Skip to main content

fallow_engine/
git_env.rs

1//! Git process environment helpers owned by the engine boundary.
2
3use std::process::{Command, Stdio};
4
5/// Environment variables that describe an enclosing git operation's repository
6/// state and should not leak into fallow-owned git subprocesses.
7pub const AMBIENT_GIT_ENV_VARS: &[&str] = &[
8    "GIT_DIR",
9    "GIT_WORK_TREE",
10    "GIT_INDEX_FILE",
11    "GIT_OBJECT_DIRECTORY",
12    "GIT_COMMON_DIR",
13    "GIT_PREFIX",
14];
15
16/// Strip ambient git repository-state environment variables from a `Command`.
17///
18/// Returns the `Command` for fluent chaining alongside `.args()` and
19/// `.current_dir()`.
20pub fn clear_ambient_git_env(cmd: &mut Command) -> &mut Command {
21    for var in AMBIENT_GIT_ENV_VARS {
22        cmd.env_remove(var);
23    }
24    cmd
25}
26
27/// Build a `git` command with the ambient repository-state environment cleared
28/// and stdin closed. Long-lived embedders keep protocol stdin open, which Git
29/// for Windows can inherit and hold.
30#[expect(
31    clippy::disallowed_methods,
32    reason = "engine-owned git spawn wrapper clears ambient git env before every git subprocess"
33)]
34pub fn git_command() -> Command {
35    let mut command = Command::new("git");
36    clear_ambient_git_env(&mut command);
37    command.stdin(Stdio::null());
38    command
39}