#[allow(unused_imports)]
use anyhow::{Context, Result};
use chrono::{DateTime, Utc};
use serde::{Deserialize, Serialize};
use serde_json::json;
use std::collections::HashMap;
use std::io::{Read, Write};
use std::path::{Path, PathBuf};
use std::process::{Child, Command, Stdio};
use std::sync::mpsc::{self, Receiver, RecvTimeoutError};
use std::thread::{self, JoinHandle};
use std::time::{Duration, Instant};
use wait_timeout::ChildExt;
#[cfg(windows)]
use std::os::windows::io::AsRawHandle;
#[cfg(windows)]
use windows::Win32::Foundation::{CloseHandle, HANDLE};
#[cfg(windows)]
use windows::Win32::System::Diagnostics::ToolHelp::{
CreateToolhelp32Snapshot, TH32CS_SNAPTHREAD, THREADENTRY32, Thread32First, Thread32Next,
};
#[cfg(windows)]
use windows::Win32::System::JobObjects::{
AssignProcessToJobObject, CreateJobObjectW, JOB_OBJECT_LIMIT_KILL_ON_JOB_CLOSE,
JOBOBJECT_EXTENDED_LIMIT_INFORMATION, JobObjectExtendedLimitInformation,
SetInformationJobObject, TerminateJobObject,
};
#[cfg(windows)]
use windows::Win32::System::Threading::{OpenThread, ResumeThread, THREAD_SUSPEND_RESUME};
#[cfg(windows)]
use windows::core::PCWSTR;
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum HookEvent {
SessionStart,
SessionEnd,
MessageSubmit,
ToolCallBefore,
ToolCallAfter,
ModeChange,
OnError,
TurnEnd,
SubagentSpawn,
SubagentComplete,
ShellEnv,
}
impl HookEvent {
#[allow(dead_code)] pub fn as_str(self) -> &'static str {
match self {
HookEvent::SessionStart => "session_start",
HookEvent::SessionEnd => "session_end",
HookEvent::MessageSubmit => "message_submit",
HookEvent::ToolCallBefore => "tool_call_before",
HookEvent::ToolCallAfter => "tool_call_after",
HookEvent::ModeChange => "mode_change",
HookEvent::OnError => "on_error",
HookEvent::TurnEnd => "turn_end",
HookEvent::SubagentSpawn => "subagent_spawn",
HookEvent::SubagentComplete => "subagent_complete",
HookEvent::ShellEnv => "shell_env",
}
}
}
#[derive(Debug, Clone, Serialize, Deserialize)]
#[serde(tag = "type", rename_all = "snake_case")]
#[derive(Default)]
pub enum HookCondition {
#[default]
Always,
ToolName {
name: String,
},
ToolCategory {
category: String,
},
Mode {
mode: String,
},
ExitCode {
code: i32,
},
All { conditions: Vec<HookCondition> },
Any { conditions: Vec<HookCondition> },
}
#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct Hook {
pub event: HookEvent,
pub command: String,
#[serde(default)]
pub condition: Option<HookCondition>,
#[serde(default = "default_timeout")]
pub timeout_secs: u64,
#[serde(default)]
pub background: bool,
#[serde(default = "default_continue_on_error")]
pub continue_on_error: bool,
#[serde(default)]
pub name: Option<String>,
}
fn default_timeout() -> u64 {
30
}
fn default_continue_on_error() -> bool {
true
}
impl Hook {
#[allow(dead_code)] pub fn new(event: HookEvent, command: &str) -> Self {
Self {
event,
command: command.to_string(),
condition: None,
timeout_secs: 30,
background: false,
continue_on_error: true,
name: None,
}
}
#[allow(dead_code)] pub fn with_condition(mut self, condition: HookCondition) -> Self {
self.condition = Some(condition);
self
}
#[allow(dead_code)] pub fn with_timeout(mut self, secs: u64) -> Self {
self.timeout_secs = secs;
self
}
#[allow(dead_code)] pub fn background(mut self) -> Self {
self.background = true;
self
}
#[allow(dead_code)] pub fn with_name(mut self, name: &str) -> Self {
self.name = Some(name.to_string());
self
}
}
#[derive(Debug, Clone, Default, Serialize, Deserialize)]
pub struct HooksConfig {
#[serde(default)]
pub hooks: Vec<Hook>,
#[serde(default = "default_enabled")]
pub enabled: bool,
#[serde(default)]
pub default_timeout_secs: Option<u64>,
#[serde(default)]
pub working_dir: Option<PathBuf>,
}
fn default_enabled() -> bool {
true
}
impl HooksConfig {
pub fn load_with_project(global: HooksConfig, workspace: &Path) -> HooksConfig {
let project_path = workspace.join(".codewhale").join("hooks.toml");
if !project_path.exists() || !workspace_allows_project_hooks(workspace) {
return global;
}
let Ok(contents) = std::fs::read_to_string(&project_path) else {
return global;
};
let project: HooksConfig = match toml::from_str(&contents) {
Ok(cfg) => cfg,
Err(e) => {
tracing::warn!(
"Failed to parse project hooks at {}: {e}; falling back to global hooks only",
project_path.display()
);
return global;
}
};
let mut merged = global;
merged.hooks.extend(project.hooks);
merged
}
pub fn hooks_for_event(&self, event: HookEvent) -> Vec<&Hook> {
if !self.enabled {
return Vec::new();
}
self.hooks.iter().filter(|h| h.event == event).collect()
}
#[allow(dead_code)] pub fn has_hooks(&self) -> bool {
self.enabled && !self.hooks.is_empty()
}
}
fn workspace_allows_project_hooks(workspace: &Path) -> bool {
crate::config::is_workspace_trusted(workspace)
}
#[derive(Debug, Clone, Default)]
pub struct HookContext {
pub tool_name: Option<String>,
pub tool_args: Option<String>,
pub tool_result: Option<String>,
pub tool_exit_code: Option<i32>,
pub tool_success: Option<bool>,
pub mode: Option<String>,
pub previous_mode: Option<String>,
pub session_id: Option<String>,
pub message: Option<String>,
pub error_message: Option<String>,
pub workspace: Option<PathBuf>,
pub model: Option<String>,
pub total_tokens: Option<u32>,
pub session_cost: Option<f64>,
}
impl HookContext {
pub fn new() -> Self {
Self::default()
}
#[allow(dead_code)] pub fn with_tool_name(mut self, name: &str) -> Self {
self.tool_name = Some(name.to_string());
self
}
#[allow(dead_code)] pub fn with_tool_args(mut self, args: &serde_json::Value) -> Self {
self.tool_args = Some(args.to_string());
self
}
#[allow(dead_code)] pub fn with_tool_result(mut self, result: &str, success: bool, exit_code: Option<i32>) -> Self {
self.tool_result = Some(result.to_string());
self.tool_success = Some(success);
self.tool_exit_code = exit_code;
self
}
#[allow(dead_code)] pub fn with_mode(mut self, mode: &str) -> Self {
self.mode = Some(mode.to_string());
self
}
pub fn with_previous_mode(mut self, mode: &str) -> Self {
self.previous_mode = Some(mode.to_string());
self
}
#[allow(dead_code)] pub fn with_workspace(mut self, path: PathBuf) -> Self {
self.workspace = Some(path);
self
}
pub fn with_model(mut self, model: &str) -> Self {
self.model = Some(model.to_string());
self
}
pub fn with_session_id(mut self, session_id: &str) -> Self {
self.session_id = Some(session_id.to_string());
self
}
#[allow(dead_code)] pub fn with_message(mut self, message: &str) -> Self {
self.message = Some(message.to_string());
self
}
#[allow(dead_code)] pub fn with_error(mut self, error: &str) -> Self {
self.error_message = Some(error.to_string());
self
}
pub fn with_tokens(mut self, tokens: u32) -> Self {
self.total_tokens = Some(tokens);
self
}
#[allow(dead_code)] pub fn with_cost(mut self, cost: f64) -> Self {
self.session_cost = Some(cost);
self
}
pub fn to_env_vars(&self) -> HashMap<String, String> {
let mut env = HashMap::new();
if let Some(ref name) = self.tool_name {
env.insert("DEEPSEEK_TOOL_NAME".to_string(), name.clone());
}
if let Some(ref args) = self.tool_args {
env.insert("DEEPSEEK_TOOL_ARGS".to_string(), args.clone());
}
if let Some(ref result) = self.tool_result {
let truncated = if result.len() > 10000 {
let safe_end = result
.char_indices()
.take_while(|(i, _)| *i < 10000)
.last()
.map(|(i, c)| i + c.len_utf8())
.unwrap_or(0);
format!("{}...[truncated]", &result[..safe_end])
} else {
result.clone()
};
env.insert("DEEPSEEK_TOOL_RESULT".to_string(), truncated);
}
if let Some(code) = self.tool_exit_code {
env.insert("DEEPSEEK_TOOL_EXIT_CODE".to_string(), code.to_string());
}
if let Some(success) = self.tool_success {
