Fold all 10 residual isWindsurf branches in bin/install.js onto descriptor-driven hostBehaviors (byte-parity — no fold changes any install output): - 2 dead destructures dropped (uninstall, finishInstall); the dead `else if (isWindsurf)` legacy agent-loop arm removed (windsurf ∈ _DESCRIPTOR_AGENTS_RUNTIMES → unreachable). - skipSharedHooksInstall:true folds the two `!isWindsurf` shared-hooks exclusions. - legacyDevinSkillsCleanup:true folds the `.devin`→`.windsurf` one-time cleanup gate. - installsCommandBodiesForWorkflowDelegation:true folds the #1629 command-body copy (workflow-delegation target — load-bearing; local-install verified intact). - verificationStyle:"windsurf-workflows" folds the workflow-count report. - Corrected stale _LEGACY_SCAN_SUBDIR_NAMES + hooks-json manifest comments (cursor + windsurf). Zero live runtime==='windsurf'/isWindsurf branches remain across bin/install.js, install-engine.cts, surface.cts, runtime-artifact-conversion.cts (AC2 guard scans all four). UPGRADE (Cascade hook bus): wire GSD's write/command safety guards into Windsurf's native hook bus. New hooksSurface 'windsurf-hooks-json' (VALID_HOOKS_SURFACES 7→8, GATE A profile-marker-only allowlist, the HooksSurface union) + writeWindsurfHooksJson (Cursor-templated, Cascade's flat {hooks:{<event>:[{command}]}} shape) writing .windsurf/hooks.json with two BLOCKING pre-hooks: - pre_write_code → gsd-windsurf-pre-write.js: blocks writes to a file outside the active git worktree / into .git internals. - pre_run_command → gsd-windsurf-pre-command.js: conservative destructive-command deny-list (rm -rf of root/home incl. sudo/env/path-prefixed forms; fork bombs; force-push refspec forms — HEAD:main, +main, --force/-f — to main/master/next). Both use Cascade's protocol (stdin JSON, exit 2 + stderr to block, exit 0 to allow, fail-open on error/timeout). Tokenize-based classifier (no catastrophic-backtracking regex; 4096-char cap) with the fail-closed false-positives fixed post-review. The 4 advisory GSD guards + pre_mcp_tool_use + 5 post_* logging events are deliberately NOT wired: Cascade has no context-injection channel for advisory hooks and GSD has no MCP guard — porting them would be non-functional padding (documented; codebuddy #2098 / copilot #2099 faithful-subset precedent). extendedHookEvents stays []. Golden: the 2 guard scripts ship in the shared hook bundle (HOOKS_TO_COPY + the shared managed-hooks-registry), exactly like cursor's 6 gsd-cursor-*.js scripts — so the 8 shared-bundle runtimes' fixtures gain the 2 inert windsurf scripts + the registry hash (functionally inert for non-windsurf; the established cursor pattern). No install-output change beyond that (the folds are byte-parity; skip-bundle runtimes untouched). New scripts registered in managed-hooks-registry + build-hooks + INVENTORY. Tests: declarative-reference- windsurf (adapter/axes/fail-closed + AC2 guard) + windsurf-hooks-bridge (live exit-2 blocking + allow/fail-open + ReDoS-bound + writer/reconcile/remove idempotency); VALID_HOOKS_SURFACES pin updated to 8. Matrix hookBus delta + changeset (Changed). capability-registry regenerated. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
46 lines
1.5 KiB
JavaScript
46 lines
1.5 KiB
JavaScript
'use strict';
|
|
|
|
/**
|
|
* Authoritative list of GSD-managed hook files.
|
|
*
|
|
* Extracted from the worker script into a shared CJS module so that:
|
|
* 1. gsd-check-update-worker.js can require() it directly (no source-level
|
|
* duplication).
|
|
* 2. Tests can assert against the exported array instead of regex-parsing
|
|
* the worker source (retiring the pending-migration-to-typed-ir token
|
|
* on managed-hooks.test.cjs and orphaned-hooks.test.cjs, per #455).
|
|
*
|
|
* These are the files GSD ships into ~/.claude/hooks/ (or equivalent) and
|
|
* checks for staleness after an update. Orphaned files from removed features
|
|
* (e.g., gsd-intel-*.js) must NOT be listed here — that would cause permanent
|
|
* stale warnings for users who haven't cleaned up manually (#1750).
|
|
*/
|
|
const MANAGED_HOOKS = [
|
|
'gsd-check-update-worker.js',
|
|
'gsd-check-update.js',
|
|
'gsd-config-reload.js',
|
|
'gsd-context-monitor.js',
|
|
'gsd-cursor-post-tool.js',
|
|
'gsd-cursor-pre-tool.js',
|
|
'gsd-cursor-session-start.js',
|
|
'gsd-cursor-stop.js',
|
|
'gsd-cursor-subagent-start.js',
|
|
'gsd-cursor-subagent-stop.js',
|
|
'gsd-ensure-canonical-path.js',
|
|
'gsd-graphify-update.sh',
|
|
'gsd-phase-boundary.sh',
|
|
'gsd-prompt-guard.js',
|
|
'gsd-read-guard.js',
|
|
'gsd-read-injection-scanner.js',
|
|
'gsd-session-state.sh',
|
|
'gsd-statusline.js',
|
|
'gsd-update-banner.js',
|
|
'gsd-validate-commit.sh',
|
|
'gsd-windsurf-pre-command.js',
|
|
'gsd-windsurf-pre-write.js',
|
|
'gsd-workflow-guard.js',
|
|
'gsd-worktree-path-guard.js',
|
|
];
|
|
|
|
module.exports = { MANAGED_HOOKS };
|