Skip to content

Track rtk-ai/rtk#3693: 'rtk init -g' can silently unregister rtk #129

Description

@gatezh

Tracking issue for an open upstream bug that affects every image in this repo. Split out of #125, which cited it as the reason to keep the timeout guard but correctly treated it as out of scope.

Upstream: rtk-ai/rtk#3693 — "rtk init -g deletes the legacy hook script and either unregisters rtk entirely or leaves a dangling reference — both reported as 'RTK hook registered (global)'". Open, priority:high, area:security.

Why it applies here

All three of our call sites run exactly the affected invocation:

  • .devcontainer/init-plugins.sh
  • claude-code/.devcontainer/init-plugins.sh
  • ralphex-fe/init-docker.sh
rtk init -g --hook-only --auto-patch

Per the upstream report this can delete ~/.claude/hooks/rtk-rewrite.sh and leave rtk either fully unregistered or pointing at a path that no longer exists — while exiting 0 and printing a success banner. Our call sites all end in || true or 2>/dev/null || true, so even a non-zero exit would be swallowed; a zero exit with a success banner is completely invisible.

Preconditions that make this reachable for us

  • ~/.claude is a named volume that survives rebuilds, so a hook script written by an older rtk can persist into a container running a newer rtk — the exact state the upstream bug describes.
  • ralphex-fe can run this against a host-mounted ~/.claude, so a bad run could damage the developer's real hook configuration rather than a throwaway container's.

What to do

Nothing to fix locally — this is upstream's bug. This issue exists so that:

  1. We notice when it's fixed and can re-evaluate the timeout guard (rtk: drop telemetry-consent-hang workaround once stable v0.44.0 hits releases/latest #117 wanted it dropped; docs(rtk): record RTK_TELEMETRY_DISABLED as the supported opt-out (#117) #125 kept it partly because of this).
  2. If it bites someone, there's a place to record the symptom rather than rediscovering it.

Symptom to watch for: rtk installed in the image, rtk --version fine, but git status etc. not being rewritten — check whether ~/.claude/settings.json still has a PreToolUse entry whose command is rtk hook claude.

Currently pinned to RTK_VERSION=0.48.0 in claude-code/.devcontainer/Dockerfile and ralphex-fe/Dockerfile. Note the root .devcontainer/Dockerfile still resolves rtk from releases/latest at build time, so it can pick up a regression unpinned.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions