fix(gate): 会话实测 6 项——守卫绕过闭环 + 提交面收窄 + 报告指令前置(叠于 v0.10.1) - #31
Merged
Merged
Conversation
来自真实多仓修复会话的反馈批次(门禁在主工作树拦 3 次、又被 4 种命令形态
静默绕过、长报告把指令段截掉):
1) 守卫绕过闭环(4 形态实测漏网 + 0.8.2 roots 层击穿)
- 切段扫描前展开 $(...) 与反引号内层文本(ro=$(git push…) 实测静默放行)
- 段首归一化剥 shell 控制引导词 if/then/else/elif/while/until/do/!
(if git push; then、for x; do git push; done 实测静默放行)
- resolve_project_roots 与 is_guarded 同源判定 + git -C <path> 显式仓边界:
0.8.2 ①只修了 _guarded_mode,roots 层仍用原始 tokens[0]——git -C /
FOO=1 git / sudo git 三形态 is_guarded=True 但 roots=[] → main 静默放行
2) commit 面按命令链收窄(staging_intent)
- 纯 git commit → 仅 staged;add -A/-a/-u 或 commit -a → 扩到未暂存/未跟踪;
git add <paths> → 并入 extra(PreToolUse 时 add 未执行、暂存区是旧的);
并行会话的未暂存 WIP 不再拦无关提交(本会话实测误拦点)
- lanes/extra 进缓存键(窄面 pass 被宽面复用 = 绕过);extra 按仓根换算 +
各仓存在性过滤;UPS 保持三路宽口径(软门无命令可预测,注释+协议已改)
3) 报告结构:整调用声明/skipGate/同意边界前置到首行综述紧后;总长硬上限
REPORT_MAX_CHARS=3000;超限保头保尾截细节(尾部日志路径不截掉)
4) 存量归因:delta 下项目级命令报错文件全部在改动集外 → skipped + 完整日志
(防"历史债不还就永远提交不了 → 只能 skipGate"的信誉清零)
5) append_files=false:java/kotlin/rust/go/csharp/vbnet/terraform/protobuf/elm
九个项目级命令不再被追加文件路径(mvn javadoc:jar foo.java → Unknown
lifecycle phase 假失败)
6) SessionStart 版本积压检测(version_backlog_note 纯函数)+ 缓存指纹轻量化
(name-only+stat 替代全仓全文 diff,staged 由 index mtime 兜底)
契约同 commit 同步:__protocol__.md §4(归一化/同源判定/指令前置/上限/存量
skip/lanes 语义)+ openspec hook-protocol(MUST 扩写 + 新 Requirement: The
commit face SHALL match the actual staging surface + 3 Scenario);README 双语
与 4 份 manifest → 0.8.3。
验证:unittest 120 OK(+26:tests/test_session_fixes_20260922.py)、
run_all 141/0、validate_languages_json 11 规则、README/manifest 一致性全绿
…back 并行会话先合入 #30(v0.10.0) 与 #32(v0.10.1),本分支叠上去。冲突解法: - 4 份版本 manifest 取 theirs(0.10.1,不回退已发布版本号) - README 双语版本行对齐 0.10.1(#30/#32 未更新该行,顺手修正既存偏差) - scripts/languages.json 自动合并:他们的 find 门禁 -not -path/xargs -r 与本分支 append_files= false ×9 共存(9+13 处断言通过) - hooks/gate_lib.py:scope_cmd 调用双参数并存 (本分支 append_files=append + 上游 full_excludes=not uses_delta_files) - scripts/scope.py:模块 docstring 合并双意图描述 验证:unittest 135/135(含上游新增用例)、run_all 141/0、schema 11 规则
loong10k
added a commit
that referenced
this pull request
Sep 22, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
摘要
会话实测反馈批次(门禁误拦 3 次 + 4 种命令形态静默绕过 + 长报告截断指令段):
$(...)/反引号内层展开;段首剥 shell 控制词(if/then/do/while/!);resolve_project_roots与is_guarded同源判定 +git -C显式仓边界(修复 0.8.2 半修击穿:三形态 is_guarded=True 但 roots=[] 静默放行)staging_intent——纯 commit 只查 staged(并行会话未暂存 WIP 不再误拦);add -A/commit -a扩面;add <paths>并入 extra;lanes/extra 进缓存键REPORT_MAX_CHARS=3000+ 保尾截断(日志路径不丢)append_files=false×9 项目级语言(mvn 把foo.java当 goal 假失败)契约同 commit:
__protocol__.md§4 +openspec/hook-protocol新 Requirement/3 Scenario。叠于 v0.10.1 的合并说明
上游 #30/#32 先落地:版本 manifest 取 theirs(0.10.1)、README 版本行对齐 0.10.1、
languages.json上游 find 门禁改动与本 PRappend_files共存、gate_lib的scope_cmd调用append_files+full_excludes双参数并存。本 PR 不再含版本号 bump。验证
run_all.py141/0、validate_languages_json11 规则、README/manifest 一致性全绿