Skip to content

fix(guards): block worktree-rewriting git in OneDrive repos; sync segment splitter - #7

Merged
lukisch merged 1 commit into
mainfrom
fix/onedrive-git-guard
Sep 24, 2026
Merged

lukisch merged 1 commit into
mainfrom
fix/onedrive-git-guard

Conversation

@lukisch

@lukisch lukisch commented Sep 24, 2026

Copy link
Copy Markdown
Member

Summary

  • Adds check_onedrive_git(): pull, rebase, reset --hard|--keep|--merge, checkout -B|-f|-- <path>, switch -C, restore, merge and branch -f are blocked when the target directory (hook cwd, cd …, git -C …) lies in a OneDrive tree. Explicit release: prefix the command with ONEDRIVE_GIT_OK=1. An undeterminable target fails closed.
  • Brings _segmente() (real command separators, force-push fix from 2026-09-13) into this library copy, which was still missing it.

Why

A scheduled agent run did pull --rebase followed by checkout -B main origin/main in a research repo whose .git lives in OneDrive. The rebase first checked out the remote state and removed every file that existed only in the local commit; resetting the branch then orphaned that commit. 6039 files were gone from the working tree until they were recovered from the dangling commit two months later.

Test plan

  • pytest in hook-master: green
  • Canonical case table (test_guards.py, 22 OneDrive cases in both directions plus the existing bach/git cases) passes against library/guards.py
  • Review and merge by a second model (author model must not merge)

🤖 Generated with Claude Code

…ment splitter

Brings library/guards.py up to the canonical .SYNC/hooks/guards.py:
- check_onedrive_git(): pull/rebase/reset --hard|--keep|--merge/checkout -B|-f|-- <path>/
  switch -C/restore/merge/branch -f in OneDrive paths are blocked unless the command
  carries ONEDRIVE_GIT_OK=1; unknown target directory fails closed (T-20260924-532136326:
  pull --rebase + checkout -B deleted 6039 files in a OneDrive research repo).
- _segmente(): real command separators (force-push fix T-20260913-235210967) that this
  copy was still missing.
Tests: hook-master pytest green; .SYNC/hooks/test_guards.py all cases pass against this file.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

Welcome! 👋 Thanks for your first pull request in this repository.

A maintainer will review it soon. Please make sure:

  • Your changes are tested
  • Documentation is updated if needed
  • The PR description explains what and why

Thanks for contributing!

@lukisch lukisch left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review Befunde zu PR #7 (fix/onedrive-git-guard)

Reviewer: agy@ASUS-GEI (Antigravity)
Modell: Gemini 3.8 Flash (High)

1. Branch-Schutz & CI Status

  • Branch Protection auf \main: nicht aktiv / keine Rulesets hinterlegt.
  • GitHub Actions CI (\gh pr checks 7): 13/13 Checks erfolgreich (macOS, Ubuntu, Windows auf Python 3.10, 3.11, 3.12, 3.13 + welcome).

2. Kriterien-Pruefung (Diff & Code in \library/guards.py)

  • (a) Faelschliche Treffer ausserhalb OneDrive: Erfolgreich verifiziert. Git-Befehle (pull, rebase, etc.) in \C:/_Local_DEV/repos/...\ werden nicht faelschlich blockiert.
  • (b) Umgehungs-Schreibweisen: Robust gegen Pfad-Aliase (/c/...), relative Pfade, Backslashes/Slashes, -C , \cd &&, Umgebungsvariablen-Praefixe (\VAR=val), quoted refs und \git.exe.
  • (c) Fail-closed: Bei fehlendem/leerem \cwd\ im Payload wird bei riskanten Operationen zuverlaessig fail-closed blockiert (Exit 2 mit klarer Freigabe-Instruktion \ONEDRIVE_GIT_OK=1), waehrend unkritische Operationen (\git status, non-git) weiterhin durchlaufen.
  • (d) Sensible Daten: Keine Nutzernamen, privaten Pfade oder Tokens vorhanden. Code ist sauber neutralisiert und public-ready.
  • (e) Interpreter-Invarianten: \library/guards.py\ nutzt ausschliesslich Standardbibliothek (\json,
    e, \shlex, \sys), startet fehlerfrei unter \python -S -X utf8\ (ohne site-packages).

3. Testmessungen (synchron im Vordergrund)

  • Hook-Master Test-Suite: 107/107 Tests bestanden (pytest mit isoliertem basetemp)
  • Guard-Spezifikationstests (\ est_guards.py): 52/52 Testfaelle bestanden (inkl. 22 OneDrive-spezifischer Faelle)
  • Manuelle Subprozess-Tests mit -S -X utf8\ und JSON Payloads: alle Exit-Codes (0 / 2) und Fehlermeldungen verifiziert
  • Linter:
    uff check\ fehlerfrei bestanden

Fazit: PR ist sauber und verifiziert. Ready for squash merge.

@lukisch
lukisch merged commit 534297c into main Sep 24, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant