mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-16 18:05:31 +02:00
The PR's hook exec'd the vendor binary with the full environment and passed its stdout to Claude verbatim. It is now the house pattern: a fail-open bash shim over a .ts twin that (1) gates on the memorable_recall consent key, (2) skips repos whose trust policy is deny or read-only, (3) scans the prompt (raw bytes and decoded string leaves) and refuses to hand over a HIGH-tier credential shape, (4) writes a fail-closed egress receipt naming the local executable it ran, (5) spawns the vendor in its own process group with an allowlisted environment and group-kills it on timeout, (6) accepts only a string additionalContext back, caps it at 8 KiB on a UTF-8 boundary and wraps it in the trust envelope, and (7) records an `output-written` outcome after the stdout write completes. One deadline clock (4.5 s) undercuts Claude Code's 5 s kill and bounds both ledger writes through the new lockBudgetMs option on writeReceipt/writeOutcome (default unchanged). spawn-bin gains runExternal for external executables (detached group, stderr drained, stdin EPIPE handled, stdout capped, win32 refused). The wiring test pins the sink fail-closed and sweeps hosts/. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
12 lines
527 B
Bash
Executable File
12 lines
527 B
Bash
Executable File
#!/usr/bin/env bash
|
|
# Bash shim — Claude Code hooks run `command` strings via /bin/sh, so this
|
|
# wrapper makes the TypeScript hook executable via bun. Settings.json
|
|
# references this file directly (registered by bin/gstack-memorable enable,
|
|
# never by ./setup).
|
|
#
|
|
# FAIL-OPEN: a third-party recall bridge must never block a prompt. Every
|
|
# failure path — bun missing, script crash — still exits 0 with empty stdout.
|
|
HERE="$(cd "$(dirname "$0")" && pwd)" || exit 0
|
|
bun "$HERE/memorable-user-prompt-hook.ts" || true
|
|
exit 0
|