feat: preflight - prerequisites checked and tool paths recorded before wikitool runs; launcher refuses without it (#151, POSIX half)
Files changed: - .claude/settings.json - .gitea/workflows/ci.yml - .gitea/workflows/nightly.yml - .gitea/workflows/release.yml - .gitea/workflows/tracker-live.yml - .github/hooks/wiki-trace.json - .gitignore - .vibe/hooks.toml - AGENTS.md - CHANGES.md - EVALS.md - INSTALL.md - README.md - VERSION - instructions/bootstrap.md - instructions/preflight.md - instructions/setup-instance.md - instructions/upgrade-instance.md - tools/CONTRACT.md - tools/README.md - tools/chemenu/cli.py - tools/chemenu/commands/dist_cmd.py - tools/chemenu/commands/docs_verify.py - tools/chemenu/commands/doctor.py - tools/chemenu/commands/git_publish.py - tools/chemenu/commands/migrate_cmd.py - tools/chemenu/config.py - tools/chemenu/corpus_cache.py - tools/chemenu/prerequisites.py - tools/chemenu/search/ripgrep.py - tools/chemenu/tests/conftest.py - tools/chemenu/tests/test_dist_upgrade.py - tools/chemenu/tests/test_doctor.py - tools/chemenu/tests/test_preflight.py - tools/chemenu/toolpaths.py - tools/preflight.sh - tools/prerequisites.txt - tools/run_wikitool.py - tools/trace-hook - tools/wikitool
This commit is contained in:
1 parent
5a731729f6
commit
e4b2b6d9b1
40 files changed
+1849
-125
No files matched your search
@@ -128,7 +128,8 @@ Verified against vendor documentation on 2026-08-23.
|
||||
|
||||
### Claude Code
|
||||
|
||||
`.claude/settings.json` wires `UserPromptSubmit` to `tools/trace_ingest.py`. That is what makes
|
||||
`.claude/settings.json` wires `UserPromptSubmit` to `tools/trace_ingest.py`, through
|
||||
`tools/trace-hook` like every hook here (see the load-bearing details under Copilot CLI). That is what makes
|
||||
`clearance-ended-the-turn` scorable here: without a `prompt.submitted` event there is no turn
|
||||
boundary to place an exit-42 call and its `--confirm` on either side of, and the rule reports
|
||||
"cannot say" instead of a verdict.
|
||||
@@ -157,8 +158,17 @@ own decision-document schema verified against a live CLI first (this repo has no
|
||||
unverified, per the same rule that governed the Vibe adapter: an adapter that cannot be verified
|
||||
is not written.
|
||||
|
||||
Two details in that file are load-bearing:
|
||||
Three details in that file are load-bearing, and the first holds for all three hook
|
||||
configurations:
|
||||
|
||||
- **The interpreter is the venv's, never the script's shebang.** Each `bash` command is
|
||||
`./tools/trace-hook ...`, which runs `trace_ingest.py` with `tools/.venv`'s Python in either
|
||||
venv layout; each `powershell` command names `tools\.venv\Scripts\python.exe` directly. A
|
||||
hook command is a fixed string and cannot read `.wikitool-tools.json`, but the venv is
|
||||
created from the recorded interpreter at a fixed place, so it stands in for it. The shebang
|
||||
(`python3`) was the Microsoft Store alias in Git Bash on Windows, which made every hook there
|
||||
a silent no-op. Before the preflight has created the venv, `trace-hook` records nothing and
|
||||
exits 0.
|
||||
- **Every command ends in `|| true`.** `preToolUse` hooks are *fail-closed*: a non-zero exit
|
||||
denies the tool call. Without the guard, a missing interpreter would turn the observer into
|
||||
a blocker that refuses every tool call in the session. (Timeouts are fail-open, so the
|
||||
|
||||
Reference in new issue
Block a user