openclaw/scripts/pre-commit
Peter Steinberger 68fec8569d
fix(git-hooks): keep unstaged bytes out of pre-commit formatting (#137723)
* fix(git-hooks): keep unstaged bytes out of pre-commit formatting

format-staged.sh formatted working-tree files and then git-added the
complete working-tree contents of every staged file, so partial staging
(hunk-level git apply --cached) silently committed unstaged work, and
dirty non-format files were restaged wholesale.

Fully staged files keep the fast batch oxfmt --write + restage path, now
scoped to format-eligible files only. Partially staged files are formatted
index-only: the staged blob goes through oxfmt --stdin-filepath (same repo
config and ignorePatterns as batch mode, verified live), then
git hash-object --no-filters and git update-index --index-info, preserving
the staged mode and never touching working-tree bytes. Non-format staged
files are no longer restaged at all; staged deletions, unstaged working-tree
deletions, symlinks, and executable modes are preserved, and a formatter
that exits 0 with empty output for nonempty input fails the hook instead of
staging an emptied file.

Security scans (pre/post-format literal scan), filename protections, and
the sequencer early-exit are unchanged. Regression tests fail on the
pre-fix script; the guard/boundary suites now protect the staged-bytes-only
invariant instead of the old restage behavior.

* fix(git-hooks): pin literal pathspecs in formatter Git lookups

Enumerated staged filenames re-enter Git as pathspecs in the new
partial-state diff, staged-entry lookup, and restage add. Production runs
under the guard's GIT_LITERAL_PATHSPECS env, but the script now pins
--literal-pathspecs itself so bracket or ":(...)" magic filenames cannot
misclassify partial staging when invoked without that env. Regression
covers direct invocation with magic names; it fails without the flags.
2026-09-03 18:34:45 -07:00
..
filter-staged-files.mjs
format-staged.sh fix(git-hooks): keep unstaged bytes out of pre-commit formatting (#137723) 2026-09-03 18:34:45 -07:00
guard-staged-content.mjs fix: preserve private hook checks and diagnostics (#132403) 2026-08-29 11:25:36 -07:00
pnpm-audit-prod.mjs fix(ci): retry transient npm advisory timeouts (#137716) 2026-09-04 08:55:10 +08:00
run-node-tool.sh