What
Claude Code's internal checks for tampered or unusual git repositories have been strengthened in several ways:
- Paths containing a 'character device' (a special kind of filesystem entry, not a normal file or folder) are now specifically detected and refused or guarded against during repo verification.
- Worktree config (settings tied to a secondary git worktree) can now be treated as a recognized 'extension' instead of always being refused, controlled by a new
perWorktreeConfigoption that defaults to "refuse". - Git's split-index files (named
sharedindex.*) are now copied into Claude Code's sandboxed internal git copy, up to a capped number of files, so operations relying on a split index continue to work. - When Claude Code runs git commands in its hardened mode, it now passes through a curated list of allowed
GIT_*, proxy, and SSH-related environment variables, instead of stripping all environment variables.
Why
These changes make Claude Code's git safety checks more precise: instead of broadly refusing or stripping things that look unusual, it now recognizes and correctly handles more legitimate git setups (like repos using split indexes, worktrees, or environment-based proxy/SSH configuration) while still guarding against tampered paths involving device files.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
The finding does not fully specify what triggers refuse-vs-guard behavior for character-device paths, nor the exact cap on split-index files…