Problem
With the Cloud Hypervisor runtime, HOME is /workspace/.awf-home, represented by cloudHypervisorAwfHomeWritePath in pkg/workflow/sandbox.go. This places the agent's home directory inside the checked-out repository rather than outside its working tree.
Caches and other tool state written under HOME therefore appear as untracked repository files. A normal git add -A can stage them, and agent patch generation can pick them up, allowing runtime state to enter commits and patches alongside intentional source changes.
This becomes particularly visible with uv's default cache under HOME now that AWF stops forwarding setup-uv's inaccessible UV_CACHE_DIR and UV_PYTHON_INSTALL_DIR values, as addressed by github/gh-aw-firewall#9705. The underlying problem applies to any tool that writes state under this HOME directory, not just uv.
Proposed fix
When buildCloudHypervisorFilesystemMkdirScript in pkg/workflow/awf_command_builder.go creates the checkout's .awf-home directory, also add the root-anchored exclusion /.awf-home/ to that repository's local Git exclude file, info/exclude, before AWF starts.
Resolve the exclude file through Git so the setup does not assume that .git is a directory. Preserve existing exclude entries and make the addition idempotent, including when the file is missing or its last entry lacks a trailing newline. Keep this as checkout-local configuration rather than modifying the repository's tracked .gitignore.
Retain the existing Cloud Hypervisor runtime and version gates, HOME location, and directory-creation behavior. The change should keep HOME writable for tools while preventing newly created state there from being included in ordinary staging and agent patches.
Regression coverage
Add a compile test confirming that Cloud Hypervisor's generated setup creates .awf-home and installs the local Git exclusion before invoking AWF. Verify that the generated exclusion is guarded against duplicate entries and remains absent when the existing runtime or version gates do not emit this HOME setup. Regression coverage should preserve existing exclude entries and demonstrate that HOME tool state is omitted while intentional source changes remain stageable.
Provenance
This change was first written in #66958, "Disable uv Actions caching and isolate sandbox runtime paths." That PR is being split per maintainer request; this issue tracks the Cloud Hypervisor HOME-state exclusion separately from the uv caching and environment-forwarding changes.
Problem
With the Cloud Hypervisor runtime, HOME is
/workspace/.awf-home, represented bycloudHypervisorAwfHomeWritePathinpkg/workflow/sandbox.go. This places the agent's home directory inside the checked-out repository rather than outside its working tree.Caches and other tool state written under HOME therefore appear as untracked repository files. A normal
git add -Acan stage them, and agent patch generation can pick them up, allowing runtime state to enter commits and patches alongside intentional source changes.This becomes particularly visible with uv's default cache under HOME now that AWF stops forwarding setup-uv's inaccessible
UV_CACHE_DIRandUV_PYTHON_INSTALL_DIRvalues, as addressed by github/gh-aw-firewall#9705. The underlying problem applies to any tool that writes state under this HOME directory, not just uv.Proposed fix
When buildCloudHypervisorFilesystemMkdirScript in
pkg/workflow/awf_command_builder.gocreates the checkout's.awf-homedirectory, also add the root-anchored exclusion/.awf-home/to that repository's local Git exclude file,info/exclude, before AWF starts.Resolve the exclude file through Git so the setup does not assume that
.gitis a directory. Preserve existing exclude entries and make the addition idempotent, including when the file is missing or its last entry lacks a trailing newline. Keep this as checkout-local configuration rather than modifying the repository's tracked.gitignore.Retain the existing Cloud Hypervisor runtime and version gates, HOME location, and directory-creation behavior. The change should keep HOME writable for tools while preventing newly created state there from being included in ordinary staging and agent patches.
Regression coverage
Add a compile test confirming that Cloud Hypervisor's generated setup creates
.awf-homeand installs the local Git exclusion before invoking AWF. Verify that the generated exclusion is guarded against duplicate entries and remains absent when the existing runtime or version gates do not emit this HOME setup. Regression coverage should preserve existing exclude entries and demonstrate that HOME tool state is omitted while intentional source changes remain stageable.Provenance
This change was first written in #66958, "Disable uv Actions caching and isolate sandbox runtime paths." That PR is being split per maintainer request; this issue tracks the Cloud Hypervisor HOME-state exclusion separately from the uv caching and environment-forwarding changes.