The full-suite hook refuses WRITING about the suite, not just running it
What happened
Three refusals in one session, none of which ran anything:
- A
cat > ticket.md <<'EOF'heredoc whose ticket body contained the wordsgate.sh fullwhile explaining that the wide gate was red. - A
cat >> LOGBOOK.mdheredoc whose log line listed the tests added as atest/glob. git commit -F -with a heredoc message containingmake test, in a sentence explaining why the quick tier was sufficient — the exact justification the hook's own refusal text asks authors to write.
Each was worked around with a different tool (Write for the files, a message
file for the commit), so nothing was lost but time. The third is the sharpest:
the hook demands you "say in the commit why the quick tier was not enough", and
then refuses the commit for saying it.
Why this is not a request to weaken the guard
The guard is doing real work and the refusal text is correct about the policy.
PXX_ALLOW_FULL_SUITE=1 exists and is lift-it-yourself, and I used it
autonomously and legitimately in the same session for a two-backend
calling-convention change. Do not fix this by loosening what counts as a
suite invocation, and do not fix it by teaching agents to rephrase prose so it
slips past — a guard you route around is a guard the owner no longer has.
The aperture
The hook reads the command STRING. A command that WRITES a file whose CONTENT
mentions a suite is not a suite invocation, and the two are distinguishable:
the suite name appears inside heredoc body lines, or after -m/-F, rather
than in command position.
Cheapest honest fix is probably to ignore heredoc bodies (between <<'EOF' and
the terminator) and git commit message arguments when scanning, leaving
command-position matching exactly as it is. That keeps every real invocation
refused and stops the false positives.
Check the positive control after any change: a real make test inside a
heredoc-writing command must STILL be refused if it is in command position, and
PXX_ALLOW_FULL_SUITE=1 make test must still be allowed. A fix that makes the
hook stop refusing anything is the failure mode here.
A fourth instance, while filing this
The commit that first tried to land THIS TICKET was refused, for a message describing the refusals. That is the cleanest possible statement of the aperture problem: the hook cannot distinguish a suite invocation from a document about suite invocations, including the document filed to report that it cannot. Landed via a message file instead.
Cost
Low but recurring, and it lands on exactly the agents doing the right thing — writing down why they did or did not widen their gate. It also mildly discourages naming the suite in a commit message, which is the one place that information is useful later.
A fifth instance, 2026-09-05 — and it is the same shape as the fourth
A cat >> LOGBOOK.md heredoc was refused because the log line described a
census that had compiled "621 further test/*.c" — the glob appeared in PROSE
describing what had already been run, hours earlier, with
PXX_ALLOW_FULL_SUITE=1 set and declared.
So the tally is now: a ticket body, a logbook line, a commit message, the commit filing this ticket, and a logbook line recording a sweep that was properly declared. Every one of the five is an author writing down what they did. None ran anything.
Worth noting for whoever fixes it: the refusal text tells the author to say in
the commit why the quick tier was not enough, and this is the second time that
exact sentence has been refused for containing the words it asks for. The
workaround stays the same — the Write tool for file content, a message file
for git commit -F — and it stays deliberate. Do not reword the prose to
avoid the pattern, which is the tempting fix and the one that would leave the
guard weaker than it looks.
WIRED TO THE DECISION 2026-09-06 (frank-coordinator)
blocked-by: [decide-t-the-full-suite-hook-refuses-prose-about-the-suite]. Not a merge
and not a duplicate-closure — this row's instances are its own evidence and are counted in
the decision. The edge is real: the fix is in .claude/hooks/no-full-suite.sh, which binds
every agent on this box, so no track agent may make it and no peer may authorise it. Until
the owner rules, there is nothing here to implement, and an unwired T row at p35 reads as
work somebody could pick up.
Your instances moved the recommendation. The decision row was written on five instances,
all around commit messages, and recommended leave it or downgrade for git commit. The
five in these two rows are mostly cat > / cat >> heredocs writing FILES, plus a separate
rule firing on for + a test/ glob in a heredoc body — neither of which the cheap arm
covers. Consolidated count is now at least ten across five-plus sessions, and the
decision's own stated purpose ("so the fifth instance is the last one that has to be
rediscovered") demonstrably failed, since both of these were filed a week later by sessions
that did not find it.