validate: fix path filter — explicit prune instead of "*/.*" trap

The `-not -path "*/.*"` filter on the `find` probes in lint.sh and sast.sh
was intended to exclude .venv / .git / __pycache__ but also excludes any
target path that lives UNDER a hidden ancestor directory.

Concrete trigger: running the gauntlet on a Claude Code worktree at
.../.claude/worktrees/<name>/. Every file in the tree matches `*/.*` via
the .claude/ component, so the probes return empty, the scripts skip
with "No Python or Go files found", and run-all.sh records the check as
passed by virtue of the 0 exit. The check never actually ran.

Switch to explicit prunes for the well-known noise dirs. As a free
bonus, replace `| head -1` with `-print -quit` so the probe also stops
being susceptible to SIGPIPE under `set -o pipefail` (relevant on dense
trees with many matches).

Verified: probe now returns first .py file in both .claude/-rooted and
normal project paths.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Travis Herbranson 2026-05-12 07:50:32 -04:00
parent 47f48873e0
commit 172f426ccd
2 changed files with 22 additions and 4 deletions

View File

@ -11,8 +11,17 @@ errors=0
echo "=== Lint Scan ==="
has_python=$(find "$TARGET" -name "*.py" -not -path "*/.*" | head -1)
has_go=$(find "$TARGET" -name "*.go" -not -path "*/.*" | head -1)
# Probe for source files. Explicit prunes (rather than -not -path "*/.*")
# so that target paths under hidden ancestor dirs (e.g. a Claude Code
# worktree at .../.claude/worktrees/<name>/) still match real source.
# -print -quit instead of `| head -1` avoids SIGPIPE under `set -o pipefail`.
has_python=$(find "$TARGET" \
\( -path '*/__pycache__' -o -path '*/.venv' -o -path '*/venv' \
-o -path '*/.git' -o -path '*/node_modules' \) -prune \
-o -name '*.py' -print -quit)
has_go=$(find "$TARGET" \
\( -path '*/.git' -o -path '*/vendor' -o -path '*/node_modules' \) -prune \
-o -name '*.go' -print -quit)
if [ -z "$has_python" ] && [ -z "$has_go" ]; then
printf "${YELLOW}!${NC} No Python or Go files found — skipping\n"

View File

@ -16,8 +16,17 @@ if ! command -v semgrep &>/dev/null; then
exit 2
fi
has_python=$(find "$TARGET" -name "*.py" -not -path "*/.*" | head -1)
has_go=$(find "$TARGET" -name "*.go" -not -path "*/.*" | head -1)
# Probe for source files. Explicit prunes (rather than -not -path "*/.*")
# so that target paths under hidden ancestor dirs (e.g. a Claude Code
# worktree at .../.claude/worktrees/<name>/) still match real source.
# -print -quit instead of `| head -1` avoids SIGPIPE under `set -o pipefail`.
has_python=$(find "$TARGET" \
\( -path '*/__pycache__' -o -path '*/.venv' -o -path '*/venv' \
-o -path '*/.git' -o -path '*/node_modules' \) -prune \
-o -name '*.py' -print -quit)
has_go=$(find "$TARGET" \
\( -path '*/.git' -o -path '*/vendor' -o -path '*/node_modules' \) -prune \
-o -name '*.go' -print -quit)
if [ -z "$has_python" ] && [ -z "$has_go" ]; then
printf "${YELLOW}!${NC} No Python or Go files found — skipping\n"