Repository navigation
fix(core): normalize git environment and resolve workspace state mismatch - #28792
DavidAPierce merged 3 commits into
Conversation
|
📊 PR Size: size/L
|
🛑 Action Required: Evaluation ApprovalSteering changes have been detected in this PR. To prevent regressions, a maintainer must approve the evaluation run before this PR can be merged. Maintainers:
Once approved, the evaluation results will be posted here automatically. |
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request standardizes the environment configuration for Git subprocesses and resolves critical issues in workspace trust evaluation. By isolating Git subprocesses and enforcing stricter policy checks for untrusted workspaces, these changes ensure consistent behavior across repositories and mitigate potential security risks associated with external Git configurations. Highlights
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. Footnotes
|
There was a problem hiding this comment.
Code Review
This pull request implements robust security mitigations against Remote Code Execution (RCE) vulnerabilities by securing Git command execution. It introduces a getSafeGitEnv utility to sanitize environment variables and enforce safe Git configuration overrides (disabling hooks, custom SSH commands, credential helpers, etc.) across all Git invocations. Furthermore, the PolicyEngine is updated to prevent automatic execution of Git commands in untrusted workspaces, forcing user confirmation instead. Workspace trust evaluation has also been consolidated and thoroughly tested. I have reviewed the changes and have no additional feedback to provide.
Note: Security Review did not run due to the size of the PR.
1d5aa1f to
4671609
Compare
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces security hardening for Git command execution within untrusted workspaces. It implements getSafeGitEnv to sanitize Git environment variables and enforce safe default configurations across GitService, WorktreeService, GrepTool, and shell executions, while updating the PolicyEngine to restrict Git commands in untrusted folders. The review feedback highlights two important issues: first, the containsGitCommand helper uses a loose regular expression that can cause false positives on arguments or URLs containing 'git', which should be refined to target only the actual executable; second, a potential TypeScript compilation error exists in grep.ts due to a type mismatch between the string | undefined record returned by getSafeGitEnv() and the strict Record<string, string> expected by ShellExecutionConfig.
Note: Security Review did not run due to the size of the PR.
14a296c to
3db605e
Compare
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request enhances security by introducing a safe Git environment (getSafeGitEnv) that neutralizes global/system Git configurations and overrides dangerous Git settings (such as hooks, fsmonitor, and sshCommand) to prevent arbitrary code execution in untrusted workspaces. It also updates the PolicyEngine to force user confirmation (ASK_USER) for Git commands executed in untrusted folders, and updates workspace trust configuration to use GEMINI_CLI_TRUST_WORKSPACE. A critical security review comment points out that the containsGitCommand helper in PolicyEngine can be bypassed using shell operators (e.g., &&, ||, ;) because it only checks a limited set of hardcoded predecessors, and suggests expanding the allowed predecessors to include common shell operators and separators.
Note: Security Review did not run due to the size of the PR.
…atch - Introduces `getSafeGitEnv` to normalize Git configuration variables across all shell executions. - Updates `PolicyEngine` to enforce `ASK_USER` prompts for Git commands in unverified workspaces. - Corrects workspace trust evaluation logic in `setIsTrusted`. - Ensures internal programmatic Git calls utilize the normalized environment. - Adds comprehensive unit tests to verify policy engine decision logic and environment normalization.
3514ecb to
8dda2df
Compare
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces a safe Git environment configuration (getSafeGitEnv) to neutralize potentially dangerous Git settings across several services and tools, and updates the policy engine to prompt the user (ASK_USER) when Git commands are evaluated in untrusted workspaces. The code review highlights two critical security issues in the policy engine: first, the containsGitCommand check can be bypassed by prefixing commands with environment variable assignments; second, the heuristic check unconditionally returns ASK_USER for Git commands in untrusted workspaces, which could inappropriately upgrade an existing DENY decision.
Note: Security Review did not run due to the size of the PR.
8dbad30 to
20062eb
Compare
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces comprehensive security enhancements to mitigate Remote Code Execution (RCE) vulnerabilities associated with Git execution. It implements a getSafeGitEnv utility that sanitizes the environment by stripping untrusted GIT_CONFIG_* variables, neutralizing global and system Git configurations, and overriding potentially dangerous settings like core.hooksPath and core.sshCommand. Furthermore, the PolicyEngine is updated to detect Git commands and enforce user confirmation (ASK_USER) in untrusted workspaces, while workspace trust detection is standardized across packages using the GEMINI_CLI_TRUST_WORKSPACE environment variable. I have no additional feedback to provide as there are no review comments.
c0d1924
Setting `diff.external` to an empty string tells git to spawn an executable
named "" (the platform treats it as a command, not a disable), causing all
git invocations run inside the shell sandbox to fail with:
cannot spawn : No such file or directory
The override was added by commit c0d1924 (PR google-gemini#28792). Drop it from the
`defaultGitOverrides` array in shellExecutionService.ts and from the
safe-env helper getSafeGitEnv(), and bump GIT_CONFIG_COUNT from 8 to 7 to
drop the trailing empty slot.
If callers want a guarantee that no external diff tool is invoked, they
can pass `--no-ext-diff` per call instead - that is the official git switch.
Regression test added in packages/core/src/utils/gitUtils.test.ts so the
helper never re-introduces a GIT_CONFIG_KEY that maps to diff.external.
(cherry picked from commit 09bb9c3)
(cherry picked from commit 09bb9c3b2f20f22bdb1688b6efcb78b24f1f19d6) (cherry picked from commit 413b6ba)
(cherry picked from commit 09bb9c3)
Summary
This PR standardizes environment configuration for Git subprocesses and resolves a state initialization issue in workspace trust evaluation. These changes ensure predictable, non-interactive execution of internal Git utilities across repositories and maintain consistent policy enforcement in restricted workspace mode.
Details
getSafeGitEnvutility to establish a clean, non-interactive Git subprocess environment (disabling custom pagers, external hooks, and background monitors) usingGIT_CONFIG_COUNToverrides. This is applied acrossShellExecutionService,WorktreeService,GrepTool, andGitService.setIsTrusted(packages/a2a-server/src/config/config.ts) to properly evaluate workspace trust status rather than checking an unrelated feature flag.PolicyEngineconsistently evaluates Git command invocations against workspace trust settings in restricted mode.How to Validate
npm run test:ci -w @google/gemini-cli-coreandnpm run test:ci -w @google/gemini-cli-a2a-server.git config core.pager "cat"ASK_USER) as expected in restricted mode.Pre-Merge Checklist