The exit-0 branch emitted permissionDecision:allow, making rtk's internal
Rust registry a PARALLEL permission authority: a rewritten command
bypassed settings.json deny/ask entirely (audit #11). Both rewrite paths
now emit updatedInput only; the rewritten command goes through native
evaluation. Companion allow rules for read-only 'rtk <tool>' forms land
in settings.json (audit-hardening branch) to keep the safe majority
frictionless. Re-pinned.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
rtk lives at ~/.cargo/bin but the hand-managed .bashrc lost the cargo
line: command -v failed in hook AND tool shell, so the hook no-op'd with
a stderr warn on every Bash call — input compression silently OFF.
- Resolve RTK_BIN by probing known install dirs (LRN-036 class).
- Substitute the ABSOLUTE path at the rewrite head: a bare 'rtk …'
exits 127 in the tool shell, whose PATH the hook cannot fix (proven).
- Compound rewrites carrying further bare rtk segments pass through
unrewritten: quoted text (commit messages) makes a global substitution
unsafe — lose compression, never emit a command that 127s (proven:
a commit chain 127'd mid-flow).
- detect_rtk probes the same dirs so the banner reports capability.
- Re-pinned .rtk-hook.sha256: the rtk BINARY verifies the hook against
it at execution time and refuses a modified hook — the pin is live
machinery, not a vestige; coupling documented in the header.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR