fix(1.16.1): wiki-first-search 補 Bash 破口(1.16.0 隔天即被自己繞過)
leo 點破:wiki 早記著寄信已驗證可用,我卻沒查又自創 curl 部署法。 根因=昨天的 hook 只掛 Grep|Glob|Read,但我實際用的是 Bash → 完全不觸發。 - matcher 加 Bash,只認高風險指令(wrangler|curl|npx|acr|gh|deploy|push) - update.sh 對既有註冊就地補 Bash,不只新裝生效 教訓:防跳過 wiki 的機制本身要蓋到所有實際查詢途徑。 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -10,6 +10,27 @@
|
||||
|
||||
---
|
||||
|
||||
## 1.16.1 — 補破口:wiki-first-search 漏掉 Bash(隔天就被自己繞過)
|
||||
|
||||
**1.16.0 上線隔天即實證失效**:hook 只掛 `Grep|Glob|Read`,但「用 curl/wrangler
|
||||
亂試部署方法」走的是 **Bash** → 整支 hook 不觸發。
|
||||
|
||||
leo 當場點破:「昨天我已經發信給你看了,你今天還說系統不對,**就表示這件事沒記錄下來?
|
||||
還是你凡是要查就會去查 wiki?**」
|
||||
→ 查證:wiki `status.md` 早記著「landing 寄信 live、實測 leo21c 連 4 次成功」,
|
||||
**記錄在、我沒查**;而昨天做的 hook **蓋不到我實際用的工具**。
|
||||
|
||||
修正:
|
||||
- matcher 加 `Bash`;只認會動外部系統的高風險指令
|
||||
(`wrangler|curl|npx|acr|gh|deploy|push`),避免每個 `ls` 洗版
|
||||
- 從指令中取最具識別度的詞當搜尋詞(濾掉 https/accounts/workers 等雜訊)
|
||||
- `update.sh` 對**既有註冊**就地補 `Bash`(不只新裝才有)
|
||||
|
||||
> 教訓:**防「跳過 wiki」的機制,本身要蓋到所有實際查詢途徑**,
|
||||
> 否則就是換個工具照樣跳過。
|
||||
|
||||
---
|
||||
|
||||
## 1.16.0 — 讓 wiki 真的被讀到:查詢即搜尋+subagent 自動注入
|
||||
|
||||
**病根(leo 2026-07-20 點破,真實事故)**:總管三次擋回 leo「某機制早已棄用」的正確判斷,
|
||||
|
||||
+6
-1
@@ -355,8 +355,13 @@ except Exception:
|
||||
pre = d.setdefault("hooks", {}).setdefault("PreToolUse", [])
|
||||
blob = json.dumps(pre)
|
||||
added = []
|
||||
# 1.16.1:既有註冊若漏 Bash(原版只掛 Grep|Glob|Read)就地補上——
|
||||
# 破口實例:用 curl/wrangler 亂試部署方法走 Bash,整支 hook 不觸發。
|
||||
for _e in pre:
|
||||
if "wiki-first-search" in json.dumps(_e) and "Bash" not in _e.get("matcher", ""):
|
||||
_e["matcher"] = "Grep|Glob|Read|Bash"; added.append("wiki-first-search(補Bash)")
|
||||
if "wiki-first-search" not in blob:
|
||||
pre.append({"matcher": "Grep|Glob|Read", "hooks": [
|
||||
pre.append({"matcher": "Grep|Glob|Read|Bash", "hooks": [
|
||||
{"type": "command", "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/wiki-first-search.sh"}]})
|
||||
added.append("wiki-first-search")
|
||||
if "subagent-wiki-guard" not in blob:
|
||||
|
||||
@@ -1 +1 @@
|
||||
1.16.0
|
||||
1.16.1
|
||||
|
||||
@@ -29,6 +29,20 @@ try:
|
||||
if not q:
|
||||
p = ti.get('file_path') or ti.get('path') or ''
|
||||
q = os.path.splitext(os.path.basename(p))[0] if p else ''
|
||||
if not q:
|
||||
# Bash:2026-07-21 補的破口——原版只掛 Grep|Glob|Read,
|
||||
# 但「用 curl/wrangler 亂試部署方法」走的是 Bash,整支 hook 不觸發。
|
||||
# leo 當場點破:wiki 早記著「寄信已驗證可用」,我卻沒查又自創方法。
|
||||
# 只認「會動到外部系統/部署」的高風險指令,避免每個 ls 都洗版。
|
||||
cmd = ti.get('command') or ''
|
||||
if re.search(r'\b(wrangler|curl|npx|acr|gh|deploy|push)\b', cmd):
|
||||
# 取指令中最具識別度的詞(worker 名/資源名/子命令)當搜尋詞
|
||||
cand = re.findall(r'[A-Za-z_][A-Za-z0-9_-]{4,}', cmd)
|
||||
skip = {'https','http','client','accounts','workers','scripts',
|
||||
'application','content','Authorization','Bearer','python3',
|
||||
'curl','npx','bash','echo','grep','local','branch','origin'}
|
||||
cand = [c for c in cand if c not in skip and not c.startswith('-')]
|
||||
q = max(cand, key=len) if cand else ''
|
||||
# grep pattern 常含 regex 元字元;取最長的英數/底線詞當搜尋詞
|
||||
words = re.findall(r'[A-Za-z_][A-Za-z0-9_]{3,}', q)
|
||||
print(max(words, key=len) if words else '')
|
||||
|
||||
@@ -30,7 +30,7 @@
|
||||
]
|
||||
},
|
||||
{
|
||||
"matcher": "Grep|Glob|Read",
|
||||
"matcher": "Grep|Glob|Read|Bash",
|
||||
"hooks": [
|
||||
{
|
||||
"type": "command",
|
||||
|
||||
@@ -1 +1 @@
|
||||
1.16.0
|
||||
1.16.1
|
||||
|
||||
Reference in New Issue
Block a user