Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,10 @@ Versions follow [SemVer](https://semver.org).
- The review and verify posting CLIs now share one gate for the untrusted
emitted envelope, so a security fix to the decode/identity/kind checks lands
in both (#337).
- The `.git` guard's object read no longer derives filter-driver overrides
(`cat-file -e` never converts working-tree files), dropping one
`git config --get-regexp` subprocess from every guarded kernel git call
with no change to what is refused or neutralized (#512).
- A review round refused because the pinned harness is too old for the model,
or because the runner's harness install is missing or stale, now says which
and how to fix it instead of calling it an API outage (#475).
Expand Down
4 changes: 3 additions & 1 deletion src/outerloop/github.py
Original file line number Diff line number Diff line change
Expand Up @@ -1248,9 +1248,11 @@ def _unreadable(err: OSError) -> None:
sha = _head_commit_sha(git_dir) or _any_ref_sha(git_dir)
if sha is not None:
try:
# No root, so no filter-override listing: `cat-file -e` never
# converts working-tree files, so no filter driver can run in it.
_run_git(
["git", "-C", str(root), *SAFE_GIT_FLAGS, "cat-file", "-e", f"{sha}^{{commit}}"],
_git_env(None, Path(root)),
_git_env(None),
Comment thread
renmengye marked this conversation as resolved.
timeout=GUARD_GIT_TIMEOUT_S, # a stalled read is refused, not waited on
)
except GitError as exc:
Expand Down
Loading