Make xmd run worktree paths readable #752

Description

@taras

Story

As someone using xmd run interactively, I want its managed worktrees to have short, readable paths, so I can enter them, inspect files, and continue working with ordinary filesystem tools.

Example

Given an ordinary run started in a repository named xmd-demo:

<Worktreename="task"branch="worktree-task">
```bash exec
pwd
```

The worktree lives at and reports:

~/.xmd/worktrees/xmd-demo/task

Current gap

Ordinary xmd run currently places the same worktree under two full SHA-256 directory names and a final checkout directory:

~/.xmd/repositories/worktrees/ff326cec5b976a415f5dd20209cce334181533390b6655ec44df2d1ed8bfbfd1/86842adba411256398ba49ad04bf9070f3f558efd7a45ea1897ed1a3e78539b4/checkout

The first digest identifies the repository's canonical Git directory and the second identifies the authored worktree name. This protects provider-owned storage from collisions and path traversal, but it exposes an internal identity layout as the directory where a person is expected to work.

That tradeoff is appropriate for workflow-owned storage, which users do not navigate as an interactive checkout. It is a poor default for xmd run: ordinary managed worktrees deliberately survive the invocation because they contain work a person or Agent may continue afterward.

Contract

An ordinary xmd run worktree uses this readable common-path layout:

~/.xmd/worktrees/<repository>/<worktree>

For a root-level <Worktree> using the ambient repository, <repository> is a filesystem-safe form of the repository directory name. For a <Worktree> inside a lexical <Repository name="project">, it is a filesystem-safe form of that Repository name. <worktree> is a filesystem-safe form of the authored Worktree name.

Names remain labels, not path authority. No authored repository or worktree name can escape ~/.xmd/worktrees, select another checkout, or collide after filesystem case and normalization rules are applied. The original repository identity and Worktree name remain in trusted metadata and continue to decide compatibility and reuse.

The ordinary case stays simple. A short stable suffix is added only when two distinct identities would otherwise claim the same readable path, for example:

~/.xmd/worktrees/xmd-demo-ff326cec/task

Full identity digests may remain internal for metadata, locking, and collision proofs; they do not appear in the normal checkout path.

The readable directory is the checkout root. A captured <Worktree as="path" />, the contextual working directory inside a paired <Worktree>, and pwd all observe that path without an additional checkout segment.

Changing placement does not weaken the existing ordinary-run guarantees: managed worktrees persist across executions, compatible requests reuse them, conflicting identity or Git state refuses without mutation, and one invocation holds the same exclusive lock while using one.

Existing full-digest ordinary-run worktrees are not orphaned or duplicated. On compatible reuse, XMD makes the existing checkout available at its readable path without changing its branch, commits, index, working files, or Git worktree registration. If it cannot prove a safe transition—because the target conflicts, the checkout is active, or its identity is incompatible—it refuses actionably and leaves the existing worktree untouched.

Workflow-run Workspace paths and retained workflow identity do not change.

Acceptance

  • A root-level <Worktree name="task"> started in xmd-demo uses ~/.xmd/worktrees/xmd-demo/task when that readable repository name is unclaimed.
  • A Worktree inside <Repository name="project"> uses ~/.xmd/worktrees/project/<worktree> when that readable Repository name is unclaimed.
  • The path returned through as, the contextual working directory, and pwd name the readable checkout root and contain neither full SHA-256 segments nor a trailing checkout segment in the common case.
  • Repeating the same request reuses the same directory and preserves committed, staged, modified, and untracked work.
  • Distinct repositories with the same readable name receive stable, distinguishable paths; the common path remains unsuffixed when no collision exists.
  • Authored names containing traversal syntax or values that collide after filesystem normalization cannot escape the managed root or select another checkout.
  • A compatible legacy full-digest worktree is reused at the readable path without data loss or duplicate Git registration.
  • A conflicting or active legacy worktree refuses without moving, copying, resetting, or deleting it.
  • Lock ownership and immutable creation-metadata checks continue to use the complete repository and Worktree identities rather than trusting readable directory names.
  • Workflow-run worktree placement remains unchanged.
  • architecture.md and the ordinary-run topology in specs/workflow-workspace-spec.md describe the readable interactive layout and its collision behavior.

Evidence

Run the focused ordinary-run placement and integration suites:

deno task test packages/workflow/tests/run-composition-managed.test.ts packages/workflow/tests/run-composition-ambient.test.ts packages/cli/tests/run-composition-deno.test.ts packages/cli/tests/run-composition-nested.test.ts

The regression evidence covers the simple ambient path, lexical Repository path, collisions, hostile names, persistent reuse, legacy adoption, active-use refusal, and the unchanged workflow boundary.

Related

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    UXUser-facing usability and interaction improvements

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
       blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
      }
      } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
      })();
      (function(){
      try {
      var __m = "github.com";
      var __re = new RegExp('^' + "github\\.com" + '
      
      Skip to content

      Make xmd run worktree paths readable #752

      Description

      @taras

      Story

      As someone using xmd run interactively, I want its managed worktrees to have short, readable paths, so I can enter them, inspect files, and continue working with ordinary filesystem tools.

      Example

      Given an ordinary run started in a repository named xmd-demo:

      <Worktreename="task"branch="worktree-task">
      ```bash exec
      pwd
      ```

      The worktree lives at and reports:

      ~/.xmd/worktrees/xmd-demo/task
      

      Current gap

      Ordinary xmd run currently places the same worktree under two full SHA-256 directory names and a final checkout directory:

      ~/.xmd/repositories/worktrees/ff326cec5b976a415f5dd20209cce334181533390b6655ec44df2d1ed8bfbfd1/86842adba411256398ba49ad04bf9070f3f558efd7a45ea1897ed1a3e78539b4/checkout
      

      The first digest identifies the repository's canonical Git directory and the second identifies the authored worktree name. This protects provider-owned storage from collisions and path traversal, but it exposes an internal identity layout as the directory where a person is expected to work.

      That tradeoff is appropriate for workflow-owned storage, which users do not navigate as an interactive checkout. It is a poor default for xmd run: ordinary managed worktrees deliberately survive the invocation because they contain work a person or Agent may continue afterward.

      Contract

      An ordinary xmd run worktree uses this readable common-path layout:

      ~/.xmd/worktrees/<repository>/<worktree>
      

      For a root-level <Worktree> using the ambient repository, <repository> is a filesystem-safe form of the repository directory name. For a <Worktree> inside a lexical <Repository name="project">, it is a filesystem-safe form of that Repository name. <worktree> is a filesystem-safe form of the authored Worktree name.

      Names remain labels, not path authority. No authored repository or worktree name can escape ~/.xmd/worktrees, select another checkout, or collide after filesystem case and normalization rules are applied. The original repository identity and Worktree name remain in trusted metadata and continue to decide compatibility and reuse.

      The ordinary case stays simple. A short stable suffix is added only when two distinct identities would otherwise claim the same readable path, for example:

      ~/.xmd/worktrees/xmd-demo-ff326cec/task
      

      Full identity digests may remain internal for metadata, locking, and collision proofs; they do not appear in the normal checkout path.

      The readable directory is the checkout root. A captured <Worktree as="path" />, the contextual working directory inside a paired <Worktree>, and pwd all observe that path without an additional checkout segment.

      Changing placement does not weaken the existing ordinary-run guarantees: managed worktrees persist across executions, compatible requests reuse them, conflicting identity or Git state refuses without mutation, and one invocation holds the same exclusive lock while using one.

      Existing full-digest ordinary-run worktrees are not orphaned or duplicated. On compatible reuse, XMD makes the existing checkout available at its readable path without changing its branch, commits, index, working files, or Git worktree registration. If it cannot prove a safe transition—because the target conflicts, the checkout is active, or its identity is incompatible—it refuses actionably and leaves the existing worktree untouched.

      Workflow-run Workspace paths and retained workflow identity do not change.

      Acceptance

      • A root-level <Worktree name="task"> started in xmd-demo uses ~/.xmd/worktrees/xmd-demo/task when that readable repository name is unclaimed.
      • A Worktree inside <Repository name="project"> uses ~/.xmd/worktrees/project/<worktree> when that readable Repository name is unclaimed.
      • The path returned through as, the contextual working directory, and pwd name the readable checkout root and contain neither full SHA-256 segments nor a trailing checkout segment in the common case.
      • Repeating the same request reuses the same directory and preserves committed, staged, modified, and untracked work.
      • Distinct repositories with the same readable name receive stable, distinguishable paths; the common path remains unsuffixed when no collision exists.
      • Authored names containing traversal syntax or values that collide after filesystem normalization cannot escape the managed root or select another checkout.
      • A compatible legacy full-digest worktree is reused at the readable path without data loss or duplicate Git registration.
      • A conflicting or active legacy worktree refuses without moving, copying, resetting, or deleting it.
      • Lock ownership and immutable creation-metadata checks continue to use the complete repository and Worktree identities rather than trusting readable directory names.
      • Workflow-run worktree placement remains unchanged.
      • architecture.md and the ordinary-run topology in specs/workflow-workspace-spec.md describe the readable interactive layout and its collision behavior.

      Evidence

      Run the focused ordinary-run placement and integration suites:

      deno task test packages/workflow/tests/run-composition-managed.test.ts packages/workflow/tests/run-composition-ambient.test.ts packages/cli/tests/run-composition-deno.test.ts packages/cli/tests/run-composition-nested.test.ts

      The regression evidence covers the simple ambient path, lexical Repository path, collisions, hostile names, persistent reuse, legacy adoption, active-use refusal, and the unchanged workflow boundary.

      Related

      Activity

      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

      Metadata

      Metadata

      Assignees

      No one assigned

        Labels

        UXUser-facing usability and interaction improvements

        Projects

        No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
          Skip to content

          Make xmd run worktree paths readable #752

          Description

          @taras

          Story

          As someone using xmd run interactively, I want its managed worktrees to have short, readable paths, so I can enter them, inspect files, and continue working with ordinary filesystem tools.

          Example

          Given an ordinary run started in a repository named xmd-demo:

          <Worktreename="task"branch="worktree-task">
          ```bash exec
          pwd
          ```

          The worktree lives at and reports:

          ~/.xmd/worktrees/xmd-demo/task
          

          Current gap

          Ordinary xmd run currently places the same worktree under two full SHA-256 directory names and a final checkout directory:

          ~/.xmd/repositories/worktrees/ff326cec5b976a415f5dd20209cce334181533390b6655ec44df2d1ed8bfbfd1/86842adba411256398ba49ad04bf9070f3f558efd7a45ea1897ed1a3e78539b4/checkout
          

          The first digest identifies the repository's canonical Git directory and the second identifies the authored worktree name. This protects provider-owned storage from collisions and path traversal, but it exposes an internal identity layout as the directory where a person is expected to work.

          That tradeoff is appropriate for workflow-owned storage, which users do not navigate as an interactive checkout. It is a poor default for xmd run: ordinary managed worktrees deliberately survive the invocation because they contain work a person or Agent may continue afterward.

          Contract

          An ordinary xmd run worktree uses this readable common-path layout:

          ~/.xmd/worktrees/<repository>/<worktree>
          

          For a root-level <Worktree> using the ambient repository, <repository> is a filesystem-safe form of the repository directory name. For a <Worktree> inside a lexical <Repository name="project">, it is a filesystem-safe form of that Repository name. <worktree> is a filesystem-safe form of the authored Worktree name.

          Names remain labels, not path authority. No authored repository or worktree name can escape ~/.xmd/worktrees, select another checkout, or collide after filesystem case and normalization rules are applied. The original repository identity and Worktree name remain in trusted metadata and continue to decide compatibility and reuse.

          The ordinary case stays simple. A short stable suffix is added only when two distinct identities would otherwise claim the same readable path, for example:

          ~/.xmd/worktrees/xmd-demo-ff326cec/task
          

          Full identity digests may remain internal for metadata, locking, and collision proofs; they do not appear in the normal checkout path.

          The readable directory is the checkout root. A captured <Worktree as="path" />, the contextual working directory inside a paired <Worktree>, and pwd all observe that path without an additional checkout segment.

          Changing placement does not weaken the existing ordinary-run guarantees: managed worktrees persist across executions, compatible requests reuse them, conflicting identity or Git state refuses without mutation, and one invocation holds the same exclusive lock while using one.

          Existing full-digest ordinary-run worktrees are not orphaned or duplicated. On compatible reuse, XMD makes the existing checkout available at its readable path without changing its branch, commits, index, working files, or Git worktree registration. If it cannot prove a safe transition—because the target conflicts, the checkout is active, or its identity is incompatible—it refuses actionably and leaves the existing worktree untouched.

          Workflow-run Workspace paths and retained workflow identity do not change.

          Acceptance

          • A root-level <Worktree name="task"> started in xmd-demo uses ~/.xmd/worktrees/xmd-demo/task when that readable repository name is unclaimed.
          • A Worktree inside <Repository name="project"> uses ~/.xmd/worktrees/project/<worktree> when that readable Repository name is unclaimed.
          • The path returned through as, the contextual working directory, and pwd name the readable checkout root and contain neither full SHA-256 segments nor a trailing checkout segment in the common case.
          • Repeating the same request reuses the same directory and preserves committed, staged, modified, and untracked work.
          • Distinct repositories with the same readable name receive stable, distinguishable paths; the common path remains unsuffixed when no collision exists.
          • Authored names containing traversal syntax or values that collide after filesystem normalization cannot escape the managed root or select another checkout.
          • A compatible legacy full-digest worktree is reused at the readable path without data loss or duplicate Git registration.
          • A conflicting or active legacy worktree refuses without moving, copying, resetting, or deleting it.
          • Lock ownership and immutable creation-metadata checks continue to use the complete repository and Worktree identities rather than trusting readable directory names.
          • Workflow-run worktree placement remains unchanged.
          • architecture.md and the ordinary-run topology in specs/workflow-workspace-spec.md describe the readable interactive layout and its collision behavior.

          Evidence

          Run the focused ordinary-run placement and integration suites:

          deno task test packages/workflow/tests/run-composition-managed.test.ts packages/workflow/tests/run-composition-ambient.test.ts packages/cli/tests/run-composition-deno.test.ts packages/cli/tests/run-composition-nested.test.ts

          The regression evidence covers the simple ambient path, lexical Repository path, collisions, hostile names, persistent reuse, legacy adoption, active-use refusal, and the unchanged workflow boundary.

          Related

          Activity

          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

          Metadata

          Metadata

          Assignees

          No one assigned

            Labels

            UXUser-facing usability and interaction improvements

            Projects

            No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
              Skip to content

              Make xmd run worktree paths readable #752

              Description

              @taras

              Story

              As someone using xmd run interactively, I want its managed worktrees to have short, readable paths, so I can enter them, inspect files, and continue working with ordinary filesystem tools.

              Example

              Given an ordinary run started in a repository named xmd-demo:

              <Worktreename="task"branch="worktree-task">
              ```bash exec
              pwd
              ```

              The worktree lives at and reports:

              ~/.xmd/worktrees/xmd-demo/task
              

              Current gap

              Ordinary xmd run currently places the same worktree under two full SHA-256 directory names and a final checkout directory:

              ~/.xmd/repositories/worktrees/ff326cec5b976a415f5dd20209cce334181533390b6655ec44df2d1ed8bfbfd1/86842adba411256398ba49ad04bf9070f3f558efd7a45ea1897ed1a3e78539b4/checkout
              

              The first digest identifies the repository's canonical Git directory and the second identifies the authored worktree name. This protects provider-owned storage from collisions and path traversal, but it exposes an internal identity layout as the directory where a person is expected to work.

              That tradeoff is appropriate for workflow-owned storage, which users do not navigate as an interactive checkout. It is a poor default for xmd run: ordinary managed worktrees deliberately survive the invocation because they contain work a person or Agent may continue afterward.

              Contract

              An ordinary xmd run worktree uses this readable common-path layout:

              ~/.xmd/worktrees/<repository>/<worktree>
              

              For a root-level <Worktree> using the ambient repository, <repository> is a filesystem-safe form of the repository directory name. For a <Worktree> inside a lexical <Repository name="project">, it is a filesystem-safe form of that Repository name. <worktree> is a filesystem-safe form of the authored Worktree name.

              Names remain labels, not path authority. No authored repository or worktree name can escape ~/.xmd/worktrees, select another checkout, or collide after filesystem case and normalization rules are applied. The original repository identity and Worktree name remain in trusted metadata and continue to decide compatibility and reuse.

              The ordinary case stays simple. A short stable suffix is added only when two distinct identities would otherwise claim the same readable path, for example:

              ~/.xmd/worktrees/xmd-demo-ff326cec/task
              

              Full identity digests may remain internal for metadata, locking, and collision proofs; they do not appear in the normal checkout path.

              The readable directory is the checkout root. A captured <Worktree as="path" />, the contextual working directory inside a paired <Worktree>, and pwd all observe that path without an additional checkout segment.

              Changing placement does not weaken the existing ordinary-run guarantees: managed worktrees persist across executions, compatible requests reuse them, conflicting identity or Git state refuses without mutation, and one invocation holds the same exclusive lock while using one.

              Existing full-digest ordinary-run worktrees are not orphaned or duplicated. On compatible reuse, XMD makes the existing checkout available at its readable path without changing its branch, commits, index, working files, or Git worktree registration. If it cannot prove a safe transition—because the target conflicts, the checkout is active, or its identity is incompatible—it refuses actionably and leaves the existing worktree untouched.

              Workflow-run Workspace paths and retained workflow identity do not change.

              Acceptance

              • A root-level <Worktree name="task"> started in xmd-demo uses ~/.xmd/worktrees/xmd-demo/task when that readable repository name is unclaimed.
              • A Worktree inside <Repository name="project"> uses ~/.xmd/worktrees/project/<worktree> when that readable Repository name is unclaimed.
              • The path returned through as, the contextual working directory, and pwd name the readable checkout root and contain neither full SHA-256 segments nor a trailing checkout segment in the common case.
              • Repeating the same request reuses the same directory and preserves committed, staged, modified, and untracked work.
              • Distinct repositories with the same readable name receive stable, distinguishable paths; the common path remains unsuffixed when no collision exists.
              • Authored names containing traversal syntax or values that collide after filesystem normalization cannot escape the managed root or select another checkout.
              • A compatible legacy full-digest worktree is reused at the readable path without data loss or duplicate Git registration.
              • A conflicting or active legacy worktree refuses without moving, copying, resetting, or deleting it.
              • Lock ownership and immutable creation-metadata checks continue to use the complete repository and Worktree identities rather than trusting readable directory names.
              • Workflow-run worktree placement remains unchanged.
              • architecture.md and the ordinary-run topology in specs/workflow-workspace-spec.md describe the readable interactive layout and its collision behavior.

              Evidence

              Run the focused ordinary-run placement and integration suites:

              deno task test packages/workflow/tests/run-composition-managed.test.ts packages/workflow/tests/run-composition-ambient.test.ts packages/cli/tests/run-composition-deno.test.ts packages/cli/tests/run-composition-nested.test.ts

              The regression evidence covers the simple ambient path, lexical Repository path, collisions, hostile names, persistent reuse, legacy adoption, active-use refusal, and the unchanged workflow boundary.

              Related

              Activity

              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

              Metadata

              Metadata

              Assignees

              No one assigned

                Labels

                UXUser-facing usability and interaction improvements

                Projects

                No projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions

                  , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
                  Skip to content

                  Make xmd run worktree paths readable #752

                  Description

                  @taras

                  Story

                  As someone using xmd run interactively, I want its managed worktrees to have short, readable paths, so I can enter them, inspect files, and continue working with ordinary filesystem tools.

                  Example

                  Given an ordinary run started in a repository named xmd-demo:

                  <Worktreename="task"branch="worktree-task">
                  ```bash exec
                  pwd
                  ```

                  The worktree lives at and reports:

                  ~/.xmd/worktrees/xmd-demo/task
                  

                  Current gap

                  Ordinary xmd run currently places the same worktree under two full SHA-256 directory names and a final checkout directory:

                  ~/.xmd/repositories/worktrees/ff326cec5b976a415f5dd20209cce334181533390b6655ec44df2d1ed8bfbfd1/86842adba411256398ba49ad04bf9070f3f558efd7a45ea1897ed1a3e78539b4/checkout
                  

                  The first digest identifies the repository's canonical Git directory and the second identifies the authored worktree name. This protects provider-owned storage from collisions and path traversal, but it exposes an internal identity layout as the directory where a person is expected to work.

                  That tradeoff is appropriate for workflow-owned storage, which users do not navigate as an interactive checkout. It is a poor default for xmd run: ordinary managed worktrees deliberately survive the invocation because they contain work a person or Agent may continue afterward.

                  Contract

                  An ordinary xmd run worktree uses this readable common-path layout:

                  ~/.xmd/worktrees/<repository>/<worktree>
                  

                  For a root-level <Worktree> using the ambient repository, <repository> is a filesystem-safe form of the repository directory name. For a <Worktree> inside a lexical <Repository name="project">, it is a filesystem-safe form of that Repository name. <worktree> is a filesystem-safe form of the authored Worktree name.

                  Names remain labels, not path authority. No authored repository or worktree name can escape ~/.xmd/worktrees, select another checkout, or collide after filesystem case and normalization rules are applied. The original repository identity and Worktree name remain in trusted metadata and continue to decide compatibility and reuse.

                  The ordinary case stays simple. A short stable suffix is added only when two distinct identities would otherwise claim the same readable path, for example:

                  ~/.xmd/worktrees/xmd-demo-ff326cec/task
                  

                  Full identity digests may remain internal for metadata, locking, and collision proofs; they do not appear in the normal checkout path.

                  The readable directory is the checkout root. A captured <Worktree as="path" />, the contextual working directory inside a paired <Worktree>, and pwd all observe that path without an additional checkout segment.

                  Changing placement does not weaken the existing ordinary-run guarantees: managed worktrees persist across executions, compatible requests reuse them, conflicting identity or Git state refuses without mutation, and one invocation holds the same exclusive lock while using one.

                  Existing full-digest ordinary-run worktrees are not orphaned or duplicated. On compatible reuse, XMD makes the existing checkout available at its readable path without changing its branch, commits, index, working files, or Git worktree registration. If it cannot prove a safe transition—because the target conflicts, the checkout is active, or its identity is incompatible—it refuses actionably and leaves the existing worktree untouched.

                  Workflow-run Workspace paths and retained workflow identity do not change.

                  Acceptance

                  • A root-level <Worktree name="task"> started in xmd-demo uses ~/.xmd/worktrees/xmd-demo/task when that readable repository name is unclaimed.
                  • A Worktree inside <Repository name="project"> uses ~/.xmd/worktrees/project/<worktree> when that readable Repository name is unclaimed.
                  • The path returned through as, the contextual working directory, and pwd name the readable checkout root and contain neither full SHA-256 segments nor a trailing checkout segment in the common case.
                  • Repeating the same request reuses the same directory and preserves committed, staged, modified, and untracked work.
                  • Distinct repositories with the same readable name receive stable, distinguishable paths; the common path remains unsuffixed when no collision exists.
                  • Authored names containing traversal syntax or values that collide after filesystem normalization cannot escape the managed root or select another checkout.
                  • A compatible legacy full-digest worktree is reused at the readable path without data loss or duplicate Git registration.
                  • A conflicting or active legacy worktree refuses without moving, copying, resetting, or deleting it.
                  • Lock ownership and immutable creation-metadata checks continue to use the complete repository and Worktree identities rather than trusting readable directory names.
                  • Workflow-run worktree placement remains unchanged.
                  • architecture.md and the ordinary-run topology in specs/workflow-workspace-spec.md describe the readable interactive layout and its collision behavior.

                  Evidence

                  Run the focused ordinary-run placement and integration suites:

                  deno task test packages/workflow/tests/run-composition-managed.test.ts packages/workflow/tests/run-composition-ambient.test.ts packages/cli/tests/run-composition-deno.test.ts packages/cli/tests/run-composition-nested.test.ts

                  The regression evidence covers the simple ambient path, lexical Repository path, collisions, hostile names, persistent reuse, legacy adoption, active-use refusal, and the unchanged workflow boundary.

                  Related

                  Activity

                  Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                  Metadata

                  Metadata

                  Assignees

                  No one assigned

                    Labels

                    UXUser-facing usability and interaction improvements

                    Projects

                    No projects

                      Milestone

                      No milestone

                      Relationships

                      None yet

                      Development

                      No branches or pull requests

                      Issue actions

                      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                      Skip to content

                      Make xmd run worktree paths readable #752

                      Description

                      @taras

                      Story

                      As someone using xmd run interactively, I want its managed worktrees to have short, readable paths, so I can enter them, inspect files, and continue working with ordinary filesystem tools.

                      Example

                      Given an ordinary run started in a repository named xmd-demo:

                      <Worktreename="task"branch="worktree-task">
                      ```bash exec
                      pwd
                      ```

                      The worktree lives at and reports:

                      ~/.xmd/worktrees/xmd-demo/task
                      

                      Current gap

                      Ordinary xmd run currently places the same worktree under two full SHA-256 directory names and a final checkout directory:

                      ~/.xmd/repositories/worktrees/ff326cec5b976a415f5dd20209cce334181533390b6655ec44df2d1ed8bfbfd1/86842adba411256398ba49ad04bf9070f3f558efd7a45ea1897ed1a3e78539b4/checkout
                      

                      The first digest identifies the repository's canonical Git directory and the second identifies the authored worktree name. This protects provider-owned storage from collisions and path traversal, but it exposes an internal identity layout as the directory where a person is expected to work.

                      That tradeoff is appropriate for workflow-owned storage, which users do not navigate as an interactive checkout. It is a poor default for xmd run: ordinary managed worktrees deliberately survive the invocation because they contain work a person or Agent may continue afterward.

                      Contract

                      An ordinary xmd run worktree uses this readable common-path layout:

                      ~/.xmd/worktrees/<repository>/<worktree>
                      

                      For a root-level <Worktree> using the ambient repository, <repository> is a filesystem-safe form of the repository directory name. For a <Worktree> inside a lexical <Repository name="project">, it is a filesystem-safe form of that Repository name. <worktree> is a filesystem-safe form of the authored Worktree name.

                      Names remain labels, not path authority. No authored repository or worktree name can escape ~/.xmd/worktrees, select another checkout, or collide after filesystem case and normalization rules are applied. The original repository identity and Worktree name remain in trusted metadata and continue to decide compatibility and reuse.

                      The ordinary case stays simple. A short stable suffix is added only when two distinct identities would otherwise claim the same readable path, for example:

                      ~/.xmd/worktrees/xmd-demo-ff326cec/task
                      

                      Full identity digests may remain internal for metadata, locking, and collision proofs; they do not appear in the normal checkout path.

                      The readable directory is the checkout root. A captured <Worktree as="path" />, the contextual working directory inside a paired <Worktree>, and pwd all observe that path without an additional checkout segment.

                      Changing placement does not weaken the existing ordinary-run guarantees: managed worktrees persist across executions, compatible requests reuse them, conflicting identity or Git state refuses without mutation, and one invocation holds the same exclusive lock while using one.

                      Existing full-digest ordinary-run worktrees are not orphaned or duplicated. On compatible reuse, XMD makes the existing checkout available at its readable path without changing its branch, commits, index, working files, or Git worktree registration. If it cannot prove a safe transition—because the target conflicts, the checkout is active, or its identity is incompatible—it refuses actionably and leaves the existing worktree untouched.

                      Workflow-run Workspace paths and retained workflow identity do not change.

                      Acceptance

                      • A root-level <Worktree name="task"> started in xmd-demo uses ~/.xmd/worktrees/xmd-demo/task when that readable repository name is unclaimed.
                      • A Worktree inside <Repository name="project"> uses ~/.xmd/worktrees/project/<worktree> when that readable Repository name is unclaimed.
                      • The path returned through as, the contextual working directory, and pwd name the readable checkout root and contain neither full SHA-256 segments nor a trailing checkout segment in the common case.
                      • Repeating the same request reuses the same directory and preserves committed, staged, modified, and untracked work.
                      • Distinct repositories with the same readable name receive stable, distinguishable paths; the common path remains unsuffixed when no collision exists.
                      • Authored names containing traversal syntax or values that collide after filesystem normalization cannot escape the managed root or select another checkout.
                      • A compatible legacy full-digest worktree is reused at the readable path without data loss or duplicate Git registration.
                      • A conflicting or active legacy worktree refuses without moving, copying, resetting, or deleting it.
                      • Lock ownership and immutable creation-metadata checks continue to use the complete repository and Worktree identities rather than trusting readable directory names.
                      • Workflow-run worktree placement remains unchanged.
                      • architecture.md and the ordinary-run topology in specs/workflow-workspace-spec.md describe the readable interactive layout and its collision behavior.

                      Evidence

                      Run the focused ordinary-run placement and integration suites:

                      deno task test packages/workflow/tests/run-composition-managed.test.ts packages/workflow/tests/run-composition-ambient.test.ts packages/cli/tests/run-composition-deno.test.ts packages/cli/tests/run-composition-nested.test.ts

                      The regression evidence covers the simple ambient path, lexical Repository path, collisions, hostile names, persistent reuse, legacy adoption, active-use refusal, and the unchanged workflow boundary.

                      Related

                      Activity

                      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                      Metadata

                      Metadata

                      Assignees

                      No one assigned

                        Labels

                        UXUser-facing usability and interaction improvements

                        Projects

                        No projects

                          Milestone

                          No milestone

                          Relationships

                          None yet

                          Development

                          No branches or pull requests

                          Issue actions

                          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                          Skip to content

                          Make xmd run worktree paths readable #752

                          Description

                          @taras

                          Story

                          As someone using xmd run interactively, I want its managed worktrees to have short, readable paths, so I can enter them, inspect files, and continue working with ordinary filesystem tools.

                          Example

                          Given an ordinary run started in a repository named xmd-demo:

                          <Worktreename="task"branch="worktree-task">
                          ```bash exec
                          pwd
                          ```

                          The worktree lives at and reports:

                          ~/.xmd/worktrees/xmd-demo/task
                          

                          Current gap

                          Ordinary xmd run currently places the same worktree under two full SHA-256 directory names and a final checkout directory:

                          ~/.xmd/repositories/worktrees/ff326cec5b976a415f5dd20209cce334181533390b6655ec44df2d1ed8bfbfd1/86842adba411256398ba49ad04bf9070f3f558efd7a45ea1897ed1a3e78539b4/checkout
                          

                          The first digest identifies the repository's canonical Git directory and the second identifies the authored worktree name. This protects provider-owned storage from collisions and path traversal, but it exposes an internal identity layout as the directory where a person is expected to work.

                          That tradeoff is appropriate for workflow-owned storage, which users do not navigate as an interactive checkout. It is a poor default for xmd run: ordinary managed worktrees deliberately survive the invocation because they contain work a person or Agent may continue afterward.

                          Contract

                          An ordinary xmd run worktree uses this readable common-path layout:

                          ~/.xmd/worktrees/<repository>/<worktree>
                          

                          For a root-level <Worktree> using the ambient repository, <repository> is a filesystem-safe form of the repository directory name. For a <Worktree> inside a lexical <Repository name="project">, it is a filesystem-safe form of that Repository name. <worktree> is a filesystem-safe form of the authored Worktree name.

                          Names remain labels, not path authority. No authored repository or worktree name can escape ~/.xmd/worktrees, select another checkout, or collide after filesystem case and normalization rules are applied. The original repository identity and Worktree name remain in trusted metadata and continue to decide compatibility and reuse.

                          The ordinary case stays simple. A short stable suffix is added only when two distinct identities would otherwise claim the same readable path, for example:

                          ~/.xmd/worktrees/xmd-demo-ff326cec/task
                          

                          Full identity digests may remain internal for metadata, locking, and collision proofs; they do not appear in the normal checkout path.

                          The readable directory is the checkout root. A captured <Worktree as="path" />, the contextual working directory inside a paired <Worktree>, and pwd all observe that path without an additional checkout segment.

                          Changing placement does not weaken the existing ordinary-run guarantees: managed worktrees persist across executions, compatible requests reuse them, conflicting identity or Git state refuses without mutation, and one invocation holds the same exclusive lock while using one.

                          Existing full-digest ordinary-run worktrees are not orphaned or duplicated. On compatible reuse, XMD makes the existing checkout available at its readable path without changing its branch, commits, index, working files, or Git worktree registration. If it cannot prove a safe transition—because the target conflicts, the checkout is active, or its identity is incompatible—it refuses actionably and leaves the existing worktree untouched.

                          Workflow-run Workspace paths and retained workflow identity do not change.

                          Acceptance

                          • A root-level <Worktree name="task"> started in xmd-demo uses ~/.xmd/worktrees/xmd-demo/task when that readable repository name is unclaimed.
                          • A Worktree inside <Repository name="project"> uses ~/.xmd/worktrees/project/<worktree> when that readable Repository name is unclaimed.
                          • The path returned through as, the contextual working directory, and pwd name the readable checkout root and contain neither full SHA-256 segments nor a trailing checkout segment in the common case.
                          • Repeating the same request reuses the same directory and preserves committed, staged, modified, and untracked work.
                          • Distinct repositories with the same readable name receive stable, distinguishable paths; the common path remains unsuffixed when no collision exists.
                          • Authored names containing traversal syntax or values that collide after filesystem normalization cannot escape the managed root or select another checkout.
                          • A compatible legacy full-digest worktree is reused at the readable path without data loss or duplicate Git registration.
                          • A conflicting or active legacy worktree refuses without moving, copying, resetting, or deleting it.
                          • Lock ownership and immutable creation-metadata checks continue to use the complete repository and Worktree identities rather than trusting readable directory names.
                          • Workflow-run worktree placement remains unchanged.
                          • architecture.md and the ordinary-run topology in specs/workflow-workspace-spec.md describe the readable interactive layout and its collision behavior.

                          Evidence

                          Run the focused ordinary-run placement and integration suites:

                          deno task test packages/workflow/tests/run-composition-managed.test.ts packages/workflow/tests/run-composition-ambient.test.ts packages/cli/tests/run-composition-deno.test.ts packages/cli/tests/run-composition-nested.test.ts

                          The regression evidence covers the simple ambient path, lexical Repository path, collisions, hostile names, persistent reuse, legacy adoption, active-use refusal, and the unchanged workflow boundary.

                          Related

                          Activity

                          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                          Metadata

                          Metadata

                          Assignees

                          No one assigned

                            Labels

                            UXUser-facing usability and interaction improvements

                            Projects

                            No projects

                              Milestone

                              No milestone

                              Relationships

                              None yet

                              Development

                              No branches or pull requests

                              Issue actions

                              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
                              Skip to content

                              Make xmd run worktree paths readable #752

                              Description

                              @taras

                              Story

                              As someone using xmd run interactively, I want its managed worktrees to have short, readable paths, so I can enter them, inspect files, and continue working with ordinary filesystem tools.

