From f84d8be7b2c170691c4dbfed5744de875e0fe335 Mon Sep 17 00:00:00 2001 From: Chris Bookholt Date: Thu, 2 Jul 2026 09:02:37 -0700 Subject: [PATCH] test(git-utils): use native lexical authority decoy --- codex-rs/git-utils/src/safe_git_tests.rs | 69 ++++++++++-------------- 1 file changed, 29 insertions(+), 40 deletions(-) diff --git a/codex-rs/git-utils/src/safe_git_tests.rs b/codex-rs/git-utils/src/safe_git_tests.rs index 911344cd97..b503c3c07e 100644 --- a/codex-rs/git-utils/src/safe_git_tests.rs +++ b/codex-rs/git-utils/src/safe_git_tests.rs @@ -750,8 +750,6 @@ async fn checked_has_changes_accepts_non_utf8_repository_root() { #[tokio::test] async fn checked_has_changes_preserves_lexical_repository_ancestry_for_git_selection() { if std::env::var_os("CODEX_GIT_UTILS_SAFE_GIT_ENV_CHILD").is_none() { - use std::os::unix::fs::PermissionsExt; - let fixture = tempfile::tempdir().expect("fixture"); let outer = fixture.path().join("outer"); let physical_nested = fixture.path().join("physical-nested"); @@ -764,58 +762,49 @@ async fn checked_has_changes_preserves_lexical_repository_ancestry_for_git_selec std::os::unix::fs::symlink(&physical_nested, &lexical_nested) .expect("symlink nested repository"); - let output = std::process::Command::new("/bin/sh") - .args(["-c", "command -v git"]) - .output() - .expect("resolve Git executable"); - assert!(output.status.success(), "resolve Git executable"); - let real_git = PathBuf::from( - String::from_utf8(output.stdout) - .expect("Git path UTF-8") - .trim(), - ); - let marker = fixture.path().join("outer-git-ran"); + let native_false = std::env::split_paths(&std::env::var_os("PATH").expect("PATH")) + .find_map(|directory| { + let candidate = std::fs::canonicalize(directory.join("false")).ok()?; + crate::git_executable::is_native_executable_file(&candidate).then_some(candidate) + }) + .expect("native false executable"); let outer_git = outer_bin.join("git"); - std::fs::write( - &outer_git, - "#!/bin/sh\nprintf ran > \"$CODEX_GIT_UTILS_LEXICAL_GIT_MARKER\"\nexec \"$CODEX_GIT_UTILS_REAL_GIT\" \"$@\"\n", - ) - .expect("write outer Git wrapper"); - let mut permissions = std::fs::metadata(&outer_git) - .expect("outer Git metadata") - .permissions(); - permissions.set_mode(0o755); - std::fs::set_permissions(&outer_git, permissions).expect("make outer Git executable"); + std::fs::copy(native_false, &outer_git).expect("copy native false as outer Git"); + assert!( + crate::git_executable::is_native_executable_file(&outer_git), + "decoy Git must pass production native-executable selection" + ); - let search_path = std::env::join_paths([ - outer_bin.as_path(), - real_git.parent().expect("Git executable directory"), - ]) - .expect("construct controlled PATH"); + let search_path = + std::env::join_paths([outer_bin.as_path()]).expect("construct single-candidate PATH"); run_isolated_test( "safe_git::tests::checked_has_changes_preserves_lexical_repository_ancestry_for_git_selection", &[ ("CODEX_GIT_UTILS_TARGET_REPO", lexical_nested.as_os_str()), - ("CODEX_GIT_UTILS_LEXICAL_GIT_MARKER", marker.as_os_str()), - ("CODEX_GIT_UTILS_REAL_GIT", real_git.as_os_str()), + ("CODEX_GIT_UTILS_PHYSICAL_REPO", physical_nested.as_os_str()), ("PATH", search_path.as_os_str()), ], ); - assert!( - !marker.exists(), - "Git from the lexical enclosing repository must not run" - ); return; } + let physical_nested = PathBuf::from( + std::env::var_os("CODEX_GIT_UTILS_PHYSICAL_REPO").expect("physical repository"), + ); + assert_eq!( + try_get_has_changes(&physical_nested).await, + Err(GitReadError::CommandFailed { + operation: "statusFilterPreparation".to_string(), + exit_code: None, + }), + "the canonical spelling must select and fail on the first eligible native decoy" + ); let lexical_nested = PathBuf::from(std::env::var_os("CODEX_GIT_UTILS_TARGET_REPO").expect("target repository")); - assert_eq!(try_get_has_changes(&lexical_nested).await, Ok(false)); - let marker = - PathBuf::from(std::env::var_os("CODEX_GIT_UTILS_LEXICAL_GIT_MARKER").expect("Git marker")); - assert!( - !marker.exists(), - "Git from the lexical enclosing repository must not run" + assert_eq!( + try_get_has_changes(&lexical_nested).await, + Err(GitReadError::NoTrustedGit), + "the lexical spelling must exclude the enclosing repository's native Git decoy" ); }