diff options
| author | Craig Jennings <c@cjennings.net> | 2026-07-24 11:00:39 -0500 |
|---|---|---|
| committer | Craig Jennings <c@cjennings.net> | 2026-07-24 11:00:39 -0500 |
| commit | 781fa0786e2096797e630dcb81ffbc62ed98460b (patch) | |
| tree | e47a1662ed9ff8ea1b1744c407873974a6bd0b2b /working/hook-fail-open/pre-commit.diff | |
| parent | 267d1de7b8a8e7fd22b156433567c88216ec3d0f (diff) | |
| download | rulesets-781fa0786e2096797e630dcb81ffbc62ed98460b.tar.gz rulesets-781fa0786e2096797e630dcb81ffbc62ed98460b.zip | |
chore(inbox): park two hook fail-open fixes from .emacs.d
Diffstat (limited to 'working/hook-fail-open/pre-commit.diff')
| -rw-r--r-- | working/hook-fail-open/pre-commit.diff | 38 |
1 files changed, 38 insertions, 0 deletions
diff --git a/working/hook-fail-open/pre-commit.diff b/working/hook-fail-open/pre-commit.diff new file mode 100644 index 0000000..26b3d7e --- /dev/null +++ b/working/hook-fail-open/pre-commit.diff @@ -0,0 +1,38 @@ +--- languages/elisp/githooks/pre-commit 2026-07-23 20:37:08.136094097 -0500 ++++ working/hook-fail-open/pre-commit 2026-07-24 09:02:54.812347251 -0500 +@@ -18,8 +18,17 @@ + SECRET_PATTERNS_CS='(AKIA[0-9A-Z]{16}|sk-[a-zA-Z0-9_-]{20,}|-----BEGIN (RSA|DSA|EC|OPENSSH|PGP)( PRIVATE)?( KEY| KEY BLOCK)?-----)' + SECRET_PATTERNS_CI='(api[_-]?key|api[_-]?secret|auth[_-]?token|secret[_-]?key|bearer[_-]?token|access[_-]?token|password)[[:space:]]*[:=][[:space:]]*["'"'"'][^"'"'"']{16,}["'"'"']' + +-added_lines="$(git diff --cached -U0 --diff-filter=AM \ +- | grep '^+' | grep -v '^+++' || true)" ++# Read the diff on its own so a git failure is distinguishable from "grep ++# matched nothing". Both end in a non-zero status, but only one of them means ++# there is nothing to scan; piping them together and swallowing the result with ++# `|| true` made a broken git look like a clean commit. ++if ! staged_diff="$(git diff --cached -U0 --diff-filter=AM)"; then ++ echo "pre-commit: cannot read the staged diff — refusing to skip the secret scan" >&2 ++ exit 1 ++fi ++ ++# The greps keep their `|| true`: exiting 1 on no match is their normal result. ++added_lines="$(printf '%s\n' "$staged_diff" | grep '^+' | grep -v '^+++' || true)" + + cs_hits="$(printf '%s\n' "$added_lines" | grep -nE "$SECRET_PATTERNS_CS" || true)" + ci_hits="$(printf '%s\n' "$added_lines" | grep -niE "$SECRET_PATTERNS_CI" || true)" +@@ -37,7 +46,14 @@ + fi + + # --- 2. Paren check on staged .el files --- +-staged_el="$(git diff --cached --name-only --diff-filter=AM | grep '\.el$' || true)" ++# Same split as the secret scan above: a git failure must not read as "no .el ++# files staged", which would skip the paren check silently. ++if ! staged_names="$(git diff --cached --name-only --diff-filter=AM)"; then ++ echo "pre-commit: cannot read the staged file list — refusing to skip the paren check" >&2 ++ exit 1 ++fi ++ ++staged_el="$(printf '%s\n' "$staged_names" | grep '\.el$' || true)" + + if [ -n "$staged_el" ]; then + paren_fail="" |
