You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(repo): preserve literal separate Git directory paths
<!-- Byron -->
The code-change itself is trivial. Skimmed the tests, better to have them,
but kind of low value given the amount of code they take. Oh well...
<!-- agent -->
`Repo._clone()` expanded `separate_git_dir` before invoking Git, so
metadata could be written under a different directory name from the one
requested. Preserve literal paths to address `GHSA-fx3j-rwgx-fr94`.
Disable expansion in the shared `Git.polish_url()` call. Normalize
path-like arguments with `os.fspath()` first so `pathlib.Path` and other
`os.PathLike` implementations remain supported. Existing path separator
conversion still applies.
Add local regression coverage for both clone APIs, three path argument
types, variable-like names, and recursive submodule initialization. Check
the metadata location, usable submodule commit, and debug output.
Git reference: checkout `d38352cd43ab9745686d697872408bc3249a153f`,
`builtin/clone.c` and `t/t5601-clone.sh`'s separate-git-dir tests.
Native Git 2.54.0 also preserved all three literal variable forms.
Assisted-by: GPT 6.0
Co-authored-by: GPT 6.0 <codex@openai.com>
0 commit comments