@@ -195,7 +195,8 @@ func TestDockerBindWorkspace_DiffRestoresTrustedGitConfig(t *testing.T) {
195195 }
196196
197197 dir := * workspace .WorkDir ()
198- configPath := filepath .Join (dir , ".git" , "config" )
198+ dotGit := filepath .Join (dir , ".git" )
199+ configPath := filepath .Join (dotGit , "config" )
199200 trustedConfig , err := os .ReadFile (configPath )
200201 if err != nil {
201202 t .Fatal (err )
@@ -210,6 +211,26 @@ func TestDockerBindWorkspace_DiffRestoresTrustedGitConfig(t *testing.T) {
210211 if err := config .Close (); err != nil {
211212 t .Fatal (err )
212213 }
214+
215+ // A commondir file redirects Git to the config in another directory. That
216+ // config must not survive metadata restoration and reach host-side Git.
217+ attackerCommon := filepath .Join (dir , "attacker-common" )
218+ if err := os .CopyFS (attackerCommon , os .DirFS (dotGit )); err != nil {
219+ t .Fatal (err )
220+ }
221+ attackerConfig , err := os .OpenFile (filepath .Join (attackerCommon , "config" ), os .O_APPEND | os .O_WRONLY , 0 )
222+ if err != nil {
223+ t .Fatal (err )
224+ }
225+ if _ , err := attackerConfig .WriteString ("[filter \" attack\" ]\n \t clean = command-that-must-not-run\n \t required = true\n " ); err != nil {
226+ t .Fatal (err )
227+ }
228+ if err := attackerConfig .Close (); err != nil {
229+ t .Fatal (err )
230+ }
231+ if err := os .WriteFile (filepath .Join (dotGit , "commondir" ), []byte ("../attacker-common\n " ), 0644 ); err != nil {
232+ t .Fatal (err )
233+ }
213234 if err := os .WriteFile (filepath .Join (dir , ".gitattributes" ), []byte ("*.txt filter=attack\n " ), 0644 ); err != nil {
214235 t .Fatal (err )
215236 }
@@ -231,6 +252,9 @@ func TestDockerBindWorkspace_DiffRestoresTrustedGitConfig(t *testing.T) {
231252 if ! cmp .Equal (restoredConfig , trustedConfig ) {
232253 t .Fatalf ("Git config was not restored:\n %s" , cmp .Diff (string (trustedConfig ), string (restoredConfig )))
233254 }
255+ if _ , err := os .Stat (filepath .Join (dotGit , "commondir" )); ! os .IsNotExist (err ) {
256+ t .Fatalf ("untrusted commondir was not removed: %v" , err )
257+ }
234258}
235259
236260func TestUnzipRejectsGitMetadata (t * testing.T ) {
0 commit comments