igneum/tools/ci/install-hooks.sh
igneum-labs 60eb06ec24 CI hardening: one gate script for the hook and CI, the research exclusion list, the Windows paths check, the red watcher, the box runner switch, the failure classification
168 non-green runs since the first workflow run were classified (docs/analysis/ci-failures-2026-10-06.md): 102 were tree checks that finish in under 25 s on the pushing machine, 40 were GitHub-side refusals nobody saw.

tools/ci/pre-push.sh is the one list of fast checks; ci.yml's site job calls it with --ci and the pre-push hook with --hook (full gate for master and release-*, structural checks for other refs; never writes into the worktree). tools/ci/export-exclude.txt lists research documents outside the public export list, pruned by identity-check.sh and by the mirror's sync.sh (self-test: an excluded path may quote the patterns, an exported one may not); polish.md and this record are its first entries, which makes master green. tools/ci/windows-paths-check.sh (colon, trailing dot or space, reserved names, over 240 characters) runs as the pre-commit hook on staged paths and in the gate. tools/ci/red-watch.mjs plus the red job on the box's runner record one line per failed master or release-* run to /srv/ci-red/red.jsonl; igneum-ci-red.timer posts each once to the updates channel. pow and sims read IGNEUM_CI_RUNNER for the box. no-foreign-tree-writes.sh no longer exits silently on its warning pipeline under pipefail.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 20:58:54 +00:00

28 lines
1.8 KiB
Bash
Executable file

#!/usr/bin/env bash
# Installs the repository's git hooks into this checkout's shared hooks directory (one set for the main checkout and
# every worktree, since worktrees share .git/hooks). Each hook is a two-line delegate to a versioned script, so a
# change to the gate is a commit, never a reinstall:
# pre-commit -> tools/ci/windows-paths-check.sh --staged (a path Windows cannot check out never enters a commit)
# pre-push -> tools/ci/pre-push.sh --hook (the full CI gate before a push to master or release-*,
# the two structural checks before any other push)
# Neither hook writes into the worktree (the site is built in a temporary copy; 063bbca, 6 October 2026).
# A tree that predates the scripts (an old branch) falls back to the conflict-marker check alone.
set -euo pipefail
cd "$(git rev-parse --show-toplevel)"
hooks="$(git rev-parse --git-common-dir)/hooks"; mkdir -p "$hooks"
cat > "$hooks/pre-push" <<'HOOK'
#!/usr/bin/env bash
# installed by tools/ci/install-hooks.sh; the gate itself is versioned in tools/ci/pre-push.sh (same script as CI)
cd "$(git rev-parse --show-toplevel)" || exit 1
if [ -f tools/ci/pre-push.sh ]; then exec bash tools/ci/pre-push.sh --hook "$@"; fi
exec bash tools/ci/no-conflict-markers.sh
HOOK
cat > "$hooks/pre-commit" <<'HOOK'
#!/usr/bin/env bash
# installed by tools/ci/install-hooks.sh; the check itself is versioned in tools/ci/windows-paths-check.sh
cd "$(git rev-parse --show-toplevel)" || exit 1
[ -f tools/ci/windows-paths-check.sh ] || exit 0
exec bash tools/ci/windows-paths-check.sh --staged
HOOK
chmod +x "$hooks/pre-push" "$hooks/pre-commit"
echo "hooks installed in $hooks: pre-commit (Windows paths of the staged files), pre-push (tools/ci/pre-push.sh --hook)"