feat: Add remote Git mirror foundations - #4160
Conversation
There was a problem hiding this comment.
Two credential-handling issues need addressing before this foundation is safe to build on; details are inline.
Want to dig deeper?
Paste this into your agent to explore the findings from this review's Buildkite build:
Download the buildsworth logs from build 10715, then answer my questions about the findings.
Install the reading-buildsworth-logs skill to run this.
About buildsworth
Model: gpt-5.6-sol with xhigh thinking.
How to request a review: Comment @buildsworth-bk review on the PR, or request buildsworth-bk as a reviewer.
Risk labels (how buildsworth classifies risk) — buildsworth classifies risk itself from the diff. To let it approve, grant L2 approval by mentioning @buildsworth-bk (see L2 approval grant):
- L1 — Low risk (dep bumps, docs/copy, lockfiles, small presentational fixes). buildsworth may approve by default.
- L2 — Standard risk (new UI, additive API fields, refactors). Approved only with an L2 grant; otherwise comment-only.
- L3 — High risk (auth, migrations, payments, secrets, perf-critical paths). Human review always required.
|
Follow-up review fix in |
There was a problem hiding this comment.
Both previous credential-handling concerns remain open, and the inherited process environment creates an additional allowlist gap. Details are in the existing threads and the new inline comment.
Want to dig deeper?
Paste this into your agent to explore the findings from this review's Buildkite build:
Download the buildsworth logs from build 10716, then answer my questions about the findings.
Install the reading-buildsworth-logs skill to run this.
|
Propagated the plan correction from #4158 in merge |
There was a problem hiding this comment.
The three previous blocking concerns remain open; I’ve re-raised each in its existing thread. I didn’t find any additional issues in this pass.
Want to dig deeper?
Paste this into your agent to explore the findings from this review's Buildkite build:
Download the buildsworth logs from build 10795, then answer my questions about the findings.
Install the reading-buildsworth-logs skill to run this.
|
Merged the revised plan through |
|
Added focused regression coverage in |
|
Implemented the foundation review fixes in |
|
Adjusted the forced-prompt regression assertion in |
|
Added the red-step eligibility coverage in |
Previous concerns have been addressed.
|
Implemented recursive-submodule eligibility in |
Previous concerns have been addressed.
There was a problem hiding this comment.
The three earlier credential/allowlist concerns are resolved. I found two new blocking gaps in the recursive-submodule guard and the debug prompt regression coverage; details are inline.
Want to dig deeper?
Paste this into your agent to explore the findings from this review's Buildkite build:
Download the buildsworth logs from build 10827, then answer my questions about the findings.
Install the reading-buildsworth-logs skill to run this.
|
Added another red-step review regression in |
|
Fixed the re-review edge cases in |
|
Follow-up |
|
Propagated the final plan alignment through |
Previous concerns have been addressed.
There was a problem hiding this comment.
The two previous blockers are fixed; I left one non-blocking note on keeping the new real-Git helper test isolated from host credential configuration. This changes credential handling in the checkout path, so I’m leaving final sign-off to a human.
Want to dig deeper?
Paste this into your agent to explore the findings from this review's Buildkite build:
Download the buildsworth logs from build 10847, then answer my questions about the findings.
Install the reading-buildsworth-logs skill to run this.
Previous concerns have been addressed.
There was a problem hiding this comment.
The original blockers are resolved, and the latest merge only updates the base plan; I found no new issues. The existing non-blocking test-isolation note is unchanged. Since this touches checkout credential handling, final sign-off still needs a human.
Want to dig deeper?
Paste this into your agent to explore the findings from this review's Buildkite build:
Download the buildsworth logs from build 10861, then answer my questions about the findings.
Install the reading-buildsworth-logs skill to run this.
|
Final foundation follow-up |
There was a problem hiding this comment.
The new --separate-git-dir guard covers Git’s accepted --sep* spellings; I found no new issues. The existing non-blocking real-Git test-isolation note remains open. Since this changes checkout credential handling, final sign-off still needs a human.
Want to dig deeper?
Paste this into your agent to explore the findings from this review's Buildkite build:
Download the buildsworth logs from build 10877, then answer my questions about the findings.
Install the reading-buildsworth-logs skill to run this.
There was a problem hiding this comment.
The prior test-isolation note is addressed; I found no new issues. This still changes checkout credential handling, so I’m leaving final sign-off to a human.
Want to dig deeper?
Paste this into your agent to explore the findings from this review's Buildkite build:
Download the buildsworth logs from build 10894, then answer my questions about the findings.
Install the reading-buildsworth-logs skill to run this.
|
@buildsworth-bk review @buildsworth-bk approve L2 |
There was a problem hiding this comment.
The latest merge only updates the base plan; I found no new issues in the scoped diff. This still changes checkout credential handling, so I’m leaving final sign-off to a human.
Want to dig deeper?
Paste this into your agent to explore the findings from this review's Buildkite build:
Download the buildsworth logs from build 10903, then answer my questions about the findings.
Install the reading-buildsworth-logs skill to run this.
9783bde to
dc340c9
Compare
There was a problem hiding this comment.
I found no new issues in the current diff. Because this changes checkout credential handling, final sign-off still needs a human.
Want to dig deeper?
Paste this into your agent to explore the findings from this review's Buildkite build:
Download the buildsworth logs from build 11065, then answer my questions about the findings.
Install the reading-buildsworth-logs skill to run this.
|
Focused review of the credential-helper change requested by @pda Verdict: approve with residual risk. I found no material correctness or command-injection defect. One low-severity test gap remains: I verified that:
Focused Go tests and real-Git experiments passed. PR CI, including the Windows suite, is green. I also checked Git-for-Windows source: leading- Residual risk: I did not execute the helper end-to-end from a native Windows absolute path. The source behavior strongly supports compatibility, but the current Windows skip leaves canonical Windows authentication unverified at runtime. |
Co-authored-by: Paul Annesley <pda@users.noreply.github.com>
Co-authored-by: Paul Annesley <pda@users.noreply.github.com>
Co-authored-by: Paul Annesley <pda@users.noreply.github.com>
Co-authored-by: Paul Annesley <pda@users.noreply.github.com>
Co-authored-by: Paul Annesley <pda@users.noreply.github.com>
Co-authored-by: Paul Annesley <pda@users.noreply.github.com>
Co-authored-by: Paul Annesley <pda@users.noreply.github.com>
Co-authored-by: Paul Annesley <pda@users.noreply.github.com>
Co-authored-by: Paul Annesley <pda@users.noreply.github.com>
Co-authored-by: Paul Annesley <pda@users.noreply.github.com>
Co-authored-by: Paul Annesley <pda@users.noreply.github.com>
Co-authored-by: Paul Annesley <pda@users.noreply.github.com>
Co-authored-by: Paul Annesley <pda@users.noreply.github.com>
Co-authored-by: Paul Annesley <pda@users.noreply.github.com>
dc340c9 to
dc815cc
Compare
| if r.droppedRemoteMirrorURL != "" { | ||
| _, _ = fmt.Fprintf( | ||
| r.jobLogs, | ||
| "Remote Git mirror is not permitted by --allowed-repositories; using canonical repository: %s\n", |
|
|
||
| type remoteMirrorSkipReason string | ||
|
|
||
| const ( |
| type gitFetchArgs struct { | ||
| Shell *shell.Shell // The shell to run the command in | ||
| GitFlags string // Global git flags to pass to the command | ||
| GitFlags []string // Global git flags to pass to the command |
Description
Establish the shared contract for backend-provided remote Git mirrors without enabling a mirror checkout site. PRs 2–4 consume these foundations.
A remote mirror is optional. If its URL is not allowed, the job continues against canonical and emits a redacted warning.
Context
Stack base: #4158. Remote mirrors require Git 2.45.0+ so
GIT_NO_LAZY_FETCH=1keeps presence checks local. Older Git compatibility is outside scope. Initial Windows support is best-effort and rough-edged; canonical checkout support is unchanged.Changes
[]string.!helper form with POSIX single-quote escaping, verified through realgit credential fill.Testing
Focused and race tests cover allowlisting, ambient masking, prompt hiding, debug redaction, real helper execution from metacharacter paths, eligibility and option abbreviations, telemetry, classification, cancellation, and local-only probes.
Disclosures / Credits
Implemented with Cursor under human direction. Independent ship-risk, maintainability, and simplicity reviews pass on the final foundation diff.