Skip to content

On Windows with a heavy corporate security stack, installing hooks can be impossible #2755

Description

@joanise

Before submitting

  • I have searched the issue list for similar bug reports.

Summary

Under some circumstances with a heavy security stack imposed from corporate security, it is difficult or almost impossible to install the pre-commit hooks.

There seems to be a race condition with prek creating a folder under scratch/ using git clone and then renaming it to repos/ where it will get used, but the security tools are still scanning and have a lock on the folder when the renaming is attempted. With a small delay, the renaming operation could have succeeded.

The error message says permissions denied but I have full permissions in the folder, it's just that on Windows, if a file is open by any process the filelock prevents renaming/moving/deleting the file itself or any of its parent folders.

My suggested solution would be to check the status code on that rename operation and when it fails, sleep for a second or two and try again.

In practice, I try again regularly and after many attempts over several hours, the hook is eventually successfully installed.

Platform

Windows 11 x86_64 using Git Bash as shell (MINGW64_NT-10.0-26200)

Version (current: 0.5.3)

prek 0.5.3 (b7eb602 2026-09-13)

.pre-commit-config.yaml

repos:
  - repo: https://github.com/pre-commit/pre-commit-hooks
    rev: v6.0.0
    hooks:
      - id: check-yaml
      - id: end-of-file-fixer
      - id: trailing-whitespace
        exclude: \.svg$
  - repo: https://github.com/PyCQA/isort
    rev: 9.0.1
    hooks:
      - id: isort
        args: [--profile=black]
  - repo: https://github.com/psf/black
    rev: 26.5.0
    hooks:
      - id: black
  # We do flake8 after black since black fixes a lot of the stuff it complains about
  - repo: https://github.com/pycqa/flake8
    rev: 7.2.0
    hooks:
      - id: flake8
  # We do mypy last because it's the slowest of them all
  - repo: https://github.com/pre-commit/mirrors-mypy
    rev: v2.3.1
    hooks:
      - id: mypy
        additional_dependencies: [pydantic, numpy, types-requests, types-pyyaml, types-setuptools, types-tabulate, types-tqdm]

