Repository navigation
fix(hooks): session-start hook never opens genie.db under orca lifecycle authority - #2835
Conversation
…cle authority The shipped SessionStart hook (plugins/genie/scripts/session-context.cjs, registered by the Claude, Codex and Kimi manifests) opened .genie/genie.db read-only without consulting orchestration.mode. In an Orca-mode repo with a pre-existing database that created -wal/-shm sidecars on every session start and injected local task/wish state as additionalContext — the same A1 breach the previous review blocked on for doctor, on the path that runs far more often than any CLI command. The hook bundle is plain Node and cannot share the CLI's zod-backed resolver, so it now carries a self-contained authority read of GENIE_CONFIG_FILE ?? $GENIE_HOME/config.json: standalone opens as before, orca refuses before any SQLite handle exists, and an unreadable or unrecognized config fails closed the same way (the wish-file scan still runs). session-context.cjs regenerated through hook-bundle-parity. Regression fixture in authority-barriers.test.ts: builds a real standalone genie.db, flips authority to orca (and to malformed JSON), runs the shipped bundle with node, and asserts no sidecar appears and the degradation reason is reported. Fails on the previous bundle. Found by the #2817 re-review (H7). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018QrkgYMEEhrWTUo5E7Nkjg
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 26c4027382
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const mode = (orchestration as { mode?: unknown }).mode; | ||
| if (mode === undefined || mode === 'standalone') return 'standalone'; |
There was a problem hiding this comment.
Reject malformed authority objects before opening SQLite
When orchestration is present but lacks mode—for example { "orchestration": {} }, { "orchestration": { "mod": "orca" } }, or an array—this returns standalone; it also ignores extra keys. The canonical resolveOrchestrationMode() in src/lib/orchestration-mode.ts deliberately rejects all of these forms, so the hook can proceed to DatabaseSync and inject stale local task state while every CLI and low-level lifecycle path fails closed. Validate the same exact authority shape here before treating it as standalone.
Useful? React with 👍 / 👎.
| const configPath = | ||
| process.env.GENIE_CONFIG_FILE ?? join(process.env.GENIE_HOME ?? join(homedir(), '.genie'), 'config.json'); |
There was a problem hiding this comment.
Resolve authority from the canonical config path
When the environment contains GENIE_CONFIG_FILE, this hook reads it instead of $GENIE_HOME/config.json, but the canonical getGenieConfigPath()/resolveOrchestrationMode() path does not recognize that variable. Thus a session with Orca selected in GENIE_HOME can still open the local database if an ambient GENIE_CONFIG_FILE points to an absent or standalone config, defeating the authority barrier. Use exactly the same path contract as the lifecycle code.
Useful? React with 👍 / 👎.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Problem (HIGH — H7 from the #2817 re-review)
plugins/genie/scripts/src/session-context.tsopenSessionDb(shipped assession-context.cjs, the SessionStart hook in all three manifests) opened.genie/genie.dbwithout consultingorchestration.mode. Reviewer's control experiment in an Orca-mode repo with an existing DB:genie board(guarded) creates nothing; the hook createsgenie.db-shm+genie.db-walon every session start and injects local task/wish state — the same A1 breach previously blocked fordoctor, on the most frequently exercised path.Change
GENIE_CONFIG_FILE ?? $GENIE_HOME/config.json→orchestration.mode):orcaand unreadable/unrecognized configs refuse before any SQLite handle exists (the wish-file scan still runs, so context degrades rather than disappears); standalone unchanged.session-context.cjsregenerated viabun scripts/hook-bundle-parity.ts --write(parity, content-binding, budgets, executables gates all OK).src/lib/v5/authority-barriers.test.ts: real standalonegenie.db→ authority flipped toorcaand to malformed JSON → shipped bundle run withnode→ no sidecar, reason on stderr. Verified to fail on the previous bundle.Validation
bun test src/lib/v5/authority-barriers.test.ts scripts/hook-bundle-parity.test.ts→ 13 pass;lint:hook-bundles/lint:hook-content/lint:hook-budgets/lint:plugin-executablesOK; typecheck clean.🤖 Generated with Claude Code
https://claude.ai/code/session_018QrkgYMEEhrWTUo5E7Nkjg