fix(checkpoint): resolve core.sshCommand and respect explicit BatchMode · Entire

fix(checkpoint): resolve core.sshCommand and respect explicit BatchMode

19a76e4→main

withBatchModeSSH only inspected GIT_SSH_COMMAND, so users who configure SSH via git config core.sshCommand had that setting silently overridden by the injected BatchMode default. Resolve the effective ssh command the way git does (GIT_SSH_COMMAND env > core.sshCommand > GIT_SSH > plain ssh) before deciding how to inject BatchMode.

Also replace the substring check for "BatchMode" with a proper option parser: matching any text containing "BatchMode" (e.g. BatchMode=no, or an unrelated substring) incorrectly skipped injection or defeated an explicit user choice. Now only an explicitly set BatchMode option (yes or no) is respected as-is; anything else gets BatchMode=yes injected.

Changes

2

7 unmodified lines

envLookup returns the value of the last occurrence of key in env (matching exec.Cmd's last-wins semantics for duplicate entries) and whether it was found.
var batchModeOptionRe = regexp.MustCompile(`(?i)\bBatchMode\s*=\s*\S+`)
func hasExplicitBatchMode(sshCmd string) bool {
    return batchModeOptionRe.MatchString(sshCmd)
}
func gitConfigSSHCommand(ctx context.Context, env []string) string {
    cmd := exec.CommandContext(ctx, "git", "config", "--get", "core.sshCommand")
    cmd.Env = env
    out, err := cmd.Output()
    if err != nil {
        return ""
    }
    return strings.TrimSpace(string(out))
}
func effectiveSSHCommand(ctx context.Context, env []string) string {
    if v, ok := envLookup(env, "GIT_SSH_COMMAND"); ok {
        if trimmed := strings.TrimSpace(v); trimmed != "" {
            return trimmed
        }
    }
    if v := gitConfigSSHCommand(ctx, env); v != "" {
        return v
    }
    if v, ok := envLookup(env, "GIT_SSH"); ok {
        if trimmed := strings.TrimSpace(v); trimmed != "" {
            return trimmed
        }
    }
    return "ssh"
}
func withBatchModeSSH(env []string) []string {
    const key = "GIT_SSH_COMMAND="
    base := "ssh"
    base := effectiveSSHCommand(ctx, env)
    out := make([]string, 0, len(env)+1)
    for _, e := range env {
        if v, ok := strings.CutPrefix(e, key); ok {
            if trimmed := strings.TrimSpace(v); trimmed != "" {
                base = trimmed
            }
            if strings.HasPrefix(e, key) {
                continue
            }
            out = append(out, e)
        }
    }
    if !strings.Contains(base, "BatchMode") {
        if !hasExplicitBatchMode(base) {
            base += " -o BatchMode=yes"
        }
    }
    return append(out, key+base)
}

Tests

tests := []struct {
    name string
    in   []string
    want string
}{
    {
        name: "no existing GIT_SSH_COMMAND defaults to ssh",
        in:   []string{"PATH=/usr/bin"},
        want: "ssh -o BatchMode=yes",
    },
    {
        name: "preserves and extends a custom ssh command",
        in:   []string{"GIT_SSH_COMMAND=ssh -i /home/me/.ssh/id"},
        want: "ssh -i /home/me/.ssh/id -o BatchMode=yes",
    },
    {
        name: "idempotent when BatchMode already present",
        in:   []string{"GIT_SSH_COMMAND=ssh -o BatchMode=yes"},
        want: "ssh -o BatchMode=yes",
    },
    {
        name: "GIT_SSH_COMMAND with explicit BatchMode=no is respected, not overridden",
        in:   []string{"GIT_SSH_COMMAND=ssh -o BatchMode=no"},
        want: "ssh -o BatchMode=no",
    },
}