mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 11:33:14 +00:00
57 lines
2.3 KiB
Bash
57 lines
2.3 KiB
Bash
|
|
#!/usr/bin/env bash
|
||
|
|
# Install the cherry-pick triage hooks for THIS clone.
|
||
|
|
#
|
||
|
|
# What it does (per-clone; git never auto-adopts a repo's core.hooksPath):
|
||
|
|
# 0. FIRST verify the Sea Haven global security pre-push still fires through our shim.
|
||
|
|
# 1. chmod +x the hooks + scripts.
|
||
|
|
# 2. git config core.hooksPath .githooks
|
||
|
|
# 3. git config alias.cp -> scripts/git-cp
|
||
|
|
#
|
||
|
|
# Safe to run repeatedly.
|
||
|
|
set -euo pipefail
|
||
|
|
|
||
|
|
root="$(git rev-parse --show-toplevel)"
|
||
|
|
cd "$root"
|
||
|
|
|
||
|
|
global_dir="${SH_GLOBAL_HOOKS:-$HOME/.config/git/hooks}"
|
||
|
|
global_pp="$global_dir/pre-push"
|
||
|
|
shim="$root/.githooks/pre-push"
|
||
|
|
|
||
|
|
echo "==> [1/4] Verifying the Sea Haven global security pre-push will still fire..."
|
||
|
|
if [ -x "$global_pp" ]; then
|
||
|
|
if [ ! -f "$shim" ]; then
|
||
|
|
echo "FATAL: global security pre-push exists ($global_pp) but the shim ($shim) is MISSING." >&2
|
||
|
|
echo " Setting core.hooksPath=.githooks would SHADOW and silently disable the security" >&2
|
||
|
|
echo " gate. Refusing to install. Restore .githooks/pre-push first." >&2
|
||
|
|
exit 1
|
||
|
|
fi
|
||
|
|
if ! grep -q "$global_dir" "$shim" && ! grep -q 'SH_GLOBAL_HOOKS' "$shim"; then
|
||
|
|
echo "FATAL: shim ($shim) does not appear to delegate to the global hook dir. Refusing." >&2
|
||
|
|
exit 1
|
||
|
|
fi
|
||
|
|
if ! grep -q 'exec "\$GLOBAL"' "$shim"; then
|
||
|
|
echo "FATAL: shim ($shim) does not exec the global pre-push. Refusing." >&2
|
||
|
|
exit 1
|
||
|
|
fi
|
||
|
|
echo " OK: .githooks/pre-push shim re-execs $global_pp — security gate preserved."
|
||
|
|
else
|
||
|
|
echo " WARN: no global security pre-push found at $global_pp."
|
||
|
|
echo " If you expected the Sea Haven security gate, investigate BEFORE pushing."
|
||
|
|
fi
|
||
|
|
|
||
|
|
echo "==> [2/4] Marking hooks + scripts executable..."
|
||
|
|
chmod +x "$root/.githooks/"* 2>/dev/null || true
|
||
|
|
chmod +x "$root/scripts/git-cp" "$root/scripts/install-hooks.sh" 2>/dev/null || true
|
||
|
|
|
||
|
|
echo "==> [3/4] Pointing core.hooksPath at .githooks..."
|
||
|
|
git config core.hooksPath .githooks
|
||
|
|
|
||
|
|
echo "==> [4/4] Installing the 'git cp' alias..."
|
||
|
|
git config alias.cp '!bash "$(git rev-parse --show-toplevel)/scripts/git-cp"'
|
||
|
|
|
||
|
|
echo ""
|
||
|
|
echo "Done. This clone now:"
|
||
|
|
echo " - journals cherry-picks (post-commit) and blocks known-rejects (commit-msg)"
|
||
|
|
echo " - runs 'git cp' as the guarded cherry-pick wrapper"
|
||
|
|
echo " - STILL runs the global security pre-push via the .githooks/pre-push shim"
|