CI & Build / Python lint (push) Successful in 2s
CI & Build / Plugin hooks (push) Successful in 9s
CI & Build / integration (push) Successful in 49s
CI & Build / TypeScript typecheck (push) Successful in 57s
CI & Build / Python tests (push) Failing after 1m7s
CI & Build / Build & push image (push) Skipped
Every hook opened `command -v jq >/dev/null 2>&1 || exit 0`, so on a machine without jq the operator got no session context, no rules, no prior art and no process sync — and not one word saying why, because `exit 0` is indistinguishable from "ran fine, nothing to say". jq is absent by default on macOS, on the Debian/Ubuntu slim images, on Alpine and in most CI containers. That is not a prerequisite to document; it is the plugin handing its own packaging problem to whoever installs it. `tac` was worse: GNU-only, so the prior-art hook's enclosing-definition arm did nothing at all on every Mac, silently, from the day it shipped. It is not replaced but removed — scribe_defs judges each line independently, so extracting forward and taking `tail -1` is the same answer as reversing and taking the head, and it drops the early-exit `head` that #4042 was filed for. No server contract changed, so a lagging plugin cache keeps working. scribe_json.awk JSON -> IDX<TAB>PATH<TAB>VALUE. Two modes: `whole` for an event or a response body, `lines` for a transcript, where an unparseable record is dropped and the rest still read — the `map(try fromjson catch empty)` the jq program opened with. Arrays also report their LENGTH at `[#]`, which is what keeps "zero notes" distinct from "no answer" (#2932). scribe_turn.awk the turn-bounding program, replacing the thirty lines of jq in the Stop hook. scribe_defs.sh scribe_json_flat / _pick / _list / _len / _list_minus read, scribe_json_out writes the envelope (five copies of one shape, gone), scribe_urlenc replaces `jq -sRr '@uri'`. Percent-encoding goes through `od -tu1` rather than an awk character loop on purpose: awk's idea of a character follows the locale, so gawk reads an accented letter as one and mawk as two, and an encoder built on substr() would emit a different URL depending on which awk is installed. Encoding is defined on bytes. Verified byte-identical to `jq -sRr '@uri'`. Measured, not assumed. The per-event path costs 8ms against jq's 3ms. The transcript path was 70x slower until two fixes: the Stop hook now finds where the turn starts with a fixed-string grep before parsing (a needle carrying unescaped quotes cannot occur inside a JSON string, so it matches only at a record's top level — checked against a full JSON parse of a 27MB transcript: 152 prompt records, 152 matches, no misses, no extras), and the parser reads each token out of a 1024-byte window instead of copying the rest of the buffer per token, which was quadratic in line length on the 400KB tool results a transcript carries. Differential-tested against the jq program it replaces over 724 windows cut from three real transcripts — 724 identical, 0 mismatched, 45 of them exercising a real task close and a real reply. That sweep is what caught `scribe_turn.awk` never setting FS, which truncated every multi-word reply at its first space and was invisible to a test whose replies were all empty. check_plugin.py's `jq -R` lint becomes a guard against either binary coming back, and three smoke checks lose their `shutil.which("jq")` skip. jq is not in `ci-python` either, so those three announced a skip on every CI run and had never once run there: removing the dependency from the product also closed a permanent hole in its verification. They pass now across all ten hooks. tests/test_hook_json_reader.py is a differential against Python's `json` over nested objects, arrays, unicode, escapes, control characters, empty cases and a value longer than the token window, plus the envelope, the encoder and the turn analyzer. 139 cases. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01821k5B3Ysecp9fNYs92Kuy
72 lines
3.4 KiB
Bash
72 lines
3.4 KiB
Bash
#!/usr/bin/env bash
|
|
# Scribe — record that this session OPENED a rule, not merely saw it named (#4100).
|
|
#
|
|
# WHAT THIS CLOSES
|
|
#
|
|
# The rule arms keep a ledger of every id they have NAMED, and the injected
|
|
# line used to tell the reader "You saw it earlier this session". That claim
|
|
# was never checked. The line those arms emit is a TEASER — title, trigger,
|
|
# `get_rule(N)` — so a session can be named a rule twenty times and never read
|
|
# one word of it, and after a compaction the teaser is summarised away leaving
|
|
# nothing at all. The server was asserting something about the reader's
|
|
# context that it had no way to know.
|
|
#
|
|
# This is the observable half. PostToolUse fires for MCP tools (the event's own
|
|
# output schema carries `updatedMCPToolOutput`, which would be meaningless
|
|
# otherwise), so the `get_rule` CALL can be watched directly.
|
|
#
|
|
# WHY THIS IS NOT THE SELF-REPORT MILESTONE 386 REJECTED
|
|
#
|
|
# 386 ruled out asking the session whether it holds a rule, because a model
|
|
# asked "do you still hold rule 156?" will say yes and the answer is
|
|
# unverifiable self-report. That objection is about ASKING. This asks nobody:
|
|
# a tool call happened or it did not, and the harness reports it either way.
|
|
# Recording what a session DID is a different kind of evidence from believing
|
|
# what it says about itself.
|
|
#
|
|
# WHAT IT DELIBERATELY DOES NOT DO
|
|
#
|
|
# It does not prove the rule is still in context — nothing can, and a
|
|
# compaction can drop it moments later. That is why `.opened.ids` ages exactly
|
|
# like `.rules.ids` and is cleared on the same events (#3749): both ledgers
|
|
# describe a context that no longer exists once the context is destroyed. The
|
|
# claim it supports is only ever "you opened this, pull it again if you no
|
|
# longer hold it", which stays true in every case and carries its own remedy.
|
|
#
|
|
# EXIT 0, ALWAYS. This decorates a ledger; a bookkeeping failure must never
|
|
# turn a successful tool call into a hook error. Worst case the id is missed
|
|
# and the reader is offered a rule it already read — the cost of a wrong guess
|
|
# here is one extra line, in the direction that shows more rather than less.
|
|
set -uo pipefail
|
|
|
|
# shellcheck source=plugin/hooks/scribe_defs.sh
|
|
. "$(dirname "${BASH_SOURCE[0]}")/scribe_defs.sh"
|
|
|
|
event=$(cat 2>/dev/null || true)
|
|
[ -n "$event" ] || exit 0
|
|
|
|
event_flat=$(printf '%s' "$event" | scribe_json_flat)
|
|
session_id=$(scribe_json_pick "$event_flat" '.session_id')
|
|
[ -n "$session_id" ] || exit 0
|
|
|
|
# The matcher in hooks.json already narrows to the get_rule tools, but the
|
|
# server segment of an MCP tool name varies with how the plugin was installed,
|
|
# so the id is read from whichever field is actually present rather than from
|
|
# an assumed tool name. An event that carries none simply records nothing.
|
|
rule_id=$(scribe_json_pick "$event_flat" '.tool_input.rule_id')
|
|
rule_id=$(printf '%s' "$rule_id" | tr -cd '0-9')
|
|
[ -n "$rule_id" ] || exit 0
|
|
|
|
# The same directory the naming ledger uses. One session keeps its state in one
|
|
# place, and the prior-art name is kept for the reason scribe_tool_rules.sh
|
|
# gives: renaming it would orphan every live session's state for a cosmetic
|
|
# gain.
|
|
state_dir="${TMPDIR:-/tmp}/scribe-priorart"
|
|
mkdir -p "$state_dir" 2>/dev/null || true
|
|
safe_sid=$(printf '%s' "$session_id" | tr -c 'A-Za-z0-9._-' '_')
|
|
|
|
# Stamped and append-only, exactly like the naming ledger — so the same reader
|
|
# (`scribe_rules_live`) ages both, and the last entry for an id wins.
|
|
printf '%s\n' "$rule_id" | scribe_rules_append "$state_dir/${safe_sid}.opened.ids"
|
|
exit 0
|