Skip to content

fix(core): normalize git environment and resolve workspace state mismatch - #28792

Merged
DavidAPierce merged 3 commits into
google-gemini:mainfrom
luisfelipe-alt:bugfix/WT-engineer_534311278
Aug 13, 2026
Merged

DavidAPierce merged 3 commits into
google-gemini:mainfrom
luisfelipe-alt:bugfix/WT-engineer_534311278

Conversation

@luisfelipe-alt

Copy link
Copy Markdown
Contributor

Summary

This PR standardizes environment configuration for Git subprocesses and resolves a state initialization issue in workspace trust evaluation. These changes ensure predictable, non-interactive execution of internal Git utilities across repositories and maintain consistent policy enforcement in restricted workspace mode.

Details

  • Subprocess Environment Isolation: Added the getSafeGitEnv utility to establish a clean, non-interactive Git subprocess environment (disabling custom pagers, external hooks, and background monitors) using GIT_CONFIG_COUNT overrides. This is applied across ShellExecutionService, WorktreeService, GrepTool, and GitService.
  • Workspace Trust Evaluation: Corrected state initialization logic in setIsTrusted (packages/a2a-server/src/config/config.ts) to properly evaluate workspace trust status rather than checking an unrelated feature flag.
  • Policy Enforcement: Ensured PolicyEngine consistently evaluates Git command invocations against workspace trust settings in restricted mode.
  • Testing: Added Vitest unit tests covering environment variable construction and policy decision handling.

How to Validate

  1. Unit Tests: Run npm run test:ci -w @google/gemini-cli-core and npm run test:ci -w @google/gemini-cli-a2a-server.
  2. Subprocess Isolation Verification:
    • In a test repository, set a custom pager: git config core.pager "cat"
    • Execute a git operation through Gemini CLI (e.g., viewing git logs).
    • Verify that standard programmatic output is returned without invoking custom pagers.
  3. Workspace Trust Verification:
    • Open a repository in Restricted Mode (untrusted workspace).
    • Execute a git command.
    • Verify that the CLI requests user confirmation (ASK_USER) as expected in restricted mode.

Pre-Merge Checklist

  • Updated relevant documentation and README (if needed)
  • Added/updated tests (if needed)
  • Noted breaking changes (if any)
  • Validated on required platforms/methods:
    • MacOS
      • npm run
      • npx
      • Docker
      • Podman
      • Seatbelt
    • Windows
      • npm run
      • npx
      • Docker
    • Linux
      • npm run
      • npx
      • Docker

@luisfelipe-alt
luisfelipe-alt requested review from a team as code owners August 12, 2026 21:20
@github-actions github-actions Bot added the size/l A large sized PR label Aug 12, 2026
@github-actions

github-actions Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

📊 PR Size: size/L

  • Lines changed: 513
  • Additions: +414
  • Deletions: -99
  • Files changed: 21

@github-actions

github-actions Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

🛑 Action Required: Evaluation Approval

Steering changes have been detected in this PR. To prevent regressions, a maintainer must approve the evaluation run before this PR can be merged.

Maintainers:

  1. Go to the Workflow Run Summary.
  2. Click the yellow 'Review deployments' button.
  3. Select the 'eval-gate' environment and click 'Approve'.

Once approved, the evaluation results will be posted here automatically.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request standardizes the environment configuration for Git subprocesses and resolves critical issues in workspace trust evaluation. By isolating Git subprocesses and enforcing stricter policy checks for untrusted workspaces, these changes ensure consistent behavior across repositories and mitigate potential security risks associated with external Git configurations.

Highlights

  • Environment Isolation: Introduced the getSafeGitEnv utility to sanitize Git subprocess environments by disabling custom pagers, hooks, and background monitors, ensuring predictable and secure execution.
  • Workspace Trust Evaluation: Refactored setIsTrusted to correctly evaluate workspace trust status, replacing reliance on unrelated feature flags.
  • Policy Enforcement: Updated the PolicyEngine to detect Git commands and force ASK_USER confirmation when operating within untrusted workspaces.
  • Testing: Added comprehensive unit tests to verify environment variable construction, policy decision handling, and secure Git operation isolation.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request implements robust security mitigations against Remote Code Execution (RCE) vulnerabilities by securing Git command execution. It introduces a getSafeGitEnv utility to sanitize environment variables and enforce safe Git configuration overrides (disabling hooks, custom SSH commands, credential helpers, etc.) across all Git invocations. Furthermore, the PolicyEngine is updated to prevent automatic execution of Git commands in untrusted workspaces, forcing user confirmation instead. Workspace trust evaluation has also been consolidated and thoroughly tested. I have reviewed the changes and have no additional feedback to provide.

Note: Security Review did not run due to the size of the PR.

@gemini-cli gemini-cli Bot added the status/need-issue Pull requests that need to have an associated issue. label Aug 12, 2026
@luisfelipe-alt
luisfelipe-alt force-pushed the bugfix/WT-engineer_534311278 branch from 1d5aa1f to 4671609 Compare August 13, 2026 19:24
@luisfelipe-alt

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces security hardening for Git command execution within untrusted workspaces. It implements getSafeGitEnv to sanitize Git environment variables and enforce safe default configurations across GitService, WorktreeService, GrepTool, and shell executions, while updating the PolicyEngine to restrict Git commands in untrusted folders. The review feedback highlights two important issues: first, the containsGitCommand helper uses a loose regular expression that can cause false positives on arguments or URLs containing 'git', which should be refined to target only the actual executable; second, a potential TypeScript compilation error exists in grep.ts due to a type mismatch between the string | undefined record returned by getSafeGitEnv() and the strict Record<string, string> expected by ShellExecutionConfig.

Note: Security Review did not run due to the size of the PR.

Comment thread packages/core/src/policy/policy-engine.ts
Comment thread packages/core/src/tools/grep.ts
@luisfelipe-alt

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request enhances security by introducing a safe Git environment (getSafeGitEnv) that neutralizes global/system Git configurations and overrides dangerous Git settings (such as hooks, fsmonitor, and sshCommand) to prevent arbitrary code execution in untrusted workspaces. It also updates the PolicyEngine to force user confirmation (ASK_USER) for Git commands executed in untrusted folders, and updates workspace trust configuration to use GEMINI_CLI_TRUST_WORKSPACE. A critical security review comment points out that the containsGitCommand helper in PolicyEngine can be bypassed using shell operators (e.g., &&, ||, ;) because it only checks a limited set of hardcoded predecessors, and suggests expanding the allowed predecessors to include common shell operators and separators.

Note: Security Review did not run due to the size of the PR.

Comment thread packages/core/src/policy/policy-engine.ts
…atch

- Introduces `getSafeGitEnv` to normalize Git configuration variables across all shell executions.

- Updates `PolicyEngine` to enforce `ASK_USER` prompts for Git commands in unverified workspaces.

- Corrects workspace trust evaluation logic in `setIsTrusted`.

- Ensures internal programmatic Git calls utilize the normalized environment.

- Adds comprehensive unit tests to verify policy engine decision logic and environment normalization.
@luisfelipe-alt

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a safe Git environment configuration (getSafeGitEnv) to neutralize potentially dangerous Git settings across several services and tools, and updates the policy engine to prompt the user (ASK_USER) when Git commands are evaluated in untrusted workspaces. The code review highlights two critical security issues in the policy engine: first, the containsGitCommand check can be bypassed by prefixing commands with environment variable assignments; second, the heuristic check unconditionally returns ASK_USER for Git commands in untrusted workspaces, which could inappropriately upgrade an existing DENY decision.

Note: Security Review did not run due to the size of the PR.

Comment thread packages/core/src/policy/policy-engine.ts
Comment thread packages/core/src/policy/policy-engine.ts
@DavidAPierce
DavidAPierce self-requested a review August 13, 2026 20:30
@luisfelipe-alt
luisfelipe-alt force-pushed the bugfix/WT-engineer_534311278 branch from 8dbad30 to 20062eb Compare August 13, 2026 20:35
@luisfelipe-alt

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces comprehensive security enhancements to mitigate Remote Code Execution (RCE) vulnerabilities associated with Git execution. It implements a getSafeGitEnv utility that sanitizes the environment by stripping untrusted GIT_CONFIG_* variables, neutralizing global and system Git configurations, and overriding potentially dangerous settings like core.hooksPath and core.sshCommand. Furthermore, the PolicyEngine is updated to detect Git commands and enforce user confirmation (ASK_USER) in untrusted workspaces, while workspace trust detection is standardized across packages using the GEMINI_CLI_TRUST_WORKSPACE environment variable. I have no additional feedback to provide as there are no review comments.

@DavidAPierce
DavidAPierce enabled auto-merge August 13, 2026 21:06
@DavidAPierce
DavidAPierce added this pull request to the merge queue Aug 13, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Aug 13, 2026
@DavidAPierce
DavidAPierce added this pull request to the merge queue Aug 13, 2026
Merged via the queue into google-gemini:main with commit c0d1924 Aug 13, 2026
34 of 35 checks passed
sharonyao1127 pushed a commit to sharonyao1127/gemini-cli that referenced this pull request Aug 20, 2026
Setting `diff.external` to an empty string tells git to spawn an executable
named "" (the platform treats it as a command, not a disable), causing all
git invocations run inside the shell sandbox to fail with:

    cannot spawn : No such file or directory

The override was added by commit c0d1924 (PR google-gemini#28792). Drop it from the
`defaultGitOverrides` array in shellExecutionService.ts and from the
safe-env helper getSafeGitEnv(), and bump GIT_CONFIG_COUNT from 8 to 7 to
drop the trailing empty slot.

If callers want a guarantee that no external diff tool is invoked, they
can pass `--no-ext-diff` per call instead - that is the official git switch.

Regression test added in packages/core/src/utils/gitUtils.test.ts so the
helper never re-introduces a GIT_CONFIG_KEY that maps to diff.external.
teknium1 added a commit to NousResearch/hermes-agent that referenced this pull request Sep 2, 2026
TrungKiencding pushed a commit to TrungKiencding/AgentX-Workmate that referenced this pull request Sep 3, 2026
(cherry picked from commit 09bb9c3b2f20f22bdb1688b6efcb78b24f1f19d6)
(cherry picked from commit 413b6ba)
melon-xf added a commit to melon-xf/hermes-agent that referenced this pull request Sep 3, 2026

This branch had an error being deployed

1 failed deployment
eval-gate — df848558 Deployed Aug 13, 2026 by DavidAPierce via Evaluate Steering & Regressions #1782
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/l A large sized PR status/need-issue Pull requests that need to have an associated issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants