Global: `make link` generates githooks/ from lib/gitflow.sh and sets git's global core.hooksPath to ~/.claude/githooks, so every repo on the machine runs the pre-commit protection and the post-commit / post-merge push, even one that never ran gitflow init. A repo's own local core.hooksPath still wins, so hooks/session-start.sh calls `gitflow reconcile-hooks` once per session and rewrites a .githooks/ that lags the lib (LRN-114 automated); the pre-commit exemption now covers .githooks/** next to .claude/**. Per-repo opt-outs for a foreign clone: `git config gitflow.protect false` (branch model) and `git config gitflow.autopush false` (push). Both, and the GIT_CONFIG_GLOBAL= / GIT_CONFIG= env bypass, are static deny rules. `make test` and the two suites that commit on main export GIT_CONFIG_GLOBAL=/dev/null so the machine's global hooks never fire in throwaway repos. doctor gains "Git hooks" (global setting, githooks/ equal to the emitters) and "Scratchpad" (warn when TMPDIR sits on a tmpfs with usrquota: systemd caps each user at 80% of it, which killed two shells today, BLK-021). Tests: T18h, T19d, T20 (reconcile), T21 (whitelist and protect opt-out); this repo's own stale .githooks/ refreshed.
42 lines
1.9 KiB
Bash
Executable File
42 lines
1.9 KiB
Bash
Executable File
#!/bin/sh
|
|
# gitflow pre-commit — generated by gitflow_init. Do not hand-edit.
|
|
# Mirrors gitflow_protected_base (lib/gitflow.sh). Drift caught by T10.
|
|
gd=$(git rev-parse --git-dir)
|
|
br=$(git symbolic-ref --short -q HEAD 2>/dev/null)
|
|
|
|
git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — allow
|
|
[ -f "$gd/MERGE_HEAD" ] && exit 0 # merge in progress — allow
|
|
|
|
# Secret backstop (job7) — any branch, not just protected ones. Non-blocking
|
|
# if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root).
|
|
if command -v gitleaks >/dev/null 2>&1; then
|
|
if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then
|
|
echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2
|
|
echo " Details: gitleaks git --staged --no-banner" >&2
|
|
echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2
|
|
exit 1
|
|
fi
|
|
else
|
|
echo "gitflow pre-commit: gitleaks not installed — secret scan skipped (https://github.com/gitleaks/gitleaks)." >&2
|
|
fi
|
|
|
|
# Per-repo opt-out of the branch model (a clone of a foreign project):
|
|
# git config gitflow.protect false
|
|
[ "$(git config --bool --default true gitflow.protect)" = false ] && exit 0
|
|
|
|
case "$br" in
|
|
main|develop) ;; # protected — keep checking
|
|
*) exit 0 ;; # working branch — allow
|
|
esac
|
|
|
|
# whitelist: all-staged-under-.claude/ (memory/doc/deploy helpers) or
|
|
# .githooks/ (the hooks themselves, refreshed by the lib) — allow
|
|
if [ -z "$(git diff --cached --name-only | grep -vE '^\.(claude|githooks)/' | head -1)" ]; then
|
|
exit 0
|
|
fi
|
|
|
|
echo "gitflow pre-commit: BLOCKED — direct commit on '$br'." >&2
|
|
echo " Branch from the right base (feature/bugfix->develop, hotfix->main), or merge." >&2
|
|
echo " (.claude/** and .githooks/** commits are exempt; foreign clone? git config gitflow.protect false)" >&2
|
|
exit 1
|