skill: run nothing a scanned repo's git config names, for v1.0.3 - #5
Merged
Merged
Conversation
ClawHub re-scanned v1.0.2 on 2026-09-25 and moved its audit to Review (A.I.G T09): git_classify.py runs read-only git commands in every repository it finds, and a repository's own config can still make git start programs during them — core.fsmonitor, a filter driver's clean or process command, gpg.program through log.showSignature, the same in a checked-out submodule. Every git command in git_classify.py now runs with those switched off, handed over in GIT_CONFIG_COUNT (a driver's name may contain "=", which -c splits at). Filter drivers are switched off only when the repository or one of its submodules defines them, so git lfs, installed in the global config, keeps working. That needs git 2.31: with an older git every repository is "unknown", and install.sh names an older git at install time. tests/git_classify.py shows each case unrun by the script and run by plain git; CI runs it. ADR-028 records it. The description now says migrate, new Mac, laptop and SSH keys, the words people search ClawHub with, and that the skill installs the envrelay binary. docs/publishing.md gives the new ClawHub name, topics and categories, how its search ranks, and v1.0.2's changed audit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
Author
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
1 similar comment
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ClawHub re-scanned v1.0.2 on 2026-09-25 at 15:43 UTC and moved its audit from Pass to Review. Its one substantive finding (A.I.G T09, high):
git_classify.pyruns read-only git commands in every repository the scan finds, and a repository's own config can still make git start programs during them.git_classify.pyswitches those off for every git command:core.fsmonitorempty (notfalse, which git before 2.36 runs),core.hooksPath=/dev/null,log.showSignature=false(stopsstash listfrom callinggpg.program), and forstatustheclean/smudge/processcommands of every filter driver the repository or one of its checked-out submodules defines. Drivers from the system, global or command scope keep running, so git lfs still works.GIT_CONFIG_COUNT/KEY_n/VALUE_n, not-c:-csplits at the first=, and the environment also reaches thegit statusthat runs inside each submodule. That needs git 2.31; with an older git every repository isunknownwith the version in the detail, andinstall.shnames an older git at install time.tests/git_classify.py(stdlib unittest, run in CI on Linux under Python 3.9 and on macOS) builds a repository per case — fsmonitor, filter driver, a driver named with=, a filter in a submodule, a signed stash — and shows the script leaves the program unrun while plain git making the same read runs it; plus git lfs's case and an old git.~/.local/bin.docs/publishing.mdgives the new ClawHub name (EnvRelay: Backup, Restore & Migrate Dev Environments), categories (operations,development,productivity) and topics (backup,migration,dotfiles,developer-environment,new-machine-setup), how ClawHub's search ranks, and v1.0.2's changed audit.Validation
python3 tests/git_classify.py -v: 7 passedtests/installer.shunder sh, dash, bash and zsh: 99 passed each (newold-gitscenario)cargo fmt --check,cargo clippy --all-targets --locked -- -D warnings,cargo test --locked,cargo build --release --lockedshellcheck,python3 -m compileall -q skills/envrelay/scripts,check-versions.sh(1.0.3)git_classify.py --scan ~/futrixdevon real repositories: same states as before🤖 Generated with Claude Code