Skip to content

fix(hooks): run the gate from a local dependency, not npx - #688

Merged
0xPlayerOne merged 3 commits into
mainfrom
fix/local-dependency-gate
Oct 1, 2026
Merged

0xPlayerOne merged 3 commits into
mainfrom
fix/local-dependency-gate

Conversation

@0xPlayerOne

@0xPlayerOne 0xPlayerOne commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Follow-up to #684, which shipped in 1.39.2 and does not work.

Two defects, both observed

The gate's exit status was discarded.

if command -v npx >/dev/null 2>&1 && npx --yes code-foundry@1.39.2 pre-commit; then
  exit 0
fi

git diff --cached --check

The gate itself exits 1 correctly. A failing gate took the if as false,
fell through to the whitespace check, passed, and the commit landed. Caught
in this repository: a commit carrying an unused import ran the hook, which
printed the oxlint finding, and the commit still succeeded.

The fleet paid for it on every commit. fleet-manifest.mjs:491 sets
core.hooksPath and chmods the hook executable in every managed consumer
worktree, so the npx invocation ran in each of them — and it broke the
fleet upgrade test (test/fleet-manifest.test.mjs, 2/2 with the change,
0/2 without).

The fix

The hook prefers a runtime the repository already depends on:

  1. node_modules/.bin/code-foundry
  2. a vendored src/runtime.mjs

Nothing is fetched at commit time. A repository opts into the gate by
depending on code-foundry; one that does not keeps the whitespace guard and
stays offline. The fallback is last, so a failing gate can no longer be
swallowed.

This also resolves the concern that the hook was injected into every
consumer as noise: with no dependency present it does one
git diff --cached --check and exits.

Tests

Four, all hermetic and no network:

  • no npx or registry reference in the generated hook
  • a depended-on gate exiting 7 fails the commit with status 7
  • with no dependency, a clean commit passes
  • with no dependency, trailing whitespace still blocks

The exit-status test is the regression guard: it fails against the 1.39.2
template and passes here.

Verification

566 tests pass, 0 fail. Lint, format, and type-check clean.

The 1.39.2 hook shelled to `npx --yes code-foundry@<version>` on every
commit. Two problems, both observed rather than anticipated:

- The gate's exit status was discarded. `if npx ...; then exit 0; fi`
  followed by an unconditional `git diff --cached --check` meant a failing
  gate fell through to the fallback and the commit went through. In this
  repository a commit carrying an unused import passed the hook, which
  printed the oxlint finding and landed anyway.
- `fleet-manifest.mjs` installs `core.hooksPath` and makes the hook
  executable in every managed consumer worktree, so the npx call ran on
  every commit in every fleet worktree, and broke the fleet upgrade test.

The hook now prefers a runtime the repository already depends on:
`node_modules/.bin/code-foundry`, then a vendored `src/runtime.mjs`. Nothing
is fetched at commit time. A repository opts into the gate by depending on
code-foundry; one that does not keeps the whitespace guard and stays
offline. The fallback is last, so a failing gate can no longer be swallowed.

Four tests, all hermetic: no npx or registry reference; a depended-on gate
that exits 7 fails the commit; no dependency falls back to the whitespace
guard; and that guard still blocks trailing whitespace.
@0xPlayerOne 0xPlayerOne changed the title fix: local-dependency-gate fix(hooks): run the gate from a local dependency, not npx Oct 1, 2026
@0xPlayerOne
0xPlayerOne marked this pull request as ready for review October 1, 2026 19:21
@0xPlayerOne
0xPlayerOne merged commit d256b69 into main Oct 1, 2026
23 checks passed
@0xPlayerOne
0xPlayerOne deleted the fix/local-dependency-gate branch October 1, 2026 19:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant