## Host-neutral runtime bindings These assignments select stable paths only; they do not install anything or grant consent: ```bash GSTACK_HOME="${GSTACK_HOME:-$HOME/.gstack}" GSTACK_ROOT="$GSTACK_HOME" GSTACK_STATE_ROOT="$GSTACK_HOME" GSTACK_BIN="$GSTACK_HOME/bin" BUN_CMD="$GSTACK_BIN/bun" B="$GSTACK_BIN/browse" D="$GSTACK_BIN/gstack-design" P="$GSTACK_BIN/make-pdf" ``` # $debug --mode Diagnose-only --module freeze — Restrict Edits to a Directory Lock file edits to a specific directory. Any Edit or Write operation targeting a file outside the allowed path will be **blocked** (not just warned). Canonical execution does not write engagement analytics or telemetry. ## Setup Ask the user which directory to restrict edits to. Use AskUserQuestion: - Question: "Which directory should I restrict edits to? Files outside this path will be blocked from editing." - Text input (not multiple choice) — the user types a path. Once the user provides a directory path: 1. Resolve it to an absolute path: ```bash FREEZE_DIR=$(cd "" 2>/dev/null && pwd) echo "$FREEZE_DIR" ``` 2. Ensure trailing slash and save to the freeze state file: ```bash FREEZE_DIR="${FREEZE_DIR%/}/" eval "$($GSTACK_BIN/gstack-paths)" STATE_DIR="$GSTACK_STATE_ROOT" mkdir -p "$STATE_DIR" echo "$FREEZE_DIR" > "$STATE_DIR/freeze-dir.txt" echo "Freeze boundary set: $FREEZE_DIR" ``` Tell the user: "Edits are now restricted to `/`. Any Edit or Write outside this directory will be blocked. To change the boundary, run `$debug --mode Diagnose-only --module freeze` again. To remove it, run `$debug --mode Diagnose-only --module unfreeze` or end the session." ## How it works The hook reads `file_path` from the Edit/Write tool input JSON, then checks whether the path starts with the freeze directory. If not, it returns `permissionDecision: "deny"` to block the operation. The freeze boundary persists for the session via the state file. The hook script reads it on every Edit/Write invocation. ## Notes - The trailing `/` on the freeze directory prevents `/src` from matching `/src-old` - Freeze applies to Edit and Write tools only — Read, Bash, Glob, Grep are unaffected - This prevents accidental edits, not a security boundary — Bash commands like `sed` can still modify files outside the boundary - To deactivate, run `$debug --mode Diagnose-only --module unfreeze` or end the conversation ## Upstream judgment port: PR #679 [Match the user language](https://github.com/garrytan/gstack/pull/679) ### User-language rule Write questions, progress updates, reports, and artifacts in the language used by the user. Source material, code identifiers, commands, and quotations may remain in their original language when translating them would reduce accuracy.