fix(plugins): treat every guard code extension as revision-owned on no-git carry

The no-git deny-list only matched `.py`, so a subdir install whose new
revision removed `server.js` / `run.sh` (or any other code file) had the
old copy resurrected into the updated tree. The post-carry re-scan is
pattern-based and cannot reliably block that. Reuse
tools.plugin_guard.CODE_FILE_EXTENSIONS as the single source of truth
for "plugin code" so removed code never survives an update.

Co-authored-by: JoaoMarcos44 <joaomarcosdias444@gmail.com>
This commit is contained in:
kshitijk4poor
2026-09-26 18:34:54 +05:30
committed by kshitij
parent ad7a4e8e53
commit b2d6fed3f1

View File

@@ -294,8 +294,9 @@ _NO_GIT_REVISION_DIRS = frozenset({"desktop", "skills", "sidecar", "node_modules
def _revision_owned_without_git(rel: Path) -> bool:
"""True for plugin code/control surfaces an update must never resurrect from the old tree."""
from tools.plugin_guard import CODE_FILE_EXTENSIONS
return (
rel.suffix == ".py"
rel.suffix.lower() in CODE_FILE_EXTENSIONS
or rel.as_posix() in _NO_GIT_REVISION_FILES
or bool(rel.parts and rel.parts[0] in _NO_GIT_REVISION_DIRS)
)