Skip to content

fix(repo): preserve literal separate Git directory paths - #2255

Merged
Byron merged 1 commit into
mainfrom
fix-polish-url
Sep 28, 2026
Merged

Byron merged 1 commit into
mainfrom
fix-polish-url

Conversation

@Byron

@Byron Byron commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Tasks

This section is for Byron only. Models continuing this PR must not add, remove, check, uncheck, rename, or reorder checkboxes here.

  • refackiew

Everything below this line was generated by Codex GPT-6.

Created by Codex on behalf of Byron. Byron will review before this is ready to merge.

Clones now preserve separate Git directory paths literally, including when Cygwin reopens a submodule through a relative .git file. The shared clone helper and gitfile resolver disable expansion during path conversion. os.fspath() keeps str, pathlib.Path, and other os.PathLike clone arguments working.

Regression tests cover both clone APIs, variable-like names, recursive submodule initialization, metadata locations, and debug output. Cygwin gitfile conversion is exercised on every platform.

Advisory summary

GHSA-fx3j-rwgx-fr94: medium severity; PyPI package GitPython, affected range <= 3.1.62. No patched version or CVE is assigned in the advisory.

Validation

  • All 22 regression cases pass. The original clone cases failed before the clone fix, and the Cygwin gitfile cases failed before the resolver fix.
  • Related clone, repository-helper, and submodule suites pass. Local fixtures required per-process commit.gpgsign=false, tag.gpgsign=false, and init.defaultBranch=master; one temporary-index test required access to this worktree's Git metadata directory.
  • Ruff lint and formatting checks pass for the changed files; mypy passes for all 46 checked source files.
  • One codex review --commit per commit found no actionable issues.
  • Native Git 2.54.0 preserves literal separate-directory paths. Reference checkout: git/git@d38352cd43ab9745686d697872408bc3249a153f, builtin/clone.c, t/t5601-clone.sh, and setup.c's read_gitfile_gently().

Commits

  • b532a50b — fix(repo): preserve literal separate Git directory paths
  • 69c5c61a — fix(repo): preserve literal Cygwin gitfile paths

<!-- Byron -->

The code-change itself is trivial. Skimmed the tests, better to have them,
but kind of low value given the amount of code they take. Oh well...

<!-- agent -->
`Repo._clone()` expanded `separate_git_dir` before invoking Git, so
metadata could be written under a different directory name from the one
requested. Preserve literal paths to address `GHSA-fx3j-rwgx-fr94`.

Disable expansion in the shared `Git.polish_url()` call. Normalize
path-like arguments with `os.fspath()` first so `pathlib.Path` and other
`os.PathLike` implementations remain supported. Existing path separator
conversion still applies.

Add local regression coverage for both clone APIs, three path argument
types, variable-like names, and recursive submodule initialization. Check
the metadata location, usable submodule commit, and debug output.

Git reference: checkout `d38352cd43ab9745686d697872408bc3249a153f`,
`builtin/clone.c` and `t/t5601-clone.sh`'s separate-git-dir tests.
Native Git 2.54.0 also preserved all three literal variable forms.

Assisted-by: GPT 6.0
Co-authored-by: GPT 6.0 <codex@openai.com>
@Byron
Byron marked this pull request as ready for review September 28, 2026 06:00
Copilot AI lite review requested due to automatic review settings September 28, 2026 06:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved blocking issues were identified.

Review effort: Lite
Findings: None

What changed in this PR

Preserves literal separate Git directory paths during cloning and submodule resolution, including Cygwin paths.

Changes:

  • Disables environment-variable expansion for Git directory paths.
  • Adds clone and recursive submodule regression tests.
  • Documents the security fix.
File Description
test/​test_submodule.py Tests recursive submodule path handling.
test/​test_clone.py Tests clone APIs and literal paths.
git/​repo/​fun.py Preserves literal Cygwin gitfile paths.
git/​repo/​base.py Preserves literal clone metadata paths.
doc/​source/​changes.rst Documents the security advisory.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Byron
Byron merged commit 93f1192 into main Sep 28, 2026
51 checks passed
@Byron
Byron deleted the fix-polish-url branch September 28, 2026 07:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants