Repository navigation
fix(trace): make requireTrace block the push again - #3555
Conversation
The managed pre-push hook script ended with exit 0, so git ignored the exit status of chainloop trace hook git pre-push and requireTrace had no effect. The pre-push script now propagates chainloop's status (a missing binary still never fails a hook), and IsInstalled compares the full script so agent hooks reinstall outdated scripts automatically. Any error of the pre-push command, setup included, now blocks the push only when requireTrace is enabled; otherwise the hook warns with the cause and the push continues. The hook log file is now closed at process exit instead of when the hook command returns, so the final error line reaches log.txt and the "file already closed" message no longer shows on every hook run. Fixes PFM-7644 Assisted-by: Claude Code Signed-off-by: Miguel Martinez Trivino <miguel@chainloop.dev> Chainloop-Trace-Sessions: a5941a7b-7e2e-46b4-b95d-cd9fadb00b3b
PR validation — ✅ 3 passing
AI Session Checks — 🟡 77% · ✅ 0 failing
|
| Status | Policy | Material | Messages |
|---|---|---|---|
| ✅ Passed | ai-config-ai-agents-allowed |
ai-coding-session-a5941a |
- |
| ✅ Passed | ai-config-no-dangerous-commands |
ai-coding-session-a5941a |
- |
| ✅ Passed | ai-config-no-secrets |
ai-coding-session-a5941a |
- |
| ✅ Passed | ai-config-mcp-servers-allowed |
ai-coding-session-a5941a |
- |
Security Checks — ✅ 5 passing
✅ secret-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | secrets-detection |
- |
✅ sast-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | owasp-top10-2025 |
- |
| ✅ Passed | sast |
- |
| ✅ Passed | cwe-top25 |
- |
| ✅ Passed | cwe-top26-40-cusp |
- |
Scans not applied (3)
| Scan | Reason |
|---|---|
vulnerability-scan |
no manifest/lockfile changed |
github-actions-scan |
no workflow files changed |
iac-scan |
no IaC files changed |
Security context
This change touches code with 2 recorded security-fix advisories. These are pointers to what past fixes established, not findings in this diff, and they never fail the check.
View in Chainloop ↗ · How this works ↗
Powered by Chainloop and Chainloop Trace
Assisted-by: Claude Code Signed-off-by: Miguel Martinez Trivino <miguel@chainloop.dev> Chainloop-Trace-Sessions: a5941a7b-7e2e-46b4-b95d-cd9fadb00b3b
|
this used to work, when did requireTrace start to fail? |
|
I pinged you in the task |
|
@jiparis It stopped working on 2026-08-18, with chainloop-dev/platform#6177 ( You may not have seen it because hook scripts are rewritten only when This PR keeps the protection for a missing binary ( 🤖 Posted by Maximus bot (Claude Code) on behalf of @migmartri |
Fixes PFM-7644.
requireTrace: truestopped blockinggit pushwhen the AI coding session upload failed, because the managed pre-push hook script always ended withexit 0. Upload failures were also silent: the error never reachedchainloop-trace/log.txt, and every hook run printedzerolog: could not write event ... file already closed.Changes:
chainloopbinary still never fails any hook.IsInstallednow compares the full script, so the agent hooks reinstall scripts written by older CLIs without users having to runchainloop trace initagain.requireTraceis enabled. Otherwise the hook prints a warning with the cause, for examplerun "chainloop auth login", and the push continues. Before, such failures were logged at debug level only.log.txt, and thefile already closedmessage is gone.app/cli/internal/trace/hooks/testdata/show the exact scripts, including the chained variants.This PR was written with AI assistance (Claude Code).
🤖 Posted by Maximus bot (Claude Code) on behalf of @migmartri