mirror of
https://github.com/openai/codex.git
synced 2026-08-23 13:09:46 +00:00
## Why A repository can contain a tracked directory that Git implicitly treats as a bare repository. Its configuration may select helpers such as `core.fsmonitor`, causing Codex Git operations in that directory to execute repository-controlled code. ## What changed - Pass `-c safe.bareRepository=explicit` to Codex-managed Git commands so they reject implicitly discovered bare repositories. - Continue to support repositories explicitly selected with `--git-dir` or `GIT_DIR`. ## Testing Add a regression test that clones a repository containing a tracked embedded Git repository and verifies that guarded Git inspection rejects it without running its configured filesystem monitor. GitOrigin-RevId: 344b5bc1e0ffa94f2a1b788488aa653222da10f3
codex-git-utils
Helpers for interacting with git, including patch application. The crate also
exposes a lightweight baseline API for internal directories that use git only
as a resettable diff mechanism: ensure_git_baseline_repository preserves a
usable root/.git baseline or creates one when it is missing or unusable,
reset_git_repository replaces root/.git with a fresh one-commit baseline,
and diff_since_latest_init returns structured file changes plus a unified
diff from that baseline to the current directory contents.
use std::path::Path;
use codex_git_utils::{apply_git_patch, ApplyGitRequest};
let repo = Path::new("/path/to/repo");
// Apply a patch (omitted here) to the repository.
let request = ApplyGitRequest {
cwd: repo.to_path_buf(),
diff: String::from("...diff contents..."),
revert: false,
preflight: false,
};
let result = apply_git_patch(&request)?;