diff --git a/.githooks/pre-push b/.githooks/pre-push index 438185d..07752a3 100755 --- a/.githooks/pre-push +++ b/.githooks/pre-push @@ -29,6 +29,41 @@ root=$(git rev-parse --show-toplevel 2>/dev/null) || { } cd "$root" || exit 1 +# ── WORKSPACE-ROOT ASSERTION (2026-08-05, R-204 rider) ─────────────────────────────────────────── +# Refuse a push from a clone outside the felhom workspace. +# +# WHY THIS IS A HOOK AND NOT A LINE IN A DOCUMENT: the workspace root is ALREADY written down, in +# documentation/runbooks/workspace-CLAUDE.md and in the workspace-root CLAUDE.md ("stay inside it"), +# and work drifted into a home directory anyway. A rule that has failed once as a reminder is not +# fixed by writing it down again — it has to be asserted where it can bite. +# +# A PUSH IS THE RIGHT TRIGGER, deliberately: throwaway clones under /tmp for probes and red-proofs +# never push, so nothing legitimate breaks. Reads and builds elsewhere stay unaffected. +# +# Symlinks are resolved on BOTH sides before comparison, so a symlinked path neither falsely passes +# nor falsely fails. If the workspace root does not exist on this machine the check is SKIPPED, not +# failed — this hook must not brick a legitimate clone on a different host. +# +# The only bypass is the documented `git push --no-verify`, whose use is already reportable. +FELHOM_WORKSPACE_ROOT=/mnt/5_hdd/felhom.eu +if [ -d "$FELHOM_WORKSPACE_ROOT" ]; then + ws_real=$(cd "$FELHOM_WORKSPACE_ROOT" 2>/dev/null && pwd -P) || ws_real="" + root_real=$(pwd -P) || root_real="" + if [ -n "$ws_real" ] && [ -n "$root_real" ]; then + case "$root_real/" in + "$ws_real"/*) : ;; # inside the workspace — proceed + *) + echo "pre-push: PUSH REFUSED - this clone is OUTSIDE the felhom workspace." >&2 + echo " clone: $root_real" >&2 + echo " expected: under $ws_real (repos live in $ws_real/git/)" >&2 + echo " Work in the workspace clone, or bypass with 'git push --no-verify'" >&2 + echo " and state that you did in the session report." >&2 + exit 1 + ;; + esac + fi +fi + if ! command -v python3 >/dev/null 2>&1; then echo "pre-push: FAIL - python3 not found, so the gates CANNOT run. This is a failure, never a" >&2 echo " pass by default. Install python3, or push with --no-verify and say so." >&2