DL-326
The P2 session-volume clone model is agent self-clone (Option A): the Runner prepares/attaches the volume (empty or snapshot-restored) and the agent clones/fetches in-container with its existing $HOME machine-user token — no new host-side forge read credential (distinct from DL-052’s Server-only write secret). Snapshot amortization is clone-only (provenance-(a)): the snapshot carries a provably-clean post-clone tree (agent clone-complete signal → Runner host-side git status-clean verify → snapshot, keyed by an (account, repo) index), never cross-session build state (target/, caches), so a new session of a seen (account, repo) skips the cold clone but builds cold on its own volume — zero cross-session leak. Runner-side box-global read-only clones of subscribed repos are a deferred follow-up optimization, and a host-side read credential earns its existence only when a sessionless prebuild service materializes trees with no session; the Materialize signature already accommodates that flip. Resolves this record’s OQ-1 (both sub-parts).
Status: Active (Matt, 2026-09-05)