Skip to content

Session Handoff [default]: Shared-Hook Install Rule and hooksPath Guard Denial Released as 2.0.774 #2181

Description

@ptr727

Next steps, in priority order

Re-read each issue and pull request rather than trusting these summaries.

  1. unattended-handoff: adopted lesson issues stall, and the promotion STOP matches any decision issue #1812, fixed on reasoning rather than waiting for a live run to hit it. For an adopted lesson, count an answer recorded on the issue as closing its choices. For the promotion STOP, match only a decision issue that states it blocks the open develop -> main PR.
  2. Close the Installer Gaps Left After the Marketplace Re-Point Fix #2019, the small installer gaps left after Refresh Skills After a Release Without Moving the Claude Marketplace Source #2017. git_in() should catch ValueError so --report survives a NUL in a registered path. The "gone" messages should not say "no longer exists" for a plain file. The host-setup cadence paragraph and check-this-repo's "Answering" section should say --snapshot-only. One short PR.
  3. Deny the Remaining core.hooksPath and no-verify Bypass Routes in the Guard #2177, the guard's remaining hook-bypass routes. These are a persistent git config core.hooksPath, the GIT_CONFIG_* environment forms, and wrapped or aliased git. Done looks like the bypass check reusing rule 6's _all_git_invocations walk and alias resolution. Its heredoc false-positive item overlaps the auto-2112 lane (Session Handoff [auto-2112]: Strip Every Heredoc Body a Line Opens in the Guard per #2112 #2123), so check that lane's state first.
  4. Exercise the unattended loop's parked-lane half. An attended "resume the handoff" of a lane parked under blocked has still never run. Done looks like one parked lane coming back through the attended procedure intact.
  5. Say the Hub Commits the Report Wherever Done-Means-Audited Is Stated #1826: reword the remaining places that say the audited repository "carries" a committed reports/<repo>/audit.md.
  6. Carry the code-review skill bootstrap to seven repos whose Copilot reviews never state coverage #1815: carry the code-review skill bootstrap and the .github/skills tree into the seven repositories listed there.
  7. Downstream resyncs for the new Fleet Bootstrap text, per-repository work in each repository's own session. When aiopurpleair resyncs, its handoff (aiopurpleair Update codegen files #177) should drop step 3, "commit an audit report".
  8. Smaller follow-ups: Copilot Refuses a Pull Request Carrying Only Default-Excluded Files, and No Rule Covers It #2180 (a Copilot refusal on a PR holding only default-excluded files has no Merge Gate substitute, filed from the HomeAutomation-Config session, not urgent), Durable Knowledge does not say where a lesson goes when no change is open #1811, audit.py --issue path never prints the no-remote hub-name warning #1810, Skill files hard-wrap while comment-and-doc-style requires one paragraph per line #1814.
  9. Carried unchanged from Session Handoff [default]: WORKFLOW.md Corrections and the pyproject.toml Decision Released as 2.0.672 #1804, in its order: the native-Windows check of bootstrap.ps1, then close Bootstrap registers its temporary tree as the live Claude Code skills source, then deletes it #1756. Then Keep an Owned Tree Recognizable When Its Final Directory Removal Fails #1795, followed by Name the Leftover Old Tree When the Bash Loader Cannot Remove It #1790, Drive the PowerShell Loader's Kept-Tree Functions from the Test Suite #1791, and Lock the Bootstrap Directory for a Kept-Tree Run #1792. Gate Every Repository's Python on Its Code, Not on Its Config #1800 comes next: settle its three decisions with the maintainer before any edit, with Spec: python.profile.detect does not describe a virtual uv workspace root #1778 folded in. Then The menu's skills task registers a clone it then removes #1771 before Re-point a Claude Code registration an older bootstrap left dangling #1769, then Say Where the Deploy-Site Task Actually Requires the SSH Key #1801 and Declare the Default Workflow Token Permission in the Repository Settings Payload #1783, and A regex pins a phrase inside a # comment, so rewrapping that comment fails the test with a false explanation #1732 before skills_install --report follow-ups: stamp-less live report, bootstrap remedy text, --intended guard test #1759, skills_install source_ref hides ignored files and trusts an enclosing git repo #1758, and skills_install --report's live channel does not check that the plugin is installed and enabled #1757. After those come A stacked pull request's diff reopens after the parent squash-merges, and nothing documents it #1742, Session Handoff [default]: One Issue Closed Whose Premise Was Wrong, and a Release #1735, Converge Financial-Modeling with the hub baseline (32 findings) #1579, The widened configuration shape misses the unspaced key=value an environment file writes #1717, and issue-ref reads no URL outside instruction text, so an own-repository tracker URL in code is banned and unreported #1719. Lower priority: Two skills describe the live skills channel only as a git checkout #1772, A kept skills tree edited by hand still stamps clean #1775, Nothing tests the bootstrap loaders' kept-tree swap sequence #1767, Two concurrent bootstrap runs can remove each other's tree #1764, and install-skills.ps1 fails under a directory whose path contains a wildcard character #1765.

External blockers

Carried from #2022 and not re-verified this round.

  • Financial-Modeling's shared pre-commit hook is broken until the maintainer restores .git/hooks/pre-commit.legacy over the prek hook in that repository's primary checkout. The hub-side cause, repo-worktree's hook step installs into the git hooks dir every worktree shares #1816, is now fixed, which stops a recurrence but does not repair the existing hook.
  • Downstream promotions: the version-literal removals sit on develop in eleven fleet repositories until the maintainer promotes each.
  • A native Windows host is needed for step 9's first item.

Internal dependencies

State

The parked decision queue

One issue: #2170, how the prose gate widens past the Latin part of the recorded-name rule. The session answers are commented below.

What the last round did

What not to repeat

  • A precondition added to a previously unconditional step removes coverage for every case the old step reached. The Husky.Net bullet gained "core.hooksPath already reads .husky", which silently dropped standalone clones. Local review took four passes (7, 2, 1, and 0 findings), and the last two findings were each against the previous round's fix.
  • A heredoc that quotes --no-verify is denied by the guard, since it tokenizes heredoc bodies as commands. Write issue or PR bodies with the Write tool, not a cat <<EOF.

New learnings

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    handoffA link in the session handoff chain, one open issue per track

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions