auto-update can run in git subdirs; review GIT_WHITELIST for daemon