mirror of
https://github.com/openai/codex.git
synced 2026-08-23 13:09:46 +00:00
## Why A checkout could point its `.git` file at a trusted repository's worktree directory without proving that the repository had registered that checkout. This could cause project configuration from an unrelated checkout to be treated as trusted. ## What changed - Verify the linked worktree's `gitdir` backlink, `commondir`, registered checkout, and main checkout ownership before resolving the main repository's trust key. - Reject missing, oversized, symlinked, mismatched, or swapped Git metadata. - Preserve valid linked worktrees that use path aliases, separate Git directories, or non-UTF-8 POSIX paths. ## Testing Add resolver and config-loading coverage for forged worktrees, metadata races, case-sensitive paths, moved worktrees, and host MCP startup from project config. GitOrigin-RevId: 6052a7d10ad2d613436f20175c356abdef8c758e
codex-git-utils
Helpers for interacting with git, including patch application. The crate also
exposes a lightweight baseline API for internal directories that use git only
as a resettable diff mechanism: ensure_git_baseline_repository preserves a
usable root/.git baseline or creates one when it is missing or unusable,
reset_git_repository replaces root/.git with a fresh one-commit baseline,
and diff_since_latest_init returns structured file changes plus a unified
diff from that baseline to the current directory contents.
use std::path::Path;
use codex_git_utils::{apply_git_patch, ApplyGitRequest};
let repo = Path::new("/path/to/repo");
// Apply a patch (omitted here) to the repository.
let request = ApplyGitRequest {
cwd: repo.to_path_buf(),
diff: String::from("...diff contents..."),
revert: false,
preflight: false,
};
let result = apply_git_patch(&request)?;