Skip to content

fix: make trust hashing portable and fail closed - #3

Merged
ddullah merged 1 commit into
mainfrom
codex/TE-7sebjb-hash-portability
Sep 7, 2026
Merged

ddullah merged 1 commit into
mainfrom
codex/TE-7sebjb-hash-portability

Conversation

@ddullah

@ddullah ddullah commented Sep 7, 2026

Copy link
Copy Markdown

PowerShell launches GTR through non-login Git Bash, which provides sha256sum but does not expose shasum. The old shasum | cut pipelines could return an empty digest with success, skip trusted hooks, and report a successful trust grant without a usable marker.

Use a shared SHA-256 helper that preserves existing keys, chooses an available executable, and rejects failed or invalid output. Propagate post-write verification errors without announcing success. An explicitly approved marker remains valid after the hasher recovers; initial hashing failures create no marker.

Validation covers actual CLI trust/worktree creation with isolated PATHs, missing/failing/malformed hash executables, retained-marker recovery, and legacy key compatibility. Baseline mutation fails the five new regression cases. ShellCheck 0.10.0 and Bash syntax checks pass. Read-only verification also confirmed that the existing Windows production marker is recognized unchanged by the repaired non-login shell.

Complete BATS regression suite on current v2.11.0 base264c6fda96679a0a0982bd62f30245ea69e4b799: 557 passed, four optional Fish/Zsh runtime tests skipped because those shells are absent; all 30 test files exited zero. All six hash regression scenarios ran and passed.

Bead: TE-7sebjb. BMAD Build Auto implementation and four review lenses completed. Parent submodule publication and installed activation follow this fork release; generated interactive shell init wrappers retain a separately tracked portability residual.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-07T00:38:29.380976Z 960808e PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@ddullah
ddullah merged commit 11a06a8 into main Sep 7, 2026
5 checks passed
ddullah added a commit that referenced this pull request Sep 28, 2026
* Detect and recover locked worktree entries with missing directories (coderabbitai#182)

git worktree prune skips locked entries by design, so a locked worktree
whose directory was deleted (e.g. a crashed agent session) lingers in the
registry and keeps its branch checked out. clean now detects this, offers
to unlock and prune (auto-confirmed by --force/--yes, previewed by
--dry-run), and prints the manual recovery command when declined.

* feat(clean): support closed PR cleanup (coderabbitai#183)

* feat(clean): support closed PR cleanup

Assisted-by: pi:gpt-5.5
Co-authored-by: chatgpt-codex-connector[bot] <199175422+chatgpt-codex-connector[bot]@users.noreply.github.com>

* fix(clean): address closed cleanup review nits

Assisted-by: pi:gpt-5.5
Co-authored-by: chatgpt-codex-connector[bot] <199175422+chatgpt-codex-connector[bot]@users.noreply.github.com>

* fix(clean): match GitLab head_sha fallback

Assisted-by: pi:gpt-5.5
Co-authored-by: chatgpt-codex-connector[bot] <199175422+chatgpt-codex-connector[bot]@users.noreply.github.com>

---------

Co-authored-by: chatgpt-codex-connector[bot] <199175422+chatgpt-codex-connector[bot]@users.noreply.github.com>

* Release v2.8.0

* Replace Homebrew bump action with direct formula update (coderabbitai#184)

* Replace Homebrew bump action with direct formula update

* Allow manual formula bump via workflow_dispatch

* Return non-zero when git gtr rm fails (coderabbitai#190)

* Fix rm exit status on removal failures

* Test public rm failure status

* chore: prepare v2.8.1 release

* fix(copy): bound includeDirs discovery (coderabbitai#191)

* fix(copy): bound includeDirs discovery

* test(copy): allow filesystem result order

* fix(copy): preserve basename fallback

* chore: prepare v2.8.2 release

* feat: inherit sparse-checkout in new worktrees (coderabbitai#186)

* feat: inherit sparse-checkout in new worktrees

When creating a new worktree from one with sparse-checkout enabled,
the new worktree inherits the cone pattern automatically. Controlled
by gtr.sparse.inherit config (default on) and --sparse/--no-sparse
flags. Adds reusable helpers for sparse-checkout replication.

* fix(sparse): address CodeRabbit review feedback on sparse-checkout inheritance

- Preserve slash-separated branch paths in _worktree_path_for_ref
- Allow fallback to top-level worktree when matching worktree is not sparse
- Add Git 2.25+ guard for sparse-checkout support with full checkout fallback
- Fix non-cone mode to use init --no-cone (git defaults to cone mode)
- Improve error handling: failed sparse inheritance now falls back to full
  checkout and hard-errors if that fails, instead of leaving --no-checkout
  worktree empty
- Add tests for slash refs, non-cone inheritance, and sparse config precedence

* fix: harden sparse-checkout inheritance

* fix: support pre-2.20 config lookup

* fix: align sparse sources with git refs

---------

Co-authored-by: Tom Elizaga <tom.elizaga@gmail.com>

* Add PR worktree checkout command (coderabbitai#187)

* feat: add pull request worktree command

Assisted-by: pi:gpt-5.5
Co-authored-by: chatgpt-codex-connector[bot] <199175422+chatgpt-codex-connector[bot]@users.noreply.github.com>

* fix: make pr worktrees gh-aware

Assisted-by: pi:gpt-5.5
Co-authored-by: chatgpt-codex-connector[bot] <199175422+chatgpt-codex-connector[bot]@users.noreply.github.com>

