Found while running gsd-test for #3308: tests/commit-files-pathspec.test.cjs's repo-wide `--files` scan runs `git ls-files -z -- *.md` directly against the checked-out repo root (not a createTempGitProject() fixture, unlike every other gitOrThrow call in this file). Inside a container-provisioned test runner the checkout's on-disk owner can legitimately differ from the running UID, tripping git's CVE-2022-24765 dubious-ownership guard and failing the scan closed (exitCode 128) rather than reporting a real file-list result — reproduced on gsd-test's linux-node22 and linux-node24 lanes. Adds `-c safe.directory=*` to that ONE invocation only, so the bypass is scoped to this call rather than a global `git config` write that would leak into every other git call in the process. No source behavior changed; test-infrastructure resilience only.
151 KiB
151 KiB