{"version":"2.1.280","anchor":"dirsync-borrowed-objects-checkouts-get-a-real-confirmation","canonical_anchor":"dirsync-borrowed-objects-checkouts-get-a-real-confirmation","heading":"Cloud session git-checkout snapshotting reworked with new tamper detection","tier":"notice","area":"Directory Sync","scope":null,"heads_up":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280\/e\/dirsync-borrowed-objects-checkouts-get-a-real-confirmation","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280","markdown":"### Cloud session git-checkout snapshotting reworked with new tamper detection\n\nCloud\/background session git-checkout snapshotting was reworked to detect tampering, with clearer refusal reasons\n\n**What**\n\n- A substantial new pipeline builds file-sync snapshots of a working tree for cloud sessions, now explicitly detecting and refusing on: a planted symlink in the git directory, an object store that started borrowing from `objects\/info\/alternates` mid-session, a git directory that moved or was replaced, and files covered by read-deny\/sandbox rules or \"named like a credential under another spelling.\" Each failure mode gives a specific explanation telling you to start a new cloud session.\n\n- Previously, a \"borrowed objects\" checkout was grouped with other cases (`old_git`, `reftable`, `temp_root`) as an immediate, settled refusal. Now it gets its own branch: a confirmation check runs first, and the refusal only settles once the borrowed\/replaced object store is actually confirmed; otherwise it's treated as retryable rather than final.\n\n- Repo layout classification gained two new cases, `git_in_reach` and `reach_unexamined`, both mapped to \"unserved layout\" alongside existing submodule\/git-dir\/temp-root cases.\n\n- Directory sync also gained a dedicated `reach_unexamined` refusal reason for when a writable directory reached through the checkout couldn't be examined, distinct from the prior generic unread refusal.\n\n**Why**\n\nThis makes cloud\/background sessions more resistant to a tampered or moved git directory going unnoticed, giving clearer, more specific reasons when a checkout can't be safely used and telling you to start a fresh cloud session when that happens.\n\n- Area: Directory Sync\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 2\/5"}