Log file

$ prek run --all-files -vvv
2026-09-23T19:56:16.322722Z DEBUG prek: 0.5.3 (b7eb60271 2026-09-13)
2026-09-23T19:56:16.323668Z DEBUG Args: ["C:\\Users\\joanise\\.local\\bin\\prek.exe", "run", "--all-files", "-vvv"]
2026-09-23T19:56:16.607272Z TRACE root: close time.busy=283ms time.idle=7.00µs
2026-09-23T19:56:16.608139Z DEBUG Git root: C:\Users\joanise\sandboxes\EveryVoice
2026-09-23T19:56:16.608610Z DEBUG Found workspace root at `C:\Users\joanise\sandboxes\EveryVoice`
2026-09-23T19:56:16.608768Z TRACE Include selectors: ``
2026-09-23T19:56:16.608921Z TRACE Skip selectors: ``
2026-09-23T19:56:16.609536Z DEBUG discover{root="C:\\Users\\joanise\\sandboxes\\EveryVoice" config=None refresh=false}: Loaded workspace from cache
2026-09-23T19:56:16.610075Z DEBUG discover{root="C:\\Users\\joanise\\sandboxes\\EveryVoice" config=None refresh=false}: Loading project configuration path=.pre-commit-config.yaml
2026-09-23T19:56:16.611096Z TRACE discover{root="C:\\Users\\joanise\\sandboxes\\EveryVoice" config=None refresh=false}: close time.busy=2.04ms time.idle=1.40µs
2026-09-23T19:56:16.614856Z TRACE Checking lock resource="store" path=C:\Users\joanise\AppData\Local\prek\.lock
2026-09-23T19:56:16.615740Z DEBUG Acquired lock resource="store"
2026-09-23T19:56:16.618104Z DEBUG Cloning repo target=C:\Users\joanise\AppData\Local\prek\scratch\.tmpFpPxQv repo=https://github.com/psf/black@26.5.0 terminal_prompt=Disabled
2026-09-23T19:56:16.618292Z TRACE Executing `C:\Users\joanise\AppData\Local\Programs\Git\mingw64\bin\git.exe -c core.useBuiltinFSMonitor=false -c init.defaultObjectFormat= init --template= C:\Users\joanise\AppData\Local\prek\scratch\.tmpFpPxQv`
2026-09-23T19:56:16.841559Z DEBUG Cloning repo target=C:\Users\joanise\AppData\Local\prek\scratch\.tmpXSMfDF repo=https://github.com/pycqa/flake8@7.2.0 terminal_prompt=Disabled
2026-09-23T19:56:16.841974Z TRACE Executing `C:\Users\joanise\AppData\Local\Programs\Git\mingw64\bin\git.exe -c core.useBuiltinFSMonitor=false -c init.defaultObjectFormat= init --template= C:\Users\joanise\AppData\Local\prek\scratch\.tmpXSMfDF`
2026-09-23T19:56:17.032614Z TRACE Executing `cd C:\Users\joanise\AppData\Local\prek\scratch\.tmpFpPxQv && C:\Users\joanise\AppData\Local\Programs\Git\mingw64\bin\git.exe -c core.useBuiltinFSMonitor=false remote add origin https://github.com/psf/black`
2026-09-23T19:56:17.237936Z TRACE Executing `cd C:\Users\joanise\AppData\Local\prek\scratch\.tmpXSMfDF && C:\Users\joanise\AppData\Local\Programs\Git\mingw64\bin\git.exe -c core.useBuiltinFSMonitor=false remote add origin https://github.com/pycqa/flake8`
2026-09-23T19:56:17.440660Z TRACE Executing `cd C:\Users\joanise\AppData\Local\prek\scratch\.tmpFpPxQv && C:\Users\joanise\AppData\Local\Programs\Git\mingw64\bin\git.exe -c core.useBuiltinFSMonitor=false -c protocol.version=2 fetch origin 26.5.0 --depth=1`
2026-09-23T19:56:17.661397Z TRACE Executing `cd C:\Users\joanise\AppData\Local\prek\scratch\.tmpXSMfDF && C:\Users\joanise\AppData\Local\Programs\Git\mingw64\bin\git.exe -c core.useBuiltinFSMonitor=false -c protocol.version=2 fetch origin 7.2.0 --depth=1`
2026-09-23T19:56:20.090388Z TRACE Executing `cd C:\Users\joanise\AppData\Local\prek\scratch\.tmpXSMfDF && C:\Users\joanise\AppData\Local\Programs\Git\mingw64\bin\git.exe -c core.useBuiltinFSMonitor=false checkout FETCH_HEAD`
2026-09-23T19:56:20.546856Z TRACE Executing `cd C:\Users\joanise\AppData\Local\prek\scratch\.tmpFpPxQv && C:\Users\joanise\AppData\Local\Programs\Git\mingw64\bin\git.exe -c core.useBuiltinFSMonitor=false checkout FETCH_HEAD`
2026-09-23T19:56:20.872342Z TRACE Executing `cd C:\Users\joanise\AppData\Local\prek\scratch\.tmpXSMfDF && C:\Users\joanise\AppData\Local\Programs\Git\mingw64\bin\git.exe -c core.useBuiltinFSMonitor=false ls-files -z -s`
2026-09-23T19:56:22.937586Z TRACE Released lock path=C:\Users\joanise\AppData\Local\prek\.lock
error: Failed to init hooks
  caused by: failed to rename file from C:\Users\joanise\AppData\Local\prek\scratch\.tmpXSMfDF to C:\Users\joanise\AppData\Local\prek\repos\3aca55ab583df104: Access is denied. (os error 5)

Note, in this log some of the hooks had been previously successfully installed, only black and flake8 needed installing.

Activity

  1. changed the title [-]On Windows with a heavy corpora security stack, installing hooks can be impossible[/-] [+]On Windows with a heavy corporate security stack, installing hooks can be impossible[/+] on Sep 23, 2026
  2. joanise commented on Sep 24, 2026

    @joanise
    Author

    Thank you for solving this so quickly, much appreciated!

  3. joanise commented on Sep 24, 2026

    @joanise
    Author

    And bounded exponential back-off from 10ms is brilliant, if obvious in retrospect, much better than my habit of going for 1s by default in these situations. I'll borrow that technique.

  4. joanise commented on Sep 24, 2026

    @joanise
    Author

    And, fantastic, with prek@main compiled from source, prek run --all-files just works on first try. Installation of the hooks was slower than it would have been on Linux, but successful.

  5. j178 commented on Sep 24, 2026

    @j178
    Owner

    Glad to hear that!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions