Both clone-path tests in git-subprocess-safety.test.ts await a real
async gap (fs.promises.mkdir before Bun.spawn is invoked) before
advancing fake timers, unlike the show/fetch variants that mock
Bun.spawn directly. Under GitHub Actions CI load this occasionally
exceeds Bun's default 5000ms per-test timeout even though the test
logic itself completes in milliseconds locally — observed twice in a
row on this PR's Linux CI runs with different underlying diffs, never
locally. Widen to 20000ms, matching the project's existing convention
for tests with a real async/IO dependency (e.g.
agent-session-python-cleanup.test.ts).
- Added GIT_NETWORK_TIMEOUT_MS (30 min) for clone/fetch with an overridable timeoutMs option; local plumbing keeps the 5-minute cap.
- Migrated fetch() from a positional AbortSignal to an options object.
Forced non-interactive credential env for git and gh subprocesses, added a default timeout, and capped captured stdout/stderr with a truncation marker. Added regression coverage for prompt env, output capping, and timeout cleanup.
Fixes#4072