Skip to content

fix: handle spaces and shell quotes in installed hook paths - #67

Merged
Dhravya merged 4 commits into
mainfrom
capy/handle-spaces-and-shell
Oct 11, 2026
Merged

Dhravya merged 4 commits into
mainfrom
capy/handle-spaces-and-shell

Conversation

@Dhravya

@Dhravya Dhravya commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Fixes #65.

Quote unsafe POSIX script paths, including embedded apostrophes, while leaving existing shell-safe commands unchanged. On Windows, pass the path as base64 to a fixed Node loader so cmd.exe cannot expand percent variables or interpret pathname metacharacters. The installed CommonJS hook bundles still receive stdin and produce the same output.

Install upgrades legacy unquoted commands in place, preserving matcher groups and custom hook fields. Status and uninstall recognize both formats, including retired capture registrations; unrelated hooks are left intact. Reinstall remains idempotent.

The PR changes only src/cli.ts. Existing tests, package scripts, and workflows match current main exactly; path regression probes are kept outside the repository in scratch. Current main's official SDK v5 migration is incorporated without modification.

Validated on this head: typecheck, all 70 unchanged baseline tests, and 13 scratch probes covering the four installed hooks, sh/bash/zsh execution, spaces, quotes, Unicode, shell metacharacters, legacy migration, status, uninstall, and unrelated-hook preservation. The baseline suite uses GIT_CONFIG_NOSYSTEM=1 to exclude this sandbox's proxy URL rewrite from an existing remote-identity fixture. The identical hook path logic passed native Linux/macOS/Windows CI on the earlier head. Independent verification at exact head 10f8be8 also passed on Linux using official Codex 0.162.1 and supported hash-bound hook approval: upgrades from released 1.0.20 in space/apostrophe HOMEs preserved unrelated settings, hooks, MCP entries, and originals; reinstall did not duplicate registrations; both persistent app-server two-turn sessions received profile/recall context, saved both synthetic replies with queued ACKs, and advanced capture cursors absent → 11 → 20. Synthetic local model/memory services were used, with no paid inference or production backend calls. Independent source review found no demonstrated scoped code blocker.

Limits: no fresh macOS/Windows runtime verification on this head, no security-clearance claim, and no fix or durability claim for short-lived exec async Stop loss or contended cursor persistence.

Dhravya and others added 2 commits October 9, 2026 05:07
Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>
Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>
Dhravya and others added 2 commits October 10, 2026 00:49
Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>
@Dhravya
Dhravya merged commit 93e3c2b into main Oct 11, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Installed hook commands fail when the Codex home path contains spaces or shell quotes

1 participant