fix(push-guard): single reader, whole-word dir tokens, payload fallback, bad-value banner
Run D2 of manual-push mode (BDR-114). - push-guard sources lib/gitflow.sh once (absolute path) and reads each candidate dir through gitflow_push_mode; a missing lib denies. - Dir tokens are extracted as whole shell words: a fully quoted token (inner apostrophe allowed) is resolved, a backslash-escaped space is unescaped deterministically, a token mixing quoted and unquoted parts is refused (fail closed) instead of resolving to its parent. - A payload jq cannot parse is scanned as raw text with its JSON escapes folded; a push-looking one gets the static deny through the trap. - The 20-token cap runs before any per-token classification (a flood of 20 000 tokens is refused in 0.13 s; T58 locks it under 5 s). - `case "$mode"` has a deny default; missing core tools warn and allow. - T42 compares the deny list against main (the last release) instead of HEAD; literal-true, mixed-token, broken-payload, lib-missing and banner-on-bad-value cases added (98 checks). - session-start banner reads the mode through the verb and shows `push : manual (autopush bad)` on an unparseable value. - tour hints quote "<abs project>".
This commit is contained in:
@@ -53,7 +53,6 @@ _gf_lib="$(dirname "${BASH_SOURCE[0]}")/../lib/gitflow.sh"
|
||||
if [ -f "$_gf_lib" ] && git rev-parse --is-inside-work-tree >/dev/null 2>&1; then
|
||||
GF_REFRESHED=$(bash "$_gf_lib" reconcile-hooks 2>/dev/null | sed -n 's/^gitflow hooks refreshed: *//p')
|
||||
fi
|
||||
unset _gf_lib
|
||||
|
||||
# ── graphify threshold signal (BDR-097) ──
|
||||
# Informs, never acts: one banner line when the repo holds ≥ 200 tracked code
|
||||
@@ -232,9 +231,12 @@ if [ -n "$GF_REFRESHED" ]; then
|
||||
fi
|
||||
# ── manual-push mode (BDR-111): one lock line when this repo never auto-pushes ──
|
||||
# %-46s, not 44: bash printf pads by BYTES and "—" is 3 bytes (2 extra).
|
||||
if [ "$(git config --bool --default true gitflow.autopush 2>/dev/null)" = false ]; then
|
||||
printf "│ 🔒 %-46s│\n" "push : manual (autopush=false) — ! git push"
|
||||
fi
|
||||
_pm=$( [ -r "$_gf_lib" ] && bash "$_gf_lib" push-mode 2>/dev/null )
|
||||
case "$_pm" in
|
||||
manual) printf "│ 🔒 %-46s│\n" "push : manual (autopush=false) — ! git push" ;;
|
||||
invalid) printf "│ 🔒 %-46s│\n" "push : manual (autopush bad) — ! git push" ;;
|
||||
esac
|
||||
unset _pm _gf_lib
|
||||
if [ -n "$GRAPHIFY_HINT" ]; then
|
||||
printf "│ 🕸️ %-44s│\n" "${GRAPHIFY_HINT:0:44}"
|
||||
printf "│ %-40s│\n" "→ /graphify (AST, seconds) — you decide"
|
||||
|
||||
Reference in New Issue
Block a user