fix(deslop-shared-libs): probe the audited repository with -C <repo>

A CI run probed safe-git from the session directory above the target repo, so
the capability probe never touched the repository and the run fell back to the
API without a local attempt. The probe (and any call from elsewhere) now names
the audited repository.
This commit is contained in:
garrytan committed 2026-09-30 18:52:14 +00:00
1 parent 271c14078b
commit 07b21ea133
4 files changed
+4 -4

No files matched your search

+1 -1
View File
@@ -72,7 +72,7 @@ changed after writing one.
protections and refuses reads that could run filters, drivers, hooks or protections and refuses reads that could run filters, drivers, hooks or
transports, naming the allowed forms. Never bypass a refusal with raw `git`. transports, naming the allowed forms. Never bypass a refusal with raw `git`.
`diff` takes exactly two explicit committed object IDs, then `--` and paths. `diff` takes exactly two explicit committed object IDs, then `--` and paths.
First probe with `~/.claude/skills/gstack/bin/gstack-safe-git rev-parse --is-inside-work-tree`; a Git First probe the audited repository with `~/.claude/skills/gstack/bin/gstack-safe-git -C <repo> rev-parse --is-inside-work-tree` (use `-C <repo>` on every call when your shell is elsewhere); a Git
version check alone is insufficient. If the probe fails (for example version check alone is insufficient. If the probe fails (for example
`unknown option: --no-lazy-fetch`), use pinned-commit GET API source `unknown option: --no-lazy-fetch`), use pinned-commit GET API source
and history reads or disclose unavailable local-history coverage. Never retry and history reads or disclose unavailable local-history coverage. Never retry
+1 -1
View File
@@ -66,7 +66,7 @@ changed after writing one.
protections and refuses reads that could run filters, drivers, hooks or protections and refuses reads that could run filters, drivers, hooks or
transports, naming the allowed forms. Never bypass a refusal with raw `git`. transports, naming the allowed forms. Never bypass a refusal with raw `git`.
`diff` takes exactly two explicit committed object IDs, then `--` and paths. `diff` takes exactly two explicit committed object IDs, then `--` and paths.
First probe with `{{SAFE_GIT}} rev-parse --is-inside-work-tree`; a Git First probe the audited repository with `{{SAFE_GIT}} -C <repo> rev-parse --is-inside-work-tree` (use `-C <repo>` on every call when your shell is elsewhere); a Git
version check alone is insufficient. If the probe fails (for example version check alone is insufficient. If the probe fails (for example
`unknown option: --no-lazy-fetch`), use pinned-commit GET API source `unknown option: --no-lazy-fetch`), use pinned-commit GET API source
and history reads or disclose unavailable local-history coverage. Never retry and history reads or disclose unavailable local-history coverage. Never retry
+1 -1
View File
@@ -36,7 +36,7 @@ describe('shared-code Git guard', () => {
installSourceShims(f); installSourceShims(f);
const instructions = fs.readFileSync(standaloneInstructions(f), 'utf8'); const instructions = fs.readFileSync(standaloneInstructions(f), 'utf8');
const helper = path.join(SHARED_LIBS_ROOT, 'bin/gstack-safe-git'); const helper = path.join(SHARED_LIBS_ROOT, 'bin/gstack-safe-git');
expect(instructions).toContain(`\`${helper} rev-parse --is-inside-work-tree\``); expect(instructions).toContain(`\`${helper} -C <repo> rev-parse --is-inside-work-tree\``);
expect(instructions).not.toContain('~/.claude/skills/gstack'); expect(instructions).not.toContain('~/.claude/skills/gstack');
const run = (command: string, args: string[]) => spawnSync(command, args, { const run = (command: string, args: string[]) => spawnSync(command, args, {
cwd: f.repo, encoding: 'utf8', timeout: 10_000, env: { ...process.env, ...f.env } }); cwd: f.repo, encoding: 'utf8', timeout: 10_000, env: { ...process.env, ...f.env } });
+1 -1
View File
@@ -56,7 +56,7 @@ describe('shared-code skill distribution', () => {
expect(standalone).toContain('Keep API responses and intermediate data on stdout or in memory'); expect(standalone).toContain('Keep API responses and intermediate data on stdout or in memory');
// Git safety is the installed helper from the trusted global runtime, not a retyped prefix. // Git safety is the installed helper from the trusted global runtime, not a retyped prefix.
const safeGit = `~/${host.globalRoot}/bin/gstack-safe-git`; const safeGit = `~/${host.globalRoot}/bin/gstack-safe-git`;
expect(standalone).toContain(`${safeGit} rev-parse --is-inside-work-tree`); expect(standalone).toContain(`${safeGit} -C <repo> rev-parse --is-inside-work-tree`);
expect(standalone).toContain(`${safeGit} ls-files --cached --others --exclude-standard -z`); expect(standalone).toContain(`${safeGit} ls-files --cached --others --exclude-standard -z`);
expect(standalone).toContain('never bare `git`'); expect(standalone).toContain('never bare `git`');
expect(standalone).not.toContain('git --no-pager'); expect(standalone).not.toContain('git --no-pager');