Skip to content

fix: advisory hooks fail open with one stderr line (#3713) - #4853

Merged
cursor[bot] merged 6 commits into
mainfrom
cursor/3713-advisory-hook-boundary-37e9
Sep 28, 2026
Merged

cursor[bot] merged 6 commits into
mainfrom
cursor/3713-advisory-hook-boundary-37e9

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Closes #3713

Summary

Advisory hooks that die of a hard error now fail open with exactly one stderr line, so Claude Code never records hook_non_blocking_error with empty stderr.

Fix

  • claude-ops hook-failure-audit.sh: EXIT trap after the kill switch writes claude-ops hook-failure-audit: did not run (status N); fail-open and exits 0. Chosen status is 0 only.
  • instruction-placement index-drift.sh: the same trap shape (instruction-placement index-drift: …).
  • disk-hygiene guard_launch_monitor.py: main catches SystemExit other than 0 and BaseException, writes one stderr line, and returns 0. SystemExit(0) is re-raised so raise SystemExit(main()) still works. Empty transcript is quiet; missing/unreadable transcript fail-opens with one stderr line.
  • Guardrails secrets-check is out of scope (it already installs the shared abort boundary).

Verification

bash plugins/claude-ops/hooks/hook-failure-audit.test.sh
bash plugins/instruction-placement/hooks/index-drift.test.sh
python3 plugins/disk-hygiene/skills/clean/scripts/test_guard_launch_monitor.py

hook-failure-audit PASS=133 FAIL=0. index-drift 23 passed, 0 failed. guard_launch_monitor 45 tests OK. Empty / malformed / minimal payloads stay exit 0. An injected exit 3 after the trap exits 0 with exactly one stderr line. The inject feeds stdin from a file so a closed pipe cannot turn pipefail into SIGPIPE 141 (#4458).

claude-ops 0.62.14 (above in-flight 0.62.13 on #4050). disk-hygiene 0.26.3 (above in-flight 0.26.2 on #4000; #4009 remains 0.27.0). instruction-placement 0.15.8.

Open in Web Open in Cursor 

cursoragent and others added 3 commits September 28, 2026 03:26
Stop/PostToolUse advisory hooks that died of a hard error left Claude Code
a hook_non_blocking_error with empty stderr. hook-failure-audit and
index-drift install an EXIT trap after the kill switch; unexpected status
writes one named line and exits 0. guard_launch_monitor catches SystemExit
other than 0 and BaseException the same way. Chosen status is 0 only.

claude-ops 0.62.14, instruction-placement 0.15.8, disk-hygiene 0.27.1.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…t 0.26.2

#4000 already occupies 0.26.2 on cursor/4000-root-children-loose-files-37e9.
This advisory-hook fail-open is a patch, so land at 0.26.3 rather than 0.27.1.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…boundary

A Stop payload naming a transcript that is not on disk used to die with
empty stderr. The abort catch now fail-opens with one line; pin that, and
keep an empty existing transcript silent.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

PR body contract — issue linkage

This PR body does not yet satisfy the issue-linkage contract:

  • Missing a "## Related" section. List related PRs, ADRs, or decision-log entries this PR does not close.

Edit the body and this comment updates itself on the next run.

cursoragent and others added 3 commits September 28, 2026 03:39
The injected exit 3 happens before the hook reads stdin. Piping the
payload left printf writing to a closed fd; with pipefail that was
SIGPIPE 141, the #4458 abort-boundary harness bug, not a hook failure.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Release the guard-launch fail-open as disk-hygiene 0.26.4, above main 0.26.3.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Shellcheck SC2034 flags empty_out. The assertion only checks the exit code.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
@cursor
cursor Bot marked this pull request as ready for review September 28, 2026 03:42
@cursor
cursor Bot merged commit 75ae49d into main Sep 28, 2026
15 checks passed
@cursor
cursor Bot deleted the cursor/3713-advisory-hook-boundary-37e9 branch September 28, 2026 03:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Advisory hooks exit 1 with empty stderr (hook-failure-audit, guard_launch_monitor, secrets check, rules index)

2 participants