Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

config.json trustedFolders (and other managed state) lost when concurrent sessions overwrite the file on exit

Open
#4,900 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
52/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
shell
Domain
cli

Research direction

Start by tracing the /add-dir flow and the exit-time write to ~/.copilot/config.json, then reproduce the two-session scenario described in the issue. Done means concurrent exits no longer discard trustedFolders or other managed changes, including the related permissions-config.json state.

Written by the indexing model from the issue text.

Description

triage

Bug

~/.copilot/config.json (marked // This file is managed automatically.) is not merged/reconciled when written — each running Copilot CLI session appears to hold its own in-memory copy of the file's managed state (e.g. trustedFolders) and rewrites the entire file on exit using that stale snapshot. If a directory is added via /add-dir in one session while other sessions are still open, the addition is silently lost as soon as any of those other sessions closes and overwrites config.json with its older list.

This makes /add-dir (intended to persist trusted directories globally, per its own help text: "Allow file access to a directory and load its .github skills and agents as trusted configuration") effectively non-persistent whenever more than one CLI session/window is used at a time — which is a common workflow.

Steps to Reproduce

  1. Open two Copilot CLI sessions (session A and session B) in different terminals.
  2. In session A, run /add-dir /path/to/new-dir. Confirm ~/.copilot/config.json's trustedFolders now includes the new path.
  3. Without closing session A, exit session B (ctrl+d or normal exit).
  4. Inspect ~/.copilot/config.json again — the directory added in step 2 is gone, because session B rewrote the file from its own (older) in-memory state.

Expected Behavior

Writes to config.json (and similar "managed automatically" files, e.g. permissions-config.json) should be done as a read-modify-write with file locking, or by merging the specific keys being changed into the on-disk state, rather than replacing the whole file with a long-lived in-memory snapshot. At minimum, list-valued fields like trustedFolders should be unioned rather than overwritten.

Additional Context

  • Copilot CLI version: 1.0.86
  • Linux
  • This looks like the same underlying root cause as #3403 ("Hooks in config.json are not preserved across session starts") and is likely contributing to the repeated reports in #2284 / #3050 / #4398 that /add-dir/trusted-directory persistence "doesn't work" — in our case the user had run /add-dir on the same path "numerous times" and it kept reverting.
  • Workaround: close all other Copilot CLI sessions before adding a directory, or edit ~/.copilot/config.json directly while no other sessions are running.
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/copilot-cli

All issues in github/copilot-cli

Similar issues

More Shell/Bash issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.