Goal
Ensure base_git_update_repo updates only the repository root supplied by its caller.
Background and reproduction
Release review of a90aa1429647b6eb4820a01aabe37799ca55ad5e; reproduced on macOS arm64 with Bash 5.3.20 and a network-free local bare origin.
base_git_update_repo changes into the requested directory and checks only git rev-parse --is-inside-work-tree. Git searches ancestor directories, so a plain child directory is accepted and the enclosing repository is pulled instead.
Reproduction:
- Create a bare local origin on main and two ordinary clones, writer and consumer.
- Commit/push file
data containing first in writer; bring consumer to that commit.
- Create an ordinary empty
consumer/nested directory, without .git.
- Commit/push
data containing second in writer, leaving consumer behind.
- Source std, call
base_init with a fresh argument array, import git, then run base_git_update_repo "$consumer/nested" "" main.
Actual: status 0; consumer HEAD advances and consumer/data changes from first to second. The requested child directory is not a repository root. Expected: reject it before fetch/pull/submodule mutation, leaving the enclosing repository unchanged. This matters for workspace updaters and partially initialized nested checkouts: a wrong or missing child checkout must not select a different repository implicitly.
The existing Git tests cover dirty, missing-origin, unreachable-origin and non-fast-forward cases, but not ancestor discovery. The documented argument is a repository path, not an arbitrary location within a worktree.
Scope and acceptance criteria
Validation
Run the two-clone reproduction, focused Git BATS, ShellCheck and tests/validate.sh. No network or changes to real workspaces are needed.
Non-goals
No release publication, unrelated API redesign, or changes to consumer workspaces.
Project fields
- Status: Ready
- Priority: P1
- Area: Shell
- Initiative: Adoption Polish
- Size: S
- Milestone: v2.2.0
Agent assignment
Assignee: @codeforester. Implement through the normal issue-backed worktree and reviewed PR workflow.
Goal
Ensure base_git_update_repo updates only the repository root supplied by its caller.
Background and reproduction
Release review of
a90aa1429647b6eb4820a01aabe37799ca55ad5e; reproduced on macOS arm64 with Bash 5.3.20 and a network-free local bare origin.base_git_update_repo changes into the requested directory and checks only
git rev-parse --is-inside-work-tree. Git searches ancestor directories, so a plain child directory is accepted and the enclosing repository is pulled instead.Reproduction:
datacontainingfirstin writer; bring consumer to that commit.consumer/nesteddirectory, without.git.datacontainingsecondin writer, leaving consumer behind.base_initwith a fresh argument array, import git, then runbase_git_update_repo "$consumer/nested" "" main.Actual: status 0; consumer HEAD advances and consumer/data changes from
firsttosecond. The requested child directory is not a repository root. Expected: reject it before fetch/pull/submodule mutation, leaving the enclosing repository unchanged. This matters for workspace updaters and partially initialized nested checkouts: a wrong or missing child checkout must not select a different repository implicitly.The existing Git tests cover dirty, missing-origin, unreachable-origin and non-fast-forward cases, but not ancestor discovery. The documented argument is a repository path, not an arbitrary location within a worktree.
Scope and acceptance criteria
Validation
Run the two-clone reproduction, focused Git BATS, ShellCheck and tests/validate.sh. No network or changes to real workspaces are needed.
Non-goals
No release publication, unrelated API redesign, or changes to consumer workspaces.
Project fields
Agent assignment
Assignee: @codeforester. Implement through the normal issue-backed worktree and reviewed PR workflow.