Repository navigation
Conversation
ReviewGood direction overall: temp-dir + trap cleanup, Bugs / risks
Tests
SecurityNothing new introduced; Minor
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d42ea0d8dd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
ReviewThe core change is sound. Hooks are downloaded to a temp file and only swapped in after the download succeeds. Issues
Minor / pre-existing
Tests
Style
|
ReviewOverall this is a solid robustness improvement: temp-dir downloads, atomic replace via Potential issues
Security
Performance
Tests and CI
Minor
Nice work. Item 1 is the one I'd fix before merging. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 92081bd422
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
ReviewSolid hardening pass. Downloads go to a temp file and replace the old one only on success, curl has -f and timeouts, config edits are atomic and symlink-aware, and the legacy source line is migrated and deduplicated. I read install.bash only and did not run the tests. Potential bugs / robustness
Security
Style
Tests None of these are blockers except possibly item 1. |
ReviewSolid hardening pass. Temp-file downloads, atomic replacement, quoted source lines and upgrade de-duplication fix real bugs, and the stubbed Potential bugs / behavior
Compatibility / design
Tests / CI
Items 1 and 2 are the ones I'd fix before merging; the rest are suggestions. 🤖 Generated with Claude Code |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3d36b451cf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| sub(/^[[:space:]]+/, "", line) | ||
| sub(/[[:space:]]+$/, "", line) | ||
| if (line == legacy || line == quoted) { | ||
| if (!found) print quoted | ||
| found = 1 |
There was a problem hiding this comment.
Restrict deduplication to installer-owned source lines
When a user intentionally sources the hook in multiple mutually exclusive blocks, trimming indentation makes every occurrence look like a previously generated top-level line, and the global found flag deletes all but the first. For example, two indented source commands in an if/else are reduced to one, leaving the else branch empty and making .bashrc syntactically invalid on the next shell launch. Only deduplicate the exact top-level spellings emitted by prior installer versions, rather than normalized lines inside user-controlled blocks.
Useful? React with 👍 / 👎.
Failed hook downloads could replace working installations, paths with spaces broke shell startup, and upgrades could append a second source line that tracked every command twice.
Validation: Bash and Zsh syntax checks and all 16 isolated Python tests passed. Tests cover failed archives/hooks, backup preservation, permissions, upgrade duplication, spaces, partial installs, successful reruns, platform mapping, piped execution, symlinked configs, missing trailing newlines, interruption cleanup, and preserved caller traps. Hook source pinning/checksums remain a separate follow-up.
Interruption follow-up: keep active hooks in place while copying backups into temporary files, then atomically replace both backups and hooks. Resolve shell-config symlinks and replace their targets atomically while preserving permissions. Clean temporary files on exit or interruption, and document Python 3 for tests.
CI follow-up: initialize Bash, Zsh, and Fish profile fixtures before installation. The six Linux/macOS shell matrix jobs passed after this fixture correction; the final backup-copy regression also passes locally.