Skip to content

No enforcement mode: a pack cannot restore a baseline once a repo has diverged #92

Description

@arcaven

A guardrails pack has no way to restore a baseline in a repo that has diverged from it. Once someone edits a distributed .golangci.yml, lefthook.yml, or CI workflow, every later sweep skips that repo and reports it as a preserved user edit. For a pack whose purpose is a floor rather than a suggestion, that means the floor quietly stops applying exactly where it is most likely to matter.

This is a capability gap, not a defect. Edit preservation is the correct default and is deliberate (#84): a repo that tunes its own linter config should keep the tuning, and #90 argues the same behavior should extend to rules:. The gap is that preservation is the only available behavior, so a pack author cannot express "this one is not negotiable."

The concrete case is the fleet-bootstrap pack (aae-orc-0jl), a tier-1 guardrails scaffold for new repos. Some of what it ships is a starting point that repos should adapt. Some of it, plausibly signing requirements or a CI gate, is meant to hold.

Sketch, not a proposal:

distribute:
  files:
    - source: distribute/editorconfig
      target: .editorconfig
      on_local_edit: preserve      # default, current behavior
    - source: distribute/workflows/codeql.yml
      target: .github/workflows/codeql.yml
      on_local_edit: report        # skip, but surface it as drift in doctor
    - source: distribute/signing.yml
      target: .github/workflows/signing.yml
      on_local_edit: restore       # overwrite, and say so

report is probably the most useful of the three and the cheapest: it needs no new write behavior, only a distinct outcome that sideshow doctor can surface as fleet drift. restore is the one that needs care, since it means a tool overwriting a human's work on a schedule, and it should not be reachable without the pack author opting a specific path into it.

There is an existing hook for the report half: doctor layer 4 is already specified as fleet drift against the lockfile (aae-orc-xteh). A file artifact whose on-disk hash does not match its receipt is exactly that signal, and it is currently computed and then discarded.

Relevant paths: internal/distribute/manifest.go (FileArtifact), internal/distribute/distribute.go (distributeFile, where the drift is already detected).

Refs #84, #90.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions