Source: BLOCKING #3 (new) from @scottschreckengaust's review of #665 — #665 (review) (agent/src/registry/loader.py:217)
Parent: #246 · Sibling blockers: #758 (symlink), and the fail-open guard issue
Problem
git update-index --skip-worktree .mcp.json makes git ignore all worktree changes to that path, not just the loader's write. Once a registry mcp_server asset is pinned, any task whose actual job touches .mcp.json — plausible here, where channel_mcp.py writes it and strip_linear_mcp_servers edits it — loses its work. Reproduced with the real loader:
# task: "register our new internal MCP server in .mcp.json"
agent: git add .mcp.json -> exit 1
"matched paths that exist outside of your sparse-checkout definition, so will not be updated"
agent: git commit -am … -> exit 1 ("nothing to commit, working tree clean")
git status --porcelain -> '' (edit is invisible)
Two harms: (a) silent loss of agent output while the PR reports success — the exact failure class ensure_committed exists to prevent; (b) git blames sparse-checkout, which is not what happened, so the model burns turns chasing a nonexistent sparse config and may trip stuck_guard.
This is a data-loss / correctness bug (not security), and it is the structural cost of masking a confidentiality problem with a VCS flag.
Fix
Disappears entirely under Scott's recommended approach — pass the resolved runtime through the SDK's in-process mcp_servers option (runner.py:525-553 already does this for the clarification server), so .mcp.json is never written in the repo. That closes #758 + the fail-open issue + this one together, with less machinery than the skip-worktree guard.
If the flag is kept as an interim: at minimum emit a TASK-level line naming .mcp.json as platform-managed and uncommittable for the task, so the trajectory records the cause instead of a misleading sparse-checkout error.
Acceptance
- A task that legitimately edits
.mcp.json is not silently dropped, and any suppression is explained in the trajectory
Source: BLOCKING #3 (new) from @scottschreckengaust's review of #665 — #665 (review) (
agent/src/registry/loader.py:217)Parent: #246 · Sibling blockers: #758 (symlink), and the fail-open guard issue
Problem
git update-index --skip-worktree .mcp.jsonmakes git ignore all worktree changes to that path, not just the loader's write. Once a registrymcp_serverasset is pinned, any task whose actual job touches.mcp.json— plausible here, wherechannel_mcp.pywrites it andstrip_linear_mcp_serversedits it — loses its work. Reproduced with the real loader:Two harms: (a) silent loss of agent output while the PR reports success — the exact failure class
ensure_committedexists to prevent; (b) git blames sparse-checkout, which is not what happened, so the model burns turns chasing a nonexistent sparse config and may tripstuck_guard.This is a data-loss / correctness bug (not security), and it is the structural cost of masking a confidentiality problem with a VCS flag.
Fix
Disappears entirely under Scott's recommended approach — pass the resolved runtime through the SDK's in-process
mcp_serversoption (runner.py:525-553already does this for the clarification server), so.mcp.jsonis never written in the repo. That closes #758 + the fail-open issue + this one together, with less machinery than the skip-worktree guard.If the flag is kept as an interim: at minimum emit a
TASK-level line naming.mcp.jsonas platform-managed and uncommittable for the task, so the trajectory records the cause instead of a misleading sparse-checkout error.Acceptance
.mcp.jsonis not silently dropped, and any suppression is explained in the trajectory