Skip to content

Respect git global ignore files (core.excludesFile) in source scanner - #20524

Open
Lukecele wants to merge 4 commits into
tailwindlabs:mainfrom
Lukecele:fix/respect-core-excludesfile
Open

Lukecele wants to merge 4 commits into
tailwindlabs:mainfrom
Lukecele:fix/respect-core-excludesfile

Conversation

@Lukecele

Copy link
Copy Markdown

When scanning for source candidates, Oxide previously disabled git global ignore files via builder.git_global(false).

As noted in #15941, the intention was to prevent .gitignore files in parent directories outside of a git repository from taking effect, while keeping global ignore files configured in git working. However, calling git_global(false) on the walker had the unintended side effect of ignoring core.excludesFile (and $XDG_CONFIG_HOME/git/ignore) entirely.

This change enables builder.git_global(true) so that ignore patterns configured in Git's global configuration are respected during source scanning.

Fixes #20509

Test plan

  • Added unit test respects_git_core_excludes_file in crates/oxide/tests/scanner.rs verifying that files matched by Git's core.excludesFile are skipped.
  • Verified that all existing unit and scanner tests continue to pass.

[ci-all]

In tailwindlabs#15941, the intention was to prevent .gitignore files outside of
a git repository from taking effect while ensuring global ignore files
configured in git (like core.excludesFile) continue to work.

However, builder.git_global(false) was explicitly set in the oxide
scanner walker, which caused git's global ignore configuration
(core.excludesFile / ~/.config/git/ignore) to be completely ignored.

This change enables git_global(true) so that global ignore rules
configured in git are honored as expected during source detection.

Fixes tailwindlabs#20509
@Lukecele
Lukecele requested a review from a team as a code owner September 27, 2026 10:02
@greptile-apps

greptile-apps Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Medium risk] Changes which files the scanner includes based on git configuration.

The PR appears safe to merge; no new actionable issues were identified.

Reviews (4) · Last reviewed commit: "test: isolate global git config environm..."

Comment thread crates/oxide/src/scanner/mod.rs
Comment thread crates/oxide/tests/scanner.rs Outdated
@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: 822cccba-7139-4f7e-afd9-85c93f7024e5

📥 Commits

Reviewing files that changed from the base of the PR and between 39cbde6 and 172a4c0.

📒 Files selected for processing (1)
  • crates/oxide/tests/scanner.rs

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


Walkthrough

The excludes-file parser now accepts quoted core.excludesFile paths that contain spaces. The scanner now respects Git global ignore files. New tests check quoted-path parsing and verify that a globally excluded HTML file is omitted from scan results.

Priority: ➖ Normal

Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to 172a4

Repository-controlled test runs isolate the Git configuration change; no actionable merge-blocking risk remains.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 172a4

The change lets Git ignore settings affect which source files are scanned. Existing source-selection controls remain, and no security vulnerability was established. The remaining uncertainty is whether shared build environments allow untrusted parties to control those settings.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — A party controlling the scanner process's Git configuration or selected excludes file can influence discovery for sources subject to those rules. Exposure is bounded by that configuration authority and existing source selection; tenant-wide or cross-service attackability was not established.

Trust Boundaries and Controls

  • observed — The PR activates an existing configuration-to-filesystem path in scanner discovery rather than adding a new configuration reader. Git settings become effective discovery policy, while the scanner's source-selection checks remain in place.

Resilience and Maintainability Implications

  • observed — With the child marker absent, the test launches only itself in a child process and returns before mutating GIT_CONFIG_GLOBAL. Child termination contains that environment state on success or failure. A pre-existing marker skips isolation and leaves the mutation in the invoking test process; this limitation is test-only.
🚥 Pre-merge checks | ✅ 6
✅ Passed checks (6 passed)
Check name Status Explanation
Description check ✅ Passed The description directly explains the scanner change, its Git configuration behavior, the related issue, and the test plan.
Linked Issues check ✅ Passed The changes directly address issue #20509 by respecting Git global ignore rules during source scanning.
Out of Scope Changes check ✅ Passed The implementation and tests remain within the stated scope of enabling Git global ignore files and validating core.excludesFile behavior.
Title check ✅ Passed The title clearly identifies the main change: respecting Git global ignore files in the source scanner.
Linked Issues check ✅ Passed Issue [#20509] requires source scanning to skip files matched by Git core.excludesFile. create_walker now calls builder.git_global(true). The new respects_git_core_excludes_file test configure…
Out of Scope Changes check ✅ Passed The changes stay within issue [#20509]. The scanner setting implements global Git ignore support. The parser change supports valid core.excludesFile paths required by that support. The test provides…

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
crates/oxide/tests/scanner.rs (1)

2961-2961: 🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick win

Synchronize the process-wide GIT_CONFIG_GLOBAL mutation.

GIT_CONFIG_GLOBAL is process-wide, and global Git-ignore handling reads it during Scanner::new. The configured pattern matches only ignored-by-global.html. The inspected concurrent scanner fixtures do not contain that basename, and their Git commands are only git init calls with ignored output. The race therefore does not currently change an asserted result or cause a command failure. It can affect a future scan that contains this basename. Isolate this test in a separate process or protect the mutation with a shared lock.


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: 7f764ba3-4601-4e02-b611-e93f5ae31d2d

📥 Commits

Reviewing files that changed from the base of the PR and between fa81d69 and 4f875f5.

📒 Files selected for processing (2)
  • crates/oxide/src/scanner/mod.rs
  • crates/oxide/tests/scanner.rs

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.

@Lukecele Lukecele left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Lukecele

Lukecele commented Oct 2, 2026

Copy link
Copy Markdown
Author

Hi maintainers, following up on this regression-test PR. It enables Git global ignore files during source scanning and adds coverage for core.excludesFile, addressing #20509. Greptile review is passing and the branch is mergeable; happy to adjust the implementation or test if there is any concern.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Source detection ignores core.excludesFile, so globally-ignored directories are scanned (reproduction for #19801)

1 participant