{"version":"2.1.281","anchor":"dir-sync-git-re-reads-when-git-itself-changes-telemetry-o","canonical_anchor":"dir-sync-git-re-reads-when-git-itself-changes-telemetry-o","heading":"Directory sync's git safety checks are stricter","tier":null,"area":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/dir-sync-git-re-reads-when-git-itself-changes-telemetry-o","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Directory sync's git safety checks are stricter\n\nDirectory sync now re-checks git when .git changes, reports clearer reasons when no safe git is found, and flags risky git config locations\n\n**What**\n\nDirectory sync is the process that keeps a local folder and a cloud session in step. It runs git, and before doing so it checks the git program and git's configuration files for anything that could run unexpected code. Those checks are stricter in this release.\n\n- Re-reading when .git changes: the saved copy of the git configuration is now thrown away when the `.git` entry itself changes (its type, device, inode or change time), recorded as `dotgit_changed`. Before, only changes to the config files triggered a re-read.\n\n- Cache scoping: the saved configuration is now also keyed by the reach scope, meaning the set of locations the session is allowed to use.\n\n- Clearer reasons when git isn't found: the report for \"no usable git on the start path\" now says `only_inside_reach` or `settings_unreadable`. Before, it carried no detail.\n\n- New warning: a warning appears when the only git program available sits somewhere the cloud session itself could write to.\n\n- Git version: the git major and minor version is now recorded.\n\n- Config inspector: the git config inspector (`Vk`) can now return `settings_unreadable`, `home_checkout` and `config_in_checkout` (with the checkout path), in addition to the earlier kinds `unread`, `includes`, `second_name`, `work_tree` and `worktree_config`. It also follows config includes into those locations, and returns `unread` for checkouts it cannot vouch for.\n\n**Why**\n\nThese checks aim to stop sync from running a git program, or loading git configuration, that the cloud session could have planted. Examples are a config file included from inside a repository checkout, or a checkout in your home directory. In practice, sync may now decline to run git in setups it used to accept, and it gives a more specific reason when it does."}