Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
115 changes: 115 additions & 0 deletions .claude/hooks/guard-tree-enum.selftest.sh
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,115 @@
#!/usr/bin/env bash
# Self-test for guard-tree-enum.sh — run it after touching that hook:
#
# .claude/hooks/guard-tree-enum.selftest.sh
#
# Feeds the hook the same JSON payload shape Claude Code delivers on PreToolUse and asserts
# the block/allow verdict per command. Needs jq (to build payloads) and nothing else: no
# install, no build, no network. Exit 0 = all cases hold.
#
# The first case is THIS repository's measured incident of 2026-08-29 (objectstack#13305)
# reproduced verbatim; it is the one case whose failure means the guard has stopped doing
# the only job it was written for.
#
# Mirrored one-for-one from objectstack's self-test of the same name alongside the hook, so
# the two repos' guards cannot drift; only example paths are localised.

set -uo pipefail

here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
hook="$here/guard-tree-enum.sh"
pass=0
fail=0

command -v jq >/dev/null 2>&1 || { echo "selftest needs jq to build payloads" >&2; exit 1; }

# verdict <command> [env assignments…] -> prints "block" or "allow"
verdict() {
local cmd="$1"; shift
local payload out rc
payload="$(jq -nc --arg c "$cmd" '{tool_name:"Bash",tool_input:{command:$c}}')"
out="$(printf '%s' "$payload" | env "$@" "$hook" 2>/dev/null)"
rc=$?
case "$rc" in
0) printf 'allow' ;;
2) printf 'block' ;;
*) printf 'exit%s' "$rc" ;;
esac
}

expect() { # expect <block|allow> <command> [env…]
local want="$1" cmd="$2"; shift 2
local got; got="$(verdict "$cmd" "$@")"
if [ "$got" = "$want" ]; then
pass=$((pass + 1)); printf ' ok %-5s %s\n' "$got" "$cmd"
else
fail=$((fail + 1)); printf ' FAIL want=%s got=%s %s\n' "$want" "$got" "$cmd"
fi
}

echo "== THE MEASURED SIGNATURE: working-tree list + origin/main read in one command =="
# objectui, 2026-08-29 — the loop that reported "no workflow subscribes ready_for_review"
expect block 'for f in .github/workflows/*.yml; do git show "origin/main:$f" | grep -q ready_for_review && echo "$f"; done'
expect block 'for f in .github/workflows/*.yml; do git show origin/main:$f; done'
expect block 'ls .github/workflows/*.yml | while read f; do git show "origin/main:$f"; done'
expect block 'for f in scripts/*.mjs; do git cat-file -e "origin/main:$f" || echo missing; done'
expect block 'find .github/workflows -name "*.yml" | while read f; do git show "origin/main:$f"; done'
expect block 'for f in packages/components/src/*.ts; do git grep -q PATTERN origin/main -- "$f"; done'

echo "== reached through separators, env prefixes and git -C =="
expect block 'cd /home/user/objectui && for f in .claude/hooks/*.sh; do git show "origin/main:$f"; done'
expect block 'for f in docs/adr/*.md; do git -C . show "origin/main:$f" | head -1; done'
expect block 'NODE_OPTIONS=--max-old-space-size=4096 ls scripts/*.mjs | xargs -I{} git show origin/main:{}'

echo "== THE CANONICAL IDIOM is never blocked, however it then reads =="
expect allow 'git ls-tree --name-only origin/main .github/workflows/'
expect allow 'for f in $(git ls-tree --name-only origin/main .github/workflows/); do git show "origin/main:$f"; done'
expect allow 'git ls-tree -r --name-only origin/main scripts/ | while read f; do git show "origin/main:$f"; done'
echo "-- the population/read cross-check the block message recommends must not itself block --"
expect allow 'git ls-tree --name-only origin/main .github/workflows/ | wc -l; ls .github/workflows/* | wc -l; git show origin/main:AGENTS.md | head -1'

echo "== EITHER HALF ALONE is ordinary and correct =="
echo "-- (a) working-tree enumeration with no origin/main read --"
expect allow 'ls .github/workflows/*.yml'
expect allow 'for f in packages/*/package.json; do jq -r .name "$f"; done'
expect allow 'find scripts -name "*.mjs" | wc -l'
expect allow 'for f in .claude/hooks/*.sh; do bash -n "$f"; done'
echo "-- (b) origin/main read with no working-tree enumeration --"
expect allow 'git show origin/main:AGENTS.md | wc -l'
expect allow 'git grep -n ready_for_review origin/main'
expect allow 'git show "origin/main:.github/workflows/governed-surface-guard.yml"'
expect allow 'git cat-file -e origin/main:.github/workflows/ci.yml'
expect allow 'git diff origin/main -- .github/workflows/'

echo "== a LOCAL ref is not the hazard this guard is about =="
expect allow 'for f in .github/workflows/*.yml; do git show "HEAD:$f"; done'
expect allow 'for f in .github/workflows/*.yml; do git show "$BASE:$f"; done'

echo "== writing ABOUT the defect must not trip the guard =="
expect allow 'grep -n "git show origin/main:" AGENTS.md'
expect allow 'grep -rn "for f in .github/workflows/\*.yml" .claude/hooks/'
expect allow 'echo "never feed a working-tree glob into git show origin/main:"'
expect allow 'git grep -n "ls-tree --name-only origin/main"'
expect allow 'cat .claude/hooks/guard-tree-enum.sh'

echo "== unrelated commands are untouched =="
expect allow 'pnpm --filter @object-ui/components test'
expect allow 'git status'
expect allow 'node scripts/check-changeset-presence.mjs'
expect allow 'git worktree add ../objectui-issue-13305 -b claude/issue-13305 origin/main'

echo "== the deliberate exception releases it =="
expect allow 'for f in .github/workflows/*.yml; do git show "origin/main:$f"; done' OS_ALLOW_TREE_ENUM=1

echo "== fails OPEN on payloads it cannot parse =="
printf '%s' '{"tool_name":"Bash","tool_input":{}}' | "$hook" >/dev/null 2>&1
if [ $? -eq 0 ]; then pass=$((pass + 1)); printf ' ok allow <no command in payload>\n'
else fail=$((fail + 1)); printf ' FAIL want=allow <no command in payload>\n'; fi
printf '%s' 'not json at all' | "$hook" >/dev/null 2>&1
if [ $? -eq 0 ]; then pass=$((pass + 1)); printf ' ok allow <malformed payload>\n'
else fail=$((fail + 1)); printf ' FAIL want=allow <malformed payload>\n'; fi

echo
echo "guard-tree-enum selftest: $pass passed, $fail failed"
[ "$fail" -eq 0 ] || exit 1
exit 0
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
feat(hooks): guard the origin/main ENUMERATION half, and record the incident in AGENTS.md by claude[bot] · Pull Request #6908 · objectstack-ai/objectui · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
115 changes: 115 additions & 0 deletions .claude/hooks/guard-tree-enum.selftest.sh
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,115 @@
#!/usr/bin/env bash
# Self-test for guard-tree-enum.sh — run it after touching that hook:
#
# .claude/hooks/guard-tree-enum.selftest.sh
#
# Feeds the hook the same JSON payload shape Claude Code delivers on PreToolUse and asserts
# the block/allow verdict per command. Needs jq (to build payloads) and nothing else: no
# install, no build, no network. Exit 0 = all cases hold.
#
# The first case is THIS repository's measured incident of 2026-08-29 (objectstack#13305)
# reproduced verbatim; it is the one case whose failure means the guard has stopped doing
# the only job it was written for.
#
# Mirrored one-for-one from objectstack's self-test of the same name alongside the hook, so
# the two repos' guards cannot drift; only example paths are localised.

