Harden the workflow-push approval guard against three bypasses found by the
security review:
- H6: the push parser passed through (returned None, unguarded) git invoked via
a path (`/usr/bin/git`), a wrapper (`command`/`env` ...), or with leading
global options (`git -c`, `--git-dir`, `--no-pager`). Recognize wrapped and
path-qualified git as pushes, and block pushes carrying unsupported global
options instead of running them unguarded.
- H1: the base was fetched via the `origin` remote name, which the sandbox can
split from the push destination via `remote set-url --push`. Fetch the base
from the effective push URL (`git remote get-url --push`) so the base and the
push target are the same authenticated repo.
- H3: an unreadable head workflow tree (`ls-tree` failure) skipped the guard;
fail closed (block) instead, mirroring the base-read path.
Adds tests for each. All confirmed guard bypasses are caught by the langsmith
unelevated-token backstop today; these close the guard's own logic for
non-langsmith providers too.
Claude-Session: https://claude.ai/code/session_01GxSndB7VoGQyeS196eUr5E