Skip to content

Exclude Git metadata from local extension installs - #1329

Merged
unbraind merged 1 commit into
mainfrom
fix/exclude-git-metadata-from-local-package-installs
Sep 27, 2026
Merged

unbraind merged 1 commit into
mainfrom
fix/exclude-git-metadata-from-local-package-installs

Conversation

@unbraind

@unbraind unbraind commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Exclude .git directories, worktree files, and symlinks at every depth from extension directory installs. The SDK install plan and runtime copy now use the same policy, and the plan counts excluded entries.
  • Add a real Git checkout regression covering dry-run planning and project/global installation and activation. Update the install evidence guide.
  • Regenerate CHANGELOG.md with the current pm-changelog package and carry PM closeout and live audit evidence in the reviewed branch.

PM lineage

Closes #1324.

Verification

  • Real disposable Git checkout: built CLI project and global installs activated, reported two exclusions each, and copied no root or nested .git metadata.
  • Focused extension tests: 16 passed; PM-linked focused tests passed in isolated tracker roots.
  • Full suite: 9,374 passed, two platform-specific skips; exact statements/branches/functions/lines coverage: 100/100/100/100.
  • Packed npm/npx/Bun/bunx smoke: nine packages passed. Docs/skills, changelog check, graph composition, record integrity, defect evidence, and mutation gates passed.
  • Local aggregate static passed its preceding checks and stopped at the unchanged CLI transport latency floor under host load 22.70 on eight CPUs. A standalone rerun missed a different command by 13 ms. Hosted exact-head static and benchmark checks are required before merge.

Summary by Sourcery

Exclude Git metadata from local extension installs while keeping planning, runtime copying, documentation, and regression coverage consistent.

Bug Fixes:

  • Prevent local extension directory installs from copying Git metadata, including nested repositories, worktree files, and symlinked Git directories.

Enhancements:

  • Align install planning and runtime copying around a shared exclusion policy and report excluded entries in install plans.

Documentation:

  • Update package installation evidence documentation to describe Git metadata exclusions and exclusion counts.

Tests:

  • Add regression coverage using a real Git checkout for dry-run planning and project/global installation and activation.

Chores:

  • Regenerate the changelog and update associated project-management tracking evidence.

Summary by cubic

Fixes local extension directory installs copying the source checkout's Git metadata (.git config, refs, object history) into the managed extension.

  • Install plans and runtime copies now share an exclusion policy that omits .git directories, worktree files, and symlinks at every depth, with excluded entries counted in the plan.
  • Adds a regression test using a real Git checkout covering dry-run planning and project/global installation and activation.
  • Updates the install evidence docs and adds a changelog security entry with closed PM issue pm-k7nxaz (Closes Local package install copies .git repository history into managed extension #1324).

Written for commit d616195. Summary will update on new commits.

Review in cubic

Apply a shared SDK copy policy to install plans and runtime copies so root and nested .git directories, worktree files, and symlinks are omitted and counted. Verify project and global activation with a real Git checkout regression and a disposable CLI acceptance run.

Close the tracked defect with exact coverage and package smoke evidence, regenerate the changelog, and record current release, quality-gate, and historical tracker observations.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 day and 19 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Advanced

Run ID: beedd51c-c3ba-4aff-a117-e802cc57fea4

📥 Commits

Reviewing files that changed from the base of the PR and between 2b14d2f and d616195.

📒 Files selected for processing (18)
  • .agents/pm/chores/pm-e9zh.toon
  • .agents/pm/extensions/.managed-extensions.json
  • .agents/pm/history/pm-7wmq.jsonl
  • .agents/pm/history/pm-e70zh5.jsonl
  • .agents/pm/history/pm-e9zh.jsonl
  • .agents/pm/history/pm-k7nxaz.jsonl
  • .agents/pm/history/pm-yse5dt.jsonl
  • .agents/pm/issues/pm-e70zh5.toon
  • .agents/pm/issues/pm-k7nxaz.toon
  • .agents/pm/tasks/pm-7wmq.toon
  • .agents/pm/tasks/pm-yse5dt.toon
  • CHANGELOG.md
  • docs/PACKAGE_EVIDENCE.md
  • src/sdk/extension/copy-scope.ts
  • src/sdk/extension/install-plan.ts
  • src/sdk/extension/install-runtime.ts
  • tests/unit/extensions/extension-copy-safety.spec.ts
  • tests/unit/extensions/extension-install-dry-run.spec.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Summary

Summary by CodeRabbit

  • Security
    • Local directory installs now exclude Git metadata—including nested .git directories, worktree files, and Git-related symlinks—from copied extensions. Extensions continue to activate normally, and excluded entries are reflected in the install plan.
  • Documentation
    • Updated package-install guidance to describe which development and installer files are excluded from copied directories.

Walkthrough

Local extension installs now exclude Git metadata from copied sources. The change updates copy planning and runtime filtering, adds checkout-based regression coverage, and records the policy and related validation results.

Changes

Local package copy behavior

Layer / File(s) Summary
Exclude Git metadata during copy
src/sdk/extension/copy-scope.ts, src/sdk/extension/install-plan.ts, src/sdk/extension/install-runtime.ts, tests/unit/extensions/*
The path filter excludes .git entries for local copies. Planning and runtime paths pass the nested-destination mode. Tests verify exclusions, install activation, and copy options.
Document and record the copy policy
.agents/pm/issues/pm-k7nxaz.toon, .agents/pm/history/pm-k7nxaz.jsonl, CHANGELOG.md, docs/PACKAGE_EVIDENCE.md
The issue and history record criteria, implementation references, and verification. The changelog and package evidence documentation describe the copy exclusions.

PM validation and run updates

Layer / File(s) Summary
Update validation and run records
.agents/pm/chores/*, .agents/pm/extensions/.managed-extensions.json, .agents/pm/history/*, .agents/pm/issues/pm-e70zh5.toon, .agents/pm/tasks/*
PM records report history-validation results, scheduled-run reliability, a successful CI rerun after a blocked package download, and local transport-floor measurements. The managed-extensions timestamp is updated.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Bug fix · Severity of issue fixed: Medium

Possibly related PRs

  • unbraind/pm-cli#1128: Establishes the pm package lifecycle and install command contract used by this change.

Merge Risk: ⚪ Minimal · up to d6161

The reliability record needs no correction, and the supplied evidence identifies no remaining issue that should block this change.

Security Architecture Review

Security architecture risk: 🔵 Low · up to d6161

The change reduces Git-metadata exposure in copied extensions, and no new public install path or weakened containment control was identified. Differently named links to Git metadata and abrupt interruption remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The affected boundary is a selected local extension directory being copied into a persistent install and activated. The changed filter narrows which Git-named paths cross that boundary.

Trust Boundaries and Controls

  • observed — The same .git exclusion precedes the direct-versus-nested branch of the predicate. A non-.git symlink name is not excluded on that basis; available evidence does not establish a newly introduced exposure through such a link.

Resilience and Maintainability Implications

  • observed — Normal repeat-copy attempts remove the destination before recopying, and handled install errors invoke snapshot restoration. Abrupt interruption remains outside the demonstrated cleanup guarantee.

Hardening Proposals

  • proposed — If the intended guarantee covers access through aliases as well as copied .git-named paths, explicitly define and test the treatment of differently named symlinks to Git metadata.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Out of Scope Changes check ⚠️ Warning The implementation, tests, documentation, changelog, and pm-k7nxaz tracking records support issue #1324. The PR also changes unrelated project-management records for other work, including `pm-e70zh5… Remove the unrelated project-management and audit updates for pm-e70zh5, pm-7wmq, pm-e9zh, and pm-yse5dt from this pull request. Keep only records directly tied to issue #1324 and its implementation.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: excluding Git metadata from local extension installs.
Description check ✅ Passed The description directly explains the Git metadata exclusion, shared install policy, regression tests, documentation updates, and verification evidence.
Linked Issues check ✅ Passed Issue #1324 requires exclusion of Git metadata at every depth, exclusion counts, preserved runtime files, and a real Git-checkout regression. includesExtensionCopyPath rejects every path containing …
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 5 files. (13 skipped: 1…
Full details: Out of Scope Changes check

Explanation

The implementation, tests, documentation, changelog, and pm-k7nxaz tracking records support issue #1324. The PR also changes unrelated project-management records for other work, including pm-e70zh5, pm-7wmq, pm-e9zh, and pm-yse5dt, plus their task/history records. Those changes do not implement Git metadata exclusion or its regression coverage.

