From 3a10f6ad17faf7f5a4abb83e27ce2f2d3868d9fb Mon Sep 17 00:00:00 2001 From: Dai Ha Date: Sat, 15 Aug 2026 13:09:01 +0200 Subject: [PATCH] Note that stage C's snapshot makes the parityOverlay gitignore rule load-bearing MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit CB-578 stage C commits a preserved dirty worktree to refs/wip/ with git add -A. The parity overlay copies the primary's environment files into every worktree, so a non-gitignored overlay path now reaches a durable git object instead of only sitting on disk. add -A respects .gitignore, which is what stops it — so the rule documented for CB-581 is now what keeps a secret out of a commit, not just out of a directory. --- .../main/java/dev/ltms/bridged/config/BridgedConfig.java | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/bridged/src/main/java/dev/ltms/bridged/config/BridgedConfig.java b/bridged/src/main/java/dev/ltms/bridged/config/BridgedConfig.java index b142b62..4c88a05 100644 --- a/bridged/src/main/java/dev/ltms/bridged/config/BridgedConfig.java +++ b/bridged/src/main/java/dev/ltms/bridged/config/BridgedConfig.java @@ -187,6 +187,14 @@ public record BridgedConfig( * every profile, so creating either file at the repo root is enough * to make it live. Add a new overlay path to {@code .gitignore} in the same * change that adds it here. + *

CB-578 stage C raised the stakes: a preserved dirty worktree is now also + * committed to {@code refs/wip/} via {@code git add -A}. The overlay + * carries the primary's own environment files into the worktree, so a + * non-gitignored overlay path no longer merely sits there as an untracked + * file — it gets committed into a git object that survives the worktree's + * removal. {@code add -A} respects {@code .gitignore}, which is exactly what + * keeps that from happening, so the gitignore rule above is now what stops a + * secret from reaching a durable commit. * @param gitTokenEnv name of the host env var holding the git-forge API token; when set, its * value is injected as {@code GITEA_TOKEN} so the worker can open its own PR * at checkpoint (CB-302). {@code null}/blank ⇒ no token is injected