Bug
~/.copilot/config.json (marked // This file is managed automatically.) is not merged/reconciled when written — each running Copilot CLI session appears to hold its own in-memory copy of the file's managed state (e.g. trustedFolders) and rewrites the entire file on exit using that stale snapshot. If a directory is added via /add-dir in one session while other sessions are still open, the addition is silently lost as soon as any of those other sessions closes and overwrites config.json with its older list.
This makes /add-dir (intended to persist trusted directories globally, per its own help text: "Allow file access to a directory and load its .github skills and agents as trusted configuration") effectively non-persistent whenever more than one CLI session/window is used at a time — which is a common workflow.
Steps to Reproduce
- Open two Copilot CLI sessions (session A and session B) in different terminals.
- In session A, run
/add-dir /path/to/new-dir. Confirm ~/.copilot/config.json's trustedFolders now includes the new path.
- Without closing session A, exit session B (
ctrl+d or normal exit).
- Inspect
~/.copilot/config.json again — the directory added in step 2 is gone, because session B rewrote the file from its own (older) in-memory state.
Expected Behavior
Writes to config.json (and similar "managed automatically" files, e.g. permissions-config.json) should be done as a read-modify-write with file locking, or by merging the specific keys being changed into the on-disk state, rather than replacing the whole file with a long-lived in-memory snapshot. At minimum, list-valued fields like trustedFolders should be unioned rather than overwritten.
Additional Context
Bug
~/.copilot/config.json(marked// This file is managed automatically.) is not merged/reconciled when written — each running Copilot CLI session appears to hold its own in-memory copy of the file's managed state (e.g.trustedFolders) and rewrites the entire file on exit using that stale snapshot. If a directory is added via/add-dirin one session while other sessions are still open, the addition is silently lost as soon as any of those other sessions closes and overwritesconfig.jsonwith its older list.This makes
/add-dir(intended to persist trusted directories globally, per its own help text: "Allow file access to a directory and load its.githubskills and agents as trusted configuration") effectively non-persistent whenever more than one CLI session/window is used at a time — which is a common workflow.Steps to Reproduce
/add-dir /path/to/new-dir. Confirm~/.copilot/config.json'strustedFoldersnow includes the new path.ctrl+dor normal exit).~/.copilot/config.jsonagain — the directory added in step 2 is gone, because session B rewrote the file from its own (older) in-memory state.Expected Behavior
Writes to
config.json(and similar "managed automatically" files, e.g.permissions-config.json) should be done as a read-modify-write with file locking, or by merging the specific keys being changed into the on-disk state, rather than replacing the whole file with a long-lived in-memory snapshot. At minimum, list-valued fields liketrustedFoldersshould be unioned rather than overwritten.Additional Context
/add-dir/trusted-directory persistence "doesn't work" — in our case the user had run/add-diron the same path "numerous times" and it kept reverting.~/.copilot/config.jsondirectly while no other sessions are running.