How Bare Repository Detection Works Under safe.bareRepository=explicit Mode
When safe.bareRepository=explicit is enabled, the no-mistakes daemon bypasses Git's automatic discovery by explicitly passing --git-dir to every command after validating the directory structure.
The kunchenguid/no-mistakes repository implements a security-hardened Git workflow where gate directories function as bare repositories. When the Git configuration flag safe.bareRepository=explicit is set—the default for all agent harnesses—the system prevents any command from falling back to current-working-directory discovery. This protection ensures the daemon never accidentally walks up the directory tree to a parent work-tree or conflicts with stray .git directories.
Structural Validation in isBareGitDir
Bare repository detection begins with filesystem inspection in internal/git/git.go. The isBareGitDir function (lines 94-112) validates the target directory by checking three specific conditions:
- The directory must contain a
HEADfile - The directory must contain an
objectssub-directory - The directory must not contain a
.gitdirectory (which would indicate a work-tree rather than a bare repository)
This structural validation serves as the first line of defense before any Git commands execute.
Safe Execution with Explicit Git Directory
The execution flow guarantees that bare repositories never rely on ambient Git discovery.
The Run Method Dispatch
The Run function in internal/git/git.go (lines 31-40) implements the gatekeeper logic. According to the source comments at lines 31-36, safe.bareRepository=explicit "forbids … cwd‑based discovery," requiring all gate-related Git operations to use explicit --git-dir arguments.
When Run(ctx, dir, …) is invoked, it first calls isBareGitDir. If the target is a bare repository, the function immediately forwards the call to RunBare rather than allowing standard Git execution.
RunBare Implementation
The RunBare function (lines 43-52) constructs safe Git invocations by:
- Prepending
--git-dir=<bareDir>to the argument list - Delegating execution to the generic
runInDirhelper
This ensures every Git command targets the explicit repository path, eliminating any dependency on the process's current working directory.
Validation and Safety Checks
Beyond runtime execution, the system provides explicit validation utilities.
ValidateBareRepository
The ValidateBareRepository function (lines 70-84) performs double verification:
- Structural confirmation: Runs
isBareGitDirto verify the filesystem layout - Git confirmation: Executes
git rev-parse --is-bare-repositoryviaRunBareto ensure Git itself reports the repository as bare
This two-phase validation occurs entirely through the safe execution path, preventing any cwd-based discovery during the verification process itself.
LooksLikeBareRepository
For callers requiring only filesystem inspection without Git verification, LooksLikeBareRepository (lines 87-92) provides a lightweight wrapper around isBareGitDir. This convenience helper supports use cases where full validation is unnecessary.
Practical Examples
The following patterns demonstrate safe bare repository interaction:
// Running `git status` on a gate (bare) repo
ctx := context.Background()
gateDir := "/path/to/gate" // e.g. NM_HOME/gates/<id>.git
out, err := git.Run(ctx, gateDir, "status")
if err != nil {
log.Fatalf("git status failed: %v", err)
}
fmt.Println(out) // uses --git-dir=gateDir internally
// Validating that a directory is a proper bare repository
ctx := context.Background()
if err := git.ValidateBareRepository(ctx, gateDir); err != nil {
log.Fatalf("not a valid bare repo: %v", err)
}
// Creating a new bare repository for a fresh gate
ctx := context.Background()
newGate := "/tmp/newgate.git"
if err := git.InitBare(ctx, newGate); err != nil {
log.Fatalf("failed to init bare repo: %v", err)
}
Security Configuration and Test Coverage
The safe.bareRepository=explicit flag is enforced across the codebase. Test coverage validates this behavior in:
internal/pipeline/steps/steps_test.go– Injects the flag for agent testinginternal/gate/gate_test.go– Exercises the flag during gate initializationinternal/daemon/helpers_test.go– Confirms the flag's presence in daemon harnesses
These safeguards protect the gate from leaking into user workspaces and prevent corruption from stray .git directories.
Summary
- Structural detection in
isBareGitDirverifies bare repositories by checking forHEADandobjectswhile ensuring no.gitdirectory exists - Explicit execution via
RunandRunBareforces--git-dirarguments on every Git invocation, bypassing cwd-based discovery - Double validation in
ValidateBareRepositoryconfirms both filesystem structure and Git's own bare-repository reporting - Security default means agent harnesses operate under
safe.bareRepository=explicitto prevent directory traversal attacks
Frequently Asked Questions
How does the code prevent Git from using the current working directory for repository discovery?
The Run method in internal/git/git.go intercepts all Git operations and routes bare repository calls through RunBare, which prepends --git-dir=<path> to every command. This explicit argument overrides Git's default behavior of walking up the directory tree to find a .git folder.
What specific filesystem checks identify a bare repository?
The isBareGitDir function requires three conditions: the presence of a HEAD file, the existence of an objects subdirectory, and the absence of a .git directory. The lack of a .git folder distinguishes bare repositories from work-trees.
Why does ValidateBareRepository run git rev-parse instead of trusting the filesystem check alone?
The function performs defense-in-depth validation. After confirming the directory structure, it executes git rev-parse --is-bare-repository through the safe RunBare path to verify that Git's own internal state matches the filesystem expectations, catching edge cases like corrupted or partially initialized repositories.
Where is the safe.bareRepository=explicit configuration enforced in the test suite?
The flag is injected in agent harnesses across internal/pipeline/steps/steps_test.go, internal/gate/gate_test.go, and internal/daemon/helpers_test.go. These tests ensure the daemon never accidentally relies on implicit repository discovery during gate operations.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →