Skip to content

fix(hooks): session-start hook never opens genie.db under orca lifecycle authority - #2835

Merged
namastex888 merged 1 commit into
devfrom
fix/session-hook-orca-authority
Aug 30, 2026
Merged

namastex888 merged 1 commit into
devfrom
fix/session-hook-orca-authority

Conversation

@namastex888

Copy link
Copy Markdown
Contributor

Problem (HIGH — H7 from the #2817 re-review)

plugins/genie/scripts/src/session-context.ts openSessionDb (shipped as session-context.cjs, the SessionStart hook in all three manifests) opened .genie/genie.db without consulting orchestration.mode. Reviewer's control experiment in an Orca-mode repo with an existing DB: genie board (guarded) creates nothing; the hook creates genie.db-shm + genie.db-wal on every session start and injects local task/wish state — the same A1 breach previously blocked for doctor, on the most frequently exercised path.

Change

  • Self-contained, fail-closed authority read in the hook (GENIE_CONFIG_FILE ?? $GENIE_HOME/config.json → orchestration.mode): orca and unreadable/unrecognized configs refuse before any SQLite handle exists (the wish-file scan still runs, so context degrades rather than disappears); standalone unchanged.
  • session-context.cjs regenerated via bun scripts/hook-bundle-parity.ts --write (parity, content-binding, budgets, executables gates all OK).
  • Regression fixture in src/lib/v5/authority-barriers.test.ts: real standalone genie.db → authority flipped to orca and to malformed JSON → shipped bundle run with node → no sidecar, reason on stderr. Verified to fail on the previous bundle.

Validation

bun test src/lib/v5/authority-barriers.test.ts scripts/hook-bundle-parity.test.ts → 13 pass; lint:hook-bundles / lint:hook-content / lint:hook-budgets / lint:plugin-executables OK; typecheck clean.

🤖 Generated with Claude Code

https://claude.ai/code/session_018QrkgYMEEhrWTUo5E7Nkjg

…cle authority

The shipped SessionStart hook (plugins/genie/scripts/session-context.cjs,
registered by the Claude, Codex and Kimi manifests) opened .genie/genie.db
read-only without consulting orchestration.mode. In an Orca-mode repo with
a pre-existing database that created -wal/-shm sidecars on every session
start and injected local task/wish state as additionalContext — the same
A1 breach the previous review blocked on for doctor, on the path that runs
far more often than any CLI command.

The hook bundle is plain Node and cannot share the CLI's zod-backed
resolver, so it now carries a self-contained authority read of
GENIE_CONFIG_FILE ?? $GENIE_HOME/config.json: standalone opens as before,
orca refuses before any SQLite handle exists, and an unreadable or
unrecognized config fails closed the same way (the wish-file scan still
runs). session-context.cjs regenerated through hook-bundle-parity.

Regression fixture in authority-barriers.test.ts: builds a real standalone
genie.db, flips authority to orca (and to malformed JSON), runs the shipped
bundle with node, and asserts no sidecar appears and the degradation
reason is reported. Fails on the previous bundle.

Found by the #2817 re-review (H7).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018QrkgYMEEhrWTUo5E7Nkjg
@coderabbitai

coderabbitai Bot commented Aug 30, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 63d7ddde-94e5-42f4-abda-f14e7fc94fcf

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 26c4027382

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +376 to +377
const mode = (orchestration as { mode?: unknown }).mode;
if (mode === undefined || mode === 'standalone') return 'standalone';

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Reject malformed authority objects before opening SQLite

When orchestration is present but lacks mode—for example { "orchestration": {} }, { "orchestration": { "mod": "orca" } }, or an array—this returns standalone; it also ignores extra keys. The canonical resolveOrchestrationMode() in src/lib/orchestration-mode.ts deliberately rejects all of these forms, so the hook can proceed to DatabaseSync and inject stale local task state while every CLI and low-level lifecycle path fails closed. Validate the same exact authority shape here before treating it as standalone.

Useful? React with 👍 / 👎.

Comment on lines +367 to +368
const configPath =
process.env.GENIE_CONFIG_FILE ?? join(process.env.GENIE_HOME ?? join(homedir(), '.genie'), 'config.json');

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Resolve authority from the canonical config path

When the environment contains GENIE_CONFIG_FILE, this hook reads it instead of $GENIE_HOME/config.json, but the canonical getGenieConfigPath()/resolveOrchestrationMode() path does not recognize that variable. Thus a session with Orca selected in GENIE_HOME can still open the local database if an ambient GENIE_CONFIG_FILE points to an absent or standalone config, defeating the authority barrier. Use exactly the same path contract as the lifecycle code.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-08-30T01:54:54.655839Z 26c4027 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@namastex888
namastex888 merged commit 299358f into dev Aug 30, 2026
18 checks passed
@automagik-genie
automagik-genie deleted the fix/session-hook-orca-authority branch September 25, 2026 04:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant