Skip to content

Linked worktree lanes may strip Git maintenance overrides from sandbox commands #273

Description

@danny-avila

In packages/code/src/native-sandbox.ts, linked worktree lanes add GIT_CONFIG_KEY_4/VALUE_4 (gc.auto=0) and GIT_CONFIG_KEY_5/VALUE_5 (maintenance.auto=false) through LINKED_WORKTREE_GIT_ENVIRONMENT. The sandbox credentials.envVars deny-list excludes only keys in TRUSTED_GIT_ENVIRONMENT. If the host environment contains those lane-only Git config names, the deny entries can remove the injected overrides from the inner command, allowing automatic Git gc/maintenance to mutate object storage shared with sibling lanes. Exclude this.gitEnvironment (or the full lane environment) from the deny list and test that the lane-only keys survive into the inner command. Found in downstream sync review: https://github.com/ClickHouse/ai/pull/4089#discussion_r4133565568

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions