Repository Development · Applicable Gov

Windows Local Repository Execution

Keep active Git repositories on compatible local storage, synchronize devices through GitHub, and recover unsafe chats through one verified XRT handover.

Reliable architecture

Local NTFS clone↔Git↔GitHub↔Git↔Local device clone

Primary checkout

Each Windows development device uses its own independent local clone. Its .git directory remains on compatible local storage.

Optional worktrees

Additional branch worktrees are optional. Every worktree and the shared Git common directory remain local.

Cloud storage

Cloud drives hold non-authoritative derived artifacts such as archives, exports, handovers, packages, and reviewed mirrors—not the active Git database.

Mandatory preflight

  1. Enumerate the workspace and every writable sandbox root without adding another root for inspection.
  2. Resolve the repository, worktree, and absolute Git common directory.
  3. Identify cloud, virtual, removable, network, or filesystem-unknown paths.
  4. Classify the environment as SAFE, UNSAFE, or UNKNOWN.
  5. Run harmless repeated command and patch probes only when SAFE.
  6. For helper investigations, correlate each probe with its exact sandbox-log setup cycle.

If the chat is unsafe

Stop safely

Do not retry from another current directory. Do not mutate, clean, or register the incompatible repository.

Preserve continuity

Create and privacy-review a semantic XRT, publish it to approved private storage when authorized, then independently verify its resolver and registry entry.

One user action

Tell the feature developer exactly how to open only the safe local repository and provide one complete copy-paste continuation block.

Managed Git write boundaries

Not sandbox damage

If repository reads, file edits, and tests work while only .git writes are blocked by the managed permission profile, treat that as an intentional authorization boundary.

Use scoped approval

Request the platform's narrowly scoped approval for the required branch, stage, commit, or merge operation, then continue automatically after approval.

Recover only with evidence

Run WIN CHK or sandbox recovery only when separate evidence identifies an actual setup, ACL, process-launch, shell, Git-ownership, or filesystem failure.

Important: reading an XRT or document that mentions an incompatible path does not register that path as writable. Workspace permission roots and semantic context are separate.