v16.24.0
What's Changed
Qwen Code: two more settings the qwencode permissions override can author
The qwencode override block in .rulesync/permissions.jsonc now authors two Qwen Code settings that previously had no canonical home and could not be written at all:
tools.listDirectory— the registry control that decides whether thelist_directorytool is registered at startup. It is the counterpart of thedisabled/visiblecontrols the override already carried. Added upstream in Qwen Code v0.22.0.tools.workflowsEnabled— enables the Workflow tool and the/workflowscommand.
Both round-trip: rulesync generate writes them into .qwen/settings.json (or ~/.qwen/settings.json), and rulesync import reads them back into the override.
Qwen settings are now written according to the scope that honors them
Qwen Code does not treat every setting the same way in a workspace file. Some are dropped before the merge, one is honored only while no higher scope sets it, and one decides trust for a scope other than the one it is written in. Writing all of them into .qwen/settings.json alike produced dead configuration in some cases and a misleading claim in others.
Each key the override authors now carries an explicit scope rule, and generation acts on it:
- Keys upstream strips from a workspace file (
tools.workflowsEnabled,security.allowPrivateNetworkHooks,security.allowedInsecureVoiceBaseUrls) are dropped from project-scoped output with a warning that names the key and says where to author it instead. - A write that changes what the settings file said is reported in either scope, naming the key, the value, and what that key decides there — so a
sandboxorapprovalModevalue that arrived with a cloned repository is visible rather than silent. - Grants are read the way Qwen Code reads them. It checks the booleans with plain truthiness, so
1, the string"false", and an empty array all turn them on and are all announced.security.allowedInsecureVoiceBaseUrlsis matched against instead, so an empty list grants nothing and stays quiet. rulesync importflags a scope-dependent key only when it actually read the project file, since a global file is a scope where those keys are honored.
The scope rules are exhaustive by construction: a new override key without a rule is a compile error, so the two directions cannot drift apart.
Every claim about upstream behavior in the code comments and in docs/reference/file-formats.md was checked against Qwen Code v0.23.0's own packages/cli/src/config/settingsUtils.ts, settingsSchema.ts, and settings.ts.