Skip to content

fix(claude-code): set git safe.directory and gh credential helper via env - #203

Merged
gatezh merged 1 commit into
masterfrom
fix/git-safe-directory
Oct 8, 2026
Merged

gatezh merged 1 commit into
masterfrom
fix/git-safe-directory

Conversation

@gatezh

@gatezh gatezh commented Oct 8, 2026

Copy link
Copy Markdown
Owner

What

Sets git config for every process in claude-code template containers through GIT_CONFIG_COUNT in containerEnv. This fixes the intermittent "dubious ownership" error on /workspace and lets git@github.com: remotes authenticate through the container's gh login.

Why

Closes #172.

Env-based config is git's command scope. Per git-config(1), that scope counts as protected configuration, so git honors safe.directory there. It also outranks the system and global files the extension writes. The two credential entries, an empty helper followed by !gh auth git-credential, are exactly what gh auth setup-git writes (cli/cli helper_config.go). It's gh's own way to "sever the chain of credential helpers", and gitcredentials(7) documents the empty value as a reset.

Changes

  • claude-code/.devcontainer/devcontainer.json and claude-sandbox/devcontainer.json: four GIT_CONFIG_* entries in containerEnv:
    • safe.directory=/workspace
    • url.https://github.com/.insteadOf=git@github.com:
    • an empty credential.https://github.com.helper, then !gh auth git-credential
  • claude-code/README.md: new "Git and GitHub Authentication" section covering each entry, the one-time gh auth login, how to inspect the config with --show-scope, and how to add entries. A link to it from "Key settings included".

Verification

Ran in ghcr.io/gatezh/devcontainers/claude-code:latest (git 2.47.3). /workspace was owned by UID 4242, and a stand-in for VS Code's credential helper was set in both /etc/gitconfig and ~/.gitconfig. The env values were parsed from each edited JSONC file:

Check Without env With env (both variants)
git status in /workspace fatal: detected dubious ownership works
git ls-remote --get-url git@github.com:owner/repo.git unchanged SSH URL https://github.com/owner/repo.git
git credential fill for github.com stale host credential gh's token
git credential fill for gitlab.com VS Code helper VS Code helper (unchanged)

Also confirmed: with only the gh helper and no empty reset, github.com still gets the stale host credential.

Notes

  • After merging, downstream projects pick this up by re-syncing their .devcontainer/ (the devcontainer-upstream-sync skill) and rebuilding. No image rebuild is needed for the fix itself.
  • Inside the container, git@github.com: remotes now always go over HTTPS through gh, even when the forwarded ssh-agent would have worked. The host's remotes and SSH setup don't change.
  • Out of scope: this repo's own root .devcontainer/ has no gh config volume, so it isn't changed here. ssh://git@github.com/ remotes and gist hosts aren't covered.

… env

VS Code's Git extension intermittently fails with "dubious ownership" on
the bind-mounted /workspace. The Dev Containers extension adds safe.directory
to ~/.gitconfig only when its one-time ownership check at attach detects a
mismatch, and Docker Desktop's reported ownership changes over time.

Set git config through GIT_CONFIG_COUNT in containerEnv instead. Git reads
it as command scope, which is protected (so safe.directory is honored) and
outranks the system and global files the extension writes:

- safe.directory=/workspace
- rewrite git@github.com: remotes to HTTPS
- reset the github.com credential helper list, then add `gh auth
  git-credential`. This is the same pair `gh auth setup-git` writes. Without
  the reset, VS Code's injected helper answers first with the host's
  possibly stale credential.

Closes #172
@gatezh
gatezh merged commit 1825a02 into master Oct 8, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant