From 50065e894f7e5093ada1d306dd7d65ce3171901e Mon Sep 17 00:00:00 2001 From: Joakim Persson Date: Mon, 21 Sep 2026 13:38:57 +0200 Subject: [PATCH] hooks: call the shared freshness notice MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit git runs whatever hooks/ holds today, so a clone that ran ./setup-hooks.sh once and never pulled runs an old gate while looking perfectly configured. Measured on tor-ms22 (logstream seq 172/173): core.hooksPath correct, .git/hooks clean, and no pre-push gate at all because the clone predated the commit that added it. Implementation: myconfigs b7acaa0, common/hooks/hook-freshness.sh — one copy for all six tracked-hook repos, not five vendored copies of a drift detector. SOFT dependency here: this repo has no myconfigs locator, so the call tries $MYCONFIGS_DIR, the sibling, then $HOME/myconfigs, and stays SILENT if none exist. It always exits 0. Verified: stale remote -> notice naming the commit; in sync -> silent; rc identical across both, so the gitleaks verdict below is untouched. --- hooks/pre-commit | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/hooks/pre-commit b/hooks/pre-commit index 5f8163a..438e362 100755 --- a/hooks/pre-commit +++ b/hooks/pre-commit @@ -1,6 +1,23 @@ #!/bin/bash # Pre-commit hook — scans staged files for secrets using gitleaks +# --- freshness notice: is this the gate that was SHIPPED? ---------------------- +# Wiring is not freshness. git runs whatever the hooks directory holds TODAY, so +# a clone that ran setup-hooks.sh once and never pulled runs an old gate while +# looking perfectly configured. Measured 2026-09-21 on tor-ms22 (logstream seq +# 172/173): core.hooksPath correct, zero stale copies in .git/hooks, tree clean +# — and no pre-push hook at all, because the clone predated the commit adding it. +# Shared implementation: myconfigs/common/hooks/hook-freshness.sh. ONE copy for +# all six tracked-hook repos in this fleet, because five vendored copies of a +# drift detector are five things that drift. SOFT dependency: silent when +# myconfigs is not alongside, and it always exits 0 — a notice, never a gate. +_fresh_root="$(git rev-parse --show-toplevel 2>/dev/null || true)" +for _m in "${MYCONFIGS_DIR:-}" "$(dirname "${_fresh_root:-.}")/myconfigs" "${HOME:-}/myconfigs"; do + [ -n "$_m" ] && [ -f "$_m/common/hooks/hook-freshness.sh" ] || continue + sh "$_m/common/hooks/hook-freshness.sh" "$_fresh_root" || true + break +done + if ! command -v gitleaks >/dev/null 2>&1; then echo "" echo "⚠️ gitleaks is not installed — skipping secret scan"