#!/usr/bin/env bash # Install the cherry-pick triage hooks for THIS clone. # # What it does (per-clone; git never auto-adopts a repo's core.hooksPath): # 0. FIRST verify the Sea Haven global security pre-push still fires through our shim. # 1. chmod +x the hooks + scripts. # 2. git config core.hooksPath .githooks # 3. git config alias.cp -> scripts/git-cp # # Safe to run repeatedly. set -euo pipefail root="$(git rev-parse --show-toplevel)" cd "$root" global_dir="${SH_GLOBAL_HOOKS:-$HOME/.config/git/hooks}" global_pp="$global_dir/pre-push" shim="$root/.githooks/pre-push" echo "==> [1/4] Verifying the Sea Haven global security pre-push will still fire..." if [ -x "$global_pp" ]; then if [ ! -f "$shim" ]; then echo "FATAL: global security pre-push exists ($global_pp) but the shim ($shim) is MISSING." >&2 echo " Setting core.hooksPath=.githooks would SHADOW and silently disable the security" >&2 echo " gate. Refusing to install. Restore .githooks/pre-push first." >&2 exit 1 fi if ! grep -q "$global_dir" "$shim" && ! grep -q 'SH_GLOBAL_HOOKS' "$shim"; then echo "FATAL: shim ($shim) does not appear to delegate to the global hook dir. Refusing." >&2 exit 1 fi if ! grep -q 'exec "\$GLOBAL"' "$shim"; then echo "FATAL: shim ($shim) does not exec the global pre-push. Refusing." >&2 exit 1 fi echo " OK: .githooks/pre-push shim re-execs $global_pp — security gate preserved." else echo " WARN: no global security pre-push found at $global_pp." echo " If you expected the Sea Haven security gate, investigate BEFORE pushing." fi echo "==> [2/4] Marking hooks + scripts executable..." chmod +x "$root/.githooks/"* 2>/dev/null || true chmod +x "$root/scripts/git-cp" "$root/scripts/install-hooks.sh" 2>/dev/null || true echo "==> [3/4] Pointing core.hooksPath at .githooks..." git config core.hooksPath .githooks echo "==> [4/4] Installing the 'git cp' alias..." git config alias.cp '!bash "$(git rev-parse --show-toplevel)/scripts/git-cp"' echo "" echo "Done. This clone now:" echo " - journals cherry-picks (post-commit) and blocks known-rejects (commit-msg)" echo " - runs 'git cp' as the guarded cherry-pick wrapper" echo " - STILL runs the global security pre-push via the .githooks/pre-push shim"