You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Tests: GIT_TEMPLATE_DIR can still inject hooks into fixtures under full config isolation #423
tests/helpers/git-config-isolation.mjs (added in #421) neutralizes all four environment-reachable git configuration sources. It does not cover GIT_TEMPLATE_DIR, which is not configuration but still reaches fixtures: git copies the template directory's contents into every git init, including hooks/.
Under otherwise-complete isolation, a GIT_TEMPLATE_DIR pointing at a directory with an executable hooks/post-commit (or pre-commit, commit-msg, …) installs that hook into every fixture repository the suite creates. Fixtures that commit — several do — would run it.
This was found during the B01 pilot review and deliberately left out of scope: #412 was about configuration, and widening a fix past its stated boundary is its own defect. Filing it so the decision is recorded rather than forgotten.
It would not silently corrupt an assertion the way a URL rewrite did; a failing hook makes the fixture's git commit fail loudly.
But it is the same shape of defect: an environment variable the developer set for their own reasons changing what fixture git commands do.
Options
delete env.GIT_TEMPLATE_DIR in the helper. One line, consistent with how the four config sources are handled. Slight scope creep — the helper's name says "config".
Rename the helper to describe what it actually guarantees (git-environment-isolation.mjs) and cover both configuration and template injection.
Set GIT_TEMPLATE_DIR to an empty directory rather than unsetting it, so fixtures are explicitly template-free instead of relying on git's default.
Do nothing and close this, on the grounds that it is not configuration and has never been observed.
Option 2 is probably right: the helper's real job is "fixture git commands see nothing of the developer's environment", and naming it that way makes the next gap easier to notice.
Acceptance
If fixed: a regression test in tests/git-config-isolation.test.mjs that first proves the vector is real (a template dir with a failing hook breaks a fixture commit under config-only isolation) and then proves it is closed — matching the shape of the GIT_CONFIG_PARAMETERS test added in #421.
Problem
tests/helpers/git-config-isolation.mjs(added in #421) neutralizes all four environment-reachable git configuration sources. It does not coverGIT_TEMPLATE_DIR, which is not configuration but still reaches fixtures: git copies the template directory's contents into everygit init, includinghooks/.Under otherwise-complete isolation, a
GIT_TEMPLATE_DIRpointing at a directory with an executablehooks/post-commit(orpre-commit,commit-msg, …) installs that hook into every fixture repository the suite creates. Fixtures that commit — several do — would run it.This was found during the B01 pilot review and deliberately left out of scope: #412 was about configuration, and widening a fix past its stated boundary is its own defect. Filing it so the decision is recorded rather than forgotten.
Impact
Low in practice, non-zero in principle:
url.insteadOfwhich motivated Tests: the git-config guard misses config injected through GIT_CONFIG_COUNT #412.git commitfail loudly.Options
delete env.GIT_TEMPLATE_DIRin the helper. One line, consistent with how the four config sources are handled. Slight scope creep — the helper's name says "config".git-environment-isolation.mjs) and cover both configuration and template injection.GIT_TEMPLATE_DIRto an empty directory rather than unsetting it, so fixtures are explicitly template-free instead of relying on git's default.Option 2 is probably right: the helper's real job is "fixture git commands see nothing of the developer's environment", and naming it that way makes the next gap easier to notice.
Acceptance
If fixed: a regression test in
tests/git-config-isolation.test.mjsthat first proves the vector is real (a template dir with a failing hook breaks a fixture commit under config-only isolation) and then proves it is closed — matching the shape of theGIT_CONFIG_PARAMETERStest added in #421.Related: #412, #421, #422.