Under the hoodTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
Git IntegrationArea: what it touches
Bug FixesKind: in v2.1.280,
Bug FixesSection of the release
What
The function that reopens a file to confirm it's still what git expects before writing now branches by platform: Windows uses fs.stat plus a plain open instead of O_NOFOLLOW, macOS gets its own no-follow flag handling, and there's an upfront check that the path is actually one git writes to.
On macOS, the open path now probes once (Nmo()) for whether the extended O_NOFOLLOW variant is supported, falling back to plain flags if not, instead of retrying after hitting an EINVAL error each time.
That probe result is now cached per-process (as "untried"/"works"/"rejected"), so once macOS is known not to support it, the code stops attempting it on every call.
Why
This avoids repeatedly hitting the same OS error on every file open and keeps the symlink-safety guard working correctly across Windows, macOS, and other platforms.