The first artifact database write shows which local file it reads and why approval is manual.
What's wrong with this entry?
The approval prompt for an artifact database write now shows the local file the document comes from, and lists reasons the automatic permission classifier cannot approve it: a path whose spelling can name a different file, a path resolving outside the allowed read paths, and a hard-linked source.
- The prompt no longer promises session-wide coverage when the write is not one that can be covered for the session.
the path\u2019s spelling can name a different file than it appears to \u2014 approval must come from the user, not the auto-permission classifier
Strings lifted out of the shipped bundle, so the claim above can be checked against them.