From b2d6fed3f186cbf192d5b222508cad92094a6203 Mon Sep 17 00:00:00 2001 From: kshitijk4poor <82637225+kshitijk4poor@users.noreply.github.com> Date: Sat, 26 Sep 2026 18:34:54 +0530 Subject: [PATCH] fix(plugins): treat every guard code extension as revision-owned on no-git carry The no-git deny-list only matched `.py`, so a subdir install whose new revision removed `server.js` / `run.sh` (or any other code file) had the old copy resurrected into the updated tree. The post-carry re-scan is pattern-based and cannot reliably block that. Reuse tools.plugin_guard.CODE_FILE_EXTENSIONS as the single source of truth for "plugin code" so removed code never survives an update. Co-authored-by: JoaoMarcos44 --- hermes_cli/plugins_cmd_catalog.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/hermes_cli/plugins_cmd_catalog.py b/hermes_cli/plugins_cmd_catalog.py index 38e691d394..677dc15cd9 100644 --- a/hermes_cli/plugins_cmd_catalog.py +++ b/hermes_cli/plugins_cmd_catalog.py @@ -294,8 +294,9 @@ _NO_GIT_REVISION_DIRS = frozenset({"desktop", "skills", "sidecar", "node_modules def _revision_owned_without_git(rel: Path) -> bool: """True for plugin code/control surfaces an update must never resurrect from the old tree.""" + from tools.plugin_guard import CODE_FILE_EXTENSIONS return ( - rel.suffix == ".py" + rel.suffix.lower() in CODE_FILE_EXTENSIONS or rel.as_posix() in _NO_GIT_REVISION_FILES or bool(rel.parts and rel.parts[0] in _NO_GIT_REVISION_DIRS) )