fix: scope Codex graph hooks to event cwd - #1061
Open
seonghobae wants to merge 1 commit into
Open
seonghobae wants to merge 1 commit into
seonghobae wants to merge 1 commit into
Conversation
Author
|
Ready for maintainer review of e4b1d7e. GitHub rejected my RequestReviewsByLogin attempt because this fork contributor lacks permission. Please review the payload cwd boundary and run the repository-required checks through the normal fork-PR path. Validation limits and the package-before-hook-regeneration requirement are recorded in the description. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Codex graph hooks currently discard the event JSON and choose a repository from inherited process cwd. When the launcher cwd differs from the event checkout, they can update the wrong graph.
Add
hook-updateandhook-statuscommands that resolve the repository from a literal absolute payloadcwd. Missing, malformed, relative, nonexistent, and non-repository paths do not trigger updates. Generated hooks forward JSON and propagate failures when the executable exists. Status delegates to the existing console command, preserving its output and failures.Validation:
The package must be upgraded to support these new commands before regenerating hooks. No installed hook configuration was changed. Payload provenance relies on the agent hook channel; filesystem/Git validation is not a separate repository trust allowlist.