You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Track rtk-ai/rtk#3693: 'rtk init -g' can silently unregister rtk #129
Tracking issue for an open upstream bug that affects every image in this repo. Split out of #125, which cited it as the reason to keep the timeout guard but correctly treated it as out of scope.
Upstream: rtk-ai/rtk#3693 — "rtk init -g deletes the legacy hook script and either unregisters rtk entirely or leaves a dangling reference — both reported as 'RTK hook registered (global)'". Open, priority:high, area:security.
Why it applies here
All three of our call sites run exactly the affected invocation:
.devcontainer/init-plugins.sh
claude-code/.devcontainer/init-plugins.sh
ralphex-fe/init-docker.sh
rtk init -g --hook-only --auto-patch
Per the upstream report this can delete ~/.claude/hooks/rtk-rewrite.sh and leave rtk either fully unregistered or pointing at a path that no longer exists — while exiting 0 and printing a success banner. Our call sites all end in || true or 2>/dev/null || true, so even a non-zero exit would be swallowed; a zero exit with a success banner is completely invisible.
Preconditions that make this reachable for us
~/.claude is a named volume that survives rebuilds, so a hook script written by an older rtk can persist into a container running a newer rtk — the exact state the upstream bug describes.
ralphex-fe can run this against a host-mounted~/.claude, so a bad run could damage the developer's real hook configuration rather than a throwaway container's.
What to do
Nothing to fix locally — this is upstream's bug. This issue exists so that:
If it bites someone, there's a place to record the symptom rather than rediscovering it.
Symptom to watch for: rtk installed in the image, rtk --version fine, but git status etc. not being rewritten — check whether ~/.claude/settings.json still has a PreToolUse entry whose command is rtk hook claude.
Currently pinned to RTK_VERSION=0.48.0 in claude-code/.devcontainer/Dockerfile and ralphex-fe/Dockerfile. Note the root .devcontainer/Dockerfile still resolves rtk from releases/latest at build time, so it can pick up a regression unpinned.
Tracking issue for an open upstream bug that affects every image in this repo. Split out of #125, which cited it as the reason to keep the
timeoutguard but correctly treated it as out of scope.Upstream: rtk-ai/rtk#3693 — "rtk init -g deletes the legacy hook script and either unregisters rtk entirely or leaves a dangling reference — both reported as 'RTK hook registered (global)'". Open,
priority:high,area:security.Why it applies here
All three of our call sites run exactly the affected invocation:
.devcontainer/init-plugins.shclaude-code/.devcontainer/init-plugins.shralphex-fe/init-docker.shPer the upstream report this can delete
~/.claude/hooks/rtk-rewrite.shand leave rtk either fully unregistered or pointing at a path that no longer exists — while exiting 0 and printing a success banner. Our call sites all end in|| trueor2>/dev/null || true, so even a non-zero exit would be swallowed; a zero exit with a success banner is completely invisible.Preconditions that make this reachable for us
~/.claudeis a named volume that survives rebuilds, so a hook script written by an older rtk can persist into a container running a newer rtk — the exact state the upstream bug describes.ralphex-fecan run this against a host-mounted~/.claude, so a bad run could damage the developer's real hook configuration rather than a throwaway container's.What to do
Nothing to fix locally — this is upstream's bug. This issue exists so that:
timeoutguard (rtk: drop telemetry-consent-hang workaround once stable v0.44.0 hits releases/latest #117 wanted it dropped; docs(rtk): record RTK_TELEMETRY_DISABLED as the supported opt-out (#117) #125 kept it partly because of this).Symptom to watch for: rtk installed in the image,
rtk --versionfine, butgit statusetc. not being rewritten — check whether~/.claude/settings.jsonstill has aPreToolUseentry whose command isrtk hook claude.Currently pinned to
RTK_VERSION=0.48.0inclaude-code/.devcontainer/Dockerfileandralphex-fe/Dockerfile. Note the root.devcontainer/Dockerfilestill resolves rtk fromreleases/latestat build time, so it can pick up a regression unpinned.