set -uo pipefail

here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
hook="$here/guard-tree-enum.sh"
pass=0
fail=0

command -v jq >/dev/null 2>&1 || { echo "selftest needs jq to build payloads" >&2; exit 1; }

# verdict <command> [env assignments…] -> prints "block" or "allow"
verdict() {
local cmd="$1"; shift
local payload out rc
payload="$(jq -nc --arg c "$cmd" '{tool_name:"Bash",tool_input:{command:$c}}')"
out="$(printf '%s' "$payload" | env "$@" "$hook" 2>/dev/null)"
rc=$?
case "$rc" in
0) printf 'allow' ;;
2) printf 'block' ;;
*) printf 'exit%s' "$rc" ;;
esac
}

expect() { # expect <block|allow> <command> [env…]
local want="$1" cmd="$2"; shift 2
local got; got="$(verdict "$cmd" "$@")"
if [ "$got" = "$want" ]; then
pass=$((pass + 1)); printf ' ok %-5s %s\n' "$got" "$cmd"
else
fail=$((fail + 1)); printf ' FAIL want=%s got=%s %s\n' "$want" "$got" "$cmd"
fi
}

echo "== THE MEASURED SIGNATURE: working-tree list + origin/main read in one command =="
# objectui, 2026-08-29 — the loop that reported "no workflow subscribes ready_for_review"
expect block 'for f in .github/workflows/*.yml; do git show "origin/main:$f" | grep -q ready_for_review && echo "$f"; done'
expect block 'for f in .github/workflows/*.yml; do git show origin/main:$f; done'
expect block 'ls .github/workflows/*.yml | while read f; do git show "origin/main:$f"; done'
expect block 'for f in scripts/*.mjs; do git cat-file -e "origin/main:$f" || echo missing; done'
expect block 'find .github/workflows -name "*.yml" | while read f; do git show "origin/main:$f"; done'
expect block 'for f in packages/components/src/*.ts; do git grep -q PATTERN origin/main -- "$f"; done'

echo "== reached through separators, env prefixes and git -C =="
expect block 'cd /home/user/objectui && for f in .claude/hooks/*.sh; do git show "origin/main:$f"; done'
expect block 'for f in docs/adr/*.md; do git -C . show "origin/main:$f" | head -1; done'
expect block 'NODE_OPTIONS=--max-old-space-size=4096 ls scripts/*.mjs | xargs -I{} git show origin/main:{}'

echo "== THE CANONICAL IDIOM is never blocked, however it then reads =="
expect allow 'git ls-tree --name-only origin/main .github/workflows/'
expect allow 'for f in $(git ls-tree --name-only origin/main .github/workflows/); do git show "origin/main:$f"; done'
expect allow 'git ls-tree -r --name-only origin/main scripts/ | while read f; do git show "origin/main:$f"; done'
echo "-- the population/read cross-check the block message recommends must not itself block --"
expect allow 'git ls-tree --name-only origin/main .github/workflows/ | wc -l; ls .github/workflows/* | wc -l; git show origin/main:AGENTS.md | head -1'

echo "== EITHER HALF ALONE is ordinary and correct =="
echo "-- (a) working-tree enumeration with no origin/main read --"
expect allow 'ls .github/workflows/*.yml'
expect allow 'for f in packages/*/package.json; do jq -r .name "$f"; done'
expect allow 'find scripts -name "*.mjs" | wc -l'
expect allow 'for f in .claude/hooks/*.sh; do bash -n "$f"; done'
echo "-- (b) origin/main read with no working-tree enumeration --"
expect allow 'git show origin/main:AGENTS.md | wc -l'
expect allow 'git grep -n ready_for_review origin/main'
expect allow 'git show "origin/main:.github/workflows/governed-surface-guard.yml"'
expect allow 'git cat-file -e origin/main:.github/workflows/ci.yml'
expect allow 'git diff origin/main -- .github/workflows/'

echo "== a LOCAL ref is not the hazard this guard is about =="
expect allow 'for f in .github/workflows/*.yml; do git show "HEAD:$f"; done'
expect allow 'for f in .github/workflows/*.yml; do git show "$BASE:$f"; done'

echo "== writing ABOUT the defect must not trip the guard =="
expect allow 'grep -n "git show origin/main:" AGENTS.md'
expect allow 'grep -rn "for f in .github/workflows/\*.yml" .claude/hooks/'
expect allow 'echo "never feed a working-tree glob into git show origin/main:"'
expect allow 'git grep -n "ls-tree --name-only origin/main"'
expect allow 'cat .claude/hooks/guard-tree-enum.sh'

echo "== unrelated commands are untouched =="
expect allow 'pnpm --filter @object-ui/components test'
expect allow 'git status'
expect allow 'node scripts/check-changeset-presence.mjs'
expect allow 'git worktree add ../objectui-issue-13305 -b claude/issue-13305 origin/main'

echo "== the deliberate exception releases it =="
expect allow 'for f in .github/workflows/*.yml; do git show "origin/main:$f"; done' OS_ALLOW_TREE_ENUM=1

echo "== fails OPEN on payloads it cannot parse =="
printf '%s' '{"tool_name":"Bash","tool_input":{}}' | "$hook" >/dev/null 2>&1
if [ $? -eq 0 ]; then pass=$((pass + 1)); printf ' ok allow <no command in payload>\n'
else fail=$((fail + 1)); printf ' FAIL want=allow <no command in payload>\n'; fi
printf '%s' 'not json at all' | "$hook" >/dev/null 2>&1
if [ $? -eq 0 ]; then pass=$((pass + 1)); printf ' ok allow <malformed payload>\n'
else fail=$((fail + 1)); printf ' FAIL want=allow <malformed payload>\n'; fi

echo
echo "guard-tree-enum selftest: $pass passed, $fail failed"
[ "$fail" -eq 0 ] || exit 1
exit 0
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(hooks): guard the origin/main ENUMERATION half, and record the incident in AGENTS.md by claude[bot] · Pull Request #6908 · objectstack-ai/objectui · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
115 changes: 115 additions & 0 deletions .claude/hooks/guard-tree-enum.selftest.sh
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,115 @@
#!/usr/bin/env bash
# Self-test for guard-tree-enum.sh — run it after touching that hook:
#
# .claude/hooks/guard-tree-enum.selftest.sh
#
# Feeds the hook the same JSON payload shape Claude Code delivers on PreToolUse and asserts
# the block/allow verdict per command. Needs jq (to build payloads) and nothing else: no
# install, no build, no network. Exit 0 = all cases hold.
#
# The first case is THIS repository's measured incident of 2026-08-29 (objectstack#13305)
# reproduced verbatim; it is the one case whose failure means the guard has stopped doing
# the only job it was written for.
#
# Mirrored one-for-one from objectstack's self-test of the same name alongside the hook, so
# the two repos' guards cannot drift; only example paths are localised.

