CI & Build / Python lint (push) Successful in 2s
CI & Build / Plugin hooks (push) Successful in 9s
CI & Build / integration (push) Successful in 49s
CI & Build / TypeScript typecheck (push) Successful in 57s
CI & Build / Python tests (push) Failing after 1m7s
CI & Build / Build & push image (push) Skipped
Every hook opened `command -v jq >/dev/null 2>&1 || exit 0`, so on a machine without jq the operator got no session context, no rules, no prior art and no process sync — and not one word saying why, because `exit 0` is indistinguishable from "ran fine, nothing to say". jq is absent by default on macOS, on the Debian/Ubuntu slim images, on Alpine and in most CI containers. That is not a prerequisite to document; it is the plugin handing its own packaging problem to whoever installs it. `tac` was worse: GNU-only, so the prior-art hook's enclosing-definition arm did nothing at all on every Mac, silently, from the day it shipped. It is not replaced but removed — scribe_defs judges each line independently, so extracting forward and taking `tail -1` is the same answer as reversing and taking the head, and it drops the early-exit `head` that #4042 was filed for. No server contract changed, so a lagging plugin cache keeps working. scribe_json.awk JSON -> IDX<TAB>PATH<TAB>VALUE. Two modes: `whole` for an event or a response body, `lines` for a transcript, where an unparseable record is dropped and the rest still read — the `map(try fromjson catch empty)` the jq program opened with. Arrays also report their LENGTH at `[#]`, which is what keeps "zero notes" distinct from "no answer" (#2932). scribe_turn.awk the turn-bounding program, replacing the thirty lines of jq in the Stop hook. scribe_defs.sh scribe_json_flat / _pick / _list / _len / _list_minus read, scribe_json_out writes the envelope (five copies of one shape, gone), scribe_urlenc replaces `jq -sRr '@uri'`. Percent-encoding goes through `od -tu1` rather than an awk character loop on purpose: awk's idea of a character follows the locale, so gawk reads an accented letter as one and mawk as two, and an encoder built on substr() would emit a different URL depending on which awk is installed. Encoding is defined on bytes. Verified byte-identical to `jq -sRr '@uri'`. Measured, not assumed. The per-event path costs 8ms against jq's 3ms. The transcript path was 70x slower until two fixes: the Stop hook now finds where the turn starts with a fixed-string grep before parsing (a needle carrying unescaped quotes cannot occur inside a JSON string, so it matches only at a record's top level — checked against a full JSON parse of a 27MB transcript: 152 prompt records, 152 matches, no misses, no extras), and the parser reads each token out of a 1024-byte window instead of copying the rest of the buffer per token, which was quadratic in line length on the 400KB tool results a transcript carries. Differential-tested against the jq program it replaces over 724 windows cut from three real transcripts — 724 identical, 0 mismatched, 45 of them exercising a real task close and a real reply. That sweep is what caught `scribe_turn.awk` never setting FS, which truncated every multi-word reply at its first space and was invisible to a test whose replies were all empty. check_plugin.py's `jq -R` lint becomes a guard against either binary coming back, and three smoke checks lose their `shutil.which("jq")` skip. jq is not in `ci-python` either, so those three announced a skip on every CI run and had never once run there: removing the dependency from the product also closed a permanent hole in its verification. They pass now across all ten hooks. tests/test_hook_json_reader.py is a differential against Python's `json` over nested objects, arrays, unicode, escapes, control characters, empty cases and a value longer than the token window, plus the envelope, the encoder and the turn analyzer. 139 cases. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01821k5B3Ysecp9fNYs92Kuy
