Skip to content

Keep the gate runtime tracked under a global bin/ ignore, and say when a hook target is not - #166

Merged
jothimani-rajendran merged 2 commits into
mainfrom
claude/track-chock-bin
Sep 26, 2026
Merged

jothimani-rajendran merged 2 commits into
mainfrom
claude/track-chock-bin

Conversation

@jothimani-rajendran

Copy link
Copy Markdown
Collaborator

What

An adopter on Windows lost every agent hook. A global gitignore bin/ rule (from the Visual Studio, .NET and Java templates) matched .chock/bin/, so git add -A skipped the gate runtime. After that, every clone, CI checkout and git clean -x had hook configs naming a file that didn't exist. Claude Code showed SessionStart hook error ... can't open file '.chock/bin/claude_code.py'. Python exits 2 when it can't open a script, so each hook either blocks the tool call or, on clients that ignore hook failures, never runs the gate. chock check said nothing about it.

  • Tracked explicitly. The new chock.scaffold.gitrules.ensure_git_rules writes chock's .gitignore rules. Both init and sync (recompile) call it.
    • It keeps .chock/log/ ignored.
    • It adds !.chock/bin/, !.chock/bin/**, !.chock/compiled/ and !.chock/compiled/**. A repository's own .gitignore outranks core.excludesFile, so the negations win.
    • Rules are appended once, and a rule the adopter already has is left alone.
    • Adopters who ran init before this change get the rules on their next chock sync. chock's own .gitignore now carries the block.
  • Reported. check_dangling_hook_targets moved to validation/checks_hook_targets.py to keep checks_repo.py within the 300-line budget.
    • It now also covers .chock/compiled/*.json targets.
    • It reports a target that exists here but is git-ignored, naming the rule by source:line:pattern and giving the fix.
    • It still reports a missing target.
    • Whether a path is ignored is decided with check-ignore -q. -v alone also lists the ! negations that re-include a path, and exits 0 for them.
  • Changelog Unreleased entries; docs/getting-started.md and docs/adopting.md updated.

Definition of done

  • chock check → 0 errors, 0 warnings, 0 infos
  • chock check --only matrix passes; matrix unchanged (no emitted surface changed)
  • chock sync --repo . --check clean
  • chock check --only verify clean
  • Registry rescanned; no stale entries
  • pytest -q: 1472 passed, 2 skipped. The new tests fail on the old code (6 of 7). One test is red in this sandbox and also red on unmodified main here: test_validate_hook_interpreter::test_a_stale_baked_interpreter_falls_back_instead_of_breaking. The system python3 has no jsonschema; this is environmental, and CI is the judge.
    • New tests/test_runtime_tracked_under_global_ignore.py uses a GIT_CONFIG_GLOBAL excludes file with [Bb]in/. It checks four things:
      • the runtime is tracked despite the global ignore, and an ignored runtime is reported with the rule named;
      • sync restores the rules;
      • a missing compiled gate is reported, and a negated path is not;
      • rules are written once and the adopter's own rules are kept.
  • pytest acceptance/ ...: 21 passed (init and sync write .gitignore)
  • Existing artifacts migrated: chock's own .gitignore carries the new block
  • Touched manifests: none; changelog Unreleased entry added
  • ruff check . and ruff format --check . clean

Claims

  • No surface is described as enforcing more than it installs. This PR changes no emitted hook or installed surface. It keeps the installed runtime in version control and makes chock check say when it isn't.

Context: open-coder-ai/chock-catalog#108 works around this in its agent test kit (kit.py doctor, force-adding the generated files).

🤖 Generated with Claude Code

https://claude.ai/code/session_01CzNYfzP8ymU3r4JB9Sz8Ha


Generated by Claude Code

…n a hook target is not

The `bin/` rule in the Visual Studio, .NET and Java gitignore templates, common in a developer's
global excludes file, matched `.chock/bin/`: `git add -A` never tracked the runtime every agent
hook runs, and a clone, a CI checkout or `git clean -x` left the agents' hook configs naming a file
that was not there. Found on Windows by chock-catalog's agent test kit: Claude Code reported
`SessionStart:startup hook error ... can't open file '.chock/bin/claude_code.py'`, and no gate
judged anything from then on.

- chock.scaffold.gitrules writes chock's .gitignore rules in one place: `.chock/log/` ignored as
  before, and `!.chock/bin/`, `!.chock/compiled/` (and `/**` under each) re-included -- a
  repository's own .gitignore outranks a global excludes file. `chock init` writes them, and
  `chock sync` adds them for adopters who initialised earlier. This repository's own .gitignore
  carries them now.
- check_dangling_hook_targets reports a hook target git would ignore, naming the rule and where
  it lives, as well as a missing one, and covers the compiled gate a hook hands the runtime.
  It asks `check-ignore -q` whether a path is ignored: `-v` also names a matching `!` negation,
  and exits 0 for it.
- docs: getting-started and adopting say what the rules are and why.

tests/test_runtime_tracked_under_global_ignore.py runs under a global excludes file with `[Bb]in/`:
the runtime and compiled gates are tracked after init and sync; without the rules the check names
the global rule; sync restores the rules; a missing compiled gate is reported; a negated path is
not; the rules are written once and an adopter's own are kept.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
checks_repo.py went past the 300-line review budget with the ignore-aware
reasons; the hook-target check is one activity and now reads as one file.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
@jothimani-rajendran
jothimani-rajendran marked this pull request as ready for review September 26, 2026 20:13
@jothimani-rajendran
jothimani-rajendran merged commit 0b63924 into main Sep 26, 2026
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants