Files
hermes-agent/tools/working_diff.py
Teknium d4cec15b47 refactor(tools): first-wave simplification of tools/ (file ops split, lazy_deps, code_exec, approval, browser, delegate, mcp, skills, terminal, voice, media)
Behavior-neutral structural pass over tools/*: god-file extractions into
sibling modules (file_operations_common/lint/search, file_tools_paths/
read_tracking/write, code_execution_env/rpc, tool_search_catalog/names/
validation, tts_command_provider, ...), duplicate helper unification,
if/elif -> dispatch tables, dead-code removal, docstring compaction.
Tool schemas (get_tool_definitions) verified byte-identical to base.
2026-09-02 14:43:45 -07:00

124 lines
4.7 KiB
Python

"""Working-tree git diff collection shared by the CLI and gateway ``/diff``.
Surface-agnostic so the CLI (colored terminal) and gateway (fenced, truncated
messages) render the same data.
Modes: ``working`` (unstaged + untracked — what ``git checkout . && git clean
-fd`` would lose), ``staged`` (``git diff --cached``), ``all`` (everything since
HEAD plus untracked). Untracked files are folded in via ``git diff --no-index
/dev/null <file>`` so brand-new files show as additions instead of being
invisible (mirrors Codex CLI's ``/diff``).
"""
from __future__ import annotations
import os
import shutil
import subprocess
from typing import Dict, List
from hermes_cli._subprocess_compat import harden_git_argv, noninteractive_git_env
_GIT_TIMEOUT = 15
_MAX_UNTRACKED_FILES = 50 # sanity cap so a node_modules explosion can't hang us
_MODE_ARGS = {
"working": ["diff"],
"staged": ["diff", "--cached"],
"all": ["diff", "HEAD"],
}
VALID_MODES = tuple(_MODE_ARGS)
def _run(args: List[str], cwd: str, timeout: int = _GIT_TIMEOUT):
"""Run git, returning (returncode, stdout). Never raises on git failure.
Hardened against a malicious repo's ``.git/config`` (GHSA-7x36-8jrh-v4pw):
``noninteractive_git_env`` disables fsmonitor/hooks/pager/editor/credential
sinks, and ``harden_git_argv`` appends ``--no-ext-diff --no-textconv`` to
the diff-rendering subcommands so attribute-scoped diff/textconv drivers
can't execute either.
"""
proc = subprocess.run(
["git", "-c", "core.quotePath=false", *harden_git_argv(args)],
cwd=cwd, capture_output=True, text=True, timeout=timeout,
encoding="utf-8", errors="replace",
stdin=subprocess.DEVNULL, env=noninteractive_git_env(),
)
return proc.returncode, proc.stdout
def _untracked_files(cwd: str) -> List[str]:
code, out = _run(["ls-files", "--others", "--exclude-standard"], cwd)
if code != 0:
return []
return [line for line in out.splitlines() if line.strip()]
def _untracked_diff(cwd: str, files: List[str]) -> str:
"""Render untracked files as new-file diffs via ``git diff --no-index``."""
chunks: List[str] = []
for rel in files[:_MAX_UNTRACKED_FILES]:
try:
# --no-index exits 1 when files differ — that's the success path,
# so the return code is ignored.
_, out = _run(["diff", "--no-index", "--", os.devnull, rel], cwd)
if out.strip():
chunks.append(out.rstrip("\n"))
except (subprocess.TimeoutExpired, OSError):
continue
if len(files) > _MAX_UNTRACKED_FILES:
chunks.append(
f"... ({len(files) - _MAX_UNTRACKED_FILES} more untracked files not shown)"
)
return "\n".join(chunks)
def collect_working_diff(cwd: str, mode: str = "working",
paths: List[str] | None = None) -> Dict:
"""Collect a git diff of the working directory.
Returns ``{"success", "stat", "diff", "untracked", "empty"}`` on success or
``{"success": False, "error": ...}`` when git is unavailable / not a repo.
``paths`` optionally restricts the diff to pathspecs (passed to git
verbatim); when given, untracked files are not collected.
"""
if mode not in _MODE_ARGS:
return {"success": False,
"error": f"Unknown mode '{mode}'. Use: {', '.join(VALID_MODES)}"}
if not shutil.which("git"):
return {"success": False, "error": "git is not installed or not on PATH."}
try:
code, _ = _run(["rev-parse", "--is-inside-work-tree"], cwd, timeout=5)
except (subprocess.TimeoutExpired, OSError) as e:
return {"success": False, "error": f"git failed: {e}"}
if code != 0:
return {"success": False, "error": "Not a git repository."}
base_args = _MODE_ARGS[mode]
pathspec = ["--", *paths] if paths else []
try:
_, stat_out = _run([*base_args, "--stat", *pathspec], cwd)
_, diff_out = _run([*base_args, *pathspec], cwd, timeout=_GIT_TIMEOUT * 2)
untracked: List[str] = []
untracked_diff = ""
if mode in ("working", "all") and not paths:
untracked = _untracked_files(cwd)
if untracked:
untracked_diff = _untracked_diff(cwd, untracked)
except subprocess.TimeoutExpired:
return {"success": False, "error": "git diff timed out."}
except OSError as e:
return {"success": False, "error": f"git failed: {e}"}
stat = stat_out.strip()
diff = diff_out.strip()
if untracked_diff:
diff = f"{diff}\n{untracked_diff}".strip()
result = {"success": True, "stat": stat, "diff": diff, "untracked": untracked}
if not stat and not diff and not untracked:
result["empty"] = True
return result