set -uo pipefail

here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
hook="$here/guard-tree-enum.sh"
pass=0
fail=0

command -v jq >/dev/null 2>&1 || { echo "selftest needs jq to build payloads" >&2; exit 1; }

# verdict <command> [env assignments…] -> prints "block" or "allow"
verdict() {
local cmd="$1"; shift
local payload out rc
payload="$(jq -nc --arg c "$cmd" '{tool_name:"Bash",tool_input:{command:$c}}')"
out="$(printf '%s' "$payload" | env "$@" "$hook" 2>/dev/null)"
rc=$?
case "$rc" in
0) printf 'allow' ;;
2) printf 'block' ;;
*) printf 'exit%s' "$rc" ;;
esac
}

expect() { # expect <block|allow> <command> [env…]
local want="$1" cmd="$2"; shift 2
local got; got="$(verdict "$cmd" "$@")"
if [ "$got" = "$want" ]; then
pass=$((pass + 1)); printf ' ok %-5s %s\n' "$got" "$cmd"
else
fail=$((fail + 1)); printf ' FAIL want=%s got=%s %s\n' "$want" "$got" "$cmd"
fi
}

echo "== THE MEASURED SIGNATURE: working-tree list + origin/main read in one command =="
# objectui, 2026-08-29 — the loop that reported "no workflow subscribes ready_for_review"
expect block 'for f in .github/workflows/*.yml; do git show "origin/main:$f" | grep -q ready_for_review && echo "$f"; done'
expect block 'for f in .github/workflows/*.yml; do git show origin/main:$f; done'
expect block 'ls .github/workflows/*.yml | while read f; do git show "origin/main:$f"; done'
expect block 'for f in scripts/*.mjs; do git cat-file -e "origin/main:$f" || echo missing; done'
expect block 'find .github/workflows -name "*.yml" | while read f; do git show "origin/main:$f"; done'
expect block 'for f in packages/components/src/*.ts; do git grep -q PATTERN origin/main -- "$f"; done'

echo "== reached through separators, env prefixes and git -C =="
expect block 'cd /home/user/objectui && for f in .claude/hooks/*.sh; do git show "origin/main:$f"; done'
expect block 'for f in docs/adr/*.md; do git -C . show "origin/main:$f" | head -1; done'
expect block 'NODE_OPTIONS=--max-old-space-size=4096 ls scripts/*.mjs | xargs -I{} git show origin/main:{}'

echo "== THE CANONICAL IDIOM is never blocked, however it then reads =="
expect allow 'git ls-tree --name-only origin/main .github/workflows/'
expect allow 'for f in $(git ls-tree --name-only origin/main .github/workflows/); do git show "origin/main:$f"; done'
expect allow 'git ls-tree -r --name-only origin/main scripts/ | while read f; do git show "origin/main:$f"; done'
echo "-- the population/read cross-check the block message recommends must not itself block --"
expect allow 'git ls-tree --name-only origin/main .github/workflows/ | wc -l; ls .github/workflows/* | wc -l; git show origin/main:AGENTS.md | head -1'

echo "== EITHER HALF ALONE is ordinary and correct =="
echo "-- (a) working-tree enumeration with no origin/main read --"
expect allow 'ls .github/workflows/*.yml'
expect allow 'for f in packages/*/package.json; do jq -r .name "$f"; done'
expect allow 'find scripts -name "*.mjs" | wc -l'
expect allow 'for f in .claude/hooks/*.sh; do bash -n "$f"; done'
echo "-- (b) origin/main read with no working-tree enumeration --"
expect allow 'git show origin/main:AGENTS.md | wc -l'
expect allow 'git grep -n ready_for_review origin/main'
expect allow 'git show "origin/main:.github/workflows/governed-surface-guard.yml"'
expect allow 'git cat-file -e origin/main:.github/workflows/ci.yml'
expect allow 'git diff origin/main -- .github/workflows/'

echo "== a LOCAL ref is not the hazard this guard is about =="
expect allow 'for f in .github/workflows/*.yml; do git show "HEAD:$f"; done'
expect allow 'for f in .github/workflows/*.yml; do git show "$BASE:$f"; done'

echo "== writing ABOUT the defect must not trip the guard =="
expect allow 'grep -n "git show origin/main:" AGENTS.md'
expect allow 'grep -rn "for f in .github/workflows/\*.yml" .claude/hooks/'
expect allow 'echo "never feed a working-tree glob into git show origin/main:"'
expect allow 'git grep -n "ls-tree --name-only origin/main"'
expect allow 'cat .claude/hooks/guard-tree-enum.sh'

echo "== unrelated commands are untouched =="
expect allow 'pnpm --filter @object-ui/components test'
expect allow 'git status'
expect allow 'node scripts/check-changeset-presence.mjs'
expect allow 'git worktree add ../objectui-issue-13305 -b claude/issue-13305 origin/main'

echo "== the deliberate exception releases it =="
expect allow 'for f in .github/workflows/*.yml; do git show "origin/main:$f"; done' OS_ALLOW_TREE_ENUM=1

echo "== fails OPEN on payloads it cannot parse =="
printf '%s' '{"tool_name":"Bash","tool_input":{}}' | "$hook" >/dev/null 2>&1
if [ $? -eq 0 ]; then pass=$((pass + 1)); printf ' ok allow <no command in payload>\n'
else fail=$((fail + 1)); printf ' FAIL want=allow <no command in payload>\n'; fi
printf '%s' 'not json at all' | "$hook" >/dev/null 2>&1
if [ $? -eq 0 ]; then pass=$((pass + 1)); printf ' ok allow <malformed payload>\n'
else fail=$((fail + 1)); printf ' FAIL want=allow <malformed payload>\n'; fi

echo
echo "guard-tree-enum selftest: $pass passed, $fail failed"
[ "$fail" -eq 0 ] || exit 1
exit 0
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(hooks): guard the origin/main ENUMERATION half, and record the incident in AGENTS.md by claude[bot] · Pull Request #6908 · objectstack-ai/objectui · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
115 changes: 115 additions & 0 deletions .claude/hooks/guard-tree-enum.selftest.sh
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,115 @@
#!/usr/bin/env bash
# Self-test for guard-tree-enum.sh — run it after touching that hook:
#
# .claude/hooks/guard-tree-enum.selftest.sh
#
# Feeds the hook the same JSON payload shape Claude Code delivers on PreToolUse and asserts
# the block/allow verdict per command. Needs jq (to build payloads) and nothing else: no
# install, no build, no network. Exit 0 = all cases hold.
#
# The first case is THIS repository's measured incident of 2026-08-29 (objectstack#13305)
# reproduced verbatim; it is the one case whose failure means the guard has stopped doing
# the only job it was written for.
#
# Mirrored one-for-one from objectstack's self-test of the same name alongside the hook, so
# the two repos' guards cannot drift; only example paths are localised.

set -uo pipefail

here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
hook="$here/guard-tree-enum.sh"
pass=0
fail=0

command -v jq >/dev/null 2>&1 || { echo "selftest needs jq to build payloads" >&2; exit 1; }

# verdict <command> [env assignments…] -> prints "block" or "allow"
verdict() {
local cmd="$1"; shift
local payload out rc
payload="$(jq -nc --arg c "$cmd" '{tool_name:"Bash",tool_input:{command:$c}}')"
out="$(printf '%s' "$payload" | env "$@" "$hook" 2>/dev/null)"
rc=$?
case "$rc" in
0) printf 'allow' ;;
2) printf 'block' ;;
*) printf 'exit%s' "$rc" ;;
esac
}

expect() { # expect <block|allow> <command> [env…]
local want="$1" cmd="$2"; shift 2
local got; got="$(verdict "$cmd" "$@")"
if [ "$got" = "$want" ]; then
pass=$((pass + 1)); printf ' ok %-5s %s\n' "$got" "$cmd"
else
fail=$((fail + 1)); printf ' FAIL want=%s got=%s %s\n' "$want" "$got" "$cmd"
fi
}

echo "== THE MEASURED SIGNATURE: working-tree list + origin/main read in one command =="
# objectui, 2026-08-29 — the loop that reported "no workflow subscribes ready_for_review"
expect block 'for f in .github/workflows/*.yml; do git show "origin/main:$f" | grep -q ready_for_review && echo "$f"; done'
expect block 'for f in .github/workflows/*.yml; do git show origin/main:$f; done'
expect block 'ls .github/workflows/*.yml | while read f; do git show "origin/main:$f"; done'
expect block 'for f in scripts/*.mjs; do git cat-file -e "origin/main:$f" || echo missing; done'
expect block 'find .github/workflows -name "*.yml" | while read f; do git show "origin/main:$f"; done'
expect block 'for f in packages/components/src/*.ts; do git grep -q PATTERN origin/main -- "$f"; done'

echo "== reached through separators, env prefixes and git -C =="
expect block 'cd /home/user/objectui && for f in .claude/hooks/*.sh; do git show "origin/main:$f"; done'
expect block 'for f in docs/adr/*.md; do git -C . show "origin/main:$f" | head -1; done'
expect block 'NODE_OPTIONS=--max-old-space-size=4096 ls scripts/*.mjs | xargs -I{} git show origin/main:{}'

echo "== THE CANONICAL IDIOM is never blocked, however it then reads =="
expect allow 'git ls-tree --name-only origin/main .github/workflows/'
expect allow 'for f in $(git ls-tree --name-only origin/main .github/workflows/); do git show "origin/main:$f"; done'
expect allow 'git ls-tree -r --name-only origin/main scripts/ | while read f; do git show "origin/main:$f"; done'
echo "-- the population/read cross-check the block message recommends must not itself block --"
expect allow 'git ls-tree --name-only origin/main .github/workflows/ | wc -l; ls .github/workflows/* | wc -l; git show origin/main:AGENTS.md | head -1'

echo "== EITHER HALF ALONE is ordinary and correct =="
echo "-- (a) working-tree enumeration with no origin/main read --"
expect allow 'ls .github/workflows/*.yml'
expect allow 'for f in packages/*/package.json; do jq -r .name "$f"; done'
expect allow 'find scripts -name "*.mjs" | wc -l'
expect allow 'for f in .claude/hooks/*.sh; do bash -n "$f"; done'
echo "-- (b) origin/main read with no working-tree enumeration --"
expect allow 'git show origin/main:AGENTS.md | wc -l'
expect allow 'git grep -n ready_for_review origin/main'
expect allow 'git show "origin/main:.github/workflows/governed-surface-guard.yml"'
expect allow 'git cat-file -e origin/main:.github/workflows/ci.yml'
expect allow 'git diff origin/main -- .github/workflows/'

echo "== a LOCAL ref is not the hazard this guard is about =="
expect allow 'for f in .github/workflows/*.yml; do git show "HEAD:$f"; done'
expect allow 'for f in .github/workflows/*.yml; do git show "$BASE:$f"; done'

echo "== writing ABOUT the defect must not trip the guard =="
expect allow 'grep -n "git show origin/main:" AGENTS.md'
expect allow 'grep -rn "for f in .github/workflows/\*.yml" .claude/hooks/'
expect allow 'echo "never feed a working-tree glob into git show origin/main:"'
expect allow 'git grep -n "ls-tree --name-only origin/main"'
expect allow 'cat .claude/hooks/guard-tree-enum.sh'

echo "== unrelated commands are untouched =="
expect allow 'pnpm --filter @object-ui/components test'
expect allow 'git status'
expect allow 'node scripts/check-changeset-presence.mjs'
expect allow 'git worktree add ../objectui-issue-13305 -b claude/issue-13305 origin/main'

echo "== the deliberate exception releases it =="
expect allow 'for f in .github/workflows/*.yml; do git show "origin/main:$f"; done' OS_ALLOW_TREE_ENUM=1

echo "== fails OPEN on payloads it cannot parse =="
printf '%s' '{"tool_name":"Bash","tool_input":{}}' | "$hook" >/dev/null 2>&1
if [ $? -eq 0 ]; then pass=$((pass + 1)); printf ' ok allow <no command in payload>\n'
else fail=$((fail + 1)); printf ' FAIL want=allow <no command in payload>\n'; fi
printf '%s' 'not json at all' | "$hook" >/dev/null 2>&1
if [ $? -eq 0 ]; then pass=$((pass + 1)); printf ' ok allow <malformed payload>\n'
else fail=$((fail + 1)); printf ' FAIL want=allow <malformed payload>\n'; fi

echo
echo "guard-tree-enum selftest: $pass passed, $fail failed"
[ "$fail" -eq 0 ] || exit 1
exit 0
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' feat(hooks): guard the origin/main ENUMERATION half, and record the incident in AGENTS.md by claude[bot] · Pull Request #6908 · objectstack-ai/objectui · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
115 changes: 115 additions & 0 deletions .claude/hooks/guard-tree-enum.selftest.sh
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,115 @@
#!/usr/bin/env bash
# Self-test for guard-tree-enum.sh — run it after touching that hook:
#
# .claude/hooks/guard-tree-enum.selftest.sh
#
# Feeds the hook the same JSON payload shape Claude Code delivers on PreToolUse and asserts
# the block/allow verdict per command. Needs jq (to build payloads) and nothing else: no
# install, no build, no network. Exit 0 = all cases hold.
#
# The first case is THIS repository's measured incident of 2026-08-29 (objectstack#13305)
# reproduced verbatim; it is the one case whose failure means the guard has stopped doing
# the only job it was written for.
#
# Mirrored one-for-one from objectstack's self-test of the same name alongside the hook, so
# the two repos' guards cannot drift; only example paths are localised.

set -uo pipefail

here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
hook="$here/guard-tree-enum.sh"
pass=0
fail=0

command -v jq >/dev/null 2>&1 || { echo "selftest needs jq to build payloads" >&2; exit 1; }

# verdict <command> [env assignments…] -> prints "block" or "allow"
verdict() {
local cmd="$1"; shift
local payload out rc
payload="$(jq -nc --arg c "$cmd" '{tool_name:"Bash",tool_input:{command:$c}}')"
out="$(printf '%s' "$payload" | env "$@" "$hook" 2>/dev/null)"
rc=$?
case "$rc" in
0) printf 'allow' ;;
2) printf 'block' ;;
*) printf 'exit%s' "$rc" ;;
esac
}

expect() { # expect <block|allow> <command> [env…]
local want="$1" cmd="$2"; shift 2
local got; got="$(verdict "$cmd" "$@")"
if [ "$got" = "$want" ]; then
pass=$((pass + 1)); printf ' ok %-5s %s\n' "$got" "$cmd"
else
fail=$((fail + 1)); printf ' FAIL want=%s got=%s %s\n' "$want" "$got" "$cmd"
fi
}

echo "== THE MEASURED SIGNATURE: working-tree list + origin/main read in one command =="
# objectui, 2026-08-29 — the loop that reported "no workflow subscribes ready_for_review"
expect block 'for f in .github/workflows/*.yml; do git show "origin/main:$f" | grep -q ready_for_review && echo "$f"; done'
expect block 'for f in .github/workflows/*.yml; do git show origin/main:$f; done'
expect block 'ls .github/workflows/*.yml | while read f; do git show "origin/main:$f"; done'
expect block 'for f in scripts/*.mjs; do git cat-file -e "origin/main:$f" || echo missing; done'
expect block 'find .github/workflows -name "*.yml" | while read f; do git show "origin/main:$f"; done'
expect block 'for f in packages/components/src/*.ts; do git grep -q PATTERN origin/main -- "$f"; done'

echo "== reached through separators, env prefixes and git -C =="
expect block 'cd /home/user/objectui && for f in .claude/hooks/*.sh; do git show "origin/main:$f"; done'
expect block 'for f in docs/adr/*.md; do git -C . show "origin/main:$f" | head -1; done'
expect block 'NODE_OPTIONS=--max-old-space-size=4096 ls scripts/*.mjs | xargs -I{} git show origin/main:{}'

echo "== THE CANONICAL IDIOM is never blocked, however it then reads =="
expect allow 'git ls-tree --name-only origin/main .github/workflows/'
expect allow 'for f in $(git ls-tree --name-only origin/main .github/workflows/); do git show "origin/main:$f"; done'
expect allow 'git ls-tree -r --name-only origin/main scripts/ | while read f; do git show "origin/main:$f"; done'
echo "-- the population/read cross-check the block message recommends must not itself block --"
expect allow 'git ls-tree --name-only origin/main .github/workflows/ | wc -l; ls .github/workflows/* | wc -l; git show origin/main:AGENTS.md | head -1'

echo "== EITHER HALF ALONE is ordinary and correct =="
echo "-- (a) working-tree enumeration with no origin/main read --"
expect allow 'ls .github/workflows/*.yml'
expect allow 'for f in packages/*/package.json; do jq -r .name "$f"; done'
expect allow 'find scripts -name "*.mjs" | wc -l'
expect allow 'for f in .claude/hooks/*.sh; do bash -n "$f"; done'
echo "-- (b) origin/main read with no working-tree enumeration --"
expect allow 'git show origin/main:AGENTS.md | wc -l'
expect allow 'git grep -n ready_for_review origin/main'
expect allow 'git show "origin/main:.github/workflows/governed-surface-guard.yml"'
expect allow 'git cat-file -e origin/main:.github/workflows/ci.yml'
expect allow 'git diff origin/main -- .github/workflows/'

echo "== a LOCAL ref is not the hazard this guard is about =="
expect allow 'for f in .github/workflows/*.yml; do git show "HEAD:$f"; done'
expect allow 'for f in .github/workflows/*.yml; do git show "$BASE:$f"; done'

echo "== writing ABOUT the defect must not trip the guard =="
expect allow 'grep -n "git show origin/main:" AGENTS.md'
expect allow 'grep -rn "for f in .github/workflows/\*.yml" .claude/hooks/'
expect allow 'echo "never feed a working-tree glob into git show origin/main:"'
expect allow 'git grep -n "ls-tree --name-only origin/main"'
expect allow 'cat .claude/hooks/guard-tree-enum.sh'

echo "== unrelated commands are untouched =="
expect allow 'pnpm --filter @object-ui/components test'
expect allow 'git status'
expect allow 'node scripts/check-changeset-presence.mjs'
expect allow 'git worktree add ../objectui-issue-13305 -b claude/issue-13305 origin/main'

echo "== the deliberate exception releases it =="
expect allow 'for f in .github/workflows/*.yml; do git show "origin/main:$f"; done' OS_ALLOW_TREE_ENUM=1

echo "== fails OPEN on payloads it cannot parse =="
printf '%s' '{"tool_name":"Bash","tool_input":{}}' | "$hook" >/dev/null 2>&1
if [ $? -eq 0 ]; then pass=$((pass + 1)); printf ' ok allow <no command in payload>\n'
else fail=$((fail + 1)); printf ' FAIL want=allow <no command in payload>\n'; fi
printf '%s' 'not json at all' | "$hook" >/dev/null 2>&1
if [ $? -eq 0 ]; then pass=$((pass + 1)); printf ' ok allow <malformed payload>\n'
else fail=$((fail + 1)); printf ' FAIL want=allow <malformed payload>\n'; fi

echo
echo "guard-tree-enum selftest: $pass passed, $fail failed"
[ "$fail" -eq 0 ] || exit 1
exit 0
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(hooks): guard the origin/main ENUMERATION half, and record the incident in AGENTS.md by claude[bot] · Pull Request #6908 · objectstack-ai/objectui · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
115 changes: 115 additions & 0 deletions .claude/hooks/guard-tree-enum.selftest.sh
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,115 @@
#!/usr/bin/env bash
# Self-test for guard-tree-enum.sh — run it after touching that hook:
#
# .claude/hooks/guard-tree-enum.selftest.sh
#
# Feeds the hook the same JSON payload shape Claude Code delivers on PreToolUse and asserts
# the block/allow verdict per command. Needs jq (to build payloads) and nothing else: no
# install, no build, no network. Exit 0 = all cases hold.
#
# The first case is THIS repository's measured incident of 2026-08-29 (objectstack#13305)
# reproduced verbatim; it is the one case whose failure means the guard has stopped doing
# the only job it was written for.
#
# Mirrored one-for-one from objectstack's self-test of the same name alongside the hook, so
# the two repos' guards cannot drift; only example paths are localised.

