Skip to content

fix(git): treat selected commit paths literally#3998

Merged
juliusmarminge merged 2 commits into
pingdotgg:mainfrom
EricTsai83:fix/literal-selected-commit-paths
Jul 17, 2026
Merged

fix(git): treat selected commit paths literally#3998
juliusmarminge merged 2 commits into
pingdotgg:mainfrom
EricTsai83:fix/literal-selected-commit-paths

Conversation

@EricTsai83

@EricTsai83 EricTsai83 commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

What Changed

  • Pass Git's global --literal-pathspecs option when staging explicitly selected files.
  • Add regression coverage for selected filenames containing Git pathspec metacharacters.

Why

Selected paths come from UI file selections and represent concrete filenames.

Without literal pathspec handling, Git interprets metacharacters in a filename as pathspec syntax. For example, selecting selected[1].txt can stage selected1.txt instead.

The existing -- separator prevents paths from being parsed as command options, but it does not disable Git pathspec expansion.

This keeps Git's normal pathspec behavior unchanged elsewhere and applies literal handling only at the exact-file selection boundary.

Testing

  • vp test run apps/server/src/vcs/GitVcsDriverCore.test.ts — passed (25 tests)
  • vp check — passed
  • vp run typecheck — passed
  • vp run test — attempted; desktop suites could not load because Electron is not installed correctly in the local environment (Electron failed to install correctly)

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • No UI changes
  • No animation or interaction changes

Note

Low Risk
Narrow change at the selected-file staging boundary with a targeted test; no auth, UI, or broad git behavior changes.

Overview
Partial commits from UI file selections now stage exact paths instead of letting Git treat brackets and other metacharacters as pathspec globs.

prepareCommitContext adds --literal-pathspecs to the git add call when filePaths is non-empty, so a selection like selected[1].txt no longer also picks up selected1.txt. Staging everything (add -A with no path list) is unchanged.

A regression test covers the bracket-in-filename case.

Reviewed by Cursor Bugbot for commit 5fb91ea. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix prepareCommitContext to treat selected file paths as literal pathspecs

Adds --literal-pathspecs to the git add invocation in GitVcsDriverCore.ts when staging specific files, preventing git from interpreting special characters (e.g. brackets) as glob patterns. A test verifies that a file named selected[1].txt is staged without also matching selected1.txt.

Macroscope summarized 5fb91ea.

@coderabbitai

coderabbitai Bot commented Jul 15, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 9ba75fe6-1fed-4824-a66a-3f028c0eda0f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Jul 15, 2026
@macroscopeapp

macroscopeapp Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved

Straightforward bug fix adding git's --literal-pathspecs flag to prevent file paths with special characters (e.g., [1]) from being interpreted as glob patterns. Single line change with comprehensive test coverage.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge
juliusmarminge enabled auto-merge (squash) July 17, 2026 11:11
@juliusmarminge
juliusmarminge merged commit 58302b2 into pingdotgg:main Jul 17, 2026
14 checks passed
adamfgr pushed a commit to agriffiths-bots/t3code that referenced this pull request Jul 18, 2026
* [codex] Expand real-route app store screenshot harness (pingdotgg#4014)

Co-authored-by: codex <codex@users.noreply.github.com>

* fix(server): use CLAUDE_CONFIG_DIR instead of HOME for Claude instanc… (pingdotgg#4017)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* feat: show nightly update changelog tooltip (pingdotgg#3832)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(git): treat selected commit paths literally (pingdotgg#3998)

* fix(server): stabilize non-repository Git diagnostics (pingdotgg#4077)

* Refresh app icons across release variants (pingdotgg#4080)

Co-authored-by: codex <codex@users.noreply.github.com>

* Update marketing GitHub star count (pingdotgg#4088)

* fix(marketing): correct Cursor icon color (pingdotgg#4090)

* Normalize protocol-relative remote host input as https (pingdotgg#3971)

* fix(cursor): default binary path to cursor-agent (avoid path conflict w/ grok) (pingdotgg#4094)

* Fix documented task-runner commands (bun run -> vp) (pingdotgg#3965)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* Allow preview panel to grow on wide displays (pingdotgg#4044)

* fix: prevent initial right-click from selecting a context menu item (pingdotgg#3877)

* Fix duplicate keybinding rule when replacing with an existing rule (pingdotgg#3969)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(server): image upload crashed dispatchCommand with a stack overflow (pingdotgg#3952)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* Remove unused code parameter from describePreviewError (pingdotgg#3970)

Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>

* [codex] prevent ACP assistant ID collisions after restarts (pingdotgg#3932)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(web): inset Windows desktop scrollbars from resize edge (pingdotgg#4097)

Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>

* [codex] fix mobile composer Enter behavior (pingdotgg#3930)

Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>

* feat(server): include runtime model and effort in Codex developer instructions (pingdotgg#3948)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(ux): spamming cmd + , no longer stack opening settings (pingdotgg#2757)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(terminal): strip AppImage runtime env from spawned terminals (pingdotgg#3108)

Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>

* fix(server): thread cwd through Claude capability probe (pingdotgg#2048) (pingdotgg#2124)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* [codex] fix: guard invalid web timestamps (pingdotgg#3515)

Co-authored-by: Codex <codex@openai.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* [codex] fix: tolerate invalid latest user message timestamps (pingdotgg#3521)

Co-authored-by: Codex <codex@openai.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* [codex] Fix provider update checks restore defaults (pingdotgg#3531)

Co-authored-by: Codex <codex@openai.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(server): skip undecodable provider runtime rows when listing sessions (pingdotgg#3951)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
Co-authored-by: codex <codex@users.noreply.github.com>

* Share MCP OAuth locks across Codex shadow homes (pingdotgg#4104)

* Preserve T3 Code identity in macOS development launcher (pingdotgg#4102)

* fix(web): increase contrast of question option descriptions (pingdotgg#3867)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(sync): reconcile fork divergences after upstream cherry-picks

Post-cherry-pick fixups for the 20260718 upstream sync:
- ElectronUpdater: restore setAllowDowngrade key dropped during pingdotgg#3832 conflict resolution
- AcpSessionRuntime: thread assistantItemRuntimeId through the fork's
  session/load replay path (observeSessionLoadAssistantSegments +
  ensureActiveAssistantSegmentState) to match upstream pingdotgg#3932's collision-safe
  assistant item id scheme
- Update fork tests asserting the old assistant item id format to the
  runtime-scoped format (AcpJsonRpcConnection, CursorAdapter)
- GitVcsDriverCore test: expect the fork's for-each-ref listRefs command under
  pingdotgg#4077's stable-diagnostics assertion
- showcasePendingTasks test: add fork-required dataAudience to EnvironmentProject fixtures

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* style: format GitVcsDriverCore.test.ts (vp check --fix)

* fix(sync): coerce optional itemId to string in CursorAdapter.test asserts

* style: format CursorAdapter.test.ts

---------

Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Dimitar Stoykov <mitkostoikov1988@gmail.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Hugo Vizcaino Santana <42343504+HugoVizcainoSantana@users.noreply.github.com>
Co-authored-by: Eric Tsai <52527831+EricTsai83@users.noreply.github.com>
Co-authored-by: Manuel De Ceglie <80224270+AmoonPod@users.noreply.github.com>
Co-authored-by: Kriday Dave <technocratix902@gmail.com>
Co-authored-by: BunnyGamezsc <146652788+BunnyGamezsc@users.noreply.github.com>
Co-authored-by: Olivier Melcher <olivier.melcher@gmail.com>
Co-authored-by: Fazal Kadivar <fazalkadivar7@gmail.com>
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
Co-authored-by: Maxwell Young <maxtheyoung@gmail.com>
Co-authored-by: Yukun Shan <92423096+nateEc@users.noreply.github.com>
Co-authored-by: James <105842516+jamesx0416@users.noreply.github.com>
Co-authored-by: Leonel Rivas <herial_vi@icloud.com>
Co-authored-by: Matt Van Horn <mvanhorn@users.noreply.github.com>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: Codex <codex@openai.com>
Co-authored-by: xxashxx-svg <xxanshxx9@gmail.com>
Co-authored-by: wizzoapp[bot] <254688279+wizzoapp[bot]@users.noreply.github.com>
Co-authored-by: Wizzo Bot <wizzoapp@users.noreply.github.com>
tarik02 added a commit to tarik02/t3code that referenced this pull request Jul 18, 2026
* Use client-side fallbacks for missing project favicons (pingdotgg#3959)

* Skip stale working-task notifications (pingdotgg#3961)

* Prepare Android beta branding and review diff UI (pingdotgg#3967)

* perf(web): duty-cycle status animations and remove fixed noise overlay (pingdotgg#3978)

* fix(docs): correct CI task-runner commands in ci.md (pingdotgg#3990)

* fix(docs): repair broken source links in architecture overview (pingdotgg#3991)

* fix(docs): replace stale codething-mvp absolute paths with repo-relative links (pingdotgg#3992)

* docs: Add T3 Code Legal Docs (pingdotgg#3972)

Co-authored-by: codex <codex@users.noreply.github.com>

* Fix Legal modal header crash (pingdotgg#4000)

Co-authored-by: codex <codex@users.noreply.github.com>

* [codex] Fix onboarding connection status (pingdotgg#4001)

Co-authored-by: codex <codex@users.noreply.github.com>

* Isolate native diff highlight grammar state (pingdotgg#4029)

* Fix macOS fullscreen titlebar spacing (pingdotgg#4019)

* Prevent duplicate project workspace roots (pingdotgg#3829)

Co-authored-by: codex <codex@users.noreply.github.com>

* Normalize over-indented markdown list items (pingdotgg#4020)

Co-authored-by: codex <codex@users.noreply.github.com>

* Resolve localhost preview URLs for remote environments (pingdotgg#4011)

Co-authored-by: codex <codex@users.noreply.github.com>

* fix(mobile): Send composer images in upload wire format (pingdotgg#4035)

* Fix iOS terminal Enter input encoding (pingdotgg#4043)

* Add native mobile share target support (pingdotgg#4021)

Co-authored-by: codex <codex@users.noreply.github.com>

* [codex] Expand real-route app store screenshot harness (pingdotgg#4014)

Co-authored-by: codex <codex@users.noreply.github.com>

* fix(server): use CLAUDE_CONFIG_DIR instead of HOME for Claude instanc… (pingdotgg#4017)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* Fix dropped events during initial thread snapshot (pingdotgg#4079)

* feat: show nightly update changelog tooltip (pingdotgg#3832)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(git): treat selected commit paths literally (pingdotgg#3998)

* fix(server): stabilize non-repository Git diagnostics (pingdotgg#4077)

* Refresh app icons across release variants (pingdotgg#4080)

Co-authored-by: codex <codex@users.noreply.github.com>

* Update marketing GitHub star count (pingdotgg#4088)

* fix(marketing): correct Cursor icon color (pingdotgg#4090)

* Normalize protocol-relative remote host input as https (pingdotgg#3971)

* fix(cursor): default binary path to cursor-agent (avoid path conflict w/ grok) (pingdotgg#4094)

* Fix documented task-runner commands (bun run -> vp) (pingdotgg#3965)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* Allow preview panel to grow on wide displays (pingdotgg#4044)

* fix: prevent initial right-click from selecting a context menu item (pingdotgg#3877)

* Fix duplicate keybinding rule when replacing with an existing rule (pingdotgg#3969)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(server): image upload crashed dispatchCommand with a stack overflow (pingdotgg#3952)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* Remove unused code parameter from describePreviewError (pingdotgg#3970)

Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>

* [codex] prevent ACP assistant ID collisions after restarts (pingdotgg#3932)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(web): inset Windows desktop scrollbars from resize edge (pingdotgg#4097)

Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>

* [codex] fix mobile composer Enter behavior (pingdotgg#3930)

Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>

* feat(server): include runtime model and effort in Codex developer instructions (pingdotgg#3948)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(ux): spamming cmd + , no longer stack opening settings (pingdotgg#2757)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(terminal): strip AppImage runtime env from spawned terminals (pingdotgg#3108)

Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>

* fix(server): thread cwd through Claude capability probe (pingdotgg#2048) (pingdotgg#2124)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* [codex] fix: guard invalid web timestamps (pingdotgg#3515)

Co-authored-by: Codex <codex@openai.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* [codex] fix: tolerate invalid latest user message timestamps (pingdotgg#3521)

Co-authored-by: Codex <codex@openai.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* [codex] Fix provider update checks restore defaults (pingdotgg#3531)

Co-authored-by: Codex <codex@openai.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(server): skip undecodable provider runtime rows when listing sessions (pingdotgg#3951)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
Co-authored-by: codex <codex@users.noreply.github.com>

* Share MCP OAuth locks across Codex shadow homes (pingdotgg#4104)

* Preserve T3 Code identity in macOS development launcher (pingdotgg#4102)

* fix(web): increase contrast of question option descriptions (pingdotgg#3867)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

---------

Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Kriday Dave <technocratix902@gmail.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Ishan <ishansachu1@gmail.com>
Co-authored-by: Dimitar Stoykov <mitkostoikov1988@gmail.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Hugo Vizcaino Santana <42343504+HugoVizcainoSantana@users.noreply.github.com>
Co-authored-by: Eric Tsai <52527831+EricTsai83@users.noreply.github.com>
Co-authored-by: Manuel De Ceglie <80224270+AmoonPod@users.noreply.github.com>
Co-authored-by: BunnyGamezsc <146652788+BunnyGamezsc@users.noreply.github.com>
Co-authored-by: Olivier Melcher <olivier.melcher@gmail.com>
Co-authored-by: Fazal Kadivar <fazalkadivar7@gmail.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
Co-authored-by: Maxwell Young <maxtheyoung@gmail.com>
Co-authored-by: Yukun Shan <92423096+nateEc@users.noreply.github.com>
Co-authored-by: James <105842516+jamesx0416@users.noreply.github.com>
Co-authored-by: Leonel Rivas <herial_vi@icloud.com>
Co-authored-by: Matt Van Horn <mvanhorn@users.noreply.github.com>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: Codex <codex@openai.com>
Co-authored-by: xxashxx-svg <xxanshxx9@gmail.com>
aaditagrawal added a commit to aaditagrawal/t3code that referenced this pull request Jul 18, 2026
…tence (pingdotgg#3998pingdotgg#4104) (#166)

## What changed

Ports upstream server-core fixes into the fork:

- `pingdotgg#3998` treat selected commit paths literally in Git VCS
- `pingdotgg#4077` stabilize non-repository Git diagnostics
- `pingdotgg#3969` fix duplicate keybinding rule replacement
- `pingdotgg#3952` fix image upload stack overflow in MIME handling
- `pingdotgg#3108` strip AppImage runtime env from spawned terminals
- `pingdotgg#3951` skip undecodable provider runtime rows when listing sessions
- `pingdotgg#4104` share MCP OAuth locks across Codex shadow homes

Preserves fork: multi-provider runtime, orchestration persistence, Codex shadow-home layout.

## Validation

- `vp check` (0 errors) and `vp run typecheck` on stack tip
- CI: pending

Stack: 1 of 5; base `main`.

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

## Summary by CodeRabbit

- **Bug Fixes**
  - Improved validation for base64 image data, including malformed, empty, padded, and case-variant inputs.
  - Prevented duplicate keybinding entries when replacing rules.
  - Preserved valid provider sessions when individual stored records are corrupted.
  - Improved Codex MCP OAuth lock handling across shared environments.
  - Cleaned AppImage-specific environment values from terminal sessions.
  - Made Git status output more consistent across locales.
  - Ensured selected file paths containing special characters are handled literally.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS 0-9 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants