fix/batch: prevent host execution through Git config - #1368
Merged
Conversation
cbrnrd
marked this pull request as ready for review
September 3, 2026 18:33
cbrnrd
enabled auto-merge (squash)
September 3, 2026 18:33
BolajiOlajide
approved these changes
Sep 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Batch steps run repository code inside a Docker container, but bind workspaces also expose the repository's
.gitdirectory to that container. A step can change.git/configand add an external diff command or Git filter. After the step finishes,src-clirunsgit addandgit diffon the host. Those commands can read the changed configuration and run the repository-provided command outside the container with the permissions ofsrc-cli.Solution
Save the trusted Git control files before repository code runs and restore them before host-side Git operations. This prevents a container step from changing the configuration used by host Git. The diff command also uses
--no-ext-diffas an additional safeguard. The restore supports normal repositories and linked worktrees, and rejects unsafe Git metadata replacements.This differs from the recent archive and Git hook fixes. Those changes reject Git metadata supplied during workspace creation and disable hooks. This change protects Git configuration modified later by a running container step, including external diff commands and clean filters that do not use hooks.
Verification Evidence
.git/config. The diff succeeds without running either command, and the trusted config is restored.go test ./...go vet ./internal/batches/workspace ./internal/batches/executor