mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 08:03:15 +00:00
* docs(upstream-sync): add triage ledger + cherry-pick hook plan Seeds the upstream triage ledger (52 diverged commits from langchain-ai/open-swe categorized: landed/won't-merge/deferred/untriaged) and the design plan for a git-hook mechanism to keep it in sync during cherry-picks. * feat(upstream-sync): jsonl-backed triage ledger + generator CLI triage.jsonl is now the source of truth (52 rows migrated from triage.md); triage.md is generated with a do-not-edit banner. scripts/triage.py provides migrate/generate/reconcile/lookup/check-reject/set; make triage-render/check/reconcile added (triage-check is CI-safe staleness gate). Stdlib-only so git hooks can call it. * feat(upstream-sync): cherry-pick triage git hooks + git cp wrapper post-commit journals each -x pick to an untracked .git-local journal; prepare-commit-msg hard-blocks known-reject picks (commit-msg is a secondary backstop — clean picks skip it on git 2.50.1), overridable via git cp --force / SH_CHERRYPICK_ALLOW_REJECT=1 / sh.cherrypick.blockRejects=false. git-cp is the pre-apply guard + auto-reconcile. pre-push is a SHIM that re-execs the global Sea Haven security pre-push so core.hooksPath=.githooks does not shadow it; install-hooks.sh verifies that shim FIRST and refuses if it is missing. * docs(upstream-sync): correct hook plan + git cp runbook Record the verified git 2.50.1 finding that clean cherry-picks skip commit-msg, so the block lives in prepare-commit-msg; note the locked HARD-BLOCK-by-default reject policy. CHERRYPICK.md now leads with make install-hooks + git cp and explains the generated-md ledger. * chore(upstream-sync): mark #1651 landed (Bedrock family fix on gateway-routing) * docs(upstream-sync): rewrite CHERRYPICK.md as a repo-specific runbook * feat(upstream-sync): add triage.py sync + make triage-sync Discovers commits on dev..upstream/main not yet in the ledger and appends them as untriaged (PR # and subject parsed from each commit), then bumps _meta 'last synced' to the upstream tip and regenerates triage.md. Closes the discovery side of the workflow: triage-sync to pull in new work, git cp to land it. * docs(upstream-sync): move cherry-pick runbook to PR1 branch as cherry-pick-runbook.md
56 lines
2.4 KiB
Bash
56 lines
2.4 KiB
Bash
# shellcheck shell=bash
|
|
# Shared cherry-pick reject guard. SOURCED (never executed directly) by both
|
|
# .githooks/prepare-commit-msg and .githooks/commit-msg. Git only executes files whose
|
|
# names exactly match a hook name, so this underscore-prefixed helper is ignored by git.
|
|
#
|
|
# Recovers the upstream SHA of an in-progress cherry-pick and HARD-BLOCKS (returns 1) when
|
|
# the triage ledger marks it "Won't merge". No-op for anything that is not a cherry-pick.
|
|
# Fail-safe: only a confirmed, non-overridden reject returns 1; every other path returns 0.
|
|
#
|
|
# Override an intentional re-pick with either:
|
|
# SH_CHERRYPICK_ALLOW_REJECT=1 git cherry-pick -x <sha>
|
|
# git config sh.cherrypick.blockRejects false # warn-only for this repo
|
|
|
|
sh_cherrypick_reject_guard() {
|
|
local msgfile="${1:-}"
|
|
local gd up_sha root triage py reason rc
|
|
|
|
gd="$(git rev-parse --absolute-git-dir 2>/dev/null)" || return 0
|
|
|
|
up_sha=""
|
|
if [ -f "$gd/CHERRY_PICK_HEAD" ]; then
|
|
up_sha="$(tr -d '[:space:]' <"$gd/CHERRY_PICK_HEAD" 2>/dev/null)"
|
|
fi
|
|
if [ -z "$up_sha" ] && [ -n "$msgfile" ] && [ -f "$msgfile" ]; then
|
|
up_sha="$(sed -n 's/.*cherry picked from commit \([0-9a-f]\{7,40\}\).*/\1/p' "$msgfile" | tail -1)"
|
|
fi
|
|
[ -z "$up_sha" ] && return 0 # not a cherry-pick -> no-op (normal commits untouched)
|
|
|
|
root="$(git rev-parse --show-toplevel 2>/dev/null)" || return 0
|
|
triage="$root/scripts/triage.py"
|
|
[ -f "$triage" ] || return 0
|
|
py="$(command -v python3 || command -v python 2>/dev/null)"
|
|
[ -n "$py" ] || return 0
|
|
|
|
reason="$("$py" "$triage" check-reject "$up_sha" 2>/dev/null)"
|
|
rc=$?
|
|
[ "$rc" -eq 3 ] || return 0 # rc 0 = ok; rc 2 = ledger error -> fail-safe; only rc 3 blocks
|
|
|
|
echo "" >&2
|
|
echo "sh-cherrypick: BLOCKED — ${up_sha:0:12} is marked \"Won't merge\" in the triage ledger." >&2
|
|
echo " reason: ${reason:-<none recorded>}" >&2
|
|
|
|
if [ "${SH_CHERRYPICK_ALLOW_REJECT:-}" = "1" ]; then
|
|
echo " override: SH_CHERRYPICK_ALLOW_REJECT=1 — allowing this pick." >&2
|
|
return 0
|
|
fi
|
|
if [ "$(git config --bool sh.cherrypick.blockRejects 2>/dev/null || echo true)" = "false" ]; then
|
|
echo " override: sh.cherrypick.blockRejects=false — warn-only, allowing." >&2
|
|
return 0
|
|
fi
|
|
|
|
echo " To re-evaluate intentionally: SH_CHERRYPICK_ALLOW_REJECT=1 git cherry-pick -x <sha>" >&2
|
|
echo " or repo-wide warn-only: git config sh.cherrypick.blockRejects false" >&2
|
|
echo " Recover this pick: git cherry-pick --abort (or --skip)" >&2
|
|
return 1
|
|
}
|