Draft: Issue #3616497: Keep hook collection inside the module it is scanning

HookCollectorPass scans each module's directory with FOLLOW_SYMLINKS, and FilesystemIterator::SKIP_DOTS only skips '.' and '..', not hidden directories. So the scan walks '.git', '.devenv', '.direnv' and the like, and follows a symlink anywhere below the module however far out of it that leads.

A module symlinked in from a working checkout therefore drags that checkout's tooling state into every container rebuild, and a module shipping a pnpm-installed node_modules walks a symlink farm around a hidden .pnpm store. file_scan_ignore_directories, honoured since #3564112, does not cover either: its default names two directories, and no list stops a symlink that leaves the module.

Add two guards to filterIterator(): skip hidden directories, as ExtensionDiscovery already does, and follow symlinks only at the top level of a module directory. The latter keeps a symlinked module working, which is what #3482283 added the flag for and what testSymlink() covers, while bounding the scan to the module itself.

Closes #3616497

AI-Generated: yes (Used Opus 5 to draft and revise)

Merge request reports

Loading
Loading