Files
msd-core/hooks/gsd-worktree-path-guard.js
Tom Boucher 07adeb50a0 fix(#1342): scope worktree-path-guard to GSD executor runs; fail open for no-repo targets (#1361)
* fix(#1342): scope worktree-path-guard to GSD executor runs; fail open for no-repo targets

The PreToolUse worktree-path-guard fired for any Write/Edit in any linked git
worktree, with no check for active GSD work — so Claude Code plan-mode writing
~/.claude/plans/<slug>.md from a manually-created worktree was hard-blocked.

- Gate enforcement on the GSD isolated-executor branch namespace
  (^worktree-agent-[A-Za-z0-9._/-]+$, per worktree-branch-check.md #2924); the
  guard is a no-op in non-GSD linked worktrees.
- Fail open when a target resolves to no git repository (e.g. ~/.claude/plans/)
  instead of blocking — that is not the #260 main-repo vector. A target inside
  a .git directory still blocks (git rev-parse --is-inside-git-dir).
- The #260 different-git-root hard block (escape to the main repo) is preserved.

Detached-HEAD executors no-op the gate; this is accepted because they are
fail-closed by worktree-branch-check.md (exit 42) before committing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* chore(#1342): add changeset for worktree-path-guard scoping fix

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test(#1342): build dot-dot traversal path portably (Windows drive-letter fix)

The traversal test built its file_path by stripping a leading slash from an
absolute externalDir and path.join-ing it after a `..` chain. On Windows the
drive letter (C:\) is not a leading slash, so it survived and path.resolve
produced an invalid doubled-drive path (C:\C:\Users\...), which resolves to no
git repo — the hook failed open (exit 0) and the test expected a block (exit 2).

Use path.relative(worktreeDir, externalTarget) + string concat so the file_path
carries literal `..` segments that resolve to externalTarget on both posix and
win32 (no drive doubling). Verified with path.win32/path.posix.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-17 08:50:28 -04:00

186 lines
7.9 KiB
JavaScript

#!/usr/bin/env node
// gsd-hook-version: {{GSD_VERSION}}
// GSD Worktree Path Guard — PreToolUse hook
// Blocks Edit/Write/MultiEdit tool calls that target absolute paths outside the worktree root.
//
// Problem: gsd-executor agents spawned with isolation="worktree" sometimes issue
// Edit/Write calls with absolute paths rooted at the MAIN repository instead of
// the worktree (issue #260). The prose guard in agents/gsd-executor.md step 0b
// is never enforced because the model under load skips it.
//
// This hook enforces the constraint at the tooling layer, making it HARD-BLOCKING.
//
// Triggers on: Edit, Write, and MultiEdit tool calls
// Action: BLOCK (exit 2) if file_path is absolute and outside the worktree root
// No-op: relative paths, non-worktree CWDs, hook errors (silent fail)
const fs = require('fs');
const path = require('path');
const { spawnSync } = require('child_process');
const SPAWNOPT = { encoding: 'utf8', stdio: ['ignore', 'pipe', 'ignore'], timeout: 2000, windowsHide: true };
function git(args, cwd) {
return spawnSync('git', args, { ...SPAWNOPT, cwd });
}
// Walk up from `start` to find the nearest existing directory.
// Returns null if we reach the filesystem root without finding one.
function nearestExistingDir(start) {
let dir = start;
let prev;
do {
prev = dir;
try { fs.accessSync(dir, fs.constants.F_OK); return dir; } catch { /* keep walking */ }
dir = path.dirname(dir);
} while (dir !== prev);
return null;
}
let input = '';
const stdinTimeout = setTimeout(() => process.exit(0), 3000);
process.stdin.setEncoding('utf8');
process.stdin.on('data', chunk => input += chunk);
process.stdin.on('end', () => {
clearTimeout(stdinTimeout);
try {
const data = JSON.parse(input);
const toolName = data.tool_name;
// Only guard Edit, Write, and MultiEdit tool calls
if (toolName !== 'Edit' && toolName !== 'Write' && toolName !== 'MultiEdit') {
process.exit(0);
}
const cwd = data.cwd || process.cwd();
// Detect whether CWD is inside a linked git worktree by inspecting
// the git-dir path. In a linked worktree, git rev-parse --git-dir
// returns a path containing .git/worktrees/ as a component.
// In the main repo or a submodule it returns .git (or a path without /worktrees/).
// This approach works even when cwd is a subdirectory of the worktree.
const gitDirResult = git(['rev-parse', '--git-dir'], cwd);
if (gitDirResult.status !== 0 || !gitDirResult.stdout) {
process.exit(0); // not a git repo — pass through
}
const gitDir = gitDirResult.stdout.trim();
// A linked worktree's --git-dir contains .git/worktrees/ as a path component
const isLinkedWorktree = /[/\\]\.git[/\\]worktrees[/\\]/.test(gitDir);
if (!isLinkedWorktree) {
process.exit(0); // main repo, submodule, or separate-git-dir — no-op
}
// #1342: Only enforce inside a GSD-managed isolated executor worktree. Those
// are always on a `worktree-agent-*` branch (the positive allow-list enforced
// by worktree-branch-check.md, #2924). A manually-created linked worktree (plain
// non-GSD work, e.g. Claude Code plan-mode) is on the user's own branch, so the
// guard must be a no-op there. Detached HEAD / error → not GSD-managed → no-op.
const branchResult = git(['symbolic-ref', '--short', 'HEAD'], cwd);
const branch = branchResult.status === 0 && branchResult.stdout ? branchResult.stdout.trim() : '';
if (!/^worktree-agent-[A-Za-z0-9._/-]+$/.test(branch)) {
process.exit(0); // not a GSD-managed executor worktree — no-op
}
// Get the raw --show-toplevel output for the worktree (cwd).
// We keep it raw (not path.resolve'd) to compare directly with the
// file's toplevel — same git binary, same format, no normalization needed.
const wtTopResult = git(['rev-parse', '--show-toplevel'], cwd);
if (wtTopResult.status !== 0 || !wtTopResult.stdout) {
process.exit(0); // can't determine root — fail open
}
const wtTopRaw = wtTopResult.stdout.trim();
const rawFilePath = data.tool_input?.file_path || '';
if (!rawFilePath) {
process.exit(0);
}
// Relative paths are always safe — they resolve relative to CWD inside the worktree
if (!path.isAbsolute(rawFilePath)) {
process.exit(0);
}
// Normalise .. traversal so /worktree/src/../../../main/file
// resolves to its true location before we check containment.
const filePath = path.resolve(rawFilePath);
// Find the nearest existing ancestor of filePath so we can ask git
// for its toplevel. The file itself may not exist yet (Write creates
// new files), but at least one ancestor directory must exist.
// We check the file itself first in case it already exists.
const checkDir = nearestExistingDir(
(() => {
try {
return fs.statSync(filePath).isDirectory() ? filePath : path.dirname(filePath);
} catch {
return path.dirname(filePath);
}
})()
);
if (!checkDir) {
// Walked to root without finding any directory — path is synthetic.
// A path with no existing ancestor is not the #260 main-repo vector;
// #260 is caught by the different-git-root branch below. Fail open. (#1342)
process.exit(0);
}
// Ask git for the toplevel of the file's location.
// Comparing two raw git --show-toplevel outputs avoids every
// platform-specific path normalisation pitfall (Windows 8.3 short names,
// case differences between realpathSync and path.resolve, forward- vs
// back-slash inconsistencies) — both values come from the same git binary
// in the same format by definition.
const fileTopResult = git(['rev-parse', '--show-toplevel'], checkDir);
if (fileTopResult.status !== 0 || !fileTopResult.stdout) {
// The target's location is not a git work tree. Two sub-cases:
// - Inside a .git directory (e.g. /main-repo/.git/config or .git/hooks/*)
// → an absolute write into a repository's internals; still a #260-class
// escape (and dangerous) → BLOCK.
// - Truly outside all git repositories (e.g. ~/.claude/plans/) → not the
// main-repo vector → fail open. (#1342)
const insideGitDir = git(['rev-parse', '--is-inside-git-dir'], checkDir);
if (insideGitDir.status === 0 && insideGitDir.stdout && insideGitDir.stdout.trim() === 'true') {
const output = {
decision: 'block',
reason:
`Worktree path guard: '${filePath}' is inside a git internal (.git) directory, ` +
`not the active worktree at '${wtTopRaw}'. Writing to repository internals via an ` +
`absolute path is not permitted from an isolated executor worktree. Use a relative path.`,
};
process.stdout.write(JSON.stringify(output));
process.exit(2);
}
// Outside all git repositories — fail open (#1342).
process.exit(0);
}
const fileTopRaw = fileTopResult.stdout.trim();
// Same git toplevel → file is inside the worktree → allow
if (fileTopRaw === wtTopRaw) {
process.exit(0);
}
// BLOCK: file resolves to a different git root than the active worktree
const output = {
decision: 'block',
reason:
`Worktree path guard: '${filePath}' resolves to git root '${fileTopRaw}' which ` +
`differs from the active worktree root '${wtTopRaw}'. This likely means an ` +
`absolute path was derived from the orchestrator's main repository instead of ` +
`the active worktree. To fix: use a relative path, or re-derive the base ` +
`directory with \`git rev-parse --show-toplevel\` from within the worktree ` +
`(hook cwd: '${cwd}').`,
};
process.stdout.write(JSON.stringify(output));
process.exit(2);
} catch {
// Silent fail — never block valid tool calls due to hook errors
process.exit(0);
}
});