# Design: Live Git Config Mount Refresh ## Canonical source Each selected Config Profile owns a writable Git working copy beneath: ```text /config-profiles//git-mounts//repo ``` `identity` is a stable hash of normalized remote URL, requested ref, and credential scope. Sources are deliberately profile-scoped; working copies are never shared across users, but are shared by compatible instances that selected the same profile. ## Runtime behavior 1. Resolve Git mounts and map them to canonical sources. 2. Acquire an exclusive lock for clone, fetch, ref resolution, and checkout. 3. Clone into a temporary sibling, then rename on initial creation. 4. For refresh, fetch and hard-reset the existing working tree in place, replacing local container/editor edits after an explicit warning. 5. Bind directory mappings writable. Compatible containers and the profile editor share the same working-copy files. 6. When profile and Git mount paths overlap, the instance-local composite source must be synchronized in place during refresh; replacing its root directory would leave a running bind mount attached to the old inode. ## Boundaries - URL/ref/source/target/mode changes, direct-file mappings, and changed glob result sets return `restart_required`. - Refresh failure is reported without mutating a known-good checkout. - No non-Git profile content may be copied into a Git checkout; overlapping targets are rejected or reported. - A refresh warning must state that local Git working-copy edits will be replaced. - A browser editor that already has a file open is not a filesystem watcher; the user must reload that editor buffer after the mounted source changes. ## Security Host Git operations use only an authorized server-side credential source. Credentials are not part of the mounted checkout and are not exposed to containers.