114 lines
5.3 KiB
Bash
114 lines
5.3 KiB
Bash
#!/usr/bin/env bash
|
|
# Scribe — PreToolUse rule arm for ACTIONS (#3476).
|
|
#
|
|
# The sibling of scribe_prior_art.sh. That hook is registered on Write|Edit and
|
|
# asks "what is recorded about the file being written". This one asks "does a
|
|
# standing rule speak to the command about to be run" — the question nothing
|
|
# could ask before, and the reason every rule about which tool to reach for had
|
|
# to live in the preload instead, back when there was one.
|
|
#
|
|
# WHY A HOOK AND NOT AN INSTRUCTION. A reflex generates no query (note #3089):
|
|
# you reach for `curl` confidently, with no moment of doubt, so a surface that
|
|
# waits to be asked never fires. Here nothing is asked — the tool call IS the
|
|
# query, and the reflex has to become a tool call before it can do anything.
|
|
#
|
|
# SILENT ON OUTAGE, deliberately, unlike the prior-art hook. A write is
|
|
# occasional; a Bash call is not, and an "instance did not answer" line before
|
|
# every command is the noise that gets a channel muted. scribe_prior_art.sh
|
|
# still speaks for both when the instance is down.
|
|
#
|
|
# Env:
|
|
# SCRIBE_URL / SCRIBE_TOKEN override for the settings.json dogfooding path.
|
|
|
|
command -v curl >/dev/null 2>&1 || exit 0
|
|
|
|
# Sourced FIRST, because the JSON reader below lives there (#4107). It defines
|
|
# functions and clears `url`/`token`; nothing here runs before it is needed.
|
|
# shellcheck source=plugin/hooks/scribe_defs.sh
|
|
. "$(dirname "${BASH_SOURCE[0]}")/scribe_defs.sh"
|
|
|
|
# PreToolUse delivers { session_id, cwd, tool_name, tool_input: {...}, ... }
|
|
event=$(cat 2>/dev/null || true)
|
|
event_flat=$(printf '%s' "$event" | scribe_json_flat)
|
|
tool_name=$(scribe_json_pick "$event_flat" '.tool_name')
|
|
session_id=$(scribe_json_pick "$event_flat" '.session_id')
|
|
event_cwd=$(scribe_json_pick "$event_flat" '.cwd')
|
|
|
|
[ -n "$tool_name" ] || exit 0
|
|
|
|
# The action, as text. `.command` is Bash's field; the fallbacks let the matcher
|
|
# in hooks.json widen to other tools without this script changing — which is the
|
|
# whole reason the server side takes a name and a string rather than a schema.
|
|
command_text=$(scribe_json_pick "$event_flat" '.tool_input.command')
|
|
[ -n "$command_text" ] || command_text=$(scribe_json_pick "$event_flat" '.tool_input.url')
|
|
[ -n "$command_text" ] || command_text=$(scribe_json_pick "$event_flat" '.tool_input.prompt')
|
|
|
|
[ -n "$command_text" ] || exit 0
|
|
|
|
# scribe_config, not a hand-rolled pair of parameter expansions: it also treats
|
|
# an UNEXPANDED `${...}` placeholder as unset, which would otherwise be sent as
|
|
# a garbage Bearer token and 401 on every call (#2198's class).
|
|
scribe_config || exit 0
|
|
|
|
# Bounded before encoding: a heredoc or a pasted script can be enormous, and
|
|
# the verb and its target — the part a rule is about — sit at the front. The
|
|
# server bounds it again; this keeps a huge payload off the wire in the first
|
|
# place. `head -c`, never `cut -c`: cut truncates each LINE and caps nothing.
|
|
command_text=$(printf '%s' "$command_text" | head -c 2000)
|
|
|
|
# Whole, never line by line: the predecessor (`jq -rR`) encoded a multi-line
|
|
# command one line at a time and joined them with raw newlines — an invalid URL.
|
|
# scribe_urlenc reads bytes and has no notion of a line.
|
|
cmd_enc=$(printf '%s' "$command_text" | scribe_urlenc)
|
|
tool_enc=$(printf '%s' "$tool_name" | scribe_urlenc)
|
|
[ -n "$cmd_enc" ] && [ -n "$tool_enc" ] || exit 0
|
|
|
|
repo_q=""
|
|
lookup_dir=${event_cwd:-${CLAUDE_PROJECT_DIR:-$PWD}}
|
|
scope=$(scribe_scope_query "$lookup_dir")
|
|
[ -n "$scope" ] && repo_q="&${scope}"
|
|
|
|
# THE SHARED SESSION LEDGER, and the thing most worth getting right here.
|
|
#
|
|
# scribe_prior_art.sh keeps the rules it has already named in
|
|
# <state>/<sid>.rules.ids and passes them as exclude_rule_ids. This hook reads
|
|
# and appends to that SAME file rather than keeping its own: two ledgers would
|
|
# mean a rule named by one arm gets re-offered by the other, and the hint that
|
|
# fires most often is exactly the one that must not repeat itself.
|
|
#
|
|
# The directory keeps the prior-art name on purpose — renaming it would orphan
|
|
# every live session's state for a cosmetic gain.
|
|
state_dir="${TMPDIR:-/tmp}/scribe-priorart"
|
|
mkdir -p "$state_dir" 2>/dev/null || true
|
|
rulefile=""
|
|
rule_exclude_q=""
|
|
if [ -n "$session_id" ]; then
|
|
safe_sid=$(printf '%s' "$session_id" | tr -c 'A-Za-z0-9._-' '_')
|
|
rulefile="$state_dir/${safe_sid}.rules.ids"
|
|
# Ageing, not a flat read (#3751): an id named two hours ago is not one the
|
|
# session is still holding. scribe_rules_live carries the reasoning.
|
|
rule_seen=$(scribe_rules_live "$rulefile")
|
|
[ -n "$rule_seen" ] && rule_exclude_q="&exclude_rule_ids=${rule_seen}"
|
|
# What the session actually OPENED, as against what it was shown (#4100).
|
|
rule_exclude_q="${rule_exclude_q}$(scribe_held_query "$state_dir/${safe_sid}.opened.ids")"
|
|
fi
|
|
|
|
# `|| exit 0` here, unlike the prior-art hook: there is no local arm whose
|
|
# finding would be discarded, and an outage line before every command is worse
|
|
# than silence. See the header.
|
|
body=$(curl -fsS --max-time 5 \
|
|
-H "Authorization: Bearer ${token}" \
|
|
"${url%/}/api/plugin/tool-rules?tool=${tool_enc}&command=${cmd_enc}${repo_q}${rule_exclude_q}" 2>/dev/null) || exit 0
|
|
|
|
body_flat=$(printf '%s' "$body" | scribe_json_flat)
|
|
context=$(scribe_json_pick "$body_flat" '.context')
|
|
[ -n "$context" ] || exit 0
|
|
|
|
# Remember what was named so it is not repeated this session.
|
|
if [ -n "$rulefile" ]; then
|
|
scribe_json_list "$body_flat" '.rule_ids' | scribe_rules_append "$rulefile"
|
|
fi
|
|
|
|
scribe_json_out PreToolUse "$context"
|
|
exit 0
|