* fix: harden pr worktree checkout

Assisted-by: pi:gpt-5.5
Co-authored-by: chatgpt-codex-connector[bot] <199175422+chatgpt-codex-connector[bot]@users.noreply.github.com>

* fix: address pr review feedback

Assisted-by: pi:gpt-5.5
Co-authored-by: chatgpt-codex-connector[bot] <199175422+chatgpt-codex-connector[bot]@users.noreply.github.com>

---------

Co-authored-by: chatgpt-codex-connector[bot] <199175422+chatgpt-codex-connector[bot]@users.noreply.github.com>
Co-authored-by: Tom Elizaga <tom.elizaga@gmail.com>

* Run CI on fork pull requests (coderabbitai#185)

* Run CI on fork pull requests

* fix(ci): minimize fork pull request permissions

* chore: prepare v2.9.0 release

* feat: add machine-readable worktree creation for agents (coderabbitai#192)

Adds stable porcelain output and hook disposition reporting for shell-native agent integrations, with tests and documentation.

* chore: prepare v2.10.0 release

* Refresh editor and AI adapter guidance (coderabbitai#193)

* Refresh editor and AI adapter guidance

* Address PR review: mark legacy adapter rows

* chore: prepare v2.11.0 release

* Use preinstalled ShellCheck in CI (coderabbitai#194)

ci: use preinstalled ShellCheck

* docs: add maintainers section to README (coderabbitai#195)

The repository has a CODEOWNERS entry but nothing in the README identifies
who maintains the project, so anyone landing on it has to check the
contributors graph to find out.

Also links the contributor list, since much of the adapter, platform and
shell-integration surface came from outside contributions.

* fix: make GTR_DEBUG actually report the failing location (coderabbitai#199)

bin/git-gtr installed an ERR trap when GTR_DEBUG was set but ran under 'set -e' alone. An ERR trap is inherited by functions, command substitutions and subshells only under 'set -E', and every command runs inside main() and a cmd_* handler, so the trap never fired.

Switch the option line to 'set -eE'. With no ERR trap installed the option has no effect, so the default path is unchanged.

Adds tests/debug_trap.bats covering the function and subshell contexts, plus silence on success, on a handled error path, and when GTR_DEBUG is unset.

* docs: refresh agent guides, README flags, and troubleshooting for v2.11 (coderabbitai#197)

Brings AGENTS.md, CLAUDE.md, README and the docs/ pages in line with what shipped in v2.9 through v2.11.

Fixes two errors: AGENTS.md pointed at a nonexistent adapters/ai/Codex.sh, and docs/troubleshooting.md told users to run 'bash -x git gtr', which cannot work because git is a binary. The architecture diagram there also had bin/git-gtr and bin/gtr the wrong way round.

Adds --sparse/--no-sparse to the README, the missing GTR_* fallback variables and the direct-read variables to docs/configuration.md, and a side-effect section to docs/agent-usage.md. AGENTS.md and CLAUDE.md now cover pr, trust, clean --closed, sparse inheritance, postCd dispatch and the current test layout.

* docs: rewrite Copilot instructions and align contributor guides with the current layout (coderabbitai#198)

The Copilot instructions predated the lib/ modularization: they described bin/gtr as a 961-line monolith with an 'open' command, cmd_* functions inside bin/gtr, six lib files, and GTR_VERSION on line 8. Rewritten as a condensed guide matching bin/git-gtr, the ten lib modules plus 18 command files, the adapter registry, pr/trust/cd handling, the --porcelain contract and the CI gates.

The per-pattern instruction files and CONTRIBUTING.md told contributors to hand-edit the three completion files, which are generated by scripts/generate-completions.sh and verified by CI. Every such place now says to edit the source and regenerate.

Also corrects four claims an independent verification pass disproved: the GTR_DEBUG behavior, the postCd dispatch paths, what 'git gtr completion zsh' prints, and the cmd_<command> dispatch rule.

* chore: prepare v2.11.1 release

* fix(tests): canonicalize the temp repo path in the integration helper (coderabbitai#200)

setup_integration_repo took its path straight from mktemp -d, which on macOS returns /var/folders/... while /var is a symlink to /private/var. git canonicalizes when it registers a worktree, so the preRemove hook received the /private/var spelling and 'cmd_clean --merged uses nested registered worktree path' compared it against the /var one.

This is the test's expectation being wrong rather than a product bug: passing a /var path to 'git worktree add' makes git itself register the resolved one.

Resolving the path once in the helper fixes it for every integration test. Linux is unaffected, since mktemp -d returns /tmp with no symlink, which is why CI stayed green.

Local suite now passes 561/561, previously 560/561.

* chore: normalize Windows shell execution for TigerEye

(cherry picked from commit 26ceb92)

* fix: make trust hashing portable and fail closed (#3)

Bead: TE-7sebjb
(cherry picked from commit 11a06a8)

---------

Co-authored-by: Tom Elizaga <tom.elizaga@gmail.com>
Co-authored-by: scarf <greenscarf005@gmail.com>
Co-authored-by: chatgpt-codex-connector[bot] <199175422+chatgpt-codex-connector[bot]@users.noreply.github.com>
Co-authored-by: Adam Wettreich <80975389+adamwett@users.noreply.github.com>
Co-authored-by: BashNetCorp <your.email@example.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant