mirror of
https://github.com/garrytan/gstack.git
synced 2026-10-02 17:40:02 +02:00
feat(deslop-shared-libs): route every Git read through bin/gstack-safe-git
The skill made the model retype a long safe-Git prefix on each call and a
dropped flag failed shared-libs-read-only. bin/gstack-safe-git applies the
fixed env + flag prefix, adds --no-ext-diff --no-textconv to log/show/diff,
allows diff only between two explicit object IDs and ls-files only in the
NUL-delimited overlay form, and refuses every other shape with one line
naming the allowed forms. The template now points at the installed helper
(host global runtime via {{SAFE_GIT}}) and drops the prose it enforces.
Fixtures resolve the helper to this checkout, the git shim records the safety
environment, and isGuardedGitRequest requires the complete prefix (env
included) for every repository read.
This commit is contained in:
1 parent
157a5ff520
commit
a367a1f265
13 files changed
+511
-77
No files matched your search
+13
-28
@@ -66,9 +66,15 @@ changed after writing one.
|
||||
A direct HTTP fallback must also return its response on stdout without
|
||||
creating files; do not replace successful authenticated results with an
|
||||
unauthenticated request and then describe the source as inaccessible.
|
||||
3. Before local object reads, probe no-lazy-fetch support using the safe Git
|
||||
prefix below and `rev-parse --is-inside-work-tree`. A successful Git version
|
||||
check alone is insufficient. If unsupported, use pinned-commit GET API source
|
||||
3. Run every Git command as `~/.claude/skills/gstack/bin/gstack-safe-git <args>`, never bare `git`;
|
||||
only the exact diagnostic `git --version` may run bare. The helper fixes the
|
||||
no-lazy-fetch, lock, pager, fsmonitor, signature and replacement-object
|
||||
protections and refuses reads that could run filters, drivers, hooks or
|
||||
transports, naming the allowed forms. Never bypass a refusal with raw `git`.
|
||||
`diff` takes exactly two explicit committed object IDs, then `--` and paths.
|
||||
First probe with `~/.claude/skills/gstack/bin/gstack-safe-git rev-parse --is-inside-work-tree`; a Git
|
||||
version check alone is insufficient. If the probe fails (for example
|
||||
`unknown option: --no-lazy-fetch`), use pinned-commit GET API source
|
||||
and history reads or disclose unavailable local-history coverage. Never retry
|
||||
object reads without the no-lazy-fetch protection, including by decoding loose
|
||||
objects or packfiles directly. After an unsupported probe, do not inspect Git
|
||||
@@ -79,31 +85,10 @@ changed after writing one.
|
||||
unavailable, continue with clearly labeled raw source and unknown tracking
|
||||
status and revision/history coverage.
|
||||
|
||||
The exact diagnostic `git --version` may run without the prefix below: it does
|
||||
not read repository state or execute configured hooks. It never substitutes for
|
||||
the guarded capability probe. For every other Git invocation disable optional
|
||||
locks, pager, fsmonitor, signature verification, replacement objects and lazy fetch.
|
||||
Signature display can execute a
|
||||
configured project verifier. Replacement refs must not substitute different contents
|
||||
under a cited commit ID. Keep submodule diffs short rather than reading their trees.
|
||||
Use this prefix, including for the capability probe:
|
||||
|
||||
```bash
|
||||
GIT_OPTIONAL_LOCKS=0 GIT_NO_LAZY_FETCH=1 GIT_TERMINAL_PROMPT=0 \
|
||||
git --no-pager --no-lazy-fetch --no-replace-objects \
|
||||
-c core.fsmonitor=false -c log.showSignature=false -c diff.submodule=short
|
||||
```
|
||||
|
||||
Restrict `git diff` to **two explicit committed object IDs**, with
|
||||
`--no-ext-diff --no-textconv` and `--` before paths. Use the same disabling
|
||||
flags for patch-producing `log`/`show` commands. Never use worktree/index diffs,
|
||||
`git status`, temporary indexes, `add`, `hash-object --path`, or other
|
||||
normalization helpers: these can execute clean/process filters or alter the index.
|
||||
Do not execute scripts from the audited project, even to inspect it.
|
||||
|
||||
For the uncommitted overlay, enumerate tracked and nonignored untracked paths with
|
||||
guarded, NUL-delimited `ls-files --cached --others --exclude-standard -z`, then
|
||||
inspect raw source with the host's read tools or isolated standard-library reads.
|
||||
Do not execute scripts from the audited project, even to inspect it. For the
|
||||
uncommitted overlay, enumerate tracked and nonignored untracked paths with
|
||||
`~/.claude/skills/gstack/bin/gstack-safe-git ls-files --cached --others --exclude-standard -z`, then inspect
|
||||
raw source with the host's read tools or isolated standard-library reads.
|
||||
For Python reads, use a trusted interpreter with `python3 -I -S`: repository-local
|
||||
modules can shadow standard-library imports and execute code or write bytecode.
|
||||
Do not add project paths to imports, import project modules, or use runtimes that
|
||||
|
||||
@@ -60,9 +60,15 @@ changed after writing one.
|
||||
A direct HTTP fallback must also return its response on stdout without
|
||||
creating files; do not replace successful authenticated results with an
|
||||
unauthenticated request and then describe the source as inaccessible.
|
||||
3. Before local object reads, probe no-lazy-fetch support using the safe Git
|
||||
prefix below and `rev-parse --is-inside-work-tree`. A successful Git version
|
||||
check alone is insufficient. If unsupported, use pinned-commit GET API source
|
||||
3. Run every Git command as `{{SAFE_GIT}} <args>`, never bare `git`;
|
||||
only the exact diagnostic `git --version` may run bare. The helper fixes the
|
||||
no-lazy-fetch, lock, pager, fsmonitor, signature and replacement-object
|
||||
protections and refuses reads that could run filters, drivers, hooks or
|
||||
transports, naming the allowed forms. Never bypass a refusal with raw `git`.
|
||||
`diff` takes exactly two explicit committed object IDs, then `--` and paths.
|
||||
First probe with `{{SAFE_GIT}} rev-parse --is-inside-work-tree`; a Git
|
||||
version check alone is insufficient. If the probe fails (for example
|
||||
`unknown option: --no-lazy-fetch`), use pinned-commit GET API source
|
||||
and history reads or disclose unavailable local-history coverage. Never retry
|
||||
object reads without the no-lazy-fetch protection, including by decoding loose
|
||||
objects or packfiles directly. After an unsupported probe, do not inspect Git
|
||||
@@ -73,31 +79,10 @@ changed after writing one.
|
||||
unavailable, continue with clearly labeled raw source and unknown tracking
|
||||
status and revision/history coverage.
|
||||
|
||||
The exact diagnostic `git --version` may run without the prefix below: it does
|
||||
not read repository state or execute configured hooks. It never substitutes for
|
||||
the guarded capability probe. For every other Git invocation disable optional
|
||||
locks, pager, fsmonitor, signature verification, replacement objects and lazy fetch.
|
||||
Signature display can execute a
|
||||
configured project verifier. Replacement refs must not substitute different contents
|
||||
under a cited commit ID. Keep submodule diffs short rather than reading their trees.
|
||||
Use this prefix, including for the capability probe:
|
||||
|
||||
```bash
|
||||
GIT_OPTIONAL_LOCKS=0 GIT_NO_LAZY_FETCH=1 GIT_TERMINAL_PROMPT=0 \
|
||||
git --no-pager --no-lazy-fetch --no-replace-objects \
|
||||
-c core.fsmonitor=false -c log.showSignature=false -c diff.submodule=short
|
||||
```
|
||||
|
||||
Restrict `git diff` to **two explicit committed object IDs**, with
|
||||
`--no-ext-diff --no-textconv` and `--` before paths. Use the same disabling
|
||||
flags for patch-producing `log`/`show` commands. Never use worktree/index diffs,
|
||||
`git status`, temporary indexes, `add`, `hash-object --path`, or other
|
||||
normalization helpers: these can execute clean/process filters or alter the index.
|
||||
Do not execute scripts from the audited project, even to inspect it.
|
||||
|
||||
For the uncommitted overlay, enumerate tracked and nonignored untracked paths with
|
||||
guarded, NUL-delimited `ls-files --cached --others --exclude-standard -z`, then
|
||||
inspect raw source with the host's read tools or isolated standard-library reads.
|
||||
Do not execute scripts from the audited project, even to inspect it. For the
|
||||
uncommitted overlay, enumerate tracked and nonignored untracked paths with
|
||||
`{{SAFE_GIT}} ls-files --cached --others --exclude-standard -z`, then inspect
|
||||
raw source with the host's read tools or isolated standard-library reads.
|
||||
For Python reads, use a trusted interpreter with `python3 -I -S`: repository-local
|
||||
modules can shadow standard-library imports and execute code or write bytecode.
|
||||
Do not add project paths to imports, import project modules, or use runtimes that
|
||||
|
||||
Reference in new issue
Block a user