fix(hooks,lib): fix hook detection and parsing edge cases (#2405)

* fix(hooks,lib): fix hook detection and parsing edge cases

- auto-tmux-dev: dev\b -> dev(?![\w-]) so one-shot dev-build/dev-docs scripts
  are not detached into tmux; align command shapes (yarn run dev, bun dev) with
  pre-bash-dev-server-block.js DEV_PATTERN.
- pre-bash-commit-quality: skip obvious non-secret placeholders (env refs,
  ${...}, <...>, whitelisted tokens) in the api-key rule without suppressing
  real high-entropy secrets; make -m message extraction quote- and
  escaped-quote-aware so `-m "fix: \"x\""` / apostrophes are not truncated.
- pre-compact: annotate the CURRENT worktree's session (match **Worktree:** /
  legacy **Project:**) instead of the newest *-session.tmp across all projects,
  layered onto the LLM-summary flow from #2388; a present-but-blank Worktree
  header is treated as non-legacy (no foreign project fallback).
- shell-substitution: stop double-appending a trailing backslash in an
  unterminated backtick span.
- utils readStdinJson: on overflow, settle and resolve {} immediately (clear
  timer + listeners) instead of waiting for end/timeout and parsing a partial
  prefix; surface the overflow on stderr.

Regression tests added/extended (new tests/hooks/pre-compact.test.js).

Addresses review feedback on #2405. The earlier block-no-verify change was
dropped: its message-value skip on merge/cherry-pick/am/rebase would let
`git rebase -m --no-verify` bypass the hook (rebase's -m is the boolean
--merge), a false-negative worse than the contrived false-positive it fixed.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(ci): align hook fixtures and drain oversized stdin

---------

Co-authored-by: djpjronline-netizen <276112803+djpjronline-netizen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: haelyra <49814733+haelyra@users.noreply.github.com>
This commit is contained in:
djpjronline-netizen
2026-07-28 21:32:42 -04:00
committed by GitHub
co-authored by Claude Opus 4.8 djpjronline-netizen haelyra
parent 6be87a56ae
commit 837acaf20b
11 changed files with 517 additions and 53 deletions
+12 -3
View File
@@ -36,9 +36,18 @@ function run(rawInput) {
const input = typeof rawInput === 'string' ? JSON.parse(rawInput) : rawInput;
const cmd = input.tool_input?.command || '';
// Detect dev server commands: npm run dev, pnpm dev, yarn dev, bun run dev
// Use word boundary (\b) to avoid matching partial commands
const devServerRegex = /(npm run dev\b|pnpm( run)? dev\b|yarn dev\b|bun run dev\b)/;
// Detect dev server commands: npm run dev, pnpm (run) dev, yarn (run) dev,
// bun (run) dev. Trailing (?![\w-]) rather than \b: \b treats a hyphen as a
// word boundary, so `dev\b` matches the `dev` prefix of distinct scripts
// like `dev-build` / `dev-docs` and would wrongly detach those one-shot
// scripts into tmux. The lookahead still matches the dev server (`dev`,
// `dev:ssr`, ...) but not a `dev-<suffix>` script. The optional `run` on
// yarn/bun mirrors the command shapes in pre-bash-dev-server-block.js
// DEV_PATTERN so the two hooks agree on what counts as a dev server.
// Flexible whitespace (\s+) and leading \b make this byte-identical to
// pre-bash-dev-server-block.js DEV_PATTERN, so a tabbed/multi-space command
// the blocker catches is also detached here (they agree exactly).
const devServerRegex = /\b(npm\s+run\s+dev|pnpm(?:\s+run)?\s+dev|yarn(?:\s+run)?\s+dev|bun(?:\s+run)?\s+dev)(?![\w-])/;
if (devServerRegex.test(cmd)) {
// Get session name from current directory basename, sanitize for shell safety