Repository navigation
git-hooks: install no pre-push hook, and prune stale chained shims - #724
Merged
Merged
Conversation
Upstream git-hooks.nix gives check-added-large-files the stages
[pre-commit pre-push manual], so every consumer's devShell installed a prek
pre-push shim. At pre-push the hook checks nothing (its candidate set is the
staged diff), but the shim fails the push whenever the checkout's
.pre-commit-config.yaml has no pre-push hook ("No hooks found for stage
pre-push"), e.g. a linked worktree or a checkout whose config predates this
hook set. In a Reprobuild workspace it is chained as pre-push.repro-local, so
it blocked the publication gate as well (metacraft-labs/infra, 2026-10-01/02).
- hooks.nix: check-added-large-files runs at pre-commit only (mkOverride 90
replaces upstream's list rather than concatenating with it; a consumer can
still mkForce a pre-push stage).
- reprobuild handoff: after an installer run, a generated pre-commit/prek
shim chained as <hook>.repro-local for a stage the installer did not
install is removed, so existing checkouts drop the stale pre-push shim on
their next shell entry. Hand-written .repro-local files are never touched,
and an entry where the installer did not run prunes nothing.
- check git-hooks-reprobuild-handoff: case 6 covers the pruning, the
hand-written exception and the no-installer-run case; it fails with the
pruning disabled.
Verified in a fresh infra clone with Reprobuild dispatchers: before, the
shell installed pre-push.repro-local (prek); after, only pre-commit is
chained, the stale pre-push shim is removed, and a commit and a push both
succeed through the dispatchers.
Contributor
|
Thanks for your Pull Request! Below you will find a summary of the cachix status of each package, for each supported platform.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Every consumer's dev shell installed a prek pre-push shim, because upstream git-hooks.nix gives
check-added-large-filesthe stages[pre-commit pre-push manual]. At pre-push that hook checks nothing: its candidate set is the staged diff, which is empty at push time. But the shim fails the push whenever the pushing checkout's.pre-commit-config.yamlhas no pre-push hook ("No hooks found for stagepre-push"), for example a linked worktree or a checkout whose config predates this hook set. In a Reprobuild workspace the shim is chained aspre-push.repro-local, so it also blocked the publication gate. It broke every metacraft-labs/infra push on 2026-10-01 and again on 10-02.Changes:
git-hooks/hooks.nix:check-added-large-filesruns at pre-commit only. It usesmkOverride 90because upstream's list is a plain definition, and lists at equal priority concatenate. A consumer can stillmkForcea pre-push stage.lib/git-hooks-reprobuild-handoff.nix: after an installer run, a generated pre-commit/prek shim chained as<hook>.repro-localfor a stage the installer did not install is removed. Existing checkouts therefore drop the stale pre-push shim on their next shell entry. Hand-written.repro-localfiles are never touched, and an entry where the installer did not run prunes nothing. The Reprobuild dispatcher contract is unchanged.checks/git-hooks-reprobuild-handoff.nix: case 6 covers the pruning, the hand-written exception and the no-installer-run case. It fails with the pruning disabled (negative control run locally).Verification:
checks.x86_64-linux.git-hooks-reprobuild-handoff: all 6 cases pass (real prek and git).pre-push.repro-local(prek), with stagespre-commit pre-push manual.--override-input nixos-modules), only pre-commit is chained, the stale pre-push shim is removed ("git-hooks: removed .git/hooks/pre-push.repro-local …"), and a commit and a push both run through the dispatchers.Not covered here: gosti calls upstream's
pre-commit-check.shellHookdirectly, without this module's installer or handoff, so its dev shell still moves Reprobuild dispatchers to.legacy. Fixing that means adopting the handoff there; it is a separate change.