Skip to content

check.js git check-ignore inherits GIT_* env, breaks in worktree pre-commit #155

Description

@vivek7405

Problem

The gitignore-vendor-not-ignored rule in packages/server/src/check.js:970 runs git check-ignore -q <probe> with a cwd: appDir option but does NOT sanitize inherited git environment variables. When webjs check (and therefore npm test, which exercises the rule against temp-dir fixtures) runs inside a git hook invoked from a linked worktree, git exports GIT_WORK_TREE (and GIT_DIR / GIT_INDEX_FILE) into the hook environment. Those inherited vars OVERRIDE cwd-based repo discovery, so git check-ignore consults the real repo instead of the temp fixture dir, and the probe returns the wrong answer.

Concretely: the pre-commit npm test cannot pass from ANY git worktree. Reproduced precisely:

  • GIT_DIR + GIT_INDEX_FILE set, no GIT_WORK_TREE: test PASSES.
  • Add GIT_WORK_TREE: test FAILS (gitignore-vendor-not-ignored: flags broader *.js rule and the .webjs/ variant both fail).

This blocks committing from worktrees, which is the recommended flow when multiple agents work in parallel.

Design / approach

Strip the inherited git env vars at the spawnSync call site so cwd is authoritative:

const { GIT_DIR, GIT_WORK_TREE, GIT_INDEX_FILE, GIT_PREFIX, ...cleanEnv } = process.env;
spawnSync('git', ['check-ignore', '-q', probe], { cwd: appDir, stdio: 'pipe', env: cleanEnv });

Apply the same hardening to the other framework git call sites flagged for the same latent issue (packages/cli/lib/create.js git init / git config, and scripts/backfill-changelog.js's git wrapper) and to the initGit() test helper.

Acceptance criteria

  • git check-ignore in check.js runs with GIT_DIR/GIT_WORK_TREE/GIT_INDEX_FILE/GIT_PREFIX cleared
  • The two gitignore-vendor-not-ignored tests pass even with GIT_WORK_TREE set in the environment (regression test)
  • Pre-commit npm test passes from a linked git worktree
  • Other framework git subprocess call sites hardened consistently
  • Tests cover the env-leak regression

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

  • Status
    Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions