Commit 8689e80
committed
chore(hooks): match guarded verbs in command position, not only at line start
Every blocking gate decided "is this the command I guard?" with a
LINE-START-anchored regex tolerating exactly one chained shape, an
optional leading `cd <path> &&`. So `git push` chained into a PR create
-- the natural way to push a branch and open its PR in one step -- did
not match and the gate never fired. Not hypothetical: that is how PR
1451's own PR-create slipped past verify-pr-gate.
The hole was in all six merge-time gates too, which is strictly worse:
those stand between an unverified destroy path and main. Chaining a
merge after any other command skipped integ-destroy, integ-broad,
integ-local, integ-schema-migration, pr-review and ci-green at once.
The anchoring was deliberate, not an oversight -- it kept a mention of
the verb inside a quoted argument from false-positiving into a hard
block. So this does not simply drop the anchor. It separates the two
concerns: strip the DATA spans (heredoc bodies, then quoted spans),
removing the false-positive source directly rather than dodging it by
position; then match the verb in command position -- line start OR
immediately after a `&&` / `||` / `;` / `|` operator.
Stripping heredoc bodies turned out to be required, not a refinement.
The first attempt at this commit was blocked by integ-broad-gate,
because the message describes the bug by naming the commands that
trigger it, and a heredoc body is not shell-quoted. Commit messages and
PR bodies routinely quote the commands they are about, so
prose-as-invocation is the common case rather than the exotic one.
A second, independent blind spot surfaced the same way: this commit
first landed as `fix(hooks):` with no src/** staged, which
commit-prefix-scope-gate exists to stop. It did not fire because it
parses `-F <path>` but not `-F -`, so a heredoc message resolved to a
nonexistent "<dir>/-", left the subject empty, and fell through. That
form is what commit-msg-heredoc-gate steers people toward, so it is the
common shape here. The gate now reads the subject out of the heredoc
body, and three cases pin it.
Fourteen matchers across thirteen hooks now share
.claude/hooks/lib/command-match.sh; restore-backup.sh uses the same
command-position prefix inline because it builds its regex from a
shared variable. The `cd <path> &&` special case disappears from the
patterns -- it is just a verb after an operator. Hooks needing the cd
TARGET still parse it from the raw command themselves.
Two existing smoke-test cases asserted the chained shape was an
"ACCEPTED FALSE-NEGATIVE" (branch-gate, pr-review-gate); both now
assert it is caught. verify-pr-gate gains five command-position cases,
including one proving a quoted mention after a chain operator still
passes -- the case where quote-stripping does the work, since position
alone no longer saves us. The shared matcher gets its own 22-case test
so a regression is reported once and precisely.
Verified: 32/32 hook smoke tests green (31 baseline + the new lib
test); reverting the helper to the line-start form fails 8 assertions.
Remaining non-goals, unchanged because the old anchor missed them too:
escaped quotes inside a quoted span, and an inner shell, which would
need real parsing.
Closes #14551 parent d4d0280 commit 8689e80
22 files changed
Lines changed: 401 additions & 41 deletions
File tree
- .claude
- hooks
- lib
- rules
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
25 | 31 | | |
26 | 32 | | |
27 | 33 | | |
| |||
75 | 81 | | |
76 | 82 | | |
77 | 83 | | |
78 | | - | |
| 84 | + | |
79 | 85 | | |
80 | 86 | | |
81 | 87 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
157 | 157 | | |
158 | 158 | | |
159 | 159 | | |
160 | | - | |
161 | | - | |
162 | | - | |
163 | | - | |
164 | | - | |
165 | | - | |
166 | | - | |
167 | | - | |
168 | | - | |
169 | | - | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
170 | 172 | | |
171 | 173 | | |
172 | 174 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
21 | 27 | | |
22 | 28 | | |
23 | 29 | | |
| |||
28 | 34 | | |
29 | 35 | | |
30 | 36 | | |
31 | | - | |
32 | | - | |
| 37 | + | |
| 38 | + | |
33 | 39 | | |
34 | | - | |
35 | | - | |
| 40 | + | |
| 41 | + | |
36 | 42 | | |
37 | 43 | | |
38 | 44 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
23 | 29 | | |
24 | 30 | | |
25 | 31 | | |
| |||
47 | 53 | | |
48 | 54 | | |
49 | 55 | | |
50 | | - | |
| 56 | + | |
51 | 57 | | |
52 | 58 | | |
53 | 59 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
32 | 38 | | |
33 | 39 | | |
34 | 40 | | |
| |||
38 | 44 | | |
39 | 45 | | |
40 | 46 | | |
41 | | - | |
| 47 | + | |
42 | 48 | | |
43 | 49 | | |
44 | 50 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
134 | 134 | | |
135 | 135 | | |
136 | 136 | | |
137 | | - | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
138 | 156 | | |
139 | 157 | | |
140 | 158 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
51 | 51 | | |
52 | 52 | | |
53 | 53 | | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
54 | 61 | | |
55 | 62 | | |
56 | 63 | | |
| |||
198 | 205 | | |
199 | 206 | | |
200 | 207 | | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
201 | 225 | | |
202 | 226 | | |
203 | 227 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
38 | 38 | | |
39 | 39 | | |
40 | 40 | | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
41 | 47 | | |
42 | 48 | | |
43 | 49 | | |
| |||
55 | 61 | | |
56 | 62 | | |
57 | 63 | | |
58 | | - | |
| 64 | + | |
59 | 65 | | |
60 | 66 | | |
61 | 67 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
26 | 32 | | |
27 | 33 | | |
28 | 34 | | |
| |||
41 | 47 | | |
42 | 48 | | |
43 | 49 | | |
44 | | - | |
| 50 | + | |
45 | 51 | | |
46 | 52 | | |
47 | 53 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
44 | 50 | | |
45 | 51 | | |
46 | 52 | | |
| |||
66 | 72 | | |
67 | 73 | | |
68 | 74 | | |
69 | | - | |
| 75 | + | |
| 76 | + | |
70 | 77 | | |
71 | 78 | | |
72 | 79 | | |
| |||
199 | 206 | | |
200 | 207 | | |
201 | 208 | | |
202 | | - | |
| 209 | + | |
203 | 210 | | |
204 | 211 | | |
205 | 212 | | |
| |||
0 commit comments