From 03e729d1036631b8884f40d8bfd113e2a484ccd6 Mon Sep 17 00:00:00 2001 From: jochen Date: Sat, 3 Oct 2026 23:49:16 +0200 Subject: [PATCH] claude-code owns /etc/claude-code and ~/.claude as declared directories So the controller's ownership check refuses a second module owning either. ~/.claude is the operator's at 0700 (it was 0755 on the workstations); of what is inside, the module owns only what it writes, and the host keeps a directory that is not empty when the module goes (hq ADR 0182). --- modules/claude-code/README.md | 11 +++++++++++ modules/claude-code/module.json | 13 +++++++++++++ 2 files changed, 24 insertions(+) diff --git a/modules/claude-code/README.md b/modules/claude-code/README.md index 697d7a6..f4af228 100644 --- a/modules/claude-code/README.md +++ b/modules/claude-code/README.md @@ -3,6 +3,17 @@ The operator's agent on a machine (novox/hq design 36): its package, its machine-wide managed configuration, and the consumer side of the Anthropic licence manager (design 39, ADR 0183). +## What it owns + +Two directories, declared, so the mesh refuses a second module owning either: + +- `/etc/claude-code`, the agent's machine-wide managed directory, root's, `0755`. +- `~/.claude` under the operator account's home, the operator's, `0700`. The module owns the directory — + that it exists, who owns it, its mode — and of what is inside only what it writes. Everything else + in it (memory, history, projects, local settings, a person's own rules and skills) is the person's + and is never read or written (hq ADR 0182). Unassigned, the module leaves the directory: the host + removes a directory only when it is empty. + ## What it writes Under the agent's managed directory, `/etc/claude-code`, owned whole by this module and rewritten diff --git a/modules/claude-code/module.json b/modules/claude-code/module.json index 1d470a0..74eec69 100644 --- a/modules/claude-code/module.json +++ b/modules/claude-code/module.json @@ -24,6 +24,19 @@ "type": "package", "package": "claude-code" }, + { + "id": "managed", + "type": "directory", + "path": "/etc/claude-code", + "mode": "0755" + }, + { + "id": "agent-home", + "type": "directory", + "path": "${machine:account-home}/.claude", + "mode": "0700", + "owner": "${machine:account}" + }, { "id": "state", "type": "directory",