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Sep 27, 2026

Copy link
Copy Markdown

Reviewer's Guide

Local extension directory installs now use a shared filtering policy that excludes Git metadata—including nested .git directories, worktree files, and symlinks—during both planning and copying, reports the exclusions, and is covered by a real Git checkout regression spanning dry-run, project, and global installation paths; documentation, changelog, and PM evidence were regenerated accordingly.

Sequence diagram for Git metadata exclusion during extension install

sequenceDiagram
    participant CLI
    participant Planner
    participant Runtime
    participant Filesystem

    CLI->>Planner: scanExtensionCopyDirectory
    loop each directory entry
        Planner->>Planner: includesExtensionCopyPath
        alt path includes .git
            Planner->>Planner: increment excluded_entries
        else path is allowed
            Planner->>Planner: include entry in install plan
        end
    end
    CLI->>Runtime: copyExtensionDirectoryWithoutSelfNesting
    Runtime->>Filesystem: copyDirectory
    Filesystem->>Runtime: evaluate filter
    Runtime->>Runtime: includesExtensionCopyPath
    alt path includes .git
        Runtime-->>Filesystem: skip entry
    else path is allowed
        Runtime-->>Filesystem: copy entry
    end
Loading

File-Level Changes

Change Details Files
Unify Git metadata exclusion across install planning and runtime directory copying.
  • Extend the copy-scope predicate to reject .git path segments at any depth while retaining nested-destination filtering behavior.
  • Apply the predicate to both top-level and nested runtime copies, including symlink paths.
  • Count filtered entries in install-plan excluded_entries.
  • Update copy-safety expectations for the runtime filter.
src/sdk/extension/copy-scope.ts
src/sdk/extension/install-plan.ts
src/sdk/extension/install-runtime.ts
tests/unit/extensions/extension-copy-safety.spec.ts
Add end-to-end regression coverage for installing real Git checkouts.
  • Create a temporary Git repository with root and nested metadata, a worktree file, and a nested Git symlink where supported.
  • Verify dry-run and project/global installs report the expected exclusions, activate successfully, and omit all Git metadata from destinations.
tests/unit/extensions/extension-install-dry-run.spec.ts
Document the expanded local-directory install policy and release evidence.
  • Clarify that .git directories, worktree files, and symlinks are excluded at every depth and counted by the planner.
  • Add the security changelog entry and update PM tracking, history, managed-extension, and evidence records.
docs/PACKAGE_EVIDENCE.md
CHANGELOG.md
.agents/pm/chores/pm-e9zh.toon
.agents/pm/extensions/.managed-extensions.json
.agents/pm/history/pm-7wmq.jsonl
.agents/pm/history/pm-e70zh5.jsonl
.agents/pm/history/pm-e9zh.jsonl
.agents/pm/history/pm-k7nxaz.jsonl
.agents/pm/history/pm-yse5dt.jsonl
.agents/pm/issues/pm-e70zh5.toon
.agents/pm/issues/pm-k7nxaz.toon
.agents/pm/tasks/pm-7wmq.toon
.agents/pm/tasks/pm-yse5dt.toon

Assessment against linked issues

Issue Objective Addressed Explanation
#1324 Exclude Git metadata from local-directory extension snapshots at every depth, including root and nested .git directories, worktree .git files, and symlinked Git metadata, in both installation planning and the actual copy. ✅
#1324 Report the number of excluded Git metadata entries in the install plan while preserving complete successful scans. ✅
#1324 Ensure extensions installed from Git checkouts still retain required runtime files and activate successfully, with regression coverage using real Git metadata and project/global installations. ✅

Possibly linked issues


Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@unbraind

Copy link
Copy Markdown
Owner Author

@coderabbitai full review
@greptileai

@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

@codspeed

codspeed Bot commented Sep 27, 2026

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 11 untouched benchmarks


Comparing fix/exclude-git-metadata-from-local-package-installs (d616195) with main (2b14d2f)

Open in CodSpeed

@codecov

codecov Bot commented Sep 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

@unbraind
unbraind merged commit 0c3b008 into main Sep 27, 2026
40 of 41 checks passed
@unbraind
unbraind deleted the fix/exclude-git-metadata-from-local-package-installs branch September 27, 2026 11:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Local package install copies .git repository history into managed extension

1 participant