set -uo pipefail

here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
hook="$here/guard-tree-enum.sh"
pass=0
fail=0

command -v jq >/dev/null 2>&1 || { echo "selftest needs jq to build payloads" >&2; exit 1; }

# verdict <command> [env assignments…] -> prints "block" or "allow"
verdict() {
local cmd="$1"; shift
local payload out rc
payload="$(jq -nc --arg c "$cmd" '{tool_name:"Bash",tool_input:{command:$c}}')"
out="$(printf '%s' "$payload" | env "$@" "$hook" 2>/dev/null)"
rc=$?
case "$rc" in
0) printf 'allow' ;;
2) printf 'block' ;;
*) printf 'exit%s' "$rc" ;;
esac
}

expect() { # expect <block|allow> <command> [env…]
local want="$1" cmd="$2"; shift 2
local got; got="$(verdict "$cmd" "$@")"
if [ "$got" = "$want" ]; then
pass=$((pass + 1)); printf ' ok %-5s %s\n' "$got" "$cmd"
else
fail=$((fail + 1)); printf ' FAIL want=%s got=%s %s\n' "$want" "$got" "$cmd"
fi
}

echo "== THE MEASURED SIGNATURE: working-tree list + origin/main read in one command =="
# objectui, 2026-08-29 — the loop that reported "no workflow subscribes ready_for_review"
expect block 'for f in .github/workflows/*.yml; do git show "origin/main:$f" | grep -q ready_for_review && echo "$f"; done'
expect block 'for f in .github/workflows/*.yml; do git show origin/main:$f; done'
expect block 'ls .github/workflows/*.yml | while read f; do git show "origin/main:$f"; done'
expect block 'for f in scripts/*.mjs; do git cat-file -e "origin/main:$f" || echo missing; done'
expect block 'find .github/workflows -name "*.yml" | while read f; do git show "origin/main:$f"; done'
expect block 'for f in packages/components/src/*.ts; do git grep -q PATTERN origin/main -- "$f"; done'

echo "== reached through separators, env prefixes and git -C =="
expect block 'cd /home/user/objectui && for f in .claude/hooks/*.sh; do git show "origin/main:$f"; done'
expect block 'for f in docs/adr/*.md; do git -C . show "origin/main:$f" | head -1; done'
expect block 'NODE_OPTIONS=--max-old-space-size=4096 ls scripts/*.mjs | xargs -I{} git show origin/main:{}'

echo "== THE CANONICAL IDIOM is never blocked, however it then reads =="
expect allow 'git ls-tree --name-only origin/main .github/workflows/'
expect allow 'for f in $(git ls-tree --name-only origin/main .github/workflows/); do git show "origin/main:$f"; done'
expect allow 'git ls-tree -r --name-only origin/main scripts/ | while read f; do git show "origin/main:$f"; done'
echo "-- the population/read cross-check the block message recommends must not itself block --"
expect allow 'git ls-tree --name-only origin/main .github/workflows/ | wc -l; ls .github/workflows/* | wc -l; git show origin/main:AGENTS.md | head -1'

echo "== EITHER HALF ALONE is ordinary and correct =="
echo "-- (a) working-tree enumeration with no origin/main read --"
expect allow 'ls .github/workflows/*.yml'
expect allow 'for f in packages/*/package.json; do jq -r .name "$f"; done'
expect allow 'find scripts -name "*.mjs" | wc -l'
expect allow 'for f in .claude/hooks/*.sh; do bash -n "$f"; done'
echo "-- (b) origin/main read with no working-tree enumeration --"
expect allow 'git show origin/main:AGENTS.md | wc -l'
expect allow 'git grep -n ready_for_review origin/main'
expect allow 'git show "origin/main:.github/workflows/governed-surface-guard.yml"'
expect allow 'git cat-file -e origin/main:.github/workflows/ci.yml'
expect allow 'git diff origin/main -- .github/workflows/'

echo "== a LOCAL ref is not the hazard this guard is about =="
expect allow 'for f in .github/workflows/*.yml; do git show "HEAD:$f"; done'
expect allow 'for f in .github/workflows/*.yml; do git show "$BASE:$f"; done'

echo "== writing ABOUT the defect must not trip the guard =="
expect allow 'grep -n "git show origin/main:" AGENTS.md'
expect allow 'grep -rn "for f in .github/workflows/\*.yml" .claude/hooks/'
expect allow 'echo "never feed a working-tree glob into git show origin/main:"'
expect allow 'git grep -n "ls-tree --name-only origin/main"'
expect allow 'cat .claude/hooks/guard-tree-enum.sh'

echo "== unrelated commands are untouched =="
expect allow 'pnpm --filter @object-ui/components test'
expect allow 'git status'
expect allow 'node scripts/check-changeset-presence.mjs'
expect allow 'git worktree add ../objectui-issue-13305 -b claude/issue-13305 origin/main'

echo "== the deliberate exception releases it =="
expect allow 'for f in .github/workflows/*.yml; do git show "origin/main:$f"; done' OS_ALLOW_TREE_ENUM=1

echo "== fails OPEN on payloads it cannot parse =="
printf '%s' '{"tool_name":"Bash","tool_input":{}}' | "$hook" >/dev/null 2>&1
if [ $? -eq 0 ]; then pass=$((pass + 1)); printf ' ok allow <no command in payload>\n'
else fail=$((fail + 1)); printf ' FAIL want=allow <no command in payload>\n'; fi
printf '%s' 'not json at all' | "$hook" >/dev/null 2>&1
if [ $? -eq 0 ]; then pass=$((pass + 1)); printf ' ok allow <malformed payload>\n'
else fail=$((fail + 1)); printf ' FAIL want=allow <malformed payload>\n'; fi

echo
echo "guard-tree-enum selftest: $pass passed, $fail failed"
[ "$fail" -eq 0 ] || exit 1
exit 0
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(hooks): guard the origin/main ENUMERATION half, and record the incident in AGENTS.md by claude[bot] · Pull Request #6908 · objectstack-ai/objectui · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
115 changes: 115 additions & 0 deletions .claude/hooks/guard-tree-enum.selftest.sh
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,115 @@
#!/usr/bin/env bash
# Self-test for guard-tree-enum.sh — run it after touching that hook:
#
# .claude/hooks/guard-tree-enum.selftest.sh
#
# Feeds the hook the same JSON payload shape Claude Code delivers on PreToolUse and asserts
# the block/allow verdict per command. Needs jq (to build payloads) and nothing else: no
# install, no build, no network. Exit 0 = all cases hold.
#
# The first case is THIS repository's measured incident of 2026-08-29 (objectstack#13305)
# reproduced verbatim; it is the one case whose failure means the guard has stopped doing
# the only job it was written for.
#
# Mirrored one-for-one from objectstack's self-test of the same name alongside the hook, so
# the two repos' guards cannot drift; only example paths are localised.

set -uo pipefail

here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
hook="$here/guard-tree-enum.sh"
pass=0
fail=0

command -v jq >/dev/null 2>&1 || { echo "selftest needs jq to build payloads" >&2; exit 1; }

# verdict <command> [env assignments…] -> prints "block" or "allow"
verdict() {
local cmd="$1"; shift
local payload out rc
payload="$(jq -nc --arg c "$cmd" '{tool_name:"Bash",tool_input:{command:$c}}')"
out="$(printf '%s' "$payload" | env "$@" "$hook" 2>/dev/null)"
rc=$?
case "$rc" in
0) printf 'allow' ;;
2) printf 'block' ;;
*) printf 'exit%s' "$rc" ;;
esac
}

expect() { # expect <block|allow> <command> [env…]
local want="$1" cmd="$2"; shift 2
local got; got="$(verdict "$cmd" "$@")"
if [ "$got" = "$want" ]; then
pass=$((pass + 1)); printf ' ok %-5s %s\n' "$got" "$cmd"
else
fail=$((fail + 1)); printf ' FAIL want=%s got=%s %s\n' "$want" "$got" "$cmd"
fi
}

echo "== THE MEASURED SIGNATURE: working-tree list + origin/main read in one command =="
# objectui, 2026-08-29 — the loop that reported "no workflow subscribes ready_for_review"
expect block 'for f in .github/workflows/*.yml; do git show "origin/main:$f" | grep -q ready_for_review && echo "$f"; done'
expect block 'for f in .github/workflows/*.yml; do git show origin/main:$f; done'
expect block 'ls .github/workflows/*.yml | while read f; do git show "origin/main:$f"; done'
expect block 'for f in scripts/*.mjs; do git cat-file -e "origin/main:$f" || echo missing; done'
expect block 'find .github/workflows -name "*.yml" | while read f; do git show "origin/main:$f"; done'
expect block 'for f in packages/components/src/*.ts; do git grep -q PATTERN origin/main -- "$f"; done'

echo "== reached through separators, env prefixes and git -C =="
expect block 'cd /home/user/objectui && for f in .claude/hooks/*.sh; do git show "origin/main:$f"; done'
expect block 'for f in docs/adr/*.md; do git -C . show "origin/main:$f" | head -1; done'
expect block 'NODE_OPTIONS=--max-old-space-size=4096 ls scripts/*.mjs | xargs -I{} git show origin/main:{}'

echo "== THE CANONICAL IDIOM is never blocked, however it then reads =="
expect allow 'git ls-tree --name-only origin/main .github/workflows/'
expect allow 'for f in $(git ls-tree --name-only origin/main .github/workflows/); do git show "origin/main:$f"; done'
expect allow 'git ls-tree -r --name-only origin/main scripts/ | while read f; do git show "origin/main:$f"; done'
echo "-- the population/read cross-check the block message recommends must not itself block --"
expect allow 'git ls-tree --name-only origin/main .github/workflows/ | wc -l; ls .github/workflows/* | wc -l; git show origin/main:AGENTS.md | head -1'

echo "== EITHER HALF ALONE is ordinary and correct =="
echo "-- (a) working-tree enumeration with no origin/main read --"
expect allow 'ls .github/workflows/*.yml'
expect allow 'for f in packages/*/package.json; do jq -r .name "$f"; done'
expect allow 'find scripts -name "*.mjs" | wc -l'
expect allow 'for f in .claude/hooks/*.sh; do bash -n "$f"; done'
echo "-- (b) origin/main read with no working-tree enumeration --"
expect allow 'git show origin/main:AGENTS.md | wc -l'
expect allow 'git grep -n ready_for_review origin/main'
expect allow 'git show "origin/main:.github/workflows/governed-surface-guard.yml"'
expect allow 'git cat-file -e origin/main:.github/workflows/ci.yml'
expect allow 'git diff origin/main -- .github/workflows/'

echo "== a LOCAL ref is not the hazard this guard is about =="
expect allow 'for f in .github/workflows/*.yml; do git show "HEAD:$f"; done'
expect allow 'for f in .github/workflows/*.yml; do git show "$BASE:$f"; done'

echo "== writing ABOUT the defect must not trip the guard =="
expect allow 'grep -n "git show origin/main:" AGENTS.md'
expect allow 'grep -rn "for f in .github/workflows/\*.yml" .claude/hooks/'
expect allow 'echo "never feed a working-tree glob into git show origin/main:"'
expect allow 'git grep -n "ls-tree --name-only origin/main"'
expect allow 'cat .claude/hooks/guard-tree-enum.sh'

echo "== unrelated commands are untouched =="
expect allow 'pnpm --filter @object-ui/components test'
expect allow 'git status'
expect allow 'node scripts/check-changeset-presence.mjs'
expect allow 'git worktree add ../objectui-issue-13305 -b claude/issue-13305 origin/main'

echo "== the deliberate exception releases it =="
expect allow 'for f in .github/workflows/*.yml; do git show "origin/main:$f"; done' OS_ALLOW_TREE_ENUM=1

echo "== fails OPEN on payloads it cannot parse =="
printf '%s' '{"tool_name":"Bash","tool_input":{}}' | "$hook" >/dev/null 2>&1
if [ $? -eq 0 ]; then pass=$((pass + 1)); printf ' ok allow <no command in payload>\n'
else fail=$((fail + 1)); printf ' FAIL want=allow <no command in payload>\n'; fi
printf '%s' 'not json at all' | "$hook" >/dev/null 2>&1
if [ $? -eq 0 ]; then pass=$((pass + 1)); printf ' ok allow <malformed payload>\n'
else fail=$((fail + 1)); printf ' FAIL want=allow <malformed payload>\n'; fi

echo
echo "guard-tree-enum selftest: $pass passed, $fail failed"
[ "$fail" -eq 0 ] || exit 1
exit 0
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); feat(hooks): guard the origin/main ENUMERATION half, and record the incident in AGENTS.md by claude[bot] · Pull Request #6908 · objectstack-ai/objectui · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
115 changes: 115 additions & 0 deletions .claude/hooks/guard-tree-enum.selftest.sh
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,115 @@
#!/usr/bin/env bash
# Self-test for guard-tree-enum.sh — run it after touching that hook:
#
# .claude/hooks/guard-tree-enum.selftest.sh
#
# Feeds the hook the same JSON payload shape Claude Code delivers on PreToolUse and asserts
# the block/allow verdict per command. Needs jq (to build payloads) and nothing else: no
# install, no build, no network. Exit 0 = all cases hold.
#
# The first case is THIS repository's measured incident of 2026-08-29 (objectstack#13305)
# reproduced verbatim; it is the one case whose failure means the guard has stopped doing
# the only job it was written for.
#
# Mirrored one-for-one from objectstack's self-test of the same name alongside the hook, so
# the two repos' guards cannot drift; only example paths are localised.

set -uo pipefail

here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
hook="$here/guard-tree-enum.sh"
pass=0
fail=0

command -v jq >/dev/null 2>&1 || { echo "selftest needs jq to build payloads" >&2; exit 1; }

# verdict <command> [env assignments…] -> prints "block" or "allow"
verdict() {
local cmd="$1"; shift
local payload out rc
payload="$(jq -nc --arg c "$cmd" '{tool_name:"Bash",tool_input:{command:$c}}')"
out="$(printf '%s' "$payload" | env "$@" "$hook" 2>/dev/null)"
rc=$?
case "$rc" in
0) printf 'allow' ;;
2) printf 'block' ;;
*) printf 'exit%s' "$rc" ;;
esac
}

expect() { # expect <block|allow> <command> [env…]
local want="$1" cmd="$2"; shift 2
local got; got="$(verdict "$cmd" "$@")"
if [ "$got" = "$want" ]; then
pass=$((pass + 1)); printf ' ok %-5s %s\n' "$got" "$cmd"
else
fail=$((fail + 1)); printf ' FAIL want=%s got=%s %s\n' "$want" "$got" "$cmd"
fi
}

echo "== THE MEASURED SIGNATURE: working-tree list + origin/main read in one command =="
# objectui, 2026-08-29 — the loop that reported "no workflow subscribes ready_for_review"
expect block 'for f in .github/workflows/*.yml; do git show "origin/main:$f" | grep -q ready_for_review && echo "$f"; done'
expect block 'for f in .github/workflows/*.yml; do git show origin/main:$f; done'
expect block 'ls .github/workflows/*.yml | while read f; do git show "origin/main:$f"; done'
expect block 'for f in scripts/*.mjs; do git cat-file -e "origin/main:$f" || echo missing; done'
expect block 'find .github/workflows -name "*.yml" | while read f; do git show "origin/main:$f"; done'
expect block 'for f in packages/components/src/*.ts; do git grep -q PATTERN origin/main -- "$f"; done'

echo "== reached through separators, env prefixes and git -C =="
expect block 'cd /home/user/objectui && for f in .claude/hooks/*.sh; do git show "origin/main:$f"; done'
expect block 'for f in docs/adr/*.md; do git -C . show "origin/main:$f" | head -1; done'
expect block 'NODE_OPTIONS=--max-old-space-size=4096 ls scripts/*.mjs | xargs -I{} git show origin/main:{}'

echo "== THE CANONICAL IDIOM is never blocked, however it then reads =="
expect allow 'git ls-tree --name-only origin/main .github/workflows/'
expect allow 'for f in $(git ls-tree --name-only origin/main .github/workflows/); do git show "origin/main:$f"; done'
expect allow 'git ls-tree -r --name-only origin/main scripts/ | while read f; do git show "origin/main:$f"; done'
echo "-- the population/read cross-check the block message recommends must not itself block --"
expect allow 'git ls-tree --name-only origin/main .github/workflows/ | wc -l; ls .github/workflows/* | wc -l; git show origin/main:AGENTS.md | head -1'

echo "== EITHER HALF ALONE is ordinary and correct =="
echo "-- (a) working-tree enumeration with no origin/main read --"
expect allow 'ls .github/workflows/*.yml'
expect allow 'for f in packages/*/package.json; do jq -r .name "$f"; done'
expect allow 'find scripts -name "*.mjs" | wc -l'
expect allow 'for f in .claude/hooks/*.sh; do bash -n "$f"; done'
echo "-- (b) origin/main read with no working-tree enumeration --"
expect allow 'git show origin/main:AGENTS.md | wc -l'
expect allow 'git grep -n ready_for_review origin/main'
expect allow 'git show "origin/main:.github/workflows/governed-surface-guard.yml"'
expect allow 'git cat-file -e origin/main:.github/workflows/ci.yml'
expect allow 'git diff origin/main -- .github/workflows/'

echo "== a LOCAL ref is not the hazard this guard is about =="
expect allow 'for f in .github/workflows/*.yml; do git show "HEAD:$f"; done'
expect allow 'for f in .github/workflows/*.yml; do git show "$BASE:$f"; done'

echo "== writing ABOUT the defect must not trip the guard =="
expect allow 'grep -n "git show origin/main:" AGENTS.md'
expect allow 'grep -rn "for f in .github/workflows/\*.yml" .claude/hooks/'
expect allow 'echo "never feed a working-tree glob into git show origin/main:"'
expect allow 'git grep -n "ls-tree --name-only origin/main"'
expect allow 'cat .claude/hooks/guard-tree-enum.sh'

echo "== unrelated commands are untouched =="
expect allow 'pnpm --filter @object-ui/components test'
expect allow 'git status'
expect allow 'node scripts/check-changeset-presence.mjs'
expect allow 'git worktree add ../objectui-issue-13305 -b claude/issue-13305 origin/main'

echo "== the deliberate exception releases it =="
expect allow 'for f in .github/workflows/*.yml; do git show "origin/main:$f"; done' OS_ALLOW_TREE_ENUM=1

echo "== fails OPEN on payloads it cannot parse =="
printf '%s' '{"tool_name":"Bash","tool_input":{}}' | "$hook" >/dev/null 2>&1
if [ $? -eq 0 ]; then pass=$((pass + 1)); printf ' ok allow <no command in payload>\n'
else fail=$((fail + 1)); printf ' FAIL want=allow <no command in payload>\n'; fi
printf '%s' 'not json at all' | "$hook" >/dev/null 2>&1
if [ $? -eq 0 ]; then pass=$((pass + 1)); printf ' ok allow <malformed payload>\n'
else fail=$((fail + 1)); printf ' FAIL want=allow <malformed payload>\n'; fi

echo
echo "guard-tree-enum selftest: $pass passed, $fail failed"
[ "$fail" -eq 0 ] || exit 1
exit 0
Loading
Loading