Skip to content

ci(guard): run the guard corpus on ubuntu, windows and macos - #8

Merged
DefaultPerson merged 1 commit into
masterfrom
fix/guard-windows-ci
Sep 18, 2026
Merged

DefaultPerson merged 1 commit into
masterfrom
fix/guard-windows-ci

Conversation

@DefaultPerson

Copy link
Copy Markdown
Owner

Follow-up to #7.

Why

A crash inside evaluate() makes main() fail open (except Exception -> exit(0)), by design — failing closed would stall an unattended session. The cost showed up in #7: one re.PatternError on Windows disabled every path rule on that platform, silently, until someone happened to run the hook there.

That is a testing gap, not a rule gap. #7 already fixed the half that could be fixed in the corpus (pinning a POSIX host, simulating Windows). This adds the other half: actually running it on the platforms the hook is installed on.

What

  • .github/workflows/guard.yml — the corpus runs on ubuntu-latest, windows-latest and macos-latest on every push and PR (fail-fast: false, so one red leg does not hide the others). Plain python via actions/setup-python, no uv: the corpus is pure stdlib, so CI does not need the extra link.
  • A second job asserts .claude/hooks/guard.py and .codex/hooks/guard.py stay byte-identical. They are today, but only by the author's discipline.
  • rm -r of a UNC share root (//server/share, \\server\share) is now denied as network share. The drive-letter check added in fix(guard): normalize Windows paths so path rules work on Windows #7 does not match a // path, so it fell through to the POSIX ladder where no rule covers it. Paths inside a share (//server/share/build) stay allowed, so working off a network drive is unaffected.

Verification

Not covered

/cygdrive/c/... is not normalized (the docs point at Git Bash, which uses /c/); to_native hands open() a lowercased path, so on a case-sensitive-flagged NTFS directory a .pem holding a key reads as non-secret; rm -rf C: is denied, but by the home-parent rule rather than the drive rule, so the reason string is wrong; PowerShell Remove-Item -Recurse is not matched by any rm rule.

A platform-specific crash in guard.py fails open silently: the Windows
path bug disabled every path rule there and surfaced only when someone
ran the hook on Windows. Run the corpus on ubuntu, windows and macos on
every push and PR, and assert the Claude and Codex copies stay identical.

Also deny rm -r of a UNC share root (//server/share), which the new
drive-letter check did not match; paths inside a share stay allowed.
@DefaultPerson
DefaultPerson merged commit 09a5595 into master Sep 18, 2026
4 checks passed
@DefaultPerson
DefaultPerson deleted the fix/guard-windows-ci branch September 18, 2026 12:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant