# How Bare Repository Detection Works Under safe.bareRepository=explicit Mode

> Discover how safe.bareRepository=explicit mode enhances bare repository detection. Learn how the no-mistakes daemon ensures security by explicitly passing --git-dir to commands.

- Repository: [Kun Chen/no-mistakes](https://github.com/kunchenguid/no-mistakes)
- Tags: internals
- Published: 2026-07-25

---

**When `safe.bareRepository=explicit` is enabled, the no-mistakes daemon bypasses Git's automatic discovery by explicitly passing `--git-dir` to every command after validating the directory structure.**

The `kunchenguid/no-mistakes` repository implements a security-hardened Git workflow where gate directories function as bare repositories. When the Git configuration flag `safe.bareRepository=explicit` is set—the default for all agent harnesses—the system prevents any command from falling back to current-working-directory discovery. This protection ensures the daemon never accidentally walks up the directory tree to a parent work-tree or conflicts with stray `.git` directories.

## Structural Validation in `isBareGitDir`

Bare repository detection begins with filesystem inspection in [`internal/git/git.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/git/git.go). The `isBareGitDir` function (lines 94-112) validates the target directory by checking three specific conditions:

- The directory must contain a `HEAD` file
- The directory must contain an `objects` sub-directory
- The directory must **not** contain a `.git` directory (which would indicate a work-tree rather than a bare repository)

This structural validation serves as the first line of defense before any Git commands execute.

## Safe Execution with Explicit Git Directory

The execution flow guarantees that bare repositories never rely on ambient Git discovery.

### The `Run` Method Dispatch

The `Run` function in [`internal/git/git.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/git/git.go) (lines 31-40) implements the gatekeeper logic. According to the source comments at lines 31-36, `safe.bareRepository=explicit` "forbids … cwd‑based discovery," requiring all gate-related Git operations to use explicit `--git-dir` arguments.

When `Run(ctx, dir, …)` is invoked, it first calls `isBareGitDir`. If the target is a bare repository, the function immediately forwards the call to `RunBare` rather than allowing standard Git execution.

### `RunBare` Implementation

The `RunBare` function (lines 43-52) constructs safe Git invocations by:

1. Prepending `--git-dir=<bareDir>` to the argument list
2. Delegating execution to the generic `runInDir` helper

This ensures every Git command targets the explicit repository path, eliminating any dependency on the process's current working directory.

## Validation and Safety Checks

Beyond runtime execution, the system provides explicit validation utilities.

### `ValidateBareRepository`

The `ValidateBareRepository` function (lines 70-84) performs double verification:

1. **Structural confirmation**: Runs `isBareGitDir` to verify the filesystem layout
2. **Git confirmation**: Executes `git rev-parse --is-bare-repository` **via `RunBare`** to ensure Git itself reports the repository as bare

This two-phase validation occurs entirely through the safe execution path, preventing any cwd-based discovery during the verification process itself.

### `LooksLikeBareRepository`

For callers requiring only filesystem inspection without Git verification, `LooksLikeBareRepository` (lines 87-92) provides a lightweight wrapper around `isBareGitDir`. This convenience helper supports use cases where full validation is unnecessary.

## Practical Examples

The following patterns demonstrate safe bare repository interaction:

```go
// Running `git status` on a gate (bare) repo
ctx := context.Background()
gateDir := "/path/to/gate"               // e.g. NM_HOME/gates/<id>.git
out, err := git.Run(ctx, gateDir, "status")
if err != nil {
    log.Fatalf("git status failed: %v", err)
}
fmt.Println(out) // uses --git-dir=gateDir internally

```

```go
// Validating that a directory is a proper bare repository
ctx := context.Background()
if err := git.ValidateBareRepository(ctx, gateDir); err != nil {
    log.Fatalf("not a valid bare repo: %v", err)
}

```

```go
// Creating a new bare repository for a fresh gate
ctx := context.Background()
newGate := "/tmp/newgate.git"
if err := git.InitBare(ctx, newGate); err != nil {
    log.Fatalf("failed to init bare repo: %v", err)
}

```

## Security Configuration and Test Coverage

The `safe.bareRepository=explicit` flag is enforced across the codebase. Test coverage validates this behavior in:

- [`internal/pipeline/steps/steps_test.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/pipeline/steps/steps_test.go) – Injects the flag for agent testing
- [`internal/gate/gate_test.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/gate/gate_test.go) – Exercises the flag during gate initialization
- [`internal/daemon/helpers_test.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/daemon/helpers_test.go) – Confirms the flag's presence in daemon harnesses

These safeguards protect the gate from leaking into user workspaces and prevent corruption from stray `.git` directories.

## Summary

- **Structural detection** in `isBareGitDir` verifies bare repositories by checking for `HEAD` and `objects` while ensuring no `.git` directory exists
- **Explicit execution** via `Run` and `RunBare` forces `--git-dir` arguments on every Git invocation, bypassing cwd-based discovery
- **Double validation** in `ValidateBareRepository` confirms both filesystem structure and Git's own bare-repository reporting
- **Security default** means agent harnesses operate under `safe.bareRepository=explicit` to prevent directory traversal attacks

## Frequently Asked Questions

### How does the code prevent Git from using the current working directory for repository discovery?

The `Run` method in [`internal/git/git.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/git/git.go) intercepts all Git operations and routes bare repository calls through `RunBare`, which prepends `--git-dir=<path>` to every command. This explicit argument overrides Git's default behavior of walking up the directory tree to find a `.git` folder.

### What specific filesystem checks identify a bare repository?

The `isBareGitDir` function requires three conditions: the presence of a `HEAD` file, the existence of an `objects` subdirectory, and the absence of a `.git` directory. The lack of a `.git` folder distinguishes bare repositories from work-trees.

### Why does `ValidateBareRepository` run `git rev-parse` instead of trusting the filesystem check alone?

The function performs defense-in-depth validation. After confirming the directory structure, it executes `git rev-parse --is-bare-repository` through the safe `RunBare` path to verify that Git's own internal state matches the filesystem expectations, catching edge cases like corrupted or partially initialized repositories.

### Where is the `safe.bareRepository=explicit` configuration enforced in the test suite?

The flag is injected in agent harnesses across [`internal/pipeline/steps/steps_test.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/pipeline/steps/steps_test.go), [`internal/gate/gate_test.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/gate/gate_test.go), and [`internal/daemon/helpers_test.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/daemon/helpers_test.go). These tests ensure the daemon never accidentally relies on implicit repository discovery during gate operations.