Skip to content

fix(bench): isolate evaluator Git from candidate config#620

Merged
drewstone merged 1 commit into
mainfrom
fix/pier-git-sandbox-escape
Jul 25, 2026
Merged

fix(bench): isolate evaluator Git from candidate config#620
drewstone merged 1 commit into
mainfrom
fix/pier-git-sandbox-escape

Conversation

@drewstone

Copy link
Copy Markdown
Contributor

Closes #559.

Replaces candidate-owned repository config before evaluator Git runs, applies command-line protections to every post-run Git command, and excludes .sidecar from captured solutions. Adds a real isolated-user regression test covering filesystem monitors, clean filters, hooks, and SHA-1/SHA-256 repositories.

Checks: Pier 23/23; Bench 61/61 files; Runtime build; public TypeScript; Ruff/format; direct isolated-user test 2/2.

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved drewstone PR — c95cc1d7

This PR was opened by the trusted drewstone account.
The full PR reviewer audit still runs separately and will publish findings if it detects issues.

tangletools · auto-approval · reason: drewstone_author · 2026-07-25T01:18:37Z

@drewstone
drewstone merged commit f4d9824 into main Jul 25, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bench(pier): root-run git against candidate-owned .git executes core.fsmonitor/filter programs (sandbox escape)

2 participants