Claude Code's (and Copilot's) native plugin installer has zero awareness of .apm/ nesting -- it convention-scans only flat skills/, agents/, commands/, hooks.json at each plugin's root. Confirmed via strings on the installed claude binary and live installs of git@holocron/gitea@holocron/kyberforge@ holocron, all reporting Skills(0) Agents(0) Hooks(0) post ADR-0015's apm conversion. Root cause (apm_cli/core/plugin_manifest.py): apm's plugin.json compiler deliberately strips skills/agents/commands keys, assuming the host already auto-discovers those convention directories -- it has no model of .apm/ being host-visible at all. Separately, apm's own bundle exporter (apm_cli/bundle/plugin_exporter.py, behind `apm pack --format plugin`) implements the correct .apm/ -> flat mapping, but only ever targeted build/<name>-<version>/, a path nothing in marketplace.json's source: points at. scripts/sync-plugin-content.sh wraps that bundle exporter and copies its agents/, skills/, commands/, instructions/, extensions/, and merged hooks.json back into each plugin's own root as a second tracked compiled-output category -- same governance status as .claude-plugin/plugin.json: generated from .apm/, never hand-edited. tests/ subdirectories are excluded from the mirror (dev fixtures, not host-visible runtime content; several hardcode a relative repo-root walk-up sized for the .apm/-nested depth, which breaks when duplicated one level shallower). Applied for real across all 6 plugins and verified two ways: `claude plugin validate --strict` passes on every real plugin directory, and a live `claude --plugin-dir <path> -p "list skills/agents"` behavioral test confirms content is now actually discovered. Also, from the same issue #90 review round: - scripts/check-manifests.sh pointed at each plugin's root-level plugin.json (checking skills/hooks/mcpServers/agents pointer fields) -- that file was a stale near-duplicate of .claude-plugin/plugin.json nothing else read or wrote, now deleted across all 6 plugins. check-manifests.sh is rewritten to validate .claude-plugin/plugin.json instead, and drops the pointer-field checks entirely (nothing to check -- those fields are correctly absent by design). Content-presence drift is now check-plugin-content-sync's job, a new pre-push hook wired in .pre-commit-config.yaml. docs/adr/0017 records the root cause and decision in full, including two rejected alternatives (patching plugin.json's path fields directly -- apm's compiler strips them on every run; pointing marketplace.json at apm pack's build/ output -- a version-suffixed non-source directory nothing can install from without an extra build step). ADR-0015 and CONTEXT.md are updated to point at it. Refs: #90
131 lines
4.2 KiB
Markdown
131 lines
4.2 KiB
Markdown
---
|
|
source_keys:
|
|
- context7-pre-commit-com
|
|
- pre-commit-com
|
|
---
|
|
|
|
# Hook Failure Patterns
|
|
|
|
Common hook failure causes and concrete next-step suggestions.
|
|
|
|
## Hook modified files — commit blocked
|
|
|
|
Cause: A fixer hook (e.g. `trailing-whitespace`, `end-of-file-fixer`, `pretty-format-json`) modified staged files. The commit is blocked because the staged version is now stale.
|
|
|
|
Fix: Re-stage and recommit.
|
|
```bash
|
|
git add -u
|
|
git commit -m "same message"
|
|
```
|
|
|
|
## Secret detected (gitleaks)
|
|
|
|
> Not sourced from the pre-commit research corpus (`context7-pre-commit-com`/`pre-commit-com` cover pre-commit itself, not gitleaks) — general tool knowledge, verify against gitleaks' own docs if precision matters.
|
|
|
|
Cause: gitleaks found a high-entropy string or known secret pattern in a staged file.
|
|
|
|
Suggestions:
|
|
- If it's a false positive: add a `# gitleaks:allow` inline comment, or add the path to `.gitleaksignore`.
|
|
- If it's a real secret: remove it from the file, rotate the credential, then commit.
|
|
|
|
## Shellcheck warning
|
|
|
|
> Not sourced from the pre-commit research corpus — general tool knowledge, verify against shellcheck's own docs if precision matters.
|
|
|
|
Cause: shellcheck found a shell script issue. The output includes the file path, line number, and SC-code.
|
|
|
|
Fix: Look up the SC-code on shellcheck.net or pass `--explain SCxxxx` to shellcheck for a detailed explanation. The most common fixes:
|
|
- SC2086 (unquoted variable): wrap in double quotes.
|
|
- SC2046 (unquoted command substitution): wrap in double quotes.
|
|
- SC2181 (check exit code of `$?`): use `if command; then` directly.
|
|
|
|
## `check-hooks-apply` fails
|
|
|
|
Cause: A hook's `files`/`types` filter matches zero files in the repo — the hook is dead weight.
|
|
|
|
Fix: Broaden the filter, or remove the hook if it no longer applies to this repo.
|
|
|
|
## `check-useless-excludes` fails
|
|
|
|
Cause: An `exclude` pattern matches no files.
|
|
|
|
Fix: Remove or fix the pattern.
|
|
|
|
## SSH cloning fails in CI
|
|
|
|
Cause: The CI environment lacks SSH credentials to clone hook repos over SSH.
|
|
|
|
Fix: Export `SSH_AUTH_SOCK` in the CI environment, or switch hook repo URLs to HTTPS.
|
|
|
|
## HTTP proxy needed
|
|
|
|
Cause: The CI/sandbox network requires a proxy to reach hook repos.
|
|
|
|
Fix:
|
|
```bash
|
|
export http_proxy=http://proxy.example.com:3128
|
|
export https_proxy=http://proxy.example.com:3128
|
|
export no_proxy=localhost,127.0.0.1
|
|
```
|
|
|
|
## `rev` is a branch name — `autoupdate` broke it
|
|
|
|
Cause: Branch refs are mutable and drift over time; pre-commit resolves them once at install time, so pinning to a branch name (instead of a tag or commit SHA) leads to silent version drift.
|
|
|
|
Fix:
|
|
```bash
|
|
pre-commit autoupdate # finds the latest tag and rewrites rev in place
|
|
```
|
|
|
|
## pretty-format-json fails but doesn't fix
|
|
|
|
Cause: `pretty-format-json` requires `args: [--autofix]` to modify files. Without it, the hook only fails.
|
|
|
|
Fix: The user (or `pc-author`) must add `args: [--autofix]` to the hook override in `.pre-commit-config.yaml`.
|
|
|
|
## Environment stale or broken
|
|
|
|
Cause: A hook's cached environment is corrupted or out of date.
|
|
|
|
Fix:
|
|
```bash
|
|
pre-commit clean # wipe all environments
|
|
pre-commit install-hooks # rebuild everything
|
|
```
|
|
|
|
Or less destructively:
|
|
```bash
|
|
pre-commit gc # remove only unused environments
|
|
```
|
|
|
|
## Hooks don't run on `git commit`
|
|
|
|
Cause: `pre-commit install` was never run in this clone.
|
|
|
|
Fix: `pre-commit install`. Git hooks are per-clone — they are not committed to the repo.
|
|
|
|
## Hook runs but matches wrong files (or no files)
|
|
|
|
Cause: The `files:` pattern uses `re.search()` not full-string match. A pattern that looks correct may match unexpectedly.
|
|
|
|
Diagnosis: `identify-cli <filename>` shows the type tags for a file. Verify `types:` filters against these.
|
|
|
|
## stages mismatch — hook never fires
|
|
|
|
Cause: Hook is defined for a stage (e.g. `pre-push`) but `pre-commit install` was not run with `-t pre-push`.
|
|
|
|
Fix:
|
|
```bash
|
|
pre-commit install -t pre-commit -t pre-push -t commit-msg
|
|
```
|
|
|
|
Or add `default_install_hook_types` to `.pre-commit-config.yaml` and re-run `pre-commit install`.
|
|
|
|
## `validate-config` schema error
|
|
|
|
Common causes:
|
|
- Missing `id` under a hook block
|
|
- Missing `rev` under a non-local repo block
|
|
- `repo: local` hook missing `language` or `entry`
|
|
- Indentation error (valid YAML but invalid pre-commit schema)
|