newer allowWrite list.

Test plan

  • npm run lint passes
  • ./claudeconfig.sh regenerates ~/.claude/settings.json and confirmed Bash(crit --public-url:*), Bash(tailscale serve:*), and ~/.crit allowWrite are present

technicalpickles and others added 2 commits September 15, 2026 08:44
crit writes its session lock under ~/.crit/sessions, which isn't in the
global sandbox allowWrite list. Every crit launch (tailscale or not) hit
a write denial and needed dangerouslyDisableSandbox as a retry, confirmed
via cq across 6 sessions with a 100% hit rate.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
crit's documented remote-review recipe (SKILL.md's tailscale block) launches
crit with --public-url + --allow-unauthenticated-network and proxies it with
tailscale serve. The auto-mode classifier flagged --allow-unauthenticated-network
as risky and forced a fresh confirmation every session, even though it's the
expected pattern (confirmed via cq across tailscale-review sessions).

Add explicit Bash allow rules for both commands so they don't need re-confirming
each time.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@technicalpickles
technicalpickles enabled auto-merge (squash) September 15, 2026 12:46
@technicalpickles
technicalpickles merged commit 1366982 into main Sep 15, 2026
1 check passed
@technicalpickles
technicalpickles deleted the fix-crit-tailscale-classifier branch September 15, 2026 12:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant