Skip to content

fix(hooks): validate event_name against the canonical event set - #806

Closed
gmoncor wants to merge 1 commit into
bmad-code-org:mainfrom
gmoncor:fix/s01-07-validate-canonical-event-name
Closed

gmoncor wants to merge 1 commit into
bmad-code-org:mainfrom
gmoncor:fix/s01-07-validate-canonical-event-name

Conversation

@gmoncor

@gmoncor gmoncor commented Sep 17, 2026

Copy link
Copy Markdown

What

Duplicate the CANONICAL_EVENTS set from adapters/profile.py into the stdlib-only hook script and its events.py twin, and emit a non-blocking warning when event_name falls outside that set.

Why

Profile-parse time already enforces this whitelist before a hook is ever registered; this closes the defense-in-depth gap with a drift-detection warning, matching the existing never-fail treatment used for hooks.relay-stale.

How

  • Duplicate CANONICAL_EVENTS inline in bmad_loop_hook.py and events.py (twin pattern, both stdlib-only, cannot import each other).
  • When event_name is outside the set, still write the event exactly as today, but also emit a non-blocking warning (stderr, never stdout).
  • Add a parity/ablation test in tests/test_hook_script.py and tests/test_events.py.

Testing

Ran tests/test_hook_script.py and tests/test_events.py (45 passed, 9 skipped platform-specific); confirmed the twin-source parity check still passes with the duplicated set in both files.

Changelog

Added: the hook script now warns (non-blocking) if it receives an event name outside the canonical set, without ever dropping the signal.

🤖 Generated with Claude Code

@coderabbitai

coderabbitai Bot commented Sep 17, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gmoncor
gmoncor force-pushed the fix/s01-07-validate-canonical-event-name branch from 7df9a67 to 2e33ede Compare September 23, 2026 10:05
@gmoncor

gmoncor commented Sep 23, 2026

Copy link
Copy Markdown
Author

Closing: adapters/profile.py already rejects non-canonical event names before a hook is ever registered, so the warning this adds fires only for a hand-edited hook config or a profile that already skipped that validation — speculative hardening rather than an observed problem. It also claims the twin-source parity test (test_the_twinned_source_is_identical) covers the new duplicated CANONICAL_EVENTS constant; I verified it does not (the name isn't in the TWINNED tuple), so that guarantee wasn't real. Not worth a maintainer's time as-is.

@gmoncor gmoncor closed this Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant