fix(repo): preserve literal separate Git directory paths - #2255
Merged
Merged
Conversation
Byron
force-pushed
the
fix-polish-url
branch
from
September 28, 2026 05:59
69c5c61 to
b0b8f1d
Compare
<!-- Byron --> The code-change itself is trivial. Skimmed the tests, better to have them, but kind of low value given the amount of code they take. Oh well... <!-- agent --> `Repo._clone()` expanded `separate_git_dir` before invoking Git, so metadata could be written under a different directory name from the one requested. Preserve literal paths to address `GHSA-fx3j-rwgx-fr94`. Disable expansion in the shared `Git.polish_url()` call. Normalize path-like arguments with `os.fspath()` first so `pathlib.Path` and other `os.PathLike` implementations remain supported. Existing path separator conversion still applies. Add local regression coverage for both clone APIs, three path argument types, variable-like names, and recursive submodule initialization. Check the metadata location, usable submodule commit, and debug output. Git reference: checkout `d38352cd43ab9745686d697872408bc3249a153f`, `builtin/clone.c` and `t/t5601-clone.sh`'s separate-git-dir tests. Native Git 2.54.0 also preserved all three literal variable forms. Assisted-by: GPT 6.0 Co-authored-by: GPT 6.0 <codex@openai.com>
Byron
force-pushed
the
fix-polish-url
branch
from
September 28, 2026 06:00
b0b8f1d to
9349ff5
Compare
Byron
marked this pull request as ready for review
September 28, 2026 06:00
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
No unresolved blocking issues were identified.
Review effort: Lite
Findings: None
What changed in this PR
Preserves literal separate Git directory paths during cloning and submodule resolution, including Cygwin paths.
Changes:
- Disables environment-variable expansion for Git directory paths.
- Adds clone and recursive submodule regression tests.
- Documents the security fix.
| File | Description |
|---|---|
test/test_submodule.py |
Tests recursive submodule path handling. |
test/test_clone.py |
Tests clone APIs and literal paths. |
git/repo/fun.py |
Preserves literal Cygwin gitfile paths. |
git/repo/base.py |
Preserves literal clone metadata paths. |
doc/source/changes.rst |
Documents the security advisory. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Tasks
This section is for Byron only. Models continuing this PR must not add, remove, check, uncheck, rename, or reorder checkboxes here.
Everything below this line was generated by
Codex GPT-6.Created by Codex on behalf of Byron. Byron will review before this is ready to merge.
Clones now preserve separate Git directory paths literally, including when Cygwin reopens a submodule through a relative
.gitfile. The shared clone helper and gitfile resolver disable expansion during path conversion.os.fspath()keepsstr,pathlib.Path, and otheros.PathLikeclone arguments working.Regression tests cover both clone APIs, variable-like names, recursive submodule initialization, metadata locations, and debug output. Cygwin gitfile conversion is exercised on every platform.
Advisory summary
GHSA-fx3j-rwgx-fr94: medium severity; PyPI package
GitPython, affected range<= 3.1.62. No patched version or CVE is assigned in the advisory.Validation
commit.gpgsign=false,tag.gpgsign=false, andinit.defaultBranch=master; one temporary-index test required access to this worktree's Git metadata directory.codex review --commitper commit found no actionable issues.git/git@d38352cd43ab9745686d697872408bc3249a153f,builtin/clone.c,t/t5601-clone.sh, andsetup.c'sread_gitfile_gently().Commits
b532a50b—fix(repo): preserve literal separate Git directory paths69c5c61a—fix(repo): preserve literal Cygwin gitfile paths