env.insert("DEEPSEEK_TOOL_SUCCESS".to_string(), success.to_string());
}
if let Some(ref mode) = self.mode {
env.insert("DEEPSEEK_MODE".to_string(), mode.clone());
}
if let Some(ref prev) = self.previous_mode {
env.insert("DEEPSEEK_PREVIOUS_MODE".to_string(), prev.clone());
}
if let Some(ref session_id) = self.session_id {
env.insert("DEEPSEEK_SESSION_ID".to_string(), session_id.clone());
}
if let Some(ref message) = self.message {
let truncated = if message.len() > 5000 {
let safe_end = message
.char_indices()
.take_while(|(i, _)| *i < 5000)
.last()
.map(|(i, c)| i + c.len_utf8())
.unwrap_or(0);
format!("{}...[truncated]", &message[..safe_end])
} else {
message.clone()
};
env.insert("DEEPSEEK_MESSAGE".to_string(), truncated);
}
if let Some(ref error) = self.error_message {
env.insert("DEEPSEEK_ERROR".to_string(), error.clone());
}
if let Some(ref ws) = self.workspace {
env.insert("DEEPSEEK_WORKSPACE".to_string(), ws.display().to_string());
}
if let Some(ref model) = self.model {
env.insert("DEEPSEEK_MODEL".to_string(), model.clone());
}
if let Some(tokens) = self.total_tokens {
env.insert("DEEPSEEK_TOTAL_TOKENS".to_string(), tokens.to_string());
}
if let Some(cost) = self.session_cost {
env.insert("DEEPSEEK_SESSION_COST".to_string(), format!("{cost:.6}"));
}
env
}
}
#[derive(Debug, Clone)]
#[allow(dead_code)] pub struct HookResult {
pub name: Option<String>,
pub success: bool,
pub exit_code: Option<i32>,
pub stdout: String,
pub stderr: String,
pub duration: Duration,
pub error: Option<String>,
}
#[derive(Debug, Clone, PartialEq, Eq)]
pub enum MessageSubmitOutcome {
Unchanged { warning: Option<String> },
Replaced {
text: String,
warning: Option<String>,
},
Blocked { reason: String },
}
impl MessageSubmitOutcome {
pub fn unchanged() -> Self {
Self::Unchanged { warning: None }
}
pub fn replaced(text: String) -> Self {
Self::Replaced {
text,
warning: None,
}
}
fn with_warning(self, warning: Option<String>) -> Self {
match self {
Self::Unchanged { .. } => Self::Unchanged { warning },
Self::Replaced { text, .. } => Self::Replaced { text, warning },
Self::Blocked { reason } => Self::Blocked { reason },
}
}
pub fn warning(&self) -> Option<&str> {
match self {
Self::Unchanged { warning } | Self::Replaced { warning, .. } => warning.as_deref(),
Self::Blocked { .. } => None,
}
}
}
#[derive(Debug, Clone, PartialEq, Eq)]
enum MessageSubmitStdout {
Unchanged,
Replaced(String),
Invalid(String),
}
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct ToolCallBeforeStdout {
pub decision: Option<ToolCallDecision>,
pub reason: Option<String>,
pub updated_input: Option<serde_json::Value>,
pub additional_context: Option<String>,
}
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub enum ToolCallDecision {
Allow,
Deny,
Ask,
}
pub(crate) fn parse_tool_call_before_stdout(stdout: &str) -> ToolCallBeforeStdout {
let passthrough = ToolCallBeforeStdout {
decision: None,
reason: None,
updated_input: None,
additional_context: None,
};
let trimmed = stdout.trim();
if trimmed.is_empty() {
return passthrough;
}
let value: serde_json::Value = match serde_json::from_str(trimmed) {
Ok(v) => v,
Err(_) => return passthrough,
};
let Some(obj) = value.as_object() else {
tracing::warn!(
"tool_call_before hook stdout is JSON but not an object; \
ignoring it (legacy passthrough)"
);
return passthrough;
};
let decision = obj
.get("decision")
.and_then(|v| v.as_str())
.and_then(|s| match s {
"allow" => Some(ToolCallDecision::Allow),
"deny" => Some(ToolCallDecision::Deny),
"ask" => Some(ToolCallDecision::Ask),
other => {
tracing::warn!(
"tool_call_before hook returned unrecognized decision \
'{other}' (expected allow|deny|ask); treating as allow"
);
None
}
});
let reason = obj
.get("reason")
.and_then(|v| v.as_str())
.map(|s| s.to_string());
let updated_input = obj.get("updatedInput").cloned().filter(|v| {
if v.is_object() {
true
} else {
tracing::warn!("tool_call_before hook updatedInput must be a JSON object; ignoring");
false
}
});
let additional_context = obj
.get("additionalContext")
.and_then(|v| v.as_str())
.map(|s| s.to_string());
ToolCallBeforeStdout {
decision,
reason,
updated_input,
additional_context,
}
}
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub struct TurnEndTotals {
pub session_tokens: u32,
pub conversation_tokens: u32,
pub input_tokens: u32,
pub output_tokens: u32,
}
pub struct TurnEndPayloadInput<'a> {
pub context: &'a HookContext,
pub created_at: DateTime<Utc>,
pub model_backed: bool,
pub provider: Option<&'a str>,
pub billing_surface: Option<&'a str>,
pub model: Option<&'a str>,
pub turn_id: &'a str,
pub status: &'a str,
pub error: Option<&'a str>,
pub duration: Duration,
pub usage: &'a crate::models::Usage,
pub totals: TurnEndTotals,
pub tool_count: usize,
pub queued_message_count: usize,
}
struct HookProcessTree {
#[cfg(unix)]
pgid: libc::pid_t,
#[cfg(windows)]
job: WindowsHookJob,
}
impl HookProcessTree {
fn attach(child: &Child) -> std::io::Result<Self> {
#[cfg(unix)]
{
Ok(Self {
pgid: child.id() as libc::pid_t,
})
}
#[cfg(windows)]
{
Ok(Self {
job: WindowsHookJob::attach(child)?,
})
}
#[cfg(not(any(unix, windows)))]
{
Ok(Self {})
}
}
fn terminate(&self, child: &mut Child) {
#[cfg(unix)]
{
let result = unsafe { libc::kill(-self.pgid, libc::SIGKILL) };
if result != 0 {
let error = std::io::Error::last_os_error();
if error.raw_os_error() != Some(libc::ESRCH) {
tracing::warn!(?error, "failed to terminate hook process group");
let _ = child.kill();
}
}
}
#[cfg(windows)]
{
let result = self
.job
.terminate()
.or_else(|_| kill_windows_process_tree(child.id()));
if let Err(error) = result {
tracing::warn!(
?error,
"failed to terminate hook process tree; killing immediate child"
);
let _ = child.kill();
}
}
#[cfg(not(any(unix, windows)))]
{
let _ = child.kill();
}
}
}
impl Drop for HookProcessTree {
fn drop(&mut self) {
#[cfg(unix)]
unsafe {
let _ = libc::kill(-self.pgid, libc::SIGKILL);
}
}
}
#[cfg(windows)]
struct WindowsHookJob {
handle: HANDLE,
}
#[cfg(windows)]
impl WindowsHookJob {
fn attach(child: &Child) -> std::io::Result<Self> {
let handle = unsafe { CreateJobObjectW(None, PCWSTR::null()).map_err(windows_io_error)? };
let job = Self { handle };
let mut limits = JOBOBJECT_EXTENDED_LIMIT_INFORMATION::default();
limits.BasicLimitInformation.LimitFlags = JOB_OBJECT_LIMIT_KILL_ON_JOB_CLOSE;
unsafe {
SetInformationJobObject(
job.handle,
JobObjectExtendedLimitInformation,
&limits as *const _ as *const core::ffi::c_void,
std::mem::size_of::<JOBOBJECT_EXTENDED_LIMIT_INFORMATION>() as u32,
)
.map_err(windows_io_error)?;
AssignProcessToJobObject(job.handle, HANDLE(child.as_raw_handle()))
.map_err(windows_io_error)?;
}
Ok(job)
}
fn terminate(&self) -> std::io::Result<()> {
unsafe { TerminateJobObject(self.handle, 1).map_err(windows_io_error) }
}
}
#[cfg(windows)]
impl Drop for WindowsHookJob {
fn drop(&mut self) {
unsafe {
let _ = CloseHandle(self.handle);
}
}
}
#[cfg(windows)]
fn windows_io_error(error: windows::core::Error) -> std::io::Error {
std::io::Error::other(error)
}
#[cfg(windows)]
fn resume_windows_process(child: &Child) -> std::io::Result<()> {
let snapshot =
unsafe { CreateToolhelp32Snapshot(TH32CS_SNAPTHREAD, 0).map_err(windows_io_error)? };
let result = (|| {
let mut entry = THREADENTRY32 {
dwSize: std::mem::size_of::<THREADENTRY32>() as u32,
..Default::default()
};
let mut next = unsafe { Thread32First(snapshot, &mut entry) };
let mut resumed = 0usize;
while next.is_ok() {
if entry.th32OwnerProcessID == child.id() {
let thread = unsafe {
OpenThread(THREAD_SUSPEND_RESUME, false, entry.th32ThreadID)
.map_err(windows_io_error)?
};
let resume_result = unsafe { ResumeThread(thread) };
let close_result = unsafe { CloseHandle(thread).map_err(windows_io_error) };
if resume_result == u32::MAX {
return Err(std::io::Error::last_os_error());
}
close_result?;
resumed += 1;
}
next = unsafe { Thread32Next(snapshot, &mut entry) };
}
if resumed == 0 {
return Err(std::io::Error::other(
"suspended hook process had no resumable thread",
));
}
Ok(())
})();
let close_result = unsafe { CloseHandle(snapshot).map_err(windows_io_error) };
result?;
close_result
}
#[cfg(windows)]
fn kill_windows_process_tree(pid: u32) -> std::io::Result<()> {
let mut command = Command::new("taskkill");
crate::utils::suppress_console_window(&mut command);
let pid = pid.to_string();
let status = command
.args(["/F", "/T", "/PID", pid.as_str()])
.stdin(Stdio::null())
.stdout(Stdio::null())
.stderr(Stdio::null())
.status()?;
if status.success() {
Ok(())
} else {
Err(std::io::Error::other(format!(
"taskkill exited with {status}"
)))
}
}
fn spawn_hook_child(
command: &mut Command,
hook_command: &str,
) -> std::io::Result<(Child, HookProcessTree)> {
let mut child = command.spawn()?;
let process_tree = match HookProcessTree::attach(&child) {
Ok(process_tree) => process_tree,
Err(error) => {
let _ = child.kill();
let _ = child.wait();
return Err(std::io::Error::other(format!(
"failed to contain hook process tree for `{hook_command}`: {error}"
)));
}
};
#[cfg(windows)]
if let Err(error) = resume_windows_process(&child) {
process_tree.terminate(&mut child);
let _ = child.wait();
return Err(std::io::Error::other(format!(
"failed to resume contained hook process for `{hook_command}`: {error}"
)));
}
Ok((child, process_tree))
}
#[derive(Debug, Clone)]
pub struct HookExecutor {
config: HooksConfig,
default_working_dir: PathBuf,
session_id: String,
}
impl HookExecutor {
fn build_shell_command(command: &str) -> Command {
#[cfg(windows)]
{
use std::os::windows::process::CommandExt as _;
let mut cmd = Command::new("cmd");
const CREATE_SUSPENDED: u32 = 0x0000_0004;
const CREATE_NO_WINDOW: u32 = 0x0800_0000;
cmd.creation_flags(CREATE_SUSPENDED | CREATE_NO_WINDOW);
cmd.arg("/C").raw_arg(command);
cmd
}
#[cfg(not(windows))]
{
let mut cmd = Command::new("sh");
cmd.arg("-c").arg(command);
#[cfg(unix)]
{
use std::os::unix::process::CommandExt as _;
cmd.process_group(0);
}
cmd
}
}
pub fn new(config: HooksConfig, default_working_dir: PathBuf) -> Self {
let session_id = format!("sess_{}", &uuid::Uuid::new_v4().to_string()[..8]);
Self {
config,
default_working_dir,
session_id,
}
}
#[allow(dead_code)] pub fn disabled() -> Self {
Self {
config: HooksConfig {
enabled: false,
..Default::default()
},
default_working_dir: PathBuf::from("."),
session_id: String::new(),
}
}
#[allow(dead_code)] pub fn is_enabled(&self) -> bool {
self.config.enabled
}
pub fn config(&self) -> &HooksConfig {
&self.config
}
pub fn session_id(&self) -> &str {
&self.session_id
}
#[must_use]
pub fn has_hooks_for_event(&self, event: HookEvent) -> bool {
self.config.enabled && self.config.hooks.iter().any(|h| h.event == event)
}
#[must_use]
pub fn has_background_hooks_for_event(&self, event: HookEvent) -> bool {
if !self.config.enabled {
return false;
}
self.config
.hooks
.iter()
.any(|h| h.event == event && h.background)
}
pub fn execute_message_submit_transform(
&self,
context: &HookContext,
original_text: &str,
) -> MessageSubmitOutcome {
if !self.config.enabled {
return MessageSubmitOutcome::unchanged();
}
let hooks = self.config.hooks_for_event(HookEvent::MessageSubmit);
if hooks.is_empty() {
return MessageSubmitOutcome::unchanged();
}
let mut current_text = original_text.to_string();
let mut warning = None;
for hook in hooks {
let hook_context = context.clone().with_message(¤t_text);
if !self.matches_condition(hook, &hook_context) {
continue;
}
let env_vars = hook_context.to_env_vars();
if hook.background {
let _ = self.execute_background(hook, &env_vars);
continue;
}
let payload = message_submit_payload(&hook_context, ¤t_text);
let result = self.execute_sync_with_stdin(hook, &env_vars, &payload);
if result.exit_code == Some(2) {
return MessageSubmitOutcome::Blocked {
reason: message_submit_block_reason(
&result,
"message_submit hook blocked submission",
),
};
}
if !result.success {
let label = result.name.as_deref().unwrap_or("(unnamed)");
tracing::warn!(
target: "hooks",
hook = label,
event = "message_submit",
exit_code = ?result.exit_code,
duration_ms = result.duration.as_millis() as u64,
error = result.error.as_deref().unwrap_or(""),
stderr_head = %result.stderr.lines().next().unwrap_or(""),
"message_submit hook failed"
);
if hook.continue_on_error {
warning = message_submit_continue_warning(&result).or(warning);
continue;
}
return MessageSubmitOutcome::Blocked {
reason: message_submit_block_reason(
&result,
"message_submit hook failed and blocked submission",
),
};
}
match parse_message_submit_stdout(&result.stdout) {
MessageSubmitStdout::Unchanged => {}
MessageSubmitStdout::Replaced(text) => {
current_text = text;
}
MessageSubmitStdout::Invalid(reason) => {
tracing::warn!(
target: "hooks",
hook = result.name.as_deref().unwrap_or("(unnamed)"),
event = "message_submit",
reason = %reason,
"ignored invalid message_submit hook stdout"
);
}
}
}
if current_text == original_text {
MessageSubmitOutcome::unchanged().with_warning(warning)
} else {
MessageSubmitOutcome::replaced(current_text).with_warning(warning)
}
}
pub fn collect_shell_env(&self, context: &HookContext) -> HashMap<String, String> {
let mut merged: HashMap<String, String> = HashMap::new();
if !self.config.enabled {
return merged;
}
let hooks = self.config.hooks_for_event(HookEvent::ShellEnv);
if hooks.is_empty() {
return merged;
}
let env_vars = context.to_env_vars();
for hook in hooks {
if !self.matches_condition(hook, context) {
continue;
}
let result = self.execute_sync(hook, &env_vars);
if !result.success {
tracing::warn!(
target: "hooks",
hook = result.name.as_deref().unwrap_or("(unnamed)"),
event = "shell_env",
exit_code = ?result.exit_code,
error = result.error.as_deref().unwrap_or(""),
"shell_env hook failed; contributing no env vars"
);
continue;
}
let parsed = parse_env_lines(&result.stdout);
if parsed.is_empty() {
continue;
}
crate::audit::log_sensitive_event(
"shell_env_hook",
serde_json::json!({
"hook": result.name,
"tool": context.tool_name,
"keys": parsed.keys().cloned().collect::<Vec<_>>(),
}),
);
merged.extend(parsed);
}
merged
}
pub fn execute(&self, event: HookEvent, context: &HookContext) -> Vec<HookResult> {
if !self.config.enabled {
return Vec::new();
}
let hooks = self.config.hooks_for_event(event);
if hooks.is_empty() {
return Vec::new();
}
let env_vars = context.to_env_vars();
let mut results = Vec::new();
for hook in hooks {
if !self.matches_condition(hook, context) {
continue;
}
let result = if hook.background {
self.execute_background(hook, &env_vars)
} else {
self.execute_sync(hook, &env_vars)
};
if !result.success {
let label = result.name.as_deref().unwrap_or("(unnamed)");
tracing::warn!(
target: "hooks",
hook = label,
event = event.as_str(),
exit_code = ?result.exit_code,
duration_ms = result.duration.as_millis() as u64,
error = result.error.as_deref().unwrap_or(""),
stderr_head = %result.stderr.lines().next().unwrap_or(""),
"hook failed"
);
}
let should_continue = result.success || hook.continue_on_error;
results.push(result);
if !should_continue {
break;
}
}
results
}
pub fn execute_json_observer(
&self,
event: HookEvent,
context: &HookContext,
payload: &serde_json::Value,
) -> Vec<HookResult> {
if !self.config.enabled {
return Vec::new();
}
let hooks = self.config.hooks_for_event(event);
if hooks.is_empty() {
return Vec::new();
}
let env_vars = context.to_env_vars();
let mut results = Vec::new();
for hook in hooks {
if !self.matches_condition(hook, context) {
continue;
}
let result = if hook.background {
self.execute_background_with_stdin(hook, &env_vars, payload)
} else {
self.execute_sync_with_stdin(hook, &env_vars, payload)
};
if !result.success {
let label = result.name.as_deref().unwrap_or("(unnamed)");
tracing::warn!(
target: "hooks",
hook = label,
event = event.as_str(),
exit_code = ?result.exit_code,
duration_ms = result.duration.as_millis() as u64,
error = result.error.as_deref().unwrap_or(""),
stderr_head = %result.stderr.lines().next().unwrap_or(""),
"observer hook failed"
);
}
results.push(result);
}
results
}
fn tool_name_matches_condition(tool_name: &str, pattern: &str) -> bool {
if !pattern.contains('*') {
return tool_name == pattern;
}
let escaped = regex::escape(pattern);
let regex_pattern = escaped.replace(r"\*", ".*");
let anchored = format!("^{regex_pattern}$");
regex::Regex::new(&anchored).is_ok_and(|re| re.is_match(tool_name))
}
#[allow(clippy::only_used_in_recursion)]
fn matches_condition(&self, hook: &Hook, context: &HookContext) -> bool {
match &hook.condition {
None | Some(HookCondition::Always) => true,
Some(HookCondition::ToolName { name }) => {
context
.tool_name
.as_ref()
.is_some_and(|n| Self::tool_name_matches_condition(n, name))
}
Some(HookCondition::ToolCategory { category }) => {
let tool_category = context.tool_name.as_ref().map(|name| match name.as_str() {
"exec_shell" => "shell",
"write_file" | "edit_file" | "apply_patch" => "file_write",
"read_file" | "list_dir" | "grep_files" => "safe",
_ => "other",
});
tool_category.is_some_and(|c| c == category.as_str())
}
Some(HookCondition::Mode { mode }) => context
.mode
.as_ref()
.is_some_and(|m| m.eq_ignore_ascii_case(mode)),
Some(HookCondition::ExitCode { code }) => context.tool_exit_code == Some(*code),
Some(HookCondition::All { conditions }) => conditions.iter().all(|c| {
self.matches_condition(
&Hook {
condition: Some(c.clone()),
..hook.clone()
},
context,
)
}),
Some(HookCondition::Any { conditions }) => conditions.iter().any(|c| {
self.matches_condition(
&Hook {
condition: Some(c.clone()),
..hook.clone()
},
context,
)
}),
}
}
fn execute_sync(&self, hook: &Hook, env_vars: &HashMap<String, String>) -> HookResult {
self.execute_sync_inner(hook, env_vars, None)
}
fn execute_sync_with_stdin(
&self,
hook: &Hook,
env_vars: &HashMap<String, String>,
stdin_json: &serde_json::Value,
) -> HookResult {
self.execute_sync_inner(hook, env_vars, Some(stdin_json))
}
fn execute_sync_inner(
&self,
hook: &Hook,
env_vars: &HashMap<String, String>,
stdin_json: Option<&serde_json::Value>,
) -> HookResult {
let started = Instant::now();
let working_dir = self
.config
.working_dir
.clone()
.unwrap_or_else(|| self.default_working_dir.clone());
let timeout_secs = self
.config
.default_timeout_secs
.unwrap_or(hook.timeout_secs);
let timeout = Duration::from_secs(timeout_secs);
let stdin_bytes = match stdin_json.map(serde_json::to_vec).transpose() {
Ok(bytes) => bytes,
Err(e) => {
return HookResult {
name: hook.name.clone(),
success: false,
exit_code: None,
stdout: String::new(),
stderr: String::new(),
duration: started.elapsed(),
error: Some(format!("Failed to encode hook stdin: {e}")),
};
}
};
let mut command = Self::build_shell_command(&hook.command);
command
.current_dir(&working_dir)
.envs(env_vars)
.stdout(Stdio::piped())
.stderr(Stdio::piped())
.stdin(Stdio::piped());
let (mut child, process_tree) = match spawn_hook_child(&mut command, &hook.command) {
Ok(child) => child,
Err(e) => {
return HookResult {
name: hook.name.clone(),
success: false,
exit_code: None,
stdout: String::new(),
stderr: String::new(),
duration: started.elapsed(),
error: Some(format!("Failed to start hook: {e}")),
};
}
};
let stdout_reader = child.stdout.take().map(spawn_pipe_reader);
let stderr_reader = child.stderr.take().map(spawn_pipe_reader);
let _stdin_writer = match (stdin_bytes, child.stdin.take()) {
(Some(bytes), Some(stdin)) => Some(spawn_stdin_writer(stdin, bytes)),
_ => None,
};
match child.wait_timeout(timeout) {
Ok(Some(status)) => {
drop(process_tree);
HookResult {
name: hook.name.clone(),
success: status.success(),
exit_code: status.code(),
stdout: collect_reader(stdout_reader, HOOK_PIPE_DRAIN_TIMEOUT),
stderr: collect_reader(stderr_reader, HOOK_PIPE_DRAIN_TIMEOUT),
duration: started.elapsed(),
error: None,
}
}
Ok(None) => {
process_tree.terminate(&mut child);
let _ = child.wait();
drop(process_tree);
let _ = collect_reader(stdout_reader, HOOK_PIPE_SHUTDOWN_TIMEOUT);
let _ = collect_reader(stderr_reader, HOOK_PIPE_SHUTDOWN_TIMEOUT);
HookResult {
name: hook.name.clone(),
success: false,
exit_code: None,
stdout: String::new(),
stderr: String::new(),
duration: started.elapsed(),
error: Some(format!("Hook timed out after {timeout_secs}s")),
}
}
Err(e) => {
process_tree.terminate(&mut child);
let _ = child.wait();
drop(process_tree);
let _ = collect_reader(stdout_reader, HOOK_PIPE_SHUTDOWN_TIMEOUT);
let _ = collect_reader(stderr_reader, HOOK_PIPE_SHUTDOWN_TIMEOUT);
HookResult {
name: hook.name.clone(),
success: false,
exit_code: None,
stdout: String::new(),
stderr: String::new(),
duration: started.elapsed(),
error: Some(format!("Failed to wait for hook: {e}")),
}
}
}
}
fn execute_background(&self, hook: &Hook, env_vars: &HashMap<String, String>) -> HookResult {
self.execute_background_inner(hook, env_vars, None)
}
fn execute_background_with_stdin(
&self,
hook: &Hook,
env_vars: &HashMap<String, String>,
stdin_json: &serde_json::Value,
) -> HookResult {
self.execute_background_inner(hook, env_vars, Some(stdin_json))
}
fn execute_background_inner(
&self,
hook: &Hook,
env_vars: &HashMap<String, String>,
stdin_json: Option<&serde_json::Value>,
) -> HookResult {
let started = Instant::now();
let working_dir = self
.config
.working_dir
.clone()
.unwrap_or_else(|| self.default_working_dir.clone());
let stdin_bytes = match stdin_json.map(serde_json::to_vec).transpose() {
Ok(bytes) => bytes,
Err(e) => {
return HookResult {
name: hook.name.clone(),
success: false,
exit_code: None,
stdout: String::new(),
stderr: String::new(),
duration: started.elapsed(),
error: Some(format!("Failed to encode hook stdin: {e}")),
};
}
};
let cmd = hook.command.clone();
let env = env_vars.clone();
let wd = working_dir.clone();
std::thread::spawn(move || {
let mut command = HookExecutor::build_shell_command(&cmd);
command
.current_dir(&wd)
.envs(&env)
.stdout(Stdio::null())
.stderr(Stdio::null())
.stdin(Stdio::piped());
let (mut child, process_tree) = match spawn_hook_child(&mut command, &cmd) {
Ok(child) => child,
Err(error) => {
tracing::warn!(?error, command = cmd, "failed to start background hook");
return;
}
};
if let (Some(mut bytes), Some(mut stdin)) = (stdin_bytes, child.stdin.take()) {
bytes.push(b'\n');
let _ = stdin.write_all(&bytes);
let _ = stdin.flush();
}
let _ = child.wait();
drop(process_tree);
});
HookResult {
name: hook.name.clone(),
success: true,
exit_code: None,
stdout: String::new(),
stderr: String::new(),
duration: started.elapsed(),
error: None,
}
}
}
const HOOK_PIPE_DRAIN_TIMEOUT: Duration = Duration::from_secs(5);
const HOOK_PIPE_SHUTDOWN_TIMEOUT: Duration = Duration::from_millis(250);
fn spawn_pipe_reader(mut pipe: impl Read + Send + 'static) -> Receiver<String> {
let (tx, rx) = mpsc::channel();
thread::spawn(move || {
let mut buf = String::new();
let _ = pipe.read_to_string(&mut buf);
let _ = tx.send(buf);
});
rx
}
fn collect_reader(reader: Option<Receiver<String>>, timeout: Duration) -> String {
let Some(reader) = reader else {
return String::new();
};
match reader.recv_timeout(timeout) {
Ok(output) => output,
Err(RecvTimeoutError::Timeout) => {
tracing::warn!(
?timeout,
"hook pipe reader did not finish after process cleanup"
);
String::new()
}
Err(RecvTimeoutError::Disconnected) => String::new(),
}
}
fn spawn_stdin_writer(mut stdin: std::process::ChildStdin, mut bytes: Vec<u8>) -> JoinHandle<()> {
thread::spawn(move || {
bytes.push(b'\n');
let _ = stdin.write_all(&bytes);
let _ = stdin.flush();
})
}
fn message_submit_payload(context: &HookContext, text: &str) -> serde_json::Value {
json!({
"event": HookEvent::MessageSubmit.as_str(),
"text": text,
"session_id": context.session_id.as_deref(),
"workspace": context.workspace.as_ref().map(|path| path.display().to_string()),
"mode": context.mode.as_deref(),
"model": context.model.as_deref(),
"total_tokens": context.total_tokens,
})
}
pub fn turn_end_payload(input: TurnEndPayloadInput<'_>) -> serde_json::Value {
json!({
"event": HookEvent::TurnEnd.as_str(),
"session_id": input.context.session_id.as_deref(),
"workspace": input.context.workspace.as_ref().map(|path| path.display().to_string()),
"mode": input.context.mode.as_deref(),
"created_at": input.created_at.to_rfc3339(),
"model_backed": input.model_backed,
"provider": input.provider,
"billing_surface": input.billing_surface,
"model": input.model.or(input.context.model.as_deref()),
"turn_id": input.turn_id,
"status": input.status,
"error": input.error,
"duration_ms": duration_ms_saturating(input.duration),
"usage": {
"input_tokens": input.usage.input_tokens,
"output_tokens": input.usage.output_tokens,
"prompt_cache_hit_tokens": input.usage.prompt_cache_hit_tokens,
"prompt_cache_miss_tokens": input.usage.prompt_cache_miss_tokens,
"prompt_cache_write_tokens": input.usage.prompt_cache_write_tokens,
"reasoning_tokens": input.usage.reasoning_tokens,
"reasoning_replay_tokens": input.usage.reasoning_replay_tokens,
},
"totals": {
"session_tokens": input.totals.session_tokens,
"conversation_tokens": input.totals.conversation_tokens,
"input_tokens": input.totals.input_tokens,
"output_tokens": input.totals.output_tokens,
},
"tool_count": input.tool_count,
"queued_message_count": input.queued_message_count,
"stop_hook_active": false,
})
}
fn duration_ms_saturating(duration: Duration) -> u64 {
u64::try_from(duration.as_millis()).unwrap_or(u64::MAX)
}
fn parse_message_submit_stdout(stdout: &str) -> MessageSubmitStdout {
let trimmed = stdout.trim();
if trimmed.is_empty() {
return MessageSubmitStdout::Unchanged;
}
let value: serde_json::Value = match serde_json::from_str(trimmed) {
Ok(value) => value,
Err(e) => return MessageSubmitStdout::Invalid(format!("invalid JSON: {e}")),
};
let Some(object) = value.as_object() else {
return MessageSubmitStdout::Invalid("stdout JSON must be an object".to_string());
};
match object.get("text") {
Some(serde_json::Value::String(text)) if !text.is_empty() => {
MessageSubmitStdout::Replaced(text.clone())
}
Some(serde_json::Value::String(_)) => {
MessageSubmitStdout::Invalid("stdout `text` field must not be empty".to_string())
}
Some(_) => MessageSubmitStdout::Invalid("stdout `text` field must be a string".to_string()),
None => MessageSubmitStdout::Unchanged,
}
}
fn message_submit_continue_warning(result: &HookResult) -> Option<String> {
message_submit_stdout_reason(&result.stdout)
.or_else(|| first_non_empty_line(&result.stderr))
.or_else(|| first_non_empty_line(&result.stdout))
.or_else(|| result.error.as_deref().and_then(first_non_empty_line))
}
fn message_submit_block_reason(result: &HookResult, fallback: &str) -> String {
if let Some(reason) = message_submit_stdout_reason(&result.stdout) {
return reason;
}
if let Some(reason) = first_non_empty_line(&result.stderr) {
return reason;
}
if let Some(reason) = first_non_empty_line(&result.stdout) {
return reason;
}
if let Some(reason) = result.error.as_deref().and_then(first_non_empty_line) {
return reason;
}
fallback.to_string()
}
fn message_submit_stdout_reason(stdout: &str) -> Option<String> {
let value: serde_json::Value = serde_json::from_str(stdout.trim()).ok()?;
value
.get("reason")
.and_then(serde_json::Value::as_str)
.map(truncate_hook_message)
}
fn first_non_empty_line(text: &str) -> Option<String> {
text.lines()
.map(str::trim)
.find(|line| !line.is_empty())
.map(truncate_hook_message)
}
fn truncate_hook_message(message: &str) -> String {
const MAX_CHARS: usize = 240;
let mut chars = message.chars();
let mut out: String = chars.by_ref().take(MAX_CHARS).collect();
if chars.next().is_some() {
out.push('…');
}
out
}
fn parse_env_lines(stdout: &str) -> HashMap<String, String> {
let mut out = HashMap::new();
for raw in stdout.lines() {
let line = raw.trim();
if line.is_empty() || line.starts_with('#') {
continue;
}
let line = line.strip_prefix("export ").unwrap_or(line);
let Some((key, value)) = line.split_once('=') else {
continue;
};
let key = key.trim();
if key.is_empty() {
continue;
}
let value = value.trim();
let stripped = value
.strip_prefix('"')
.and_then(|v| v.strip_suffix('"'))
.or_else(|| value.strip_prefix('\'').and_then(|v| v.strip_suffix('\'')))
.unwrap_or(value);
out.insert(key.to_string(), stripped.to_string());
}
out
}
#[cfg(test)]
mod tests {
use super::*;
use crate::test_support::{EnvVarGuard, lock_test_env};
use std::collections::HashMap;
use std::path::{Path, PathBuf};
fn trust_workspace_for_project_hooks(workspace: &Path, config_path: &Path) -> EnvVarGuard {
let guard = EnvVarGuard::set("CODEWHALE_CONFIG_PATH", config_path);
crate::config::save_workspace_trust(workspace).expect("save workspace trust");
guard
}
#[test]
fn parse_env_lines_handles_realistic_hook_output() {
let stdout = r#"
# Aux comment line, ignored
AWS_ACCESS_KEY_ID=AKIAEXAMPLE
export GITHUB_TOKEN=ghp_examplevalue
QUOTED="value with spaces"
SINGLE='also valid'
= empty key dropped
NOEQUAL line dropped
"#;
let parsed = super::parse_env_lines(stdout);
assert_eq!(
parsed.get("AWS_ACCESS_KEY_ID"),
Some(&"AKIAEXAMPLE".to_string())
);
assert_eq!(
parsed.get("GITHUB_TOKEN"),
Some(&"ghp_examplevalue".to_string())
);
assert_eq!(parsed.get("QUOTED"), Some(&"value with spaces".to_string()));
assert_eq!(parsed.get("SINGLE"), Some(&"also valid".to_string()));
assert!(!parsed.contains_key(""));
assert!(!parsed.contains_key("NOEQUAL line dropped"));
assert_eq!(parsed.len(), 4);
}
#[test]
fn parse_env_lines_empty_when_no_assignments() {
let parsed = super::parse_env_lines("# nothing\n\n \n");
assert!(parsed.is_empty());
}
#[test]
fn parse_message_submit_stdout_replaces_text() {
assert_eq!(
super::parse_message_submit_stdout(r#"{"text":"changed"}"#),
MessageSubmitStdout::Replaced("changed".to_string())
);
}
#[test]
fn parse_message_submit_stdout_empty_is_unchanged() {
assert_eq!(
super::parse_message_submit_stdout(" \n\t "),
MessageSubmitStdout::Unchanged
);
}
#[test]
fn parse_message_submit_stdout_without_text_is_unchanged() {
assert_eq!(
super::parse_message_submit_stdout(r#"{"reason":"only used for blocks"}"#),
MessageSubmitStdout::Unchanged
);
}
#[test]
fn parse_message_submit_stdout_rejects_malformed_json() {
assert!(matches!(
super::parse_message_submit_stdout("not json"),
MessageSubmitStdout::Invalid(_)
));
}
#[test]
fn parse_message_submit_stdout_rejects_non_string_text() {
assert!(matches!(
super::parse_message_submit_stdout(r#"{"text":123}"#),
MessageSubmitStdout::Invalid(_)
));
}
#[test]
fn parse_message_submit_stdout_rejects_empty_text() {
assert_eq!(
super::parse_message_submit_stdout(r#"{"text":""}"#),
MessageSubmitStdout::Invalid("stdout `text` field must not be empty".to_string())
);
}
#[test]
fn parse_message_submit_stdout_rejects_non_object_json() {
assert!(matches!(
super::parse_message_submit_stdout(r#"["not", "an", "object"]"#),
MessageSubmitStdout::Invalid(_)
));
assert!(matches!(
super::parse_message_submit_stdout(r#""not an object""#),
MessageSubmitStdout::Invalid(_)
));
}
#[test]
fn test_hook_event_as_str() {
assert_eq!(HookEvent::SessionStart.as_str(), "session_start");
assert_eq!(HookEvent::ToolCallAfter.as_str(), "tool_call_after");
assert_eq!(HookEvent::ModeChange.as_str(), "mode_change");
assert_eq!(HookEvent::TurnEnd.as_str(), "turn_end");
assert_eq!(HookEvent::SubagentSpawn.as_str(), "subagent_spawn");
assert_eq!(HookEvent::SubagentComplete.as_str(), "subagent_complete");
}
#[test]
fn turn_end_payload_contains_post_turn_observer_fields() {
let context = HookContext::new()
.with_session_id("sess_test")
.with_workspace(PathBuf::from("/tmp/codewhale"))
.with_mode("agent")
.with_model("deepseek-v4")
.with_tokens(125);
let usage = crate::models::Usage {
input_tokens: 40,
output_tokens: 9,
prompt_cache_hit_tokens: Some(10),
prompt_cache_miss_tokens: Some(30),
prompt_cache_write_tokens: None,
reasoning_tokens: Some(4),
reasoning_replay_tokens: Some(2),
server_tool_use: None,
};
let payload = super::turn_end_payload(TurnEndPayloadInput {
context: &context,
created_at: "2026-07-12T10:30:00Z".parse().expect("timestamp"),
model_backed: true,
provider: Some("deepseek"),
billing_surface: Some("test-payg"),
model: Some("deepseek-v4-pro"),
turn_id: "turn_123",
status: "completed",
error: None,
duration: Duration::from_millis(321),
usage: &usage,
totals: TurnEndTotals {
session_tokens: 125,
conversation_tokens: 100,
input_tokens: 100,
output_tokens: 25,
},
tool_count: 2,
queued_message_count: 1,
});
assert_eq!(payload["event"], "turn_end");
assert_eq!(payload["session_id"], "sess_test");
assert_eq!(payload["workspace"], "/tmp/codewhale");
assert_eq!(payload["mode"], "agent");
assert_eq!(payload["created_at"], "2026-07-12T10:30:00+00:00");
assert_eq!(payload["model_backed"], true);
assert_eq!(payload["provider"], "deepseek");
assert_eq!(payload["billing_surface"], "test-payg");
assert!(payload.get("base_url").is_none());
assert_eq!(payload["model"], "deepseek-v4-pro");
assert_eq!(payload["turn_id"], "turn_123");
assert_eq!(payload["status"], "completed");
assert_eq!(payload["error"], serde_json::Value::Null);
assert_eq!(payload["duration_ms"], 321);
assert_eq!(payload["usage"]["input_tokens"], 40);
assert_eq!(payload["usage"]["output_tokens"], 9);
assert_eq!(payload["usage"]["prompt_cache_hit_tokens"], 10);
assert_eq!(payload["usage"]["prompt_cache_miss_tokens"], 30);
assert_eq!(payload["usage"]["reasoning_tokens"], 4);
assert_eq!(payload["usage"]["reasoning_replay_tokens"], 2);
assert_eq!(payload["totals"]["session_tokens"], 125);
assert_eq!(payload["totals"]["conversation_tokens"], 100);
assert_eq!(payload["totals"]["input_tokens"], 100);
assert_eq!(payload["totals"]["output_tokens"], 25);
assert_eq!(payload["tool_count"], 2);
assert_eq!(payload["queued_message_count"], 1);
assert_eq!(payload["stop_hook_active"], false);
}
#[test]
fn test_hook_context_to_env_vars() {
let ctx = HookContext::new()
.with_tool_name("exec_shell")
.with_mode("agent")
.with_workspace(PathBuf::from("/tmp"));
let env = ctx.to_env_vars();
assert_eq!(
env.get("DEEPSEEK_TOOL_NAME"),
Some(&"exec_shell".to_string())
);
assert_eq!(env.get("DEEPSEEK_MODE"), Some(&"agent".to_string()));
assert_eq!(env.get("DEEPSEEK_WORKSPACE"), Some(&"/tmp".to_string()));
}
#[test]
fn test_hook_condition_always() {
let hook = Hook::new(HookEvent::SessionStart, "echo test");
let executor = HookExecutor::disabled();
let context = HookContext::new();
assert!(executor.matches_condition(&hook, &context));
}
#[test]
fn test_hook_condition_tool_name() {
let hook = Hook::new(HookEvent::ToolCallBefore, "echo test").with_condition(
HookCondition::ToolName {
name: "exec_shell".to_string(),
},
);
let executor = HookExecutor::disabled();
let context_match = HookContext::new().with_tool_name("exec_shell");
let context_no_match = HookContext::new().with_tool_name("write_file");
assert!(executor.matches_condition(&hook, &context_match));
assert!(!executor.matches_condition(&hook, &context_no_match));
}
#[test]
fn test_hook_condition_mode() {
let hook =
Hook::new(HookEvent::ModeChange, "echo test").with_condition(HookCondition::Mode {
mode: "agent".to_string(),
});
let executor = HookExecutor::disabled();
let context_match = HookContext::new().with_mode("AGENT"); let context_no_match = HookContext::new().with_mode("normal");
assert!(executor.matches_condition(&hook, &context_match));
assert!(!executor.matches_condition(&hook, &context_no_match));
}
#[test]
fn test_hooks_config_for_event() {
let config = HooksConfig {
enabled: true,
hooks: vec![
Hook::new(HookEvent::SessionStart, "echo start"),
Hook::new(HookEvent::SessionEnd, "echo end"),
Hook::new(HookEvent::SessionStart, "echo start2"),
],
..Default::default()
};
let start_hooks = config.hooks_for_event(HookEvent::SessionStart);
assert_eq!(start_hooks.len(), 2);
let end_hooks = config.hooks_for_event(HookEvent::SessionEnd);
assert_eq!(end_hooks.len(), 1);
}
#[test]
fn test_hooks_config_disabled() {
let config = HooksConfig {
enabled: false,
hooks: vec![Hook::new(HookEvent::SessionStart, "echo start")],
..Default::default()
};
let hooks = config.hooks_for_event(HookEvent::SessionStart);
assert!(hooks.is_empty());
}
#[test]
fn test_hook_builder() {
let hook = Hook::new(HookEvent::ToolCallAfter, "notify.sh")
.with_name("notify_tool")
.with_timeout(60)
.background()
.with_condition(HookCondition::ToolCategory {
category: "shell".to_string(),
});
assert_eq!(hook.name, Some("notify_tool".to_string()));
assert_eq!(hook.timeout_secs, 60);
assert!(hook.background);
assert!(matches!(
hook.condition,
Some(HookCondition::ToolCategory { .. })
));
}
#[test]
fn test_hook_timeout_enforced() {
let command = if cfg!(windows) {
"ping -n 3 127.0.0.1 > nul"
} else {
"sleep 2"
};
let hook = Hook::new(HookEvent::SessionStart, command).with_timeout(1);
let executor = HookExecutor::new(HooksConfig::default(), PathBuf::from("."));
let env_vars = HashMap::new();
let result = executor.execute_sync(&hook, &env_vars);
assert!(!result.success);
assert!(
result
.error
.as_ref()
.is_some_and(|e| e.contains("timed out"))
);
}
#[test]
fn observer_hook_receives_eof_instead_of_inheriting_terminal_stdin() {
const INNER_ENV: &str = "CODEWHALE_TEST_HOOK_EOF_INNER";
const TEST_NAME: &str =
"hooks::tests::observer_hook_receives_eof_instead_of_inheriting_terminal_stdin";
if std::env::var_os(INNER_ENV).is_some() {
let dir = tempfile::tempdir().expect("tempdir");
#[cfg(not(windows))]
let command = write_hook_script(
&dir,
"read_to_eof.sh",
r#"#!/bin/sh
payload=$(cat)
printf 'stdin-bytes=%s\n' "${#payload}"
"#,
);
#[cfg(windows)]
let command = "powershell -NoProfile -Command \"$value = [Console]::In.ReadToEnd(); [Console]::Out.WriteLine(('stdin-bytes=' + $value.Length))\"".to_string();
let hook_timeout_secs = if cfg!(windows) { 10 } else { 2 };
let hook =
Hook::new(HookEvent::ToolCallBefore, &command).with_timeout(hook_timeout_secs);
let executor = HookExecutor::new(HooksConfig::default(), dir.path().to_path_buf());
let result = executor.execute_sync(&hook, &HashMap::new());
assert!(result.success, "stdin-less hook should finish: {result:?}");
assert_eq!(result.stdout.trim(), "stdin-bytes=0");
return;
}
let mut child = Command::new(std::env::current_exe().expect("current test binary"))
.args(["--exact", TEST_NAME, "--nocapture", "--test-threads=1"])
.env(INNER_ENV, "1")
.stdin(Stdio::piped())
.spawn()
.expect("spawn isolated hook EOF test");
let held_open_stdin = child.stdin.take().expect("piped child stdin");
let isolated_timeout_secs = if cfg!(windows) { 25 } else { 10 };
let status = match child
.wait_timeout(Duration::from_secs(isolated_timeout_secs))
.expect("wait for isolated hook EOF test")
{
Some(status) => status,
None => {
let _ = child.kill();
let _ = child.wait();
panic!("isolated hook EOF test hung with parent stdin open");
}
};
drop(held_open_stdin);
assert!(status.success(), "isolated hook EOF test failed: {status}");
}
#[cfg(not(windows))]
#[test]
fn timed_out_hook_kills_descendant_process_group() {
let dir = tempfile::tempdir().expect("tempdir");
let marker = dir.path().join("descendant-survived");
let command = write_hook_script(
&dir,
"spawn_descendant.sh",
&format!(
"#!/bin/sh\n(sleep 2; printf leaked > '{}') &\nsleep 5\n",
marker.display()
),
);
let hook = Hook::new(HookEvent::ToolCallBefore, &command).with_timeout(1);
let executor = HookExecutor::new(HooksConfig::default(), dir.path().to_path_buf());
let result = executor.execute_sync(&hook, &HashMap::new());
assert!(
result
.error
.as_ref()
.is_some_and(|error| error.contains("timed out")),
"hook should time out: {result:?}"
);
std::thread::sleep(Duration::from_millis(1_500));
assert!(
!marker.exists(),
"the timed-out hook's descendant escaped its process group"
);
}
#[cfg(windows)]
#[test]
fn timed_out_hook_kills_windows_descendant_job() {
let dir = tempfile::tempdir().expect("tempdir");
let started = dir.path().join("descendant-started.txt");
let survived = dir.path().join("descendant-survived.txt");
let descendant = dir.path().join("descendant.cmd");
std::fs::write(
&descendant,
"@echo off\r\necho started>descendant-started.txt\r\nping -n 5 127.0.0.1 > nul\r\necho survived>descendant-survived.txt\r\n",
)
.expect("write descendant script");
let parent = dir.path().join("parent.cmd");
std::fs::write(
&parent,
"@echo off\r\nstart \"\" /b cmd.exe /d /c descendant.cmd\r\n:wait_for_child\r\nif exist descendant-started.txt goto child_started\r\nping -n 2 127.0.0.1 > nul\r\ngoto wait_for_child\r\n:child_started\r\nping -n 10 127.0.0.1 > nul\r\n",
)
.expect("write parent script");
let hook = Hook::new(HookEvent::ToolCallBefore, "call parent.cmd").with_timeout(3);
let executor = HookExecutor::new(HooksConfig::default(), dir.path().to_path_buf());
let result = executor.execute_sync(&hook, &HashMap::new());
assert!(
result
.error
.as_ref()
.is_some_and(|error| error.contains("timed out")),
"hook should time out: {result:?}"
);
assert!(
started.exists(),
"descendant never reached its start handshake"
);
std::thread::sleep(Duration::from_secs(5));
assert!(
!survived.exists(),
"the timed-out hook's descendant escaped its Job Object"
);
}
#[cfg(not(windows))]
#[test]
fn message_submit_stdin_write_does_not_deadlock_when_hook_writes_first() {
let dir = tempfile::tempdir().expect("tempdir");
let command = write_hook_script(
&dir,
"write_before_read.sh",
r#"#!/bin/sh
dd if=/dev/zero bs=1024 count=256 2>/dev/null | tr '\000' x
dd if=/dev/zero bs=1024 count=256 2>/dev/null | tr '\000' e >&2
payload=$(cat)
printf '\ndone:%s\n' "${#payload}"
"#,
);
let hook = Hook::new(HookEvent::MessageSubmit, &command).with_timeout(5);
let executor = HookExecutor::new(HooksConfig::default(), dir.path().to_path_buf());
let env_vars = HashMap::new();
let payload = json!({
"event": "message_submit",
"text": "x".repeat(256 * 1024),
});
let result = executor.execute_sync_with_stdin(&hook, &env_vars, &payload);
assert!(result.success, "hook should complete: {result:?}");
assert!(result.stdout.contains("done:"), "stdout was drained");
assert!(result.stderr.len() >= 256 * 1024, "stderr was drained");
}
#[test]
fn test_executor_session_id() {
let executor = HookExecutor::new(HooksConfig::default(), PathBuf::from("."));
assert!(executor.session_id().starts_with("sess_"));
assert_eq!(executor.session_id().len(), 13); }
#[cfg(not(windows))]
fn write_hook_script(dir: &tempfile::TempDir, name: &str, content: &str) -> String {
let path = dir.path().join(name);
std::fs::write(&path, content).expect("write hook script");
format!("sh {}", path.display())
}
#[cfg(not(windows))]
fn submit_context(dir: &tempfile::TempDir) -> HookContext {
HookContext::new()
.with_session_id("sess_test")
.with_workspace(dir.path().to_path_buf())
.with_mode("agent")
.with_model("deepseek-test")
.with_tokens(42)
}
#[cfg(not(windows))]
#[test]
fn json_observer_hook_receives_structured_stdin() {
let dir = tempfile::tempdir().expect("tempdir");
let out = dir.path().join("payload.json");
let command = write_hook_script(
&dir,
"capture_observer.sh",
&format!(
r#"#!/bin/sh
cat > "{}"
"#,
out.display()
),
);
let executor = HookExecutor::new(
HooksConfig {
enabled: true,
hooks: vec![Hook::new(HookEvent::SubagentSpawn, &command)],
..Default::default()
},
dir.path().to_path_buf(),
);
let payload = json!({
"event": "subagent_spawn",
"agent_id": "agent_123",
"prompt_preview": "inspect this",
"prompt_truncated": false,
});
let results = executor.execute_json_observer(
HookEvent::SubagentSpawn,
&submit_context(&dir),
&payload,
);
assert_eq!(results.len(), 1);
assert!(results[0].success);
let captured: serde_json::Value =
serde_json::from_str(&std::fs::read_to_string(out).expect("payload written"))
.expect("valid JSON payload");
assert_eq!(captured["event"], "subagent_spawn");
assert_eq!(captured["agent_id"], "agent_123");
assert_eq!(captured["prompt_preview"], "inspect this");
assert_eq!(captured["prompt_truncated"], false);
}
#[cfg(not(windows))]
#[test]
fn turn_end_observer_hook_receives_stdin_json_and_ignores_stdout_contract() {
let dir = tempfile::tempdir().expect("tempdir");
let out = dir.path().join("turn_end.json");
let command = write_hook_script(
&dir,
"capture_turn_end.sh",
&format!(
r#"#!/bin/sh
cat > "{}"
printf '%s\n' '{{"text":"stdout is not a mutation contract"}}'
"#,
out.display()
),
);
let executor = HookExecutor::new(
HooksConfig {
enabled: true,
hooks: vec![Hook::new(HookEvent::TurnEnd, &command)],
..Default::default()
},
dir.path().to_path_buf(),
);
let usage = crate::models::Usage {
input_tokens: 12,
output_tokens: 3,
prompt_cache_hit_tokens: None,
prompt_cache_miss_tokens: None,
prompt_cache_write_tokens: None,
reasoning_tokens: None,
reasoning_replay_tokens: None,
server_tool_use: None,
};
let context = submit_context(&dir).with_tokens(15);
let payload = super::turn_end_payload(TurnEndPayloadInput {
context: &context,
created_at: "2026-07-12T10:30:00Z".parse().expect("timestamp"),
model_backed: true,
provider: Some("openai"),
billing_surface: None,
model: Some("gpt-5.5"),
turn_id: "turn_observed",
status: "completed",
error: None,
duration: Duration::from_millis(7),
usage: &usage,
totals: TurnEndTotals {
session_tokens: 15,
conversation_tokens: 15,
input_tokens: 12,
output_tokens: 3,
},
tool_count: 0,
queued_message_count: 0,
});
let results = executor.execute_json_observer(HookEvent::TurnEnd, &context, &payload);
assert_eq!(results.len(), 1);
assert!(results[0].success);
assert!(
results[0]
.stdout
.contains("stdout is not a mutation contract"),
"stdout is still captured for diagnostics"
);
let captured: serde_json::Value =
serde_json::from_str(&std::fs::read_to_string(out).expect("payload written"))
.expect("valid JSON payload");
assert_eq!(captured["event"], "turn_end");
assert_eq!(captured["created_at"], "2026-07-12T10:30:00+00:00");
assert_eq!(captured["provider"], "openai");
assert_eq!(captured["model"], "gpt-5.5");
assert_eq!(captured["turn_id"], "turn_observed");
assert_eq!(captured["totals"]["input_tokens"], 12);
assert_eq!(captured["totals"]["output_tokens"], 3);
}
#[cfg(not(windows))]
#[test]
fn json_observer_hook_failure_does_not_stop_later_hooks() {
let dir = tempfile::tempdir().expect("tempdir");
let marker = dir.path().join("later-ran");
let failing = write_hook_script(
&dir,
"failing_observer.sh",
r#"#!/bin/sh
echo boom >&2
exit 1
"#,
);
let later = write_hook_script(
&dir,
"later_observer.sh",
&format!(
r#"#!/bin/sh
cat > "{}"
"#,
marker.display()
),
);
let mut first = Hook::new(HookEvent::SubagentComplete, &failing);
first.continue_on_error = false;
let executor = HookExecutor::new(
HooksConfig {
enabled: true,
hooks: vec![first, Hook::new(HookEvent::SubagentComplete, &later)],
..Default::default()
},
dir.path().to_path_buf(),
);
let payload = json!({
"event": "subagent_complete",
"agent_id": "agent_456",
"status": "completed",
});
let results = executor.execute_json_observer(
HookEvent::SubagentComplete,
&submit_context(&dir),
&payload,
);
assert_eq!(results.len(), 2);
assert!(!results[0].success);
assert!(results[1].success);
assert!(
marker.exists(),
"observer failures must be warn-only and non-blocking"
);
}
#[cfg(not(windows))]
#[test]
fn message_submit_transform_applies_hooks_in_order() {
let dir = tempfile::tempdir().expect("tempdir");
let first = write_hook_script(
&dir,
"first.sh",
r#"#!/bin/sh
printf '%s\n' '{"text":"first"}'
"#,
);
let second = write_hook_script(
&dir,
"second.sh",
r#"#!/bin/sh
payload=$(cat)
case "$payload" in
*'"text":"first"'*) printf '%s\n' '{"text":"first second"}' ;;
*) printf '%s\n' '{"text":"wrong"}' ;;
esac
"#,
);
let config = HooksConfig {
enabled: true,
hooks: vec![
Hook::new(HookEvent::MessageSubmit, &first),
Hook::new(HookEvent::MessageSubmit, &second),
],
working_dir: Some(dir.path().to_path_buf()),
..HooksConfig::default()
};
let executor = HookExecutor::new(config, dir.path().to_path_buf());
assert_eq!(
executor.execute_message_submit_transform(&submit_context(&dir), "original"),
MessageSubmitOutcome::replaced("first second".to_string())
);
}
#[cfg(not(windows))]
#[test]
fn message_submit_transform_exit_two_blocks_submission() {
let dir = tempfile::tempdir().expect("tempdir");
let command = write_hook_script(
&dir,
"block.sh",
r#"#!/bin/sh
printf '%s\n' '{"reason":"policy blocked this prompt"}'
exit 2
"#,
);
let config = HooksConfig {
enabled: true,
hooks: vec![Hook::new(HookEvent::MessageSubmit, &command)],
working_dir: Some(dir.path().to_path_buf()),
..HooksConfig::default()
};
let executor = HookExecutor::new(config, dir.path().to_path_buf());
assert_eq!(
executor.execute_message_submit_transform(&submit_context(&dir), "original"),
MessageSubmitOutcome::Blocked {
reason: "policy blocked this prompt".to_string()
}
);
}
#[cfg(not(windows))]
#[test]
fn background_message_submit_hook_is_observer_only() {
let dir = tempfile::tempdir().expect("tempdir");
let command = write_hook_script(
&dir,
"background.sh",
r#"#!/bin/sh
printf '%s\n' '{"text":"ignored"}'
"#,
);
let config = HooksConfig {
enabled: true,
hooks: vec![Hook::new(HookEvent::MessageSubmit, &command).background()],
working_dir: Some(dir.path().to_path_buf()),
..HooksConfig::default()
};
let executor = HookExecutor::new(config, dir.path().to_path_buf());
assert_eq!(
executor.execute_message_submit_transform(&submit_context(&dir), "original"),
MessageSubmitOutcome::unchanged()
);
}
#[test]
fn message_submit_transform_without_configured_hooks_is_unchanged() {
let executor = HookExecutor::new(HooksConfig::default(), PathBuf::from("."));
assert_eq!(
executor.execute_message_submit_transform(&HookContext::new(), "original"),
MessageSubmitOutcome::unchanged()
);
}
#[cfg(not(windows))]
#[test]
fn message_submit_transform_skips_non_matching_condition() {
let dir = tempfile::tempdir().expect("tempdir");
let command = write_hook_script(
&dir,
"replace.sh",
r#"#!/bin/sh
printf '%s\n' '{"text":"should not apply"}'
"#,
);
let hook =
Hook::new(HookEvent::MessageSubmit, &command).with_condition(HookCondition::Mode {
mode: "plan".into(),
});
let config = HooksConfig {
enabled: true,
hooks: vec![hook],
working_dir: Some(dir.path().to_path_buf()),
..HooksConfig::default()
};
let executor = HookExecutor::new(config, dir.path().to_path_buf());
assert_eq!(
executor.execute_message_submit_transform(&submit_context(&dir), "original"),
MessageSubmitOutcome::unchanged()
);
}
#[cfg(not(windows))]
#[test]
fn message_submit_continue_on_error_true_keeps_text_and_runs_later_hooks() {
let dir = tempfile::tempdir().expect("tempdir");
let failing = write_hook_script(
&dir,
"fail_continue.sh",
r#"#!/bin/sh
printf '%s\n' 'soft failure' >&2
exit 9
"#,
);
let replacing = write_hook_script(
&dir,
"replace_after_failure.sh",
r#"#!/bin/sh
printf '%s\n' '{"text":"recovered"}'
"#,
);
let config = HooksConfig {
enabled: true,
hooks: vec![
Hook::new(HookEvent::MessageSubmit, &failing),
Hook::new(HookEvent::MessageSubmit, &replacing),
],
working_dir: Some(dir.path().to_path_buf()),
..HooksConfig::default()
};
let executor = HookExecutor::new(config, dir.path().to_path_buf());
assert_eq!(
executor.execute_message_submit_transform(&submit_context(&dir), "original"),
MessageSubmitOutcome::replaced("recovered".to_string())
.with_warning(Some("soft failure".to_string()))
);
}
#[cfg(not(windows))]
#[test]
fn message_submit_timeout_continue_surfaces_warning_and_runs_later_hooks() {
let dir = tempfile::tempdir().expect("tempdir");
let slow = write_hook_script(
&dir,
"slow_continue.sh",
r#"#!/bin/sh
sleep 2
"#,
);
let replacing = write_hook_script(
&dir,
"replace_after_timeout.sh",
r#"#!/bin/sh
printf '%s\n' '{"text":"after timeout"}'
"#,
);
let mut slow_hook = Hook::new(HookEvent::MessageSubmit, &slow).with_timeout(1);
slow_hook.continue_on_error = true;
let config = HooksConfig {
enabled: true,
hooks: vec![slow_hook, Hook::new(HookEvent::MessageSubmit, &replacing)],
working_dir: Some(dir.path().to_path_buf()),
..HooksConfig::default()
};
let executor = HookExecutor::new(config, dir.path().to_path_buf());
assert_eq!(
executor.execute_message_submit_transform(&submit_context(&dir), "original"),
MessageSubmitOutcome::replaced("after timeout".to_string())
.with_warning(Some("Hook timed out after 1s".to_string()))
);
}
#[cfg(not(windows))]
#[test]
fn message_submit_invalid_stdout_keeps_text_and_runs_later_hooks() {
let dir = tempfile::tempdir().expect("tempdir");
let invalid = write_hook_script(
&dir,
"invalid_stdout.sh",
r#"#!/bin/sh
printf '%s\n' 'not json'
"#,
);
let replacing = write_hook_script(
&dir,
"replace_after_invalid.sh",
r#"#!/bin/sh
printf '%s\n' '{"text":"valid later"}'
"#,
);
let config = HooksConfig {
enabled: true,
hooks: vec![
Hook::new(HookEvent::MessageSubmit, &invalid),
Hook::new(HookEvent::MessageSubmit, &replacing),
],
working_dir: Some(dir.path().to_path_buf()),
..HooksConfig::default()
};
let executor = HookExecutor::new(config, dir.path().to_path_buf());
assert_eq!(
executor.execute_message_submit_transform(&submit_context(&dir), "original"),
MessageSubmitOutcome::replaced("valid later".to_string())
);
}
#[cfg(not(windows))]
#[test]
fn message_submit_continue_on_error_false_blocks_on_failure() {
let dir = tempfile::tempdir().expect("tempdir");
let command = write_hook_script(
&dir,
"fail.sh",
r#"#!/bin/sh
printf '%s\n' 'hard failure' >&2
exit 7
"#,
);
let mut hook = Hook::new(HookEvent::MessageSubmit, &command);
hook.continue_on_error = false;
let config = HooksConfig {
enabled: true,
hooks: vec![hook],
working_dir: Some(dir.path().to_path_buf()),
..HooksConfig::default()
};
let executor = HookExecutor::new(config, dir.path().to_path_buf());
assert_eq!(
executor.execute_message_submit_transform(&submit_context(&dir), "original"),
MessageSubmitOutcome::Blocked {
reason: "hard failure".to_string()
}
);
}
#[test]
fn has_hooks_for_event_fast_path_returns_false_for_empty_config() {
let executor = HookExecutor::disabled();
for event in [
HookEvent::SessionStart,
HookEvent::SessionEnd,
HookEvent::MessageSubmit,
HookEvent::ToolCallBefore,
HookEvent::ToolCallAfter,
HookEvent::ModeChange,
HookEvent::OnError,
HookEvent::TurnEnd,
HookEvent::SubagentSpawn,
HookEvent::SubagentComplete,
] {
assert!(
!executor.has_hooks_for_event(event),
"empty config must short-circuit for {event:?}"
);
}
}
#[test]
fn has_hooks_for_event_returns_false_when_globally_disabled() {
let config = HooksConfig {
enabled: false,
hooks: vec![Hook::new(HookEvent::ToolCallBefore, "echo blocked")],
..HooksConfig::default()
};
let executor = HookExecutor::new(config, PathBuf::from("."));
assert!(
!executor.has_hooks_for_event(HookEvent::ToolCallBefore),
"globally-disabled hooks must report no fires even when one is configured"
);
}
#[test]
fn has_hooks_for_event_distinguishes_event_types() {
let config = HooksConfig {
enabled: true,
hooks: vec![
Hook::new(HookEvent::SessionStart, "echo start"),
Hook::new(HookEvent::ToolCallBefore, "echo before"),
],
..HooksConfig::default()
};
let executor = HookExecutor::new(config, PathBuf::from("."));
assert!(executor.has_hooks_for_event(HookEvent::SessionStart));
assert!(executor.has_hooks_for_event(HookEvent::ToolCallBefore));
assert!(!executor.has_hooks_for_event(HookEvent::ToolCallAfter));
assert!(!executor.has_hooks_for_event(HookEvent::OnError));
assert!(!executor.has_hooks_for_event(HookEvent::ModeChange));
}
#[test]
fn tool_call_before_stdout_parses_deny_with_reason() {
let parsed =
parse_tool_call_before_stdout(r#"{"decision":"deny","reason":"blocked by policy"}"#);
assert_eq!(parsed.decision, Some(ToolCallDecision::Deny));
assert_eq!(parsed.reason.as_deref(), Some("blocked by policy"));
assert!(parsed.updated_input.is_none());
assert!(parsed.additional_context.is_none());
}
#[test]
fn tool_call_before_stdout_parses_ask_and_allow() {
let ask = parse_tool_call_before_stdout(r#"{"decision":"ask"}"#);
assert_eq!(ask.decision, Some(ToolCallDecision::Ask));
let allow = parse_tool_call_before_stdout(r#"{"decision":"allow"}"#);
assert_eq!(allow.decision, Some(ToolCallDecision::Allow));
}
#[test]
fn tool_call_before_stdout_parses_updated_input_object() {
let parsed =
parse_tool_call_before_stdout(r#"{"updatedInput":{"command":"ls -la","timeout":5}}"#);
assert!(parsed.decision.is_none());
assert_eq!(
parsed.updated_input,
Some(serde_json::json!({"command":"ls -la","timeout":5}))
);
}
#[test]
fn tool_call_before_stdout_rejects_non_object_updated_input() {
let parsed = parse_tool_call_before_stdout(r#"{"updatedInput":"rm -rf /"}"#);
assert!(
parsed.updated_input.is_none(),
"updatedInput must be a JSON object"
);
let parsed = parse_tool_call_before_stdout(r#"{"updatedInput":[1,2]}"#);
assert!(parsed.updated_input.is_none());
}
#[test]
fn tool_call_before_stdout_parses_additional_context() {
let parsed =
parse_tool_call_before_stdout(r#"{"additionalContext":"remember the style guide"}"#);
assert_eq!(
parsed.additional_context.as_deref(),
Some("remember the style guide")
);
}
#[test]
fn tool_call_before_stdout_empty_and_non_json_are_passthrough() {
for stdout in ["", " \n ", "ok, proceeding", "exit code zero"] {
let parsed = parse_tool_call_before_stdout(stdout);
assert!(parsed.decision.is_none(), "stdout {stdout:?}");
assert!(parsed.reason.is_none());
assert!(parsed.updated_input.is_none());
assert!(parsed.additional_context.is_none());
}
}
#[test]
fn tool_call_before_stdout_json_without_decision_is_passthrough() {
let parsed = parse_tool_call_before_stdout(r#"{"status":"fine"}"#);
assert!(parsed.decision.is_none());
}
#[test]
fn tool_call_before_stdout_non_object_json_is_passthrough() {
for stdout in [r#""deny""#, "[1,2,3]", "42", "true"] {
let parsed = parse_tool_call_before_stdout(stdout);
assert!(parsed.decision.is_none(), "stdout {stdout:?}");
}
}
#[test]
fn tool_call_before_stdout_unknown_decision_treated_as_allow() {
let parsed = parse_tool_call_before_stdout(r#"{"decision":"block"}"#);
assert!(parsed.decision.is_none());
}
#[test]
fn tool_name_glob_matches_mcp_prefix() {
assert!(HookExecutor::tool_name_matches_condition(
"mcp__github__create_issue",
"mcp__*"
));
assert!(!HookExecutor::tool_name_matches_condition(
"read_file",
"mcp__*"
));
}
#[test]
fn tool_name_exact_match_still_works() {
assert!(HookExecutor::tool_name_matches_condition(
"read_file",
"read_file"
));
assert!(!HookExecutor::tool_name_matches_condition(
"read_files",
"read_file"
));
}
#[test]
fn tool_name_glob_escapes_regex_metacharacters() {
assert!(!HookExecutor::tool_name_matches_condition(
"mcpXgithub",
"mcp.git*"
));
assert!(HookExecutor::tool_name_matches_condition(
"mcp.github",
"mcp.git*"
));
assert!(HookExecutor::tool_name_matches_condition(
"weird+tool(name)",
"weird+tool(*)"
));
}
#[test]
fn tool_name_glob_supports_infix_and_suffix_positions() {
assert!(HookExecutor::tool_name_matches_condition(
"mcp__github__create_issue",
"mcp__*__create_issue"
));
assert!(HookExecutor::tool_name_matches_condition(
"task_shell_start",
"*_shell_start"
));
assert!(!HookExecutor::tool_name_matches_condition(
"task_shell_wait",
"*_shell_start"
));
}
#[test]
fn load_with_project_missing_file_keeps_global() {
let dir = tempfile::tempdir().expect("tempdir");
let global = HooksConfig {
enabled: true,
hooks: vec![Hook::new(HookEvent::ToolCallBefore, "echo global")],
..HooksConfig::default()
};
let merged = HooksConfig::load_with_project(global.clone(), dir.path());
assert_eq!(merged.hooks.len(), 1);
assert_eq!(merged.hooks[0].command, "echo global");
}
#[test]
fn load_with_project_appends_project_hooks_after_global() {
let _lock = lock_test_env();
let dir = tempfile::tempdir().expect("tempdir");
let config_path = dir.path().join("user-config.toml");
let _config = trust_workspace_for_project_hooks(dir.path(), &config_path);
let _legacy_config = EnvVarGuard::remove("DEEPSEEK_CONFIG_PATH");
let project_dir = dir.path().join(".codewhale");
std::fs::create_dir_all(&project_dir).expect("mkdir .codewhale");
std::fs::write(
project_dir.join("hooks.toml"),
r#"
[[hooks]]
event = "tool_call_before"
command = "echo project"
"#,
)
.expect("write hooks.toml");
let global = HooksConfig {
enabled: true,
hooks: vec![Hook::new(HookEvent::ToolCallBefore, "echo global")],
..HooksConfig::default()
};
let merged = HooksConfig::load_with_project(global, dir.path());
assert_eq!(merged.hooks.len(), 2);
assert_eq!(
merged.hooks[0].command, "echo global",
"global hooks run first"
);
assert_eq!(
merged.hooks[1].command, "echo project",
"project hooks are appended after global"
);
}
#[test]
fn load_with_project_ignores_project_hooks_until_workspace_trusted() {
let _lock = lock_test_env();
let dir = tempfile::tempdir().expect("tempdir");
let _config = EnvVarGuard::set("CODEWHALE_CONFIG_PATH", dir.path().join("config.toml"));
let _legacy_config = EnvVarGuard::remove("DEEPSEEK_CONFIG_PATH");
let project_dir = dir.path().join(".codewhale");
std::fs::create_dir_all(&project_dir).expect("mkdir .codewhale");
std::fs::write(
project_dir.join("hooks.toml"),
r#"
[[hooks]]
event = "tool_call_before"
command = "echo project"
"#,
)
.expect("write hooks.toml");
let global = HooksConfig {
enabled: true,
hooks: vec![Hook::new(HookEvent::ToolCallBefore, "echo global")],
..HooksConfig::default()
};
let merged = HooksConfig::load_with_project(global, dir.path());
assert_eq!(merged.hooks.len(), 1);
assert_eq!(merged.hooks[0].command, "echo global");
}
#[test]
fn load_with_project_ignores_project_local_legacy_trust_marker() {
let _lock = lock_test_env();
let dir = tempfile::tempdir().expect("tempdir");
let _config = EnvVarGuard::set("CODEWHALE_CONFIG_PATH", dir.path().join("config.toml"));
let _legacy_config = EnvVarGuard::remove("DEEPSEEK_CONFIG_PATH");
let project_dir = dir.path().join(".codewhale");
let legacy_trust_dir = dir.path().join(".deepseek");
std::fs::create_dir_all(&project_dir).expect("mkdir .codewhale");
std::fs::create_dir_all(&legacy_trust_dir).expect("mkdir .deepseek");
std::fs::write(legacy_trust_dir.join("trusted"), "").expect("write legacy trust marker");
std::fs::write(
project_dir.join("hooks.toml"),
r#"
[[hooks]]
event = "tool_call_before"
command = "echo project"
"#,
)
.expect("write hooks.toml");
let global = HooksConfig {
enabled: true,
hooks: vec![Hook::new(HookEvent::ToolCallBefore, "echo global")],
..HooksConfig::default()
};
let merged = HooksConfig::load_with_project(global, dir.path());
assert_eq!(merged.hooks.len(), 1);
assert_eq!(merged.hooks[0].command, "echo global");
}
#[test]
fn load_with_project_malformed_file_falls_back_to_global() {
let _lock = lock_test_env();
let dir = tempfile::tempdir().expect("tempdir");
let config_path = dir.path().join("user-config.toml");
let _config = trust_workspace_for_project_hooks(dir.path(), &config_path);
let _legacy_config = EnvVarGuard::remove("DEEPSEEK_CONFIG_PATH");
let project_dir = dir.path().join(".codewhale");
std::fs::create_dir_all(&project_dir).expect("mkdir .codewhale");
std::fs::write(project_dir.join("hooks.toml"), "this is [ not toml")
.expect("write hooks.toml");
let global = HooksConfig {
enabled: true,
hooks: vec![Hook::new(HookEvent::ToolCallBefore, "echo global")],
..HooksConfig::default()
};
let merged = HooksConfig::load_with_project(global, dir.path());
assert_eq!(merged.hooks.len(), 1, "malformed project file is ignored");
assert_eq!(merged.hooks[0].command, "echo global");
}
}