{"version":"2.1.280","anchor":"git-tamper-detection-hardened-character-device-paths-split","canonical_anchor":"git-tamper-detection-hardened-character-device-paths-split","heading":"Git tamper-detection hardened: character-device paths, split-index copying, and a curated git env-var allowlist","tier":"notice","area":"Git Integration","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280\/e\/git-tamper-detection-hardened-character-device-paths-split","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280","markdown":"### Git tamper-detection hardened: character-device paths, split-index copying, and a curated git env-var allowlist\n\nClaude Code hardened its git repo-tampering checks: device-file detection, split-index copying, and a curated env-var allowlist\n\n**Unclear.** The finding does not fully specify what triggers refuse-vs-guard behavior for character-device paths, nor the exact cap on split-index files copied.\n\n**What**\n\nClaude Code's internal checks for tampered or unusual git repositories have been strengthened in several ways:\n\n- Paths containing a 'character device' (a special kind of filesystem entry, not a normal file or folder) are now specifically detected and refused or guarded against during repo verification.\n\n- Worktree config (settings tied to a secondary git worktree) can now be treated as a recognized 'extension' instead of always being refused, controlled by a new `perWorktreeConfig` option that defaults to \"refuse\".\n\n- Git's split-index files (named `sharedindex.*`) are now copied into Claude Code's sandboxed internal git copy, up to a capped number of files, so operations relying on a split index continue to work.\n\n- When Claude Code runs git commands in its hardened mode, it now passes through a curated list of allowed `GIT_*`, proxy, and SSH-related environment variables, instead of stripping all environment variables.\n\n**Why**\n\nThese changes make Claude Code's git safety checks more precise: instead of broadly refusing or stripping things that look unusual, it now recognizes and correctly handles more legitimate git setups (like repos using split indexes, worktrees, or environment-based proxy\/SSH configuration) while still guarding against tampered paths involving device files.\n\n- Area: Git Integration\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5"}