Reject implicitly discovered bare Git repositories (#36924)

## Why

A repository can contain a tracked directory that Git implicitly treats as a bare
repository. Its configuration may select helpers such as `core.fsmonitor`, causing
Codex Git operations in that directory to execute repository-controlled code.

## What changed

- Pass `-c safe.bareRepository=explicit` to Codex-managed Git commands so they
  reject implicitly discovered bare repositories.
- Continue to support repositories explicitly selected with `--git-dir` or
  `GIT_DIR`.

## Testing

Add a regression test that clones a repository containing a tracked embedded Git
repository and verifies that guarded Git inspection rejects it without running
its configured filesystem monitor.

GitOrigin-RevId: 344b5bc1e0ffa94f2a1b788488aa653222da10f3
This commit is contained in:
Jeremy Rose
2026-08-04 16:44:10 +00:00
committed by copyberry
parent 02bc1dd796
commit 7ada37a15e
13 changed files with 226 additions and 15 deletions

View File

@@ -194,6 +194,7 @@ async fn git_output(git_path: &Path, cwd: &Path, args: &[&str]) -> Option<String
let mut command = Command::new(git_path);
command
.env("GIT_OPTIONAL_LOCKS", "0")
.args(["-c", codex_git_utils::SAFE_BARE_REPOSITORY_CONFIG])
.args(args)
.current_dir(cwd)
.stdin(Stdio::null())