From 21c46ecf5230d7079cce0d172bcd35664588836c Mon Sep 17 00:00:00 2001 From: sim Date: Wed, 12 Aug 2026 22:05:05 -0400 Subject: [PATCH] fix: scope safe.directory ownership bypass to the real-repo-root git ls-files call MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Found while running gsd-test for #3308: tests/commit-files-pathspec.test.cjs's repo-wide `--files` scan runs `git ls-files -z -- *.md` directly against the checked-out repo root (not a createTempGitProject() fixture, unlike every other gitOrThrow call in this file). Inside a container-provisioned test runner the checkout's on-disk owner can legitimately differ from the running UID, tripping git's CVE-2022-24765 dubious-ownership guard and failing the scan closed (exitCode 128) rather than reporting a real file-list result — reproduced on gsd-test's linux-node22 and linux-node24 lanes. Adds `-c safe.directory=*` to that ONE invocation only, so the bypass is scoped to this call rather than a global `git config` write that would leak into every other git call in the process. No source behavior changed; test-infrastructure resilience only. --- tests/commit-files-pathspec.test.cjs | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/tests/commit-files-pathspec.test.cjs b/tests/commit-files-pathspec.test.cjs index 7b6125ed4..c72388301 100644 --- a/tests/commit-files-pathspec.test.cjs +++ b/tests/commit-files-pathspec.test.cjs @@ -2813,7 +2813,13 @@ describe('workflow call sites declare --files (#2269)', () => { // Routed through tests/helpers/git-fixture.cjs rather than a bare spawn per // #3144 — local/no-unbounded-spawn fails an unbounded spawnSync in tests, // and this file's allowlist entry was retired when that migration landed. - const trackedMd = gitOrThrow(['ls-files', '-z', '--', '*.md'], { + // -c safe.directory=* is scoped to THIS invocation only (never a global + // `git config` write): unlike every other gitOrThrow call in this file, + // which targets a createTempGitProject() fixture it owns, this one runs + // against the real checked-out repoRoot, whose ownership can legitimately + // differ from the running UID inside a container-provisioned test runner + // (git's CVE-2022-24765 dubious-ownership guard would otherwise fire). + const trackedMd = gitOrThrow(['-c', 'safe.directory=*', 'ls-files', '-z', '--', '*.md'], { cwd: repoRoot, timeoutMs: GIT_TIMEOUT_MS, }).split('\0').filter(Boolean); assert.ok(trackedMd.length > 0, 'git ls-files reported no .md files at all — the walk is broken');