Replaces the Python-based pre-push hook and long-polling HTTP logic with a native shell script using udp-send --wait to block on an ephemeral UDP port in the kernel. mcp-memory-server acts as the broker and replies to subscribers.
46 lines
1.7 KiB
Bash
46 lines
1.7 KiB
Bash
#!/bin/bash
|
|
# Native shell pre-push hook using UDP Rendezvous
|
|
|
|
PORT=${MCP_UDP_PORT1:-3001}
|
|
|
|
while read local_ref local_sha remote_ref remote_sha; do
|
|
if [ "$local_sha" = "0000000000000000000000000000000000000000" ] || [ "$local_ref" = "(delete)" ]; then
|
|
continue
|
|
fi
|
|
if [[ "$local_ref" == refs/tags/* ]]; then
|
|
continue
|
|
fi
|
|
|
|
BRANCH=${local_ref#refs/heads/}
|
|
|
|
echo -e "\033[36m[Pre-Push Gatekeeper]\033[0m Checking gate for branch '$BRANCH'..."
|
|
|
|
# Check if gate is already authorized or blocked
|
|
if mcp-memory-server gate verify --action push --target "$BRANCH" --consume 2>/dev/null; then
|
|
echo -e "\033[32m[Pre-Push Gatekeeper]\033[0m Push AUTHORIZED by MCP Memory gate for branch '$BRANCH'."
|
|
continue
|
|
else
|
|
EXIT_CODE=$?
|
|
if [ $EXIT_CODE -eq 1 ]; then
|
|
echo -e "\033[31m[Pre-Push Gatekeeper]\033[0m Push BLOCKED by MCP Memory gate for branch '$BRANCH'."
|
|
exit 1
|
|
fi
|
|
|
|
# If exit code is 2 (Not Found), we wait via UDP Rendezvous
|
|
echo -e "\033[33m[Pre-Push Gatekeeper]\033[0m No pre-authorized gate for '$BRANCH'. Waiting for approval via UDP rendezvous..."
|
|
|
|
# Payload for UDP
|
|
PAYLOAD="{\"type\":\"gate_wait\",\"action\":\"push\",\"target\":\"$BRANCH\"}"
|
|
|
|
if udp-send --wait "$PORT" "$PAYLOAD"; then
|
|
echo -e "\033[32m[Pre-Push Gatekeeper]\033[0m Push AUTHORIZED via UDP rendezvous for branch '$BRANCH'."
|
|
continue
|
|
else
|
|
echo -e "\033[31m[Pre-Push Gatekeeper]\033[0m Push DENIED or timed out via UDP rendezvous for branch '$BRANCH'."
|
|
exit 1
|
|
fi
|
|
fi
|
|
done
|
|
|
|
exit 0
|