Skip to content

hooks: pre-commit trusts a PATH tri only if it has hooks pre-commit (#6009) - #6011

Open
gHashTag wants to merge 1 commit into
masterfrom
hooks-foreign-tri
Open

gHashTag wants to merge 1 commit into
masterfrom
hooks-foreign-tri

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Closes #6009. Refs #5933.

What was wrong

.githooks/pre-commit looks for target/{debug,release}/tri and, failing that, ran whatever command -v tri named. tri is a common name. On the owner's machine PATH held two other programs:

PATH entry what it is answer to tri hooks pre-commit
~/.local/bin/tri an ops script unknown command: hooks, exit 1
~/.cargo/bin/tri an April tri build without hooks clap error, exit 2

Only 5 of 38 checkouts on that machine have a local build. Once core.hooksPath pointed at .githooks, every commit in the other 33 was refused by a message that named no defect in the commit.

The change

  • A PATH tri is used only if tri hooks pre-commit --help answers 0. That is the help of the exact subcommand the hook runs, and asking for help runs no gate. Otherwise the hook prints note: <path> is not this repository's tri ...; not used.
  • With no usable tri, the conflict-marker gate still runs: python3 tools/check_conflict_markers.py --staged, the same script and operand tri calls. Exit 1 refuses; any other non-zero prints "could NOT RUN" and refuses, as through tri. The note now says that the census and fix( gates did not run, instead of "nothing was checked". If python3 or the script is missing, it says markers were not checked either and lets the commit through, as before.
  • scripts/ci/test_pre_commit_hook_ignores_a_foreign_tri.py checks this in a fixture repository with its own PATH, so the machine's own tri copies cannot change the answer. It runs in loop-tools-gate.yml's no-compiler job, and that workflow's paths: now include .githooks/pre-commit and tools/check_conflict_markers.py.

Evidence

  • New hook: 17 of 17 checks ok.
  • Negative control: --hook pointed at master's hook. 14 of 17 checks fail by name, for example calls: ['hooks pre-commit'] and exit 1: unknown command: hooks (tri help). The 3 that pass are the controls: this repository's tri on PATH is still used, and still blocks when it says no.
  • Live run on the real PATH, which still has ~/.local/bin/tri. A clean index gives exit 0 and the notes above. A staged conflict marker gives carrying a conflict marker 1, exit 1.
  • tri census pin --gate: one census moved. In shell, run: steps went 264 -> 265 and the runner does 243 -> 244; that is the one new step. Re-blessed in the same commit.
  • check_pr_branch_filters.py CLEAN, loop-tools-tracked.sh PASS, ASCII only.

Seen, not fixed here

fix_carries_source() in cli/tri/src/hooks.rs reads git log -1 HEAD, which is the previous commit, not the one being made. That is a separate change to tri's Rust (see #6009).

🤖 Generated with Claude Code

…loses #6009)

With no target/*/tri the hook ran whatever `command -v tri` named. Two
unrelated `tri` programs on one machine (an ops script, exit 1; an April
build without `hooks`, exit 2) each refused every commit in an unbuilt
checkout once core.hooksPath pointed at .githooks.

- A PATH tri is used only if `tri hooks pre-commit --help` answers 0;
  otherwise the hook says it was not used.
- With no usable tri the conflict-marker gate still runs (python3
  tools/check_conflict_markers.py --staged, same exit vocabulary), and the
  note says the census and fix( gates did not run.
- scripts/ci/test_pre_commit_hook_ignores_a_foreign_tri.py: 17 checks in a
  fixture repository with its own PATH. Against master's hook 14 of them
  fail by name (negative control); the 3 that pass are the controls that
  this repository's tri is still used and still blocks.
- loop-tools-gate.yml runs it (no compiler needed) and its paths: filters
  now include .githooks/pre-commit and tools/check_conflict_markers.py.

Census moved: shell `run: steps` 264 -> 265 and `the runner does` 243 ->
244, the one new loop-tools-gate step. Re-blessed here.

Refs #5933

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-04 10:53:05 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 42
PRs with All Checks Green 8
READY 3
FAILING 42
PENDING 0
NO CHECKS YET 0

These columns do not partition: 3 + 42 + 0 + 0 = 45, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=d7588f739847 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

This was referenced Oct 4, 2026
This was referenced Oct 4, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

pre-commit runs a foreign tri from PATH and refuses every commit in an unbuilt checkout

1 participant