A guardrails pack has no way to restore a baseline in a repo that has diverged from it. Once someone edits a distributed .golangci.yml, lefthook.yml, or CI workflow, every later sweep skips that repo and reports it as a preserved user edit. For a pack whose purpose is a floor rather than a suggestion, that means the floor quietly stops applying exactly where it is most likely to matter.
This is a capability gap, not a defect. Edit preservation is the correct default and is deliberate (#84): a repo that tunes its own linter config should keep the tuning, and #90 argues the same behavior should extend to rules:. The gap is that preservation is the only available behavior, so a pack author cannot express "this one is not negotiable."
The concrete case is the fleet-bootstrap pack (aae-orc-0jl), a tier-1 guardrails scaffold for new repos. Some of what it ships is a starting point that repos should adapt. Some of it, plausibly signing requirements or a CI gate, is meant to hold.
Sketch, not a proposal:
distribute:
files:
- source: distribute/editorconfig
target: .editorconfig
on_local_edit: preserve # default, current behavior
- source: distribute/workflows/codeql.yml
target: .github/workflows/codeql.yml
on_local_edit: report # skip, but surface it as drift in doctor
- source: distribute/signing.yml
target: .github/workflows/signing.yml
on_local_edit: restore # overwrite, and say so
report is probably the most useful of the three and the cheapest: it needs no new write behavior, only a distinct outcome that sideshow doctor can surface as fleet drift. restore is the one that needs care, since it means a tool overwriting a human's work on a schedule, and it should not be reachable without the pack author opting a specific path into it.
There is an existing hook for the report half: doctor layer 4 is already specified as fleet drift against the lockfile (aae-orc-xteh). A file artifact whose on-disk hash does not match its receipt is exactly that signal, and it is currently computed and then discarded.
Relevant paths: internal/distribute/manifest.go (FileArtifact), internal/distribute/distribute.go (distributeFile, where the drift is already detected).
Refs #84, #90.
A guardrails pack has no way to restore a baseline in a repo that has diverged from it. Once someone edits a distributed
.golangci.yml,lefthook.yml, or CI workflow, every later sweep skips that repo and reports it as a preserved user edit. For a pack whose purpose is a floor rather than a suggestion, that means the floor quietly stops applying exactly where it is most likely to matter.This is a capability gap, not a defect. Edit preservation is the correct default and is deliberate (#84): a repo that tunes its own linter config should keep the tuning, and #90 argues the same behavior should extend to
rules:. The gap is that preservation is the only available behavior, so a pack author cannot express "this one is not negotiable."The concrete case is the fleet-bootstrap pack (aae-orc-0jl), a tier-1 guardrails scaffold for new repos. Some of what it ships is a starting point that repos should adapt. Some of it, plausibly signing requirements or a CI gate, is meant to hold.
Sketch, not a proposal:
reportis probably the most useful of the three and the cheapest: it needs no new write behavior, only a distinct outcome thatsideshow doctorcan surface as fleet drift.restoreis the one that needs care, since it means a tool overwriting a human's work on a schedule, and it should not be reachable without the pack author opting a specific path into it.There is an existing hook for the
reporthalf: doctor layer 4 is already specified as fleet drift against the lockfile (aae-orc-xteh). A file artifact whose on-disk hash does not match its receipt is exactly that signal, and it is currently computed and then discarded.Relevant paths:
internal/distribute/manifest.go(FileArtifact),internal/distribute/distribute.go(distributeFile, where the drift is already detected).Refs #84, #90.