Git Transfer Semantics
Cloud Harness MCP enforces strict isolation between repository execution containers and GitHub credentials.
The Transfer Problem
Standard coding agent sandboxes either:
- Embed the user's GitHub Personal Access Token or SSH key directly into the container filesystem or environment (allowing arbitrary scripts or dependencies to steal the credential), or
- Forbid remote push entirely, requiring manual user intervention.
The Sibling Helper Solution
Cloud Harness solves this with an ephemeral sibling Git helper:
[ Workspace Container ] (no network, no token)
▲
│ (local disk mount)
▼
[ Host Repo Directory ]
▲
│ (local disk mount)
▼
[ Sibling Git Helper ] ──(token over stdin)──► [ github.com:owner/repo.git ]- The agent invokes
git_push(refspec, forceWithLease?, expectedRemoteOid?, idempotencyKey?). - The Runner starts an ephemeral Alpine container with network access scoped only to
github.com. - The Runner streams an installation token over
stdininto the helper'sgit-credentialhelper. - The helper executes the push against the remote origin and immediately exits.
- The container is destroyed. The token is never written to disk or
.git/config.
Compare-and-Swap (CAS) & Concurrency Control
git_commitHEAD Guard (expectedHeadOid): Prevents commits on top of unexpected intermediate state. If the workspace HEAD has moved, the commit is rejected withSTALE_HEAD.git_pushForce-with-Lease (expectedRemoteOid): Pushes withforceWithLease: truerequireexpectedRemoteOid. If the remote branch has diverged, the push fails withCONFLICTto prevent silent overwrites.
Idempotency & Unknown-Outcome Recovery
Network failures or runner restarts during a push can leave the client unsure whether the commit reached the remote repository.
- Supply an
idempotencyKeyon the initialgit_pushorworkspace_finalizecall. - If a transport timeout or network drop occurs, the runner returns
UNKNOWN_REMOTE_STATEwithresumeAction: "reconcile_push". - Retrying the identical request with the same
idempotencyKeytriggers automatic remote-ref reconciliation (git ls-remoteprobe). If the commit already landed on the remote branch, the call returns success withalreadyFinalized: truewithout pushing duplicate commits.
Owner-Scoped Repository Cache
When enableRepoCache is enabled, the runner maintains bare Git repository caches partitioned strictly by the authenticated principal ID. Initial clones use git clone --reference-if-able <cache> --dissociate to leverage shared local object storage while ensuring that each workspace has a fully detached, independent, and isolated working tree.