open-swe/scripts/install-hooks.sh
Adam Moussa dfdd41879c
feat(infra): upstream-sync triage ledger, cherry-pick hooks, and git cp (#118)
* docs(upstream-sync): add triage ledger + cherry-pick hook plan

Seeds the upstream triage ledger (52 diverged commits from langchain-ai/open-swe
categorized: landed/won't-merge/deferred/untriaged) and the design plan for a
git-hook mechanism to keep it in sync during cherry-picks.

* feat(upstream-sync): jsonl-backed triage ledger + generator CLI

triage.jsonl is now the source of truth (52 rows migrated from triage.md);
triage.md is generated with a do-not-edit banner. scripts/triage.py provides
migrate/generate/reconcile/lookup/check-reject/set; make triage-render/check/reconcile
added (triage-check is CI-safe staleness gate). Stdlib-only so git hooks can call it.

* feat(upstream-sync): cherry-pick triage git hooks + git cp wrapper

post-commit journals each -x pick to an untracked .git-local journal; prepare-commit-msg
hard-blocks known-reject picks (commit-msg is a secondary backstop — clean picks skip it on
git 2.50.1), overridable via git cp --force / SH_CHERRYPICK_ALLOW_REJECT=1 /
sh.cherrypick.blockRejects=false. git-cp is the pre-apply guard + auto-reconcile. pre-push is
a SHIM that re-execs the global Sea Haven security pre-push so core.hooksPath=.githooks does
not shadow it; install-hooks.sh verifies that shim FIRST and refuses if it is missing.

* docs(upstream-sync): correct hook plan + git cp runbook

Record the verified git 2.50.1 finding that clean cherry-picks skip commit-msg, so the block
lives in prepare-commit-msg; note the locked HARD-BLOCK-by-default reject policy. CHERRYPICK.md
now leads with make install-hooks + git cp and explains the generated-md ledger.

* chore(upstream-sync): mark #1651 landed (Bedrock family fix on gateway-routing)

* docs(upstream-sync): rewrite CHERRYPICK.md as a repo-specific runbook

* feat(upstream-sync): add triage.py sync + make triage-sync

Discovers commits on dev..upstream/main not yet in the ledger and appends them
as untriaged (PR # and subject parsed from each commit), then bumps _meta
'last synced' to the upstream tip and regenerates triage.md. Closes the
discovery side of the workflow: triage-sync to pull in new work, git cp to land it.

* docs(upstream-sync): move cherry-pick runbook to PR1 branch as cherry-pick-runbook.md
2026-07-03 11:46:00 -04:00

56 lines
2.3 KiB
Bash
Executable file

#!/usr/bin/env bash
# Install the cherry-pick triage hooks for THIS clone.
#
# What it does (per-clone; git never auto-adopts a repo's core.hooksPath):
# 0. FIRST verify the Sea Haven global security pre-push still fires through our shim.
# 1. chmod +x the hooks + scripts.
# 2. git config core.hooksPath .githooks
# 3. git config alias.cp -> scripts/git-cp
#
# Safe to run repeatedly.
set -euo pipefail
root="$(git rev-parse --show-toplevel)"
cd "$root"
global_dir="${SH_GLOBAL_HOOKS:-$HOME/.config/git/hooks}"
global_pp="$global_dir/pre-push"
shim="$root/.githooks/pre-push"
echo "==> [1/4] Verifying the Sea Haven global security pre-push will still fire..."
if [ -x "$global_pp" ]; then
if [ ! -f "$shim" ]; then
echo "FATAL: global security pre-push exists ($global_pp) but the shim ($shim) is MISSING." >&2
echo " Setting core.hooksPath=.githooks would SHADOW and silently disable the security" >&2
echo " gate. Refusing to install. Restore .githooks/pre-push first." >&2
exit 1
fi
if ! grep -q "$global_dir" "$shim" && ! grep -q 'SH_GLOBAL_HOOKS' "$shim"; then
echo "FATAL: shim ($shim) does not appear to delegate to the global hook dir. Refusing." >&2
exit 1
fi
if ! grep -q 'exec "\$GLOBAL"' "$shim"; then
echo "FATAL: shim ($shim) does not exec the global pre-push. Refusing." >&2
exit 1
fi
echo " OK: .githooks/pre-push shim re-execs $global_pp — security gate preserved."
else
echo " WARN: no global security pre-push found at $global_pp."
echo " If you expected the Sea Haven security gate, investigate BEFORE pushing."
fi
echo "==> [2/4] Marking hooks + scripts executable..."
chmod +x "$root/.githooks/"* 2>/dev/null || true
chmod +x "$root/scripts/git-cp" "$root/scripts/install-hooks.sh" 2>/dev/null || true
echo "==> [3/4] Pointing core.hooksPath at .githooks..."
git config core.hooksPath .githooks
echo "==> [4/4] Installing the 'git cp' alias..."
git config alias.cp '!bash "$(git rev-parse --show-toplevel)/scripts/git-cp"'
echo ""
echo "Done. This clone now:"
echo " - journals cherry-picks (post-commit) and blocks known-rejects (commit-msg)"
echo " - runs 'git cp' as the guarded cherry-pick wrapper"
echo " - STILL runs the global security pre-push via the .githooks/pre-push shim"