fix(hooks): soften guard for stale repositories - #3730
Ha1baraA11 wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Graphify reviewed this change.
Worth a look — the grounded gate found no coupling regressions or blocking issues, but 1 advisory finding(s) below merit a look before merge.
Graphify review — findings
Extends the strict read-hook staleness check to treat a repository as stale when its latest git commit is newer than the graph build, catching cases where nearby modules were added or removed even though the read file's own mtime is unchanged. The git lookup is optional and fails open — outside a repo or on any subprocess/parse error the check is skipped rather than denying — and a stale repo softens the hook to a nudge, never a hard deny. Also updates the stale-read nudge text to mention repository-level staleness alongside per-file changes.
Worth a look
- git commit mtime compared to graph mtime uses wall-clock vs filesystem mtime, and commit time need not exceed build time even when repo changed —
graphify/cli.py:934· Escalate · medium- agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 281 functions depend on the 79 functions this change touches.
Health — this change adds coupling hotspots:
- new:
dispatch_command()— 2 callers, 125 callees - new:
_stale_graph_sources()— 7 callers, 6 callees - new:
_run_hook_guard()— 4 callers, 8 callees - new:
test_poisoned_manifest_is_healed()— 0 callers, 6 callees
Verification — 281 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 219 function(s) in the blast radius were not formally verified this run
Test selection
Test selection
24 of 290 test file(s) selected (8%) via static blast radius.
tests/test_affected_cli.py— impacttests/test_agents_platform.py— impacttests/test_codebuddy.py— impacttests/test_devin.py— impacttests/test_explain_cli.py— impacttests/test_extract_cli.py— impacttests/test_global_add_tag_inference.py— impacttests/test_god_nodes_cli.py— impacttests/test_hollow_chunks_arm_shrink_guard.py— impacttests/test_hook_guard_token_match.py— impacttests/test_hook_out_of_project_paths.py— impacttests/test_hook_strict.py— impact, changed-testtests/test_incomplete_build_guard.py— impacttests/test_install.py— impacttests/test_install_references.py— impacttests/test_merge_chunks_validation.py— impacttests/test_multigraph_diagnostics.py— impacttests/test_no_dedup_flag.py— impacttests/test_partial_cache.py— impacttests/test_path_cli.py— impacttests/test_query_cli.py— impacttests/test_query_induced_edges.py— impacttests/test_stale_prune.py— impacttests/test_unverified_semantic_shrink.py— impact
Selection is safe under the controlled-regression assumption; always-run tests + a periodic full run are the backstops. Advisory — it never changes the check verdict.
· 4 more finding(s) on lines outside this diff (see the check run).
|
Thanks @Ha1baraA11 — the intent is good (a per-file-fresh but repo-stale graph should soften to the non-blocking nudge, never hard-deny) and the fail-open is correct. Two things to address before merge:
|
What does this PR do?
Fixes #3718 by treating a repository as stale when its latest Git commit is newer than graphify-out/graph.json, even if the specific file being read has an unchanged mtime. The hook now emits the existing non-blocking stale guidance for commits that add or delete nearby modules, while failing open when Git is unavailable or the directory is not a repository.
Type of change
How was this tested?
This was tested with the following commands:
The regression test simulates a fresh target file with a newer repository commit and confirms strict mode softens to the stale guidance instead of denying the read.
Graphify-specific checklist