OpenRig v0.4.8 — Permission-posture fast-follow
OpenRig v0.4.8
Summary — Permission-posture fast-follow
Launch posture is configurable, the deny set writes at a level that project-local approvals can't override, and dangerous operations are gated by explicit prefix rules that actually hold under the current harness.
Migrations are additive only. Existing v0.4.7 databases upgrade by running rig daemon start on the new daemon.
What Shipped
Configurable launch posture
The hardcoded --permission-mode acceptEdits launch flag is replaced by a configurable posture defaulting to dontAsk. This closes the class of freezes where an autonomous seat could get stuck on a modal permission prompt with nobody to click through it. dontAsk is the default because it matches what an autonomous seat can actually respond to; acceptEdits remains selectable when a seat needs the prior behavior; a deliberate bypassPermissions value is preserved untouched across writes.
Deny set that project-local approvals can't override
The posture writes to user-level ~/.claude/settings.json instead of the project-local approval file. Deny wins over project-local approvals as a result. Writes are additive (never destructive to sibling keys) and forward-migrate a legacy acceptEdits value into the new schema. A deliberate bypassPermissions value is preserved.
Bounded-dangerous deny set
Four dangerous operations are gated by default: git push, gh pr create, npm publish, and rig down. rig down in particular is gated via the prefix rule Bash(rig down:*) — the current Claude harness (2.1.220) only supports prefix matches on Bash rules, and flag-only patterns provably don't gate target-first forms like rig down <rig> --force, so the prefix rule is the only shape that actually holds. Plain rig down is gated in v0.4.8; selective allowance (e.g. rig down <rig> for a specific target) is deferred to v0.5.0 server-side enforcement.
rig up un-gated
The prior release's ask-gate on rig up is removed — rig up is a reversible operation and doesn't warrant an interactive gate.
Permission-policy foundation (built-ins land in v0.5.0)
- Harness-neutral policy schema. The permission-policy spec is a harness-neutral surface with
default_posture,floor, andallow/ask/denyexpressed as semantic actions (push_to_remote,force_push,delete_files,read_secrets,create_pr,publish_package, and so on) rather than raw shell-command patterns. rig setup --policy <name>— a new flag onrig setuprecords a permission-policy choice into an existing rig spec. Takes a built-in name or a path to a custom policy file. The built-in policy files themselves land in v0.5.0; v0.4.8 ships the framework that consumes them.- Two surfaces. The launch-flag surface (Claude
--permission-mode, Codex sandbox / bypass flags, Pi--approve/--no-approve) is stable and set by OpenRig for you — this is where the floor and full-bypass YOLO live. The config-file surface (Claude~/.claude/settings.json, Codexconfig.toml) is where allow/ask/deny rules live; because harness rule grammars change frequently across versions, this surface is applied interactively by an agent-driven skill (that skill ships in v0.5.0 asapplying-a-permission-policy).
Deployment Note (operators read this)
For the posture writes to reach seats, the daemon's HOME must equal the seat's tmux HOME. This is a Claude 2.1.220 settings-path invariant that matters for the remote-host leg of any upgrade:
- On a local-only host, this is typically satisfied automatically.
- On a remote-host upgrade, verify HOME parity between the daemon process and the tmux seat process before treating the upgrade as complete.
(v0.5.0 documents this as a Known Issue for Codex HOME divergence; the product fix ships in v0.5.1.)
Superseded
An initial v0.4.8 attempt (with dontAsk baked as a platform default rather than an OpenRig-side default) was withdrawn on final review; the shipped v0.4.8 is a re-scoped permission-agnostic base plus a policy-spec system. Nothing from the withdrawn attempt shipped.
Behavior + Compatibility
- Migrations — additive only. Existing v0.4.7 databases upgrade by running
rig daemon starton the new daemon. - Default launch posture — changed from hardcoded
acceptEditsto configurable, defaultdontAsk. If a seat needs the prior behavior, selectacceptEditsexplicitly. - Deny-set write location — user-level
~/.claude/settings.json; the deny set wins over project-local approvals. Writes are additive. rig up— no longer ask-gated; reversible operations don't warrant interactive gates.