Repository navigation
fix: handle spaces and shell quotes in installed hook paths - #67
Merged
Merged
Conversation
Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>
Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>
Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #65.
Quote unsafe POSIX script paths, including embedded apostrophes, while leaving existing shell-safe commands unchanged. On Windows, pass the path as base64 to a fixed Node loader so cmd.exe cannot expand percent variables or interpret pathname metacharacters. The installed CommonJS hook bundles still receive stdin and produce the same output.
Install upgrades legacy unquoted commands in place, preserving matcher groups and custom hook fields. Status and uninstall recognize both formats, including retired capture registrations; unrelated hooks are left intact. Reinstall remains idempotent.
The PR changes only src/cli.ts. Existing tests, package scripts, and workflows match current main exactly; path regression probes are kept outside the repository in scratch. Current main's official SDK v5 migration is incorporated without modification.
Validated on this head: typecheck, all 70 unchanged baseline tests, and 13 scratch probes covering the four installed hooks, sh/bash/zsh execution, spaces, quotes, Unicode, shell metacharacters, legacy migration, status, uninstall, and unrelated-hook preservation. The baseline suite uses GIT_CONFIG_NOSYSTEM=1 to exclude this sandbox's proxy URL rewrite from an existing remote-identity fixture. The identical hook path logic passed native Linux/macOS/Windows CI on the earlier head. Independent verification at exact head 10f8be8 also passed on Linux using official Codex 0.162.1 and supported hash-bound hook approval: upgrades from released 1.0.20 in space/apostrophe HOMEs preserved unrelated settings, hooks, MCP entries, and originals; reinstall did not duplicate registrations; both persistent app-server two-turn sessions received profile/recall context, saved both synthetic replies with queued ACKs, and advanced capture cursors absent → 11 → 20. Synthetic local model/memory services were used, with no paid inference or production backend calls. Independent source review found no demonstrated scoped code blocker.
Limits: no fresh macOS/Windows runtime verification on this head, no security-clearance claim, and no fix or durability claim for short-lived exec async Stop loss or contended cursor persistence.