In packages/code/src/native-sandbox.ts, linked worktree lanes add GIT_CONFIG_KEY_4/VALUE_4 (gc.auto=0) and GIT_CONFIG_KEY_5/VALUE_5 (maintenance.auto=false) through LINKED_WORKTREE_GIT_ENVIRONMENT. The sandbox credentials.envVars deny-list excludes only keys in TRUSTED_GIT_ENVIRONMENT. If the host environment contains those lane-only Git config names, the deny entries can remove the injected overrides from the inner command, allowing automatic Git gc/maintenance to mutate object storage shared with sibling lanes. Exclude this.gitEnvironment (or the full lane environment) from the deny list and test that the lane-only keys survive into the inner command. Found in downstream sync review: https://github.com/ClickHouse/ai/pull/4089#discussion_r4133565568
In packages/code/src/native-sandbox.ts, linked worktree lanes add GIT_CONFIG_KEY_4/VALUE_4 (gc.auto=0) and GIT_CONFIG_KEY_5/VALUE_5 (maintenance.auto=false) through LINKED_WORKTREE_GIT_ENVIRONMENT. The sandbox credentials.envVars deny-list excludes only keys in TRUSTED_GIT_ENVIRONMENT. If the host environment contains those lane-only Git config names, the deny entries can remove the injected overrides from the inner command, allowing automatic Git gc/maintenance to mutate object storage shared with sibling lanes. Exclude this.gitEnvironment (or the full lane environment) from the deny list and test that the lane-only keys survive into the inner command. Found in downstream sync review: https://github.com/ClickHouse/ai/pull/4089#discussion_r4133565568