                              Example

                              Given an ordinary run started in a repository named xmd-demo:

                              <Worktreename="task"branch="worktree-task">
                              ```bash exec
                              pwd
                              ```

                              The worktree lives at and reports:

                              ~/.xmd/worktrees/xmd-demo/task
                              

                              Current gap

                              Ordinary xmd run currently places the same worktree under two full SHA-256 directory names and a final checkout directory:

                              ~/.xmd/repositories/worktrees/ff326cec5b976a415f5dd20209cce334181533390b6655ec44df2d1ed8bfbfd1/86842adba411256398ba49ad04bf9070f3f558efd7a45ea1897ed1a3e78539b4/checkout
                              

                              The first digest identifies the repository's canonical Git directory and the second identifies the authored worktree name. This protects provider-owned storage from collisions and path traversal, but it exposes an internal identity layout as the directory where a person is expected to work.

                              That tradeoff is appropriate for workflow-owned storage, which users do not navigate as an interactive checkout. It is a poor default for xmd run: ordinary managed worktrees deliberately survive the invocation because they contain work a person or Agent may continue afterward.

                              Contract

                              An ordinary xmd run worktree uses this readable common-path layout:

                              ~/.xmd/worktrees/<repository>/<worktree>
                              

                              For a root-level <Worktree> using the ambient repository, <repository> is a filesystem-safe form of the repository directory name. For a <Worktree> inside a lexical <Repository name="project">, it is a filesystem-safe form of that Repository name. <worktree> is a filesystem-safe form of the authored Worktree name.

                              Names remain labels, not path authority. No authored repository or worktree name can escape ~/.xmd/worktrees, select another checkout, or collide after filesystem case and normalization rules are applied. The original repository identity and Worktree name remain in trusted metadata and continue to decide compatibility and reuse.

                              The ordinary case stays simple. A short stable suffix is added only when two distinct identities would otherwise claim the same readable path, for example:

                              ~/.xmd/worktrees/xmd-demo-ff326cec/task
                              

                              Full identity digests may remain internal for metadata, locking, and collision proofs; they do not appear in the normal checkout path.

                              The readable directory is the checkout root. A captured <Worktree as="path" />, the contextual working directory inside a paired <Worktree>, and pwd all observe that path without an additional checkout segment.

                              Changing placement does not weaken the existing ordinary-run guarantees: managed worktrees persist across executions, compatible requests reuse them, conflicting identity or Git state refuses without mutation, and one invocation holds the same exclusive lock while using one.

                              Existing full-digest ordinary-run worktrees are not orphaned or duplicated. On compatible reuse, XMD makes the existing checkout available at its readable path without changing its branch, commits, index, working files, or Git worktree registration. If it cannot prove a safe transition—because the target conflicts, the checkout is active, or its identity is incompatible—it refuses actionably and leaves the existing worktree untouched.

                              Workflow-run Workspace paths and retained workflow identity do not change.

                              Acceptance

                              • A root-level <Worktree name="task"> started in xmd-demo uses ~/.xmd/worktrees/xmd-demo/task when that readable repository name is unclaimed.
                              • A Worktree inside <Repository name="project"> uses ~/.xmd/worktrees/project/<worktree> when that readable Repository name is unclaimed.
                              • The path returned through as, the contextual working directory, and pwd name the readable checkout root and contain neither full SHA-256 segments nor a trailing checkout segment in the common case.
                              • Repeating the same request reuses the same directory and preserves committed, staged, modified, and untracked work.
                              • Distinct repositories with the same readable name receive stable, distinguishable paths; the common path remains unsuffixed when no collision exists.
                              • Authored names containing traversal syntax or values that collide after filesystem normalization cannot escape the managed root or select another checkout.
                              • A compatible legacy full-digest worktree is reused at the readable path without data loss or duplicate Git registration.
                              • A conflicting or active legacy worktree refuses without moving, copying, resetting, or deleting it.
                              • Lock ownership and immutable creation-metadata checks continue to use the complete repository and Worktree identities rather than trusting readable directory names.
                              • Workflow-run worktree placement remains unchanged.
                              • architecture.md and the ordinary-run topology in specs/workflow-workspace-spec.md describe the readable interactive layout and its collision behavior.

                              Evidence

                              Run the focused ordinary-run placement and integration suites:

                              deno task test packages/workflow/tests/run-composition-managed.test.ts packages/workflow/tests/run-composition-ambient.test.ts packages/cli/tests/run-composition-deno.test.ts packages/cli/tests/run-composition-nested.test.ts

                              The regression evidence covers the simple ambient path, lexical Repository path, collisions, hostile names, persistent reuse, legacy adoption, active-use refusal, and the unchanged workflow boundary.

                              Related

                              Activity

                              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                              Metadata

                              Metadata

                              Assignees

                              No one assigned

                                Labels

                                UXUser-facing usability and interaction improvements

                                Projects

                                No projects

                                  Milestone

                                  No milestone

                                  Relationships

                                  None yet

                                  Development

                                  No branches or pull requests

                                  Issue actions