mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-09 14:38:59 +02:00
Specialist army findings, all quote-verified before fixing:
Security: careful force-push guard now catches git's plus-refspec force
syntax (git push origin +main carried force with no flag — silently allowed
before) and refspec-form targets (HEAD:main); default-branch matching is
tokenized FIXED-STRING comparison on the full branch path (slashed defaults
like release/2.0 work; no ERE interpolation), glob-safe via noglob. HIGH rm
tier is tokenized too: trailing long options (--no-preserve-root) and /* are
root-class. Stored evidence fingerprints are 40-hex re-validated before
reaching git argv. normalizeForDetection sweeps ALL Unicode format chars
(\p{Cf}: soft hyphens, bidi marks, tag chars) instead of five enumerated
zero-widths. The wiring scanner gains flagless gh pr/issue view patterns. The
release-body banner tripwire diffs against the fetched original so a hostile
pre-existing banner string can't permanently DoS doc updates. Ship/land
evidence checks now pass --expect-cmd (a green `echo ok` recorded under the
label can never mint FRESH); package.json stays allow-listed with the
residual documented.
Performance: gstack-wtree seeds its temp index by COPYING the real index
(stat cache preserved — measured 40x faster than read-tree seeding, identical
hash) with read-tree fallback; evidence uses findLast and one gstack-slug
spawn; the stream pump honors backpressure via drain; careful's pattern block
short-circuits before slug resolution when no pattern file exists.
Testing: the gh-failure envelope test was VACUOUS (killing PATH killed the
bun shebang before the code under test ran) — replaced with a PATH gh shim
that exercises the real branch, plus shimmed happy paths (issue/pr-body/
unparseable JSON); evidence check --all + empty ledger + non-numeric
--max-age (now a usage error, was silent fail-open) covered; HIGH-tier
variants pinned; hook analytics respect GSTACK_HOME so tests stop writing the
operator's real skill-usage.jsonl.
Maintainability: dead exit ternary removed; flagValue deduped into
bin-context; sentinel defusal derived from the banner constants (no invisible
literals — \u escapes only); scratch-repo git fixture extracted to
test/helpers/scratch-repo.ts (one hermetic incantation, three consumers);
shared gstack_hook_log_fire in hook-extract.sh; the dashboard/land diff-scoped
row lists are aligned (codex-review) and drift-pinned.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
49 lines
2.3 KiB
Bash
Executable File
49 lines
2.3 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# gstack-wtree — print a working-tree CONTENT fingerprint (a git tree hash).
|
|
#
|
|
# Builds a temp index, stages the full working tree into it (`git add -A`, so
|
|
# .gitignore'd scratch stays out and UNTRACKED source is included), and prints
|
|
# `git write-tree` of that index. Properties that make this the right
|
|
# staleness fingerprint, vs `git rev-parse HEAD^{tree}`:
|
|
#
|
|
# - Committing identical content does NOT change the fingerprint, so a
|
|
# record made on a dirty tree stays valid after the exact same content is
|
|
# committed (the /ship Step 5 -> Step 16 case).
|
|
# - Untracked new source files DO change the fingerprint, so "tests passed"
|
|
# can't stay FRESH after a new file appears.
|
|
# - Rebase/amend/squash that preserve content do not change it.
|
|
#
|
|
# Performance: the temp index is seeded by COPYING the real index (git writes
|
|
# it atomically via rename, so the copy is a consistent snapshot). That
|
|
# preserves the stat cache, so `git add -A` only re-hashes files whose stat
|
|
# changed — measured 40x faster than a `read-tree HEAD` seed, which zeroes
|
|
# stat data and forces a full re-hash of every tracked file. Both seeds
|
|
# produce the identical write-tree hash. Fallback: `read-tree HEAD` when the
|
|
# index copy is unavailable (fresh repo, exotic index).
|
|
#
|
|
# The real repo index is never touched. Staged blobs land in the object store
|
|
# as unreachable objects and get gc'd like stash churn (note: this means the
|
|
# CONTENT of untracked, non-ignored files enters .git/objects until gc — the
|
|
# same property `git stash -u` has). Exit 1 outside a git repo or in a repo
|
|
# with no commits — callers treat that as "no fingerprint".
|
|
set -euo pipefail
|
|
|
|
TOP=$(git rev-parse --show-toplevel 2>/dev/null) || exit 1
|
|
TMPIDX=$(mktemp "${TMPDIR:-/tmp}/gstack-wtree-XXXXXX")
|
|
trap 'rm -f "$TMPIDX"' EXIT
|
|
export GIT_INDEX_FILE="$TMPIDX"
|
|
|
|
REAL_INDEX=$(git -C "$TOP" rev-parse --git-path index 2>/dev/null || true)
|
|
# Resolve relative --git-path output against the repo root.
|
|
case "$REAL_INDEX" in
|
|
""|/*) ;;
|
|
*) REAL_INDEX="$TOP/$REAL_INDEX" ;;
|
|
esac
|
|
if [ -n "$REAL_INDEX" ] && [ -f "$REAL_INDEX" ] && cp "$REAL_INDEX" "$TMPIDX" 2>/dev/null; then
|
|
: # stat-cache-preserving seed
|
|
else
|
|
git -C "$TOP" read-tree HEAD 2>/dev/null || exit 1
|
|
fi
|
|
git -C "$TOP" add -A 2>/dev/null || exit 1
|
|
git -C "$TOP" write-tree 2>/dev/null
|