Files
msd-core/.changeset/archived/3542-executor-git-stash-prohibition.md
Tom Boucher 8616839cab chore: archive 463 shipped changeset fragments before wiring render (#714)
CHANGELOG promotion was a manual operator step that was never run, so 463
fragments for work already shipped in <=1.3.1 accumulated in .changeset/.
Their notes were already hand-curated into the dated [1.2.0]/[1.3.0]/[1.3.1]
CHANGELOG sections (#690 backfill, PR #694). Rendering them now would
duplicate and mis-attribute shipped work.

Move them to .changeset/archived/ (read non-recursively by all changeset
tooling, so never rendered), keeping only the 3 genuinely-unreleased
fragments at the top level. Prep for wiring `render` into the release
finalize job (#690 follow-up).

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-05 14:53:17 -04:00

1007 B

type, pr
type pr
Fixed 3546

Executor agents are now forbidden from running any git stash subcommand inside worktree isolation — git stores stashes at refs/stash in the parent .git/ directory, so the stash list is shared across the main checkout and every linked worktree. A git stash pop inside an executor's worktree silently applied WIP pushed from a prior sibling-worktree session, producing UU/UD merge-conflict states and phantom untracked files that violated the isolation="worktree" invariant. The <destructive_git_prohibition> block in agents/gsd-executor.md now lists the full git stash family alongside --no-verify, --hard, and git update-ref, with sanctioned alternatives (commit to a throwaway branch you own, or read-only git show <ref>:<path> / git diff <ref> -- <path>). The orchestrator-side post-wave-hook helper in execute-phase.md continues to use stash deliberately and is now annotated to make the single-checkout precondition explicit. Closes #3542.