Git backed by object storage because you can't stop me
git object-storage kefka

feat: add post-receive hooks sandboxed via kefka master

Implement automatic hook execution after a successful push: when started with -allow-hooks, objgitd runs .objgit/hooks/receive-pack from the pushed commit in a restricted shell (kefka virtual bash). The hook sees a read-only view of the commit tree at /src and writable scratch at /tmp. Execution is async post-response so hooks cannot reject a push. Only coreutils commands available (cat, grep, ls, head, tail, sort, sha256sum, etc.) — no arbitrary binaries, network, or git command. Refs before/after push are snapshotted to detect branch changes since transport.ReceivePack does not report them. One hook runs per created/updated branch; deletions are skipped. Output and exit status logged to slog only. New packages: - internal/treefs: lazy read-only billy.Filesystem view of a git tree (blobs fetched on open, no checkout to disk) - internal/mountfs: path-prefix composite FS routing /src and /tmp to separate mounted filesystems - internal/kefkash: vendored copy of kefka's billysh handler wiring (adapted to allow writes so /tmp redirections work) Includes: daemon integration, flags (-allow-hooks, -hook-timeout), tests (treefs unit tests, diffRefs, e2e push tests), example hook with regression test, and CLAUDE.md architecture documentation. Assisted-by: Claude Opus 4.8 via Claude Code Signed-off-by: Xe Iaso <me@xeiaso.net>