18.0.0 (2026-06-29)
⚠ BREAKING CHANGES
- pi-permission-system: A permissions:rpc:check query for a
path/external_directory/ path-bearing surface now matches the canonical (symlink-resolved) alias, and apath/ path-bearing query now evaluates the supplied path instead of collapsing to*. - pi-permission-system: A service (
getPermissionsService().checkPermission) query for apath/external_directory/ path-bearing surface now matches the canonical (symlink-resolved) alias, and apath/ path-bearing query now evaluates the supplied path instead of collapsing to*. A symlinked path can now match a rule on its canonical target. - pi-permission-system: a per-tool path rule (e.g.
read: deny *.env) now also fires when a symlink's resolved target matches the pattern, where previously only the lexically-referenced spelling matched. A symlink alias can no longer evade a per-tool deny/allow.
Features
- pi-permission-system: match the canonical form on service path queries (be4a3e7)
- pi-permission-system: match the canonical form on the per-tool path gate (ad36e78)
- pi-permission-system: match the canonical form on the RPC check query (bb04ca5)