feat(gitflow): hooks in every repo, no per-project step
Global: `make link` generates githooks/ from lib/gitflow.sh and sets git's global core.hooksPath to ~/.claude/githooks, so every repo on the machine runs the pre-commit protection and the post-commit / post-merge push, even one that never ran gitflow init. A repo's own local core.hooksPath still wins, so hooks/session-start.sh calls `gitflow reconcile-hooks` once per session and rewrites a .githooks/ that lags the lib (LRN-114 automated); the pre-commit exemption now covers .githooks/** next to .claude/**. Per-repo opt-outs for a foreign clone: `git config gitflow.protect false` (branch model) and `git config gitflow.autopush false` (push). Both, and the GIT_CONFIG_GLOBAL= / GIT_CONFIG= env bypass, are static deny rules. `make test` and the two suites that commit on main export GIT_CONFIG_GLOBAL=/dev/null so the machine's global hooks never fire in throwaway repos. doctor gains "Git hooks" (global setting, githooks/ equal to the emitters) and "Scratchpad" (warn when TMPDIR sits on a tmpfs with usrquota: systemd caps each user at 80% of it, which killed two shells today, BLK-021). Tests: T18h, T19d, T20 (reconcile), T21 (whitelist and protect opt-out); this repo's own stale .githooks/ refreshed.
This commit is contained in:
+11
-1
@@ -292,7 +292,17 @@
|
||||
"Bash(* | sh)",
|
||||
"Bash(* | sh -*)",
|
||||
"Bash(* | sudo *)",
|
||||
"Bash(chattr *)"
|
||||
"Bash(chattr *)",
|
||||
"Bash(GIT_CONFIG_GLOBAL=*)",
|
||||
"Bash(GIT_CONFIG_SYSTEM=*)",
|
||||
"Bash(GIT_CONFIG=*)",
|
||||
"Bash(env GIT_CONFIG*)",
|
||||
"Bash(git config --unset core.hooksPath*)",
|
||||
"Bash(git config --unset-all core.hooksPath*)",
|
||||
"Bash(git config --local core.hooksPath *)",
|
||||
"Bash(git config gitflow.*)",
|
||||
"Bash(git config --global gitflow.*)",
|
||||
"Bash(git config --local gitflow.*)"
|
||||
],
|
||||
"ask": [
|
||||
"Bash(bash -c *)",
|
||||
|
||||
Reference in New Issue
Block a user