Skip to content

fix(cli): prevent background git operations from hijacking stdin - #29148

Open
DavidAPierce wants to merge 5 commits into
mainfrom
fix/prevent-git-stdin-hijack
Open

DavidAPierce wants to merge 5 commits into
mainfrom
fix/prevent-git-stdin-hijack

Conversation

@DavidAPierce

Copy link
Copy Markdown
Contributor

Summary

This PR addresses issue #23480 where background extension update checks (git.listRemote) or clones (git.clone) spawn Git without disabling interactive terminal prompts. If credentials or passphrases are challenged under slow, private, or authenticated remotes, Git blocks waiting on stdin, which is invisible under the Ink TUI, causing the terminal CLI to freeze and hijack keyboard input.

Details

  • Implements a createNonInteractiveGit helper in packages/cli/src/config/extensions/github.ts that configures simple-git with GIT_TERMINAL_PROMPT: '0' and GIT_SSH_COMMAND: 'ssh -o BatchMode=yes' (preserving user-configured commands).
  • Integrates createNonInteractiveGit into both cloneFromGit and checkForExtensionUpdate.
  • Wraps git.listRemote background checking in checkForExtensionUpdate with a 15_000ms background timeout race to prevent indefinite network hangs.
  • Adds comprehensive unit tests in packages/cli/src/config/extensions/github.test.ts to verify environment variable injection and graceful handling of prompt suppression failures.

Related Issues

Closes #23480

How to Validate

  1. Unit Verification: Run the tests to ensure correct environment injection and exception handling:
    npm test -w @google/gemini-cli -- src/config/extensions/github.test.ts --run
  2. Build and Typecheck: Verify that the changes build cleanly:
    npm run build

Pre-Merge Checklist

  • Updated relevant documentation and README (if needed)
  • Added/updated tests (if needed)
  • Noted breaking changes (if any)
  • Validated on required platforms/methods:
    • MacOS
      • npm run
      • npx
      • Docker
      • Podman
      • Seatbelt
    • Windows
      • npm run
      • npx
      • Docker
    • Linux
      • npm run
      • npx
      • Docker

@DavidAPierce
DavidAPierce requested a review from a team as a code owner August 31, 2026 20:44
@DavidAPierce
DavidAPierce force-pushed the fix/prevent-git-stdin-hijack branch from b6539c7 to b404f4f Compare August 31, 2026 20:44
@github-actions github-actions Bot added the size/m A medium sized PR label Aug 31, 2026
@github-actions

github-actions Bot commented Aug 31, 2026 •

Copy link
Copy Markdown

📊 PR Size: size/M

  • Lines changed: 154
  • Additions: +150
  • Deletions: -4
  • Files changed: 2

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request resolves an issue where background Git operations in the CLI would inadvertently capture terminal input, causing the application to freeze. By enforcing non-interactive settings and implementing timeouts for network-dependent Git commands, the changes ensure that extension management remains resilient and does not interfere with the user's interactive session.

Highlights

  • Non-interactive Git Configuration: Introduced a helper function to configure Git instances with environment variables that suppress terminal prompts and force batch mode for SSH, preventing background operations from blocking on stdin.
  • Background Operation Timeouts: Added a 15-second timeout race to remote Git operations to ensure background extension checks do not hang indefinitely.
  • Testing and Verification: Added unit tests to verify correct environment variable injection and graceful error handling when prompt suppression is triggered.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@gemini-cli gemini-cli Bot added priority/p2 Important but can be addressed in a future release. area/extensions Issues related to Gemini CLI extensions capability 🔒 maintainer only ⛔ Do not contribute. Internal roadmap item. labels Aug 31, 2026
@github-actions

github-actions Bot commented Aug 31, 2026 •

Copy link
Copy Markdown

Size Change: +1 kB (0%)

Total Size: 35.3 MB

Filename Size Change
./bundle/chunk-AZPFKWCS.js 0 B -49.2 kB (removed) 🏆
./bundle/chunk-BBORQNE3.js 0 B -3.77 kB (removed) 🏆
./bundle/chunk-N3XQ2FJI.js 0 B -13 kB (removed) 🏆
./bundle/chunk-UQ3O5PQ3.js 0 B -3.43 kB (removed) 🏆
./bundle/chunk-WP4RMAI4.js 0 B -3.65 MB (removed) 🏆
./bundle/chunk-WWPCTSMU.js 0 B -19.5 kB (removed) 🏆
./bundle/chunk-YF3W4KQ6.js 0 B -661 kB (removed) 🏆
./bundle/chunk-ZYAT2M6J.js 0 B -16.6 MB (removed) 🏆
./bundle/core-UCH5MNJW.js 0 B -51.2 kB (removed) 🏆
./bundle/devtoolsService-2RKQH2TD.js 0 B -147 kB (removed) 🏆
./bundle/gemini-FQG4EG5P.js 0 B -624 kB (removed) 🏆
./bundle/interactiveCli-6JHSMVEV.js 0 B -1.31 MB (removed) 🏆
./bundle/liteRtServerManager-N2GUAY7O.js 0 B -2.08 kB (removed) 🏆
./bundle/oauth2-provider-REICSAUD.js 0 B -9.12 kB (removed) 🏆
./bundle/chunk-BKO6IOW6.js 661 kB +661 kB (new file) 🆕
./bundle/chunk-DGTBBVVC.js 49.2 kB +49.2 kB (new file) 🆕
./bundle/chunk-G5PA6UYN.js 19.5 kB +19.5 kB (new file) 🆕
./bundle/chunk-IT2LSZDP.js 13 kB +13 kB (new file) 🆕
./bundle/chunk-KQYVGDM3.js 16.6 MB +16.6 MB (new file) 🆕
./bundle/chunk-OFJGE7D5.js 3.65 MB +3.65 MB (new file) 🆕
./bundle/chunk-U6YUKWG2.js 3.43 kB +3.43 kB (new file) 🆕
./bundle/chunk-VTTLCU7X.js 3.77 kB +3.77 kB (new file) 🆕
./bundle/core-6KODMGSQ.js 51.2 kB +51.2 kB (new file) 🆕
./bundle/devtoolsService-D5PA33D6.js 147 kB +147 kB (new file) 🆕
./bundle/gemini-R6T6JMGB.js 624 kB +624 kB (new file) 🆕
./bundle/interactiveCli-33LDEQ7M.js 1.31 MB +1.31 MB (new file) 🆕
./bundle/liteRtServerManager-K3JDOYL7.js 2.08 kB +2.08 kB (new file) 🆕
./bundle/oauth2-provider-6K4W5NKW.js 9.12 kB +9.12 kB (new file) 🆕
ℹ️ View Unchanged
Filename Size Change
./bundle/bundled/third_party/index.js 8 MB 0 B
./bundle/chunk-34MYV7JD.js 2.45 kB 0 B
./bundle/chunk-5AUYMPVF.js 858 B 0 B
./bundle/chunk-5PS3AYFU.js 1.18 kB 0 B
./bundle/chunk-664ZODQF.js 124 kB 0 B
./bundle/chunk-DAHVX5MI.js 206 kB 0 B
./bundle/chunk-IUUIT4SU.js 56.5 kB 0 B
./bundle/chunk-L5V3KIDT.js 1.62 kB 0 B
./bundle/chunk-TUDYL3X4.js 40.3 kB 0 B
./bundle/cleanup-5C5F3DWO.js 0 B -902 B (removed) 🏆
./bundle/devtools-TYCPOPV3.js 683 kB 0 B
./bundle/events-XB7DADIJ.js 418 B 0 B
./bundle/examples/hooks/scripts/on-start.js 188 B 0 B
./bundle/examples/mcp-server/example.js 1.43 kB 0 B
./bundle/gemini.js 5.38 kB 0 B
./bundle/getMachineId-bsd-TXG52NKR.js 1.55 kB 0 B
./bundle/getMachineId-darwin-7OE4DDZ6.js 1.55 kB 0 B
./bundle/getMachineId-linux-SHIFKOOX.js 1.34 kB 0 B
./bundle/getMachineId-unsupported-5U5DOEYY.js 1.06 kB 0 B
./bundle/getMachineId-win-6KLLGOI4.js 1.72 kB 0 B
./bundle/https-proxy-agent-AVGR4LHR.js 490 B 0 B
./bundle/multipart-parser-E7RMVJWU.js 11.7 kB 0 B
./bundle/multipart-parser-KPBZEGQU.js 11.7 kB 0 B
./bundle/sandbox-macos-permissive-open.sb 7.17 kB 0 B
./bundle/sandbox-macos-permissive-proxied.sb 7.46 kB 0 B
./bundle/sandbox-macos-restrictive-open.sb 5.17 kB 0 B
./bundle/sandbox-macos-restrictive-proxied.sb 5.38 kB 0 B
./bundle/sandbox-macos-strict-open.sb 6.63 kB 0 B
./bundle/sandbox-macos-strict-proxied.sb 6.84 kB 0 B
./bundle/src-65GKNWUJ.js 45.4 kB 0 B
./bundle/src-U45KTUYT.js 45.7 kB 0 B
./bundle/src-XZYPU6PJ.js 352 kB 0 B
./bundle/start-5WYZACJM.js 0 B -622 B (removed) 🏆
./bundle/tree-sitter-7U6MW5PS.js 274 kB 0 B
./bundle/tree-sitter-bash-34ZGLXVX.js 1.84 MB 0 B
./bundle/worker/worker-entry.js 363 kB 0 B
./bundle/cleanup-HPEWPV6M.js 902 B +902 B (new file) 🆕
./bundle/start-BMRRZ53F.js 622 B +622 B (new file) 🆕

compressed-size-action

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a non-interactive Git client configuration to prevent background Git operations from prompting for user input or blocking terminal execution. It also adds a 15-second timeout to git ls-remote operations during extension update checks, along with corresponding unit tests. The review feedback correctly identifies that the setTimeout used for the background timeout is never cleared, which can keep the Node.js event loop active and cause tests or the CLI process to hang. A code suggestion is provided to clear the timeout in a .finally block.

Comment thread packages/cli/src/config/extensions/github.ts
@MuhammadQuran17

Copy link
Copy Markdown

We need this fix asap. It blocks CLI terminal entirely.

@DavidAPierce
DavidAPierce added this pull request to the merge queue Sep 3, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 3, 2026
@DavidAPierce
DavidAPierce added this pull request to the merge queue Sep 3, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 3, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/extensions Issues related to Gemini CLI extensions capability 🔒 maintainer only ⛔ Do not contribute. Internal roadmap item. priority/p2 Important but can be addressed in a future release. size/m A medium sized PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: Background git fetch for private extensions hijacks stdin, causing terminal freeze

3 participants