diff --git a/CHANGELOG.md b/CHANGELOG.md index aa1d036..fae318b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -10,6 +10,27 @@ --- +## 1.16.1 — 補破口:wiki-first-search 漏掉 Bash(隔天就被自己繞過) + +**1.16.0 上線隔天即實證失效**:hook 只掛 `Grep|Glob|Read`,但「用 curl/wrangler +亂試部署方法」走的是 **Bash** → 整支 hook 不觸發。 + +leo 當場點破:「昨天我已經發信給你看了,你今天還說系統不對,**就表示這件事沒記錄下來? +還是你凡是要查就會去查 wiki?**」 +→ 查證:wiki `status.md` 早記著「landing 寄信 live、實測 leo21c 連 4 次成功」, +**記錄在、我沒查**;而昨天做的 hook **蓋不到我實際用的工具**。 + +修正: +- matcher 加 `Bash`;只認會動外部系統的高風險指令 + (`wrangler|curl|npx|acr|gh|deploy|push`),避免每個 `ls` 洗版 +- 從指令中取最具識別度的詞當搜尋詞(濾掉 https/accounts/workers 等雜訊) +- `update.sh` 對**既有註冊**就地補 `Bash`(不只新裝才有) + +> 教訓:**防「跳過 wiki」的機制,本身要蓋到所有實際查詢途徑**, +> 否則就是換個工具照樣跳過。 + +--- + ## 1.16.0 — 讓 wiki 真的被讀到:查詢即搜尋+subagent 自動注入 **病根(leo 2026-07-20 點破,真實事故)**:總管三次擋回 leo「某機制早已棄用」的正確判斷, diff --git a/scripts/update.sh b/scripts/update.sh index 823ab46..fe3d868 100755 --- a/scripts/update.sh +++ b/scripts/update.sh @@ -355,8 +355,13 @@ except Exception: pre = d.setdefault("hooks", {}).setdefault("PreToolUse", []) blob = json.dumps(pre) added = [] +# 1.16.1:既有註冊若漏 Bash(原版只掛 Grep|Glob|Read)就地補上—— +# 破口實例:用 curl/wrangler 亂試部署方法走 Bash,整支 hook 不觸發。 +for _e in pre: + if "wiki-first-search" in json.dumps(_e) and "Bash" not in _e.get("matcher", ""): + _e["matcher"] = "Grep|Glob|Read|Bash"; added.append("wiki-first-search(補Bash)") if "wiki-first-search" not in blob: - pre.append({"matcher": "Grep|Glob|Read", "hooks": [ + pre.append({"matcher": "Grep|Glob|Read|Bash", "hooks": [ {"type": "command", "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/wiki-first-search.sh"}]}) added.append("wiki-first-search") if "subagent-wiki-guard" not in blob: diff --git a/template/.claude/VERSION b/template/.claude/VERSION index 15b989e..41c11ff 100644 --- a/template/.claude/VERSION +++ b/template/.claude/VERSION @@ -1 +1 @@ -1.16.0 +1.16.1 diff --git a/template/.claude/hooks/wiki-first-search.sh b/template/.claude/hooks/wiki-first-search.sh index 309d637..6d75785 100755 --- a/template/.claude/hooks/wiki-first-search.sh +++ b/template/.claude/hooks/wiki-first-search.sh @@ -29,6 +29,20 @@ try: if not q: p = ti.get('file_path') or ti.get('path') or '' q = os.path.splitext(os.path.basename(p))[0] if p else '' + if not q: + # Bash:2026-07-21 補的破口——原版只掛 Grep|Glob|Read, + # 但「用 curl/wrangler 亂試部署方法」走的是 Bash,整支 hook 不觸發。 + # leo 當場點破:wiki 早記著「寄信已驗證可用」,我卻沒查又自創方法。 + # 只認「會動到外部系統/部署」的高風險指令,避免每個 ls 都洗版。 + cmd = ti.get('command') or '' + if re.search(r'\b(wrangler|curl|npx|acr|gh|deploy|push)\b', cmd): + # 取指令中最具識別度的詞(worker 名/資源名/子命令)當搜尋詞 + cand = re.findall(r'[A-Za-z_][A-Za-z0-9_-]{4,}', cmd) + skip = {'https','http','client','accounts','workers','scripts', + 'application','content','Authorization','Bearer','python3', + 'curl','npx','bash','echo','grep','local','branch','origin'} + cand = [c for c in cand if c not in skip and not c.startswith('-')] + q = max(cand, key=len) if cand else '' # grep pattern 常含 regex 元字元;取最長的英數/底線詞當搜尋詞 words = re.findall(r'[A-Za-z_][A-Za-z0-9_]{3,}', q) print(max(words, key=len) if words else '') diff --git a/template/.claude/settings.json b/template/.claude/settings.json index e05057e..d0b3167 100644 --- a/template/.claude/settings.json +++ b/template/.claude/settings.json @@ -30,7 +30,7 @@ ] }, { - "matcher": "Grep|Glob|Read", + "matcher": "Grep|Glob|Read|Bash", "hooks": [ { "type": "command", diff --git a/template/system-dev/VERSION b/template/system-dev/VERSION index 15b989e..41c11ff 100644 --- a/template/system-dev/VERSION +++ b/template/system-dev/VERSION @@ -1 +1 @@ -1.16.0 +1.16.1