Skip to content

BuildNot yet confirmed elsewhere1 publisher3 min readPublished

Parallel coding agents on Windows break at the home directory, not the launcher

One practitioner's teardown notes: shared authenticated sessions, half-redirected homes, hardlinks that deny being links, and a delete that blames permissions for something else.

The Engineer · Build desk

How we use AISend a correction

What happened

  • Two agents run under the same Windows account share ~/.claude, ~/.codex and ~/.gemini, which means the same config and the same authenticated session.
  • Removing a git worktree while a process still has its working directory inside returns "failed to delete ... Permission denied".
  • The list of concerns came from a reader comment by Alex Shev, naming isolation, logs, file ownership and cleanup after failed runs as the things that decide whether a setup survives.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure A detach control built on symlink checks leaves hardlinked accounts writing into the shared global config while reporting themselves separated, so one agent's edit reaches every other pane.
  • constraint Nothing in the redirect path raises an error, so the earliest available signal of a leaked identity is commits already attributed to the wrong account.
  • decision Anyone building a launcher has to keep its own storage path and the child's home in separate variables from the start, because retrofitting that split means moving where existing agents keep their...
  • precedent Because the same teardown succeeds on Linux, maintainers on other platforms will keep closing these as unreproducible, and the cost stays with the Windows users who filed them.

Each of these failures either says nothing or points somewhere else. Redirecting `HOME` alone, a POSIX convention Windows itself does not honor [4], moves a CLI's config to the new directory while git carries on writing `.gitconfig` to the old one [5], and the first visible symptom, according to the post, is two panes sharing a git identity [6]. The set that actually works is `HOME`, `USERPROFILE`, `HOMEDRIVE` and `HOMEPATH` per process [7], plus `GEMINI_CLI_HOME` pointed at its own subdirectory for Gemini CLI [8]. Five variables to relocate one idea of home [20], and nothing errors if you set three of them.

The linking layer has the same property. Full isolation is not the goal, since `CLAUDE.md`, `settings.json` and skills are meant to be identical in every pane, so they get linked back to the global copy instead of duplicated [9]. On Windows, `mklink` needs elevation or Developer Mode for a file symlink while junctions need neither, so directories are easy and files fall back to hardlinks [10]. A hardlink returns false from `lstat().isSymbolicLink()` [11]. Build a "detach this account from shared config" action as "replace symlinks with real copies" and the hardlinked files are skipped: the account goes on editing the global config while the interface reports it detached [12]. The author's detection compares device and inode numbers with `bigint: true`, because a plain `ino` comes back as `0` on some Windows configurations, which makes every pair of files look like the same file [13]. A comparison tested without that flag would have passed.

Teardown is where the error message actively misdirects. `git worktree remove --force` returns `failed to delete ... Permission denied` [14] when the actual cause is that Windows will not delete a directory that is some process's current directory, and git renders that refusal as a permissions error [15]. Testing it is worse than reading it. PowerShell's `Set-Location` does not reproduce the failure, because the PowerShell location is a provider concept layered over a process whose real working directory never moved [16], so a harness built on `Set-Location` will tell you the bug is imaginary. Killing the shell is not sufficient either: in the author's run the `cmd.exe` was dead and the delete still failed, because the holder was `timeout.exe`, a child that had inherited the directory [17]. Any teardown that kills the pane process and then removes the worktree will fail on the first agent that leaves a grandchild running.

For people writing the launcher rather than using one, Node's `os.homedir()` does not reliably reflect a `USERPROFILE` injected at spawn time on Windows [22]. The author's project ended up with a dedicated variable for its own storage and a separate function for where a new shell should start, because collapsing the two meant every new terminal opened inside the agent's config directory [18].

This is one account, from someone who discloses that he works on a product in this space and marks which decisions are his own [19]. It is also the class of detail that only gets written down by someone who has already lost a weekend to it.

What to watch

  • Whether the CLI vendors document a supported per-instance config directory on Windows, which would retire the four-variable dance entirely.
  • Whether git changes its message for a worktree directory held open by a running process, instead of reporting it as a permissions failure.
  • Independent write-ups from other Windows launcher authors, since the hardlink and cwd findings here rest on one vendor's account of its own bugs.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence52
Adoption
Insufficient
Hype gap+8
Incentives55
Confidence48
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Alex Shev commented that parallel agents are only practical when workspace boundaries are boring and explicit, and that on Windows he would care less about the launch trick and more about isolation, logs, file ownership and cleanup after failed runs.

    ReportedSupportedSource: Alex Shev, quoted in the dev.to postView cited source
  2. [2]

    Two agents running under the same Windows account share ~/.claude, ~/.codex and ~/.gemini.

    ReportedSupportedView cited source
  3. [3]

    Sharing those directories means sharing the same config and, more importantly, the same authenticated session; two Claude accounts side by side require separate home directories.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · August 23, 2026

    Isolation, file ownership and cleanup: the boring half of running coding agents in parallel on Windows

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories