lib/deploy-commit.sh: a rejected `git commit` (pre-commit hook, protected branch, signing failure) now exits 6 (loud stderr, distinct from rc 1's "nothing to do") instead of sharing rc 1 with the no-op cases. Header comment documents the full 0/1/2/3/4/5/6 taxonomy. Closes J4-22 (UNTESTABLE): at client repos, a failed deploy-state commit was indistinguishable BY EXIT CODE from "nothing to do" (rc 1 was shared 3 ways); exit-code-only callers couldn't disambiguate (stderr-parsing callers already could). Caller census (per report's explicit gate): skills/deploy/SKILL.md documents and parses this exit-code contract in TWO places (bootstrap commit + incident-recovery commit). Flagged to the user before committing; confirmed GO to add rc 6 there too (additive — no existing code's meaning changes) so the documented contract stays accurate for live deploy runs. New T10 in lib/tests/deploy-commit.test.sh (+3 assertions, 13→16): rejecting pre-commit hook sandbox — asserts rc 6, empty stdout (no stale hash), HEAD unmoved. GREEN: full `make test` exit 0 (deploy-commit 16/16 incl. T10). shellcheck clean, bash -n clean.
87 lines
4.0 KiB
Bash
87 lines
4.0 KiB
Bash
#!/usr/bin/env bash
|
|
# deploy-commit.sh — surgical commit for the .claude/deploy/ runbook family.
|
|
# Allowlist scope = .claude/deploy/ ONLY (inverse of doc-commit's .claude exclusion).
|
|
#
|
|
# Exit code taxonomy:
|
|
# 0 committed (short-hash on stdout), or `pending`: something changed
|
|
# 1 no-op — nothing staged/changed (`pending`: clean) — NOT a failure
|
|
# 2 usage error, or not a git repo
|
|
# 3 unsafe git state (detached HEAD / merge / rebase in progress)
|
|
# 4 a passed path is outside the .claude/deploy/ allowlist
|
|
# 5 a passed path is git-ignored and would not persist
|
|
# 6 `git commit` itself was REJECTED (pre-commit hook, protected branch,
|
|
# signing failure, …) — distinct from rc 1 (no-op): here something WAS
|
|
# staged and git refused it. Client repos may parse this by exit code,
|
|
# not just stderr, so it can't share rc 1's "nothing to do" (J4-22).
|
|
set -uo pipefail
|
|
|
|
_in_git_repo() { git rev-parse --git-dir >/dev/null 2>&1; }
|
|
|
|
_unsafe_state() { # 0 = unsafe
|
|
local g; g=$(git rev-parse --git-dir 2>/dev/null) || return 0
|
|
git symbolic-ref -q HEAD >/dev/null 2>&1 || return 0 # detached HEAD
|
|
[ -e "$g/MERGE_HEAD" ] || [ -d "$g/rebase-merge" ] || \
|
|
[ -d "$g/rebase-apply" ] || [ -e "$g/CHERRY_PICK_HEAD" ] && return 0
|
|
return 1
|
|
}
|
|
|
|
_out_of_scope() { # 0 = forbidden, 1 = in scope
|
|
case "$1" in
|
|
*..*) return 0 ;; # traversal — forbidden FIRST
|
|
.claude/deploy/*) return 1 ;; # allowed
|
|
*) return 0 ;; # everything else forbidden
|
|
esac
|
|
}
|
|
|
|
_scope_violations() { local p; for p in "$@"; do _out_of_scope "$p" && printf '%s\n' "$p"; done; }
|
|
|
|
_ignored() { git check-ignore -q "$1"; } # rc 0 = ignored
|
|
|
|
_changed_only() { # echo passed files that actually have changes
|
|
local p; for p in "$@"; do
|
|
[ -n "$(git status --porcelain -- "$p" 2>/dev/null)" ] && printf '%s\n' "$p"; done
|
|
}
|
|
|
|
cmd="${1:-}"; shift || true
|
|
_in_git_repo || { echo "deploy-commit: not a git repo" >&2; exit 2; }
|
|
|
|
case "$cmd" in
|
|
pending)
|
|
[ "$#" -gt 0 ] || { echo "deploy-commit: pending needs file args" >&2; exit 2; }
|
|
mapfile -t violations < <(_scope_violations "$@")
|
|
if [ "${#violations[@]}" -gt 0 ]; then
|
|
{ echo "deploy-commit: REFUSED — path(s) outside .claude/deploy/ allowlist:";
|
|
printf ' - %s\n' "${violations[@]}";
|
|
echo "deploy-commit: NOTHING committed. Caller must pass only .claude/deploy/ files."; } >&2
|
|
exit 4
|
|
fi
|
|
[ -n "$(_changed_only "$@")" ] && exit 0 || exit 1 ;;
|
|
commit)
|
|
msg="${1:-}"; shift || true
|
|
[ -n "$msg" ] && [ "$#" -gt 0 ] || { echo "deploy-commit: commit needs <msg> <file>..." >&2; exit 2; }
|
|
mapfile -t violations < <(_scope_violations "$@")
|
|
if [ "${#violations[@]}" -gt 0 ]; then
|
|
{ echo "deploy-commit: REFUSED — path(s) outside .claude/deploy/ allowlist:";
|
|
printf ' - %s\n' "${violations[@]}";
|
|
echo "deploy-commit: NOTHING committed. Caller must pass only .claude/deploy/ files."; } >&2
|
|
exit 4
|
|
fi
|
|
mapfile -t ignored_paths < <(for p in "$@"; do _ignored "$p" && printf '%s\n' "$p"; done)
|
|
if [ "${#ignored_paths[@]}" -gt 0 ]; then
|
|
{ echo "deploy-commit: REFUSED — path(s) are git-ignored and will NOT persist; \`.claude/deploy/\` must be committable in this project:";
|
|
printf ' - %s\n' "${ignored_paths[@]}"; } >&2
|
|
exit 5
|
|
fi
|
|
_unsafe_state && { echo "deploy-commit: unsafe git state (detached/merge/rebase) — not committing" >&2; exit 3; }
|
|
mapfile -t changed < <(_changed_only "$@")
|
|
[ "${#changed[@]}" -gt 0 ] || exit 1
|
|
git add -- "${changed[@]}"
|
|
if git diff --cached --quiet -- "${changed[@]}"; then
|
|
echo "deploy-commit: nothing staged — no-op" >&2; exit 1
|
|
fi
|
|
git commit -q -m "$msg" -- "${changed[@]}" \
|
|
|| { echo "deploy-commit: COMMIT REJECTED — git commit exited non-zero (pre-commit hook? protected branch? signing?)." >&2; exit 6; }
|
|
git rev-parse --short HEAD ;;
|
|
*) echo "usage: deploy-commit.sh pending <file>... | commit \"<msg>\" <file>..." >&2; exit 2 ;;
|
|
esac
|