What
- A substantial new pipeline builds file-sync snapshots of a working tree for cloud sessions, now explicitly detecting and refusing on: a planted symlink in the git directory, an object store that started borrowing from
objects/info/alternatesmid-session, a git directory that moved or was replaced, and files covered by read-deny/sandbox rules or "named like a credential under another spelling." Each failure mode gives a specific explanation telling you to start a new cloud session. - Previously, a "borrowed objects" checkout was grouped with other cases (
old_git,reftable,temp_root) as an immediate, settled refusal. Now it gets its own branch: a confirmation check runs first, and the refusal only settles once the borrowed/replaced object store is actually confirmed; otherwise it's treated as retryable rather than final. - Repo layout classification gained two new cases,
git_in_reachandreach_unexamined, both mapped to "unserved layout" alongside existing submodule/git-dir/temp-root cases. - Directory sync also gained a dedicated
reach_unexaminedrefusal reason for when a writable directory reached through the checkout couldn't be examined, distinct from the prior generic unread refusal.
Why
This makes cloud/background sessions more resistant to a tampered or moved git directory going unnoticed, giving clearer, more specific reasons when a checkout can't be safely used and telling you to start a fresh cloud session when that happens.