config.json trustedFolders (and other managed state) lost when concurrent sessions overwrite the file on exit
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 52/100
Research direction
Start by tracing the /add-dir flow and the exit-time write to ~/.copilot/config.json, then reproduce the two-session scenario described in the issue. Done means concurrent exits no longer discard trustedFolders or other managed changes, including the related permissions-config.json state.
Written by the indexing model from the issue text.
Description
Bug
~/.copilot/config.json (marked // This file is managed automatically.) is not merged/reconciled when written — each running Copilot CLI session appears to hold its own in-memory copy of the file's managed state (e.g. trustedFolders) and rewrites the entire file on exit using that stale snapshot. If a directory is added via /add-dir in one session while other sessions are still open, the addition is silently lost as soon as any of those other sessions closes and overwrites config.json with its older list.
This makes /add-dir (intended to persist trusted directories globally, per its own help text: "Allow file access to a directory and load its .github skills and agents as trusted configuration") effectively non-persistent whenever more than one CLI session/window is used at a time — which is a common workflow.
Steps to Reproduce
- Open two Copilot CLI sessions (session A and session B) in different terminals.
- In session A, run
/add-dir /path/to/new-dir. Confirm~/.copilot/config.json'strustedFoldersnow includes the new path. - Without closing session A, exit session B (
ctrl+dor normal exit). - Inspect
~/.copilot/config.jsonagain — the directory added in step 2 is gone, because session B rewrote the file from its own (older) in-memory state.
Expected Behavior
Writes to config.json (and similar "managed automatically" files, e.g. permissions-config.json) should be done as a read-modify-write with file locking, or by merging the specific keys being changed into the on-disk state, rather than replacing the whole file with a long-lived in-memory snapshot. At minimum, list-valued fields like trustedFolders should be unioned rather than overwritten.
Additional Context
- Copilot CLI version: 1.0.86
- Linux
- This looks like the same underlying root cause as #3403 ("Hooks in config.json are not preserved across session starts") and is likely contributing to the repeated reports in #2284 / #3050 / #4398 that
/add-dir/trusted-directory persistence "doesn't work" — in our case the user had run/add-diron the same path "numerous times" and it kept reverting. - Workaround: close all other Copilot CLI sessions before adding a directory, or edit
~/.copilot/config.jsondirectly while no other sessions are running.
- Dominant language
- Shell
- Stars
- 11.2k
- Forks
- 1.9k
- Avg merge
- 14h 16m
- Merged PRs (30d)
- 6
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from github/copilot-cli
-
triage
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
github/copilot-cli#4932 ·
-
triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
github/copilot-cli#4909 ·
-
triage
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
github/copilot-cli#4906 ·
-
triage
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/copilot-cli#4848 ·
-
area:agents area:mcp
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/copilot-cli#4729 ·
All issues in github/copilot-cli
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
elastic/gradle-plugins#156 ·
-
Priority/High ready-for-agent Severity/Major Type/Bug
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
comp/cli P3 type/docs
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
NousResearch/hermes-agent#119756 · 1 comment ·
-
comp: build/pipeline type: bug version: current (v17+)
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
angular/angularfire#3766 ·
-
out-of-date
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
CachyOS/CachyOS-PKGBUILDS#1903 ·