The bare-PATH-lookup lint matched _EXEMPT_DIRS against the first path
component only, so a staged desktop payload (apps/desktop/build/) got
walked as if it were source — every repo file reported twice, at the
copy's line numbers. It now matches any component, which also covers
nested node_modules.
test_managed_git_standalone provisions through provision_tool() rather
than reaching for a private installer, so it exercises the path users
actually get.
Verified: 11035 python tests with one pre-existing DNS-dependent failure,
4724 desktop tests, typecheck clean.
macOS /usr/bin/git is the xcode-select SHIM: invoking it without the
Command Line Tools pops a modal install dialog. A bundled git is how
Hermes never asks it anything. darwin/linux now provision dugite-native
(GitHub's relocatable Git, what GitHub Desktop embeds, built with
RUNTIME_PREFIX); win32 keeps PortableGit.
dugite pins an exact release tag + per-platform sha256 rather than
resolving latest — a Git that changes under users is worse than one that
needs a pin bump, and the digest is the only thing between a CDN and a
user's source tree. A mismatch aborts before extraction.
The two suppliers run on different cadences, so the floor is the slower
one (2.53.x from dugite) with windowsVersion carrying git-for-windows'
higher floor. Found by running it: the pin said 2.55.x, which is a
PortableGit version, and every POSIX install would have failed.
managed_tool_env() now exports the portable-git contract (GIT_EXEC_PATH,
GIT_TEMPLATE_DIR, GIT_CONFIG_SYSTEM, GIT_SSL_CAINFO) for a managed git
only — exporting them at a system git we do not own would break it.
Verified end to end: real dugite download + digest check, then a real
clone with an EMPTY environment (no PATH, no system git, no
/etc/gitconfig). 6 standalone tests + 13 provisioner tests green.