mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 15:08:24 +00:00
The hostile-config run that validated the init.defaultBranch=main fix was manual, so nothing stopped the next ambient-config assumption from landing silently. Install a deliberately hostile global gitconfig (init.defaultBranch=main, a failing pre-commit hook delivered through both core.hooksPath and init.templateDir, commit.gpgsign=true, core.autocrlf=true) before the test steps, so every CI run exercises it at no extra cost. The suite runs once, under the hostile config only: the hermetic git helpers make the tests config-blind, so a green hostile run implies the unset-config case as well (additionally verified by the grasp-audit regression unit test, which proves neutralisation against this same config in-process). The hostile settings reach only test-side git: the relay under test never runs `git commit`, so hooks and gpgsign cannot fire server-side, while init.defaultBranch deliberately does affect the relay's bare-repo HEAD - the exact regression this guards. Validated locally by running the full workspace suite with the global config masked and the git-heavy subset under this hostile config.