fix(#2665): watch the hook bundle and the install markers the census found

Self-found by re-deriving the guard-shape census against bin/install.js's own
write sites, not by a review finding. Three artifacts a global install writes
into a live config ROOT were watched by nothing:

  hooks/gsd-check-update.js, hooks/gsd-context-monitor.js,
  hooks/gsd-update-banner.js   -- `hooks` was absent from GSD_PREFIXED_PARENTS
  .gsd-source, .gsd-profile    -- absent from GSD_OWNED_ENTRIES, and an
                                  exact-name list does not match a dot-prefixed
                                  name via the `gsd-` prefix rule

This is the SAME shape as the leak that motivated the prefixed-parent scan in
round 1 -- a gsd-prefixed child under a parent nobody had listed -- one parent
over. That it recurred is the argument for re-deriving this list from the
installer each round instead of trusting it: the enumeration is the weak point
of an enumerate-and-block mechanism, and it does not announce when it falls
behind.

Ownership is unchanged, only coverage: `hooks/` is shared with the host agent,
so only `gsd-`-prefixed children are watched. A test asserts a host-owned
hook is still ignored, because widening the parent list must not widen
ownership -- a guard that flags the host's own files gets switched off, and
then catches nothing at all.

Reverting the widening fails the new test.
This commit is contained in:
0xdhx
2026-08-06 16:43:32 -05:00
parent e31f706ceb
commit 104fc76f70
2 changed files with 63 additions and 3 deletions

View File

@@ -61,8 +61,20 @@ const fs = require('fs');
const os = require('os');
const path = require('path');
/** Top-level entries only a GSD install creates. See SCOPE above before widening. */
const GSD_OWNED_ENTRIES = ['gsd-core', 'gsd-file-manifest.json', 'gsd-pristine'];
/**
* Top-level entries only a GSD install creates. See SCOPE above before widening.
*
* `.gsd-source` and `.gsd-profile` were added by the round-5 census (see below):
* bin/install.js writes both at the config ROOT for a global install, and an
* exact-name list does not match a dot-prefixed name by the `gsd-` prefix rule.
*/
const GSD_OWNED_ENTRIES = [
'gsd-core',
'gsd-file-manifest.json',
'gsd-pristine',
'.gsd-source',
'.gsd-profile',
];
/**
* Directories GSD SHARES with the host agent. Watching them wholesale would
@@ -73,8 +85,16 @@ const GSD_OWNED_ENTRIES = ['gsd-core', 'gsd-file-manifest.json', 'gsd-pristine']
* `spawnSync` that sandboxed HOME but inherited an ambient CLAUDE_CONFIG_DIR
* wrote `<live>/skills/gsd-dev-preferences/SKILL.md`, which sits under none of
* the three top-level entries above.
*
* `hooks` joined them in round 5, found by re-deriving the census rather than by
* a review finding — the SAME shape one parent over. bin/install.js writes
* `hooks/gsd-check-update.js`, `hooks/gsd-context-monitor.js` and
* `hooks/gsd-update-banner.js` into the config root, and with `hooks` absent from
* this list a leak of any of them passed the guard silently. The lesson the first
* miss taught is that this list is the weak point, so it is re-derived from the
* installer's own write sites each round rather than trusted.
*/
const GSD_PREFIXED_PARENTS = ['agents', 'commands', 'skills'];
const GSD_PREFIXED_PARENTS = ['agents', 'commands', 'skills', 'hooks'];
const GSD_ARTIFACT_PREFIX = 'gsd-';
/**