Skip to content

skill: run nothing a scanned repo's git config names, for v1.0.3 - #5

Merged
wangqianqianjun merged 1 commit into
mainfrom
git-inventory-runs-no-repo-helpers
Sep 26, 2026
Merged

wangqianqianjun merged 1 commit into
mainfrom
git-inventory-runs-no-repo-helpers

Conversation

@wangqianqianjun

Copy link
Copy Markdown
Contributor

Summary

ClawHub re-scanned v1.0.2 on 2026-09-25 at 15:43 UTC and moved its audit from Pass to Review. Its one substantive finding (A.I.G T09, high): git_classify.py runs read-only git commands in every repository the scan finds, and a repository's own config can still make git start programs during them.

  • git_classify.py switches those off for every git command: core.fsmonitor empty (not false, which git before 2.36 runs), core.hooksPath=/dev/null, log.showSignature=false (stops stash list from calling gpg.program), and for status the clean/smudge/process commands of every filter driver the repository or one of its checked-out submodules defines. Drivers from the system, global or command scope keep running, so git lfs still works.
  • The settings travel in GIT_CONFIG_COUNT/KEY_n/VALUE_n, not -c: -c splits at the first =, and the environment also reaches the git status that runs inside each submodule. That needs git 2.31; with an older git every repository is unknown with the version in the detail, and install.sh names an older git at install time.
  • tests/git_classify.py (stdlib unittest, run in CI on Linux under Python 3.9 and on macOS) builds a repository per case — fsmonitor, filter driver, a driver named with =, a filter in a submodule, a signed stash — and shows the script leaves the program unrun while plain git making the same read runs it; plus git lfs's case and an old git.
  • ADR-028 records the decision.
  • SEO for ClawHub search: the SKILL.md description now carries migrate, new Mac, laptop and SSH keys, and says the skill installs the envrelay binary into ~/.local/bin. docs/publishing.md gives the new ClawHub name (EnvRelay: Backup, Restore & Migrate Dev Environments), categories (operations,development,productivity) and topics (backup,migration,dotfiles,developer-environment,new-machine-setup), how ClawHub's search ranks, and v1.0.2's changed audit.
  • Version 1.0.3 everywhere it is written.

Validation

  • python3 tests/git_classify.py -v: 7 passed
  • tests/installer.sh under sh, dash, bash and zsh: 99 passed each (new old-git scenario)
  • cargo fmt --check, cargo clippy --all-targets --locked -- -D warnings, cargo test --locked, cargo build --release --locked
  • shellcheck, python3 -m compileall -q skills/envrelay/scripts, check-versions.sh (1.0.3)
  • git_classify.py --scan ~/futrixdev on real repositories: same states as before

🤖 Generated with Claude Code

ClawHub re-scanned v1.0.2 on 2026-09-25 and moved its audit to Review
(A.I.G T09): git_classify.py runs read-only git commands in every
repository it finds, and a repository's own config can still make git
start programs during them — core.fsmonitor, a filter driver's clean or
process command, gpg.program through log.showSignature, the same in a
checked-out submodule.

Every git command in git_classify.py now runs with those switched off,
handed over in GIT_CONFIG_COUNT (a driver's name may contain "=", which
-c splits at). Filter drivers are switched off only when the repository
or one of its submodules defines them, so git lfs, installed in the
global config, keeps working. That needs git 2.31: with an older git
every repository is "unknown", and install.sh names an older git at
install time. tests/git_classify.py shows each case unrun by the script
and run by plain git; CI runs it. ADR-028 records it.

The description now says migrate, new Mac, laptop and SSH keys, the
words people search ClawHub with, and that the skill installs the
envrelay binary. docs/publishing.md gives the new ClawHub name, topics
and categories, how its search ranks, and v1.0.2's changed audit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@wangqianqianjun

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

1 similar comment
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@wangqianqianjun
wangqianqianjun merged commit c0a21c5 into main Sep 26, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant