mirror of
https://github.com/garrytan/gstack.git
synced 2026-10-03 18:06:54 +02:00
fix(deslop-shared-libs): probe the audited repository with -C <repo>
A CI run probed safe-git from the session directory above the target repo, so the capability probe never touched the repository and the run fell back to the API without a local attempt. The probe (and any call from elsewhere) now names the audited repository.
This commit is contained in:
1 parent
271c14078b
commit
07b21ea133
4 files changed
+4
-4
No files matched your search
@@ -72,7 +72,7 @@ changed after writing one.
|
||||
protections and refuses reads that could run filters, drivers, hooks or
|
||||
transports, naming the allowed forms. Never bypass a refusal with raw `git`.
|
||||
`diff` takes exactly two explicit committed object IDs, then `--` and paths.
|
||||
First probe with `~/.claude/skills/gstack/bin/gstack-safe-git rev-parse --is-inside-work-tree`; a Git
|
||||
First probe the audited repository with `~/.claude/skills/gstack/bin/gstack-safe-git -C <repo> rev-parse --is-inside-work-tree` (use `-C <repo>` on every call when your shell is elsewhere); a Git
|
||||
version check alone is insufficient. If the probe fails (for example
|
||||
`unknown option: --no-lazy-fetch`), use pinned-commit GET API source
|
||||
and history reads or disclose unavailable local-history coverage. Never retry
|
||||
|
||||
@@ -66,7 +66,7 @@ changed after writing one.
|
||||
protections and refuses reads that could run filters, drivers, hooks or
|
||||
transports, naming the allowed forms. Never bypass a refusal with raw `git`.
|
||||
`diff` takes exactly two explicit committed object IDs, then `--` and paths.
|
||||
First probe with `{{SAFE_GIT}} rev-parse --is-inside-work-tree`; a Git
|
||||
First probe the audited repository with `{{SAFE_GIT}} -C <repo> rev-parse --is-inside-work-tree` (use `-C <repo>` on every call when your shell is elsewhere); a Git
|
||||
version check alone is insufficient. If the probe fails (for example
|
||||
`unknown option: --no-lazy-fetch`), use pinned-commit GET API source
|
||||
and history reads or disclose unavailable local-history coverage. Never retry
|
||||
|
||||
@@ -36,7 +36,7 @@ describe('shared-code Git guard', () => {
|
||||
installSourceShims(f);
|
||||
const instructions = fs.readFileSync(standaloneInstructions(f), 'utf8');
|
||||
const helper = path.join(SHARED_LIBS_ROOT, 'bin/gstack-safe-git');
|
||||
expect(instructions).toContain(`\`${helper} rev-parse --is-inside-work-tree\``);
|
||||
expect(instructions).toContain(`\`${helper} -C <repo> rev-parse --is-inside-work-tree\``);
|
||||
expect(instructions).not.toContain('~/.claude/skills/gstack');
|
||||
const run = (command: string, args: string[]) => spawnSync(command, args, {
|
||||
cwd: f.repo, encoding: 'utf8', timeout: 10_000, env: { ...process.env, ...f.env } });
|
||||
|
||||
@@ -56,7 +56,7 @@ describe('shared-code skill distribution', () => {
|
||||
expect(standalone).toContain('Keep API responses and intermediate data on stdout or in memory');
|
||||
// Git safety is the installed helper from the trusted global runtime, not a retyped prefix.
|
||||
const safeGit = `~/${host.globalRoot}/bin/gstack-safe-git`;
|
||||
expect(standalone).toContain(`${safeGit} rev-parse --is-inside-work-tree`);
|
||||
expect(standalone).toContain(`${safeGit} -C <repo> rev-parse --is-inside-work-tree`);
|
||||
expect(standalone).toContain(`${safeGit} ls-files --cached --others --exclude-standard -z`);
|
||||
expect(standalone).toContain('never bare `git`');
|
||||
expect(standalone).not.toContain('git --no-pager');
|
||||
|
||||
Reference in new issue
Block a user