The shared-workspace-isolated-context split is the right call for governance, but it raises a real question once a parent fires more than one child at a task: if two subagents run against the same workspace, is there any locking around file writes, or does run_agent() stay strictly sequential per parent for now? The depth guard stops a child from recursing, but nothing stops a parent from spawning two children back to back into the same tree, and if they touch overlapping files the last write wins without either child ever knowing the other existed. Worth stating explicitly whether v0.12 assumes sequential-only delegation or whether parallel subagents are coming, because the isolation guarantee you built is over context, not files, and that only holds cleanly in the sequential case.
The shared-workspace-isolated-context split is the right call for governance, but it raises a real question once a parent fires more than one child at a task: if two subagents run against the same workspace, is there any locking around file writes, or does run_agent() stay strictly sequential per parent for now? The depth guard stops a child from recursing, but nothing stops a parent from spawning two children back to back into the same tree, and if they touch overlapping files the last write wins without either child ever knowing the other existed. Worth stating explicitly whether v0.12 assumes sequential-only delegation or whether parallel subagents are coming, because the isolation guarantee you built is over context, not files, and that only holds cleanly in the sequential case.