Skip to main content

Crate llmenv_git

Crate llmenv_git 

Source
Expand description

Consolidated git utilities.

Prevents malicious cloned repos from executing hooks or fsmonitors by centralizing GIT_CONFIG_FLAGS application across all git operations.

Constants§

DEFAULT_GIT_PLUGIN_TIMEOUT_SECS
Default TCP connection timeout for explicit, user-initiated git operations (clone/fetch for plugin installation). Longer than the background default because these are one-shot operations and users understand that a clone can take a moment.
DEFAULT_GIT_TIMEOUT_SECS
Default TCP connection timeout for background git operations (fetch/pull on every shell prompt). Short enough that a stuck remote doesn’t freeze the prompt; long enough that a briefly loaded GitHub doesn’t produce spurious failures.
GIT_CONFIG_FLAGS
Git config flags to protect cloned repos from executing hooks or fsmonitors. Prevents a malicious config repo from running arbitrary code via git hooks or fsmonitors.

Functions§

apply_git_timeout
Apply TCP connection and auth/transfer timeouts to a git command.
git_failure_detail
Build a human-readable failure detail from a git subprocess’s captured output. Prefers stderr (where git writes diagnostics), falls back to stdout (some errors — e.g. a git add index lock — print there), then to the exit status when both are empty. Control and ANSI escape bytes are stripped so a hostile remote’s error text can’t manipulate the terminal (#307), and the result is credential-scrubbed via sanitize_git_url so a URL with embedded credentials never echoes the secret to the terminal or logs (#312).
has_unpushed_commits
Check if current branch has commits not yet pushed to its upstream. Returns false if there’s no upstream, git fails, or output can’t be parsed — we only want to nudge the user when we’re certain there are unpushed commits.
sanitize_git_url
Scrub embedded credentials from a git URL before it lands in an error message or log. A URL like https://user:token@host/path becomes https://***@host/path; an SSH-style user@host:path becomes ***@host:path. Returns the input unchanged when no @ userinfo is present.
secure_git
Apply security config flags to a git command, with stdin detached.
working_tree_dirty
Check if the working tree has staged or unstaged changes.