mirror of
https://github.com/garrytan/gstack.git
synced 2026-10-04 02:16:56 +02:00
fix(deslop-shared-libs): probe the audited repository with -C <repo>
A CI run probed safe-git from the session directory above the target repo, so the capability probe never touched the repository and the run fell back to the API without a local attempt. The probe (and any call from elsewhere) now names the audited repository.
This commit is contained in:
1 parent
271c14078b
commit
07b21ea133
4 files changed
+4
-4
No files matched your search
@@ -72,7 +72,7 @@ changed after writing one.
|
|||||||
protections and refuses reads that could run filters, drivers, hooks or
|
protections and refuses reads that could run filters, drivers, hooks or
|
||||||
transports, naming the allowed forms. Never bypass a refusal with raw `git`.
|
transports, naming the allowed forms. Never bypass a refusal with raw `git`.
|
||||||
`diff` takes exactly two explicit committed object IDs, then `--` and paths.
|
`diff` takes exactly two explicit committed object IDs, then `--` and paths.
|
||||||
First probe with `~/.claude/skills/gstack/bin/gstack-safe-git rev-parse --is-inside-work-tree`; a Git
|
First probe the audited repository with `~/.claude/skills/gstack/bin/gstack-safe-git -C <repo> rev-parse --is-inside-work-tree` (use `-C <repo>` on every call when your shell is elsewhere); a Git
|
||||||
version check alone is insufficient. If the probe fails (for example
|
version check alone is insufficient. If the probe fails (for example
|
||||||
`unknown option: --no-lazy-fetch`), use pinned-commit GET API source
|
`unknown option: --no-lazy-fetch`), use pinned-commit GET API source
|
||||||
and history reads or disclose unavailable local-history coverage. Never retry
|
and history reads or disclose unavailable local-history coverage. Never retry
|
||||||
|
|||||||
@@ -66,7 +66,7 @@ changed after writing one.
|
|||||||
protections and refuses reads that could run filters, drivers, hooks or
|
protections and refuses reads that could run filters, drivers, hooks or
|
||||||
transports, naming the allowed forms. Never bypass a refusal with raw `git`.
|
transports, naming the allowed forms. Never bypass a refusal with raw `git`.
|
||||||
`diff` takes exactly two explicit committed object IDs, then `--` and paths.
|
`diff` takes exactly two explicit committed object IDs, then `--` and paths.
|
||||||
First probe with `{{SAFE_GIT}} rev-parse --is-inside-work-tree`; a Git
|
First probe the audited repository with `{{SAFE_GIT}} -C <repo> rev-parse --is-inside-work-tree` (use `-C <repo>` on every call when your shell is elsewhere); a Git
|
||||||
version check alone is insufficient. If the probe fails (for example
|
version check alone is insufficient. If the probe fails (for example
|
||||||
`unknown option: --no-lazy-fetch`), use pinned-commit GET API source
|
`unknown option: --no-lazy-fetch`), use pinned-commit GET API source
|
||||||
and history reads or disclose unavailable local-history coverage. Never retry
|
and history reads or disclose unavailable local-history coverage. Never retry
|
||||||
|
|||||||
@@ -36,7 +36,7 @@ describe('shared-code Git guard', () => {
|
|||||||
installSourceShims(f);
|
installSourceShims(f);
|
||||||
const instructions = fs.readFileSync(standaloneInstructions(f), 'utf8');
|
const instructions = fs.readFileSync(standaloneInstructions(f), 'utf8');
|
||||||
const helper = path.join(SHARED_LIBS_ROOT, 'bin/gstack-safe-git');
|
const helper = path.join(SHARED_LIBS_ROOT, 'bin/gstack-safe-git');
|
||||||
expect(instructions).toContain(`\`${helper} rev-parse --is-inside-work-tree\``);
|
expect(instructions).toContain(`\`${helper} -C <repo> rev-parse --is-inside-work-tree\``);
|
||||||
expect(instructions).not.toContain('~/.claude/skills/gstack');
|
expect(instructions).not.toContain('~/.claude/skills/gstack');
|
||||||
const run = (command: string, args: string[]) => spawnSync(command, args, {
|
const run = (command: string, args: string[]) => spawnSync(command, args, {
|
||||||
cwd: f.repo, encoding: 'utf8', timeout: 10_000, env: { ...process.env, ...f.env } });
|
cwd: f.repo, encoding: 'utf8', timeout: 10_000, env: { ...process.env, ...f.env } });
|
||||||
|
|||||||
@@ -56,7 +56,7 @@ describe('shared-code skill distribution', () => {
|
|||||||
expect(standalone).toContain('Keep API responses and intermediate data on stdout or in memory');
|
expect(standalone).toContain('Keep API responses and intermediate data on stdout or in memory');
|
||||||
// Git safety is the installed helper from the trusted global runtime, not a retyped prefix.
|
// Git safety is the installed helper from the trusted global runtime, not a retyped prefix.
|
||||||
const safeGit = `~/${host.globalRoot}/bin/gstack-safe-git`;
|
const safeGit = `~/${host.globalRoot}/bin/gstack-safe-git`;
|
||||||
expect(standalone).toContain(`${safeGit} rev-parse --is-inside-work-tree`);
|
expect(standalone).toContain(`${safeGit} -C <repo> rev-parse --is-inside-work-tree`);
|
||||||
expect(standalone).toContain(`${safeGit} ls-files --cached --others --exclude-standard -z`);
|
expect(standalone).toContain(`${safeGit} ls-files --cached --others --exclude-standard -z`);
|
||||||
expect(standalone).toContain('never bare `git`');
|
expect(standalone).toContain('never bare `git`');
|
||||||
expect(standalone).not.toContain('git --no-pager');
|
expect(standalone).not.toContain('git --no-pager');
|
||||||
|
|||||||
Reference in new issue
Block a user