Skip to content

inherit.paths reads only in-repo files, so an org-wide rule is pasted into every repository and drifts, and there is no uphold init #262

Description

@HackingGate

What consumers copy today

inherit.paths reads only files inside the repository, and a bundled set is
the only thing shared across repositories. A rule that one org wants in all
of its repositories, and that does not belong in a bundled set, has no home,
so it is pasted. From a fleet sweep against 1.21.0:

  • A pacing rule pair pasted byte-identical into 13 connector
    repositories, plus a rule in that org's root whose only job is to
    police that the copies still match.
  • no-device-model-names in four repositories of another org with four
    different regexes, because nothing made them one rule.
  • The [[shim]] block for gh and git copied into every consumer. ADR
    0006 says a set may not declare a shim, which is the right call for a
    bundled set, but it leaves the one-line-per-repo decision with no shared
    spelling either.

Onboarding has the same shape: there is no uphold init, and three
repositories in the sweep were set up by hand-copying another repository's
policy, hook config and shim block.

What would close it

  • An org-level source for inherit: a policy file fetched from another
    repository at a pinned revision (the way hook configs pin a rev), for
    example inherit.remote = [{ repo = "<org>/<policy-repo>", rev = "<tag>", path = "policy/org.toml" }]. Rules from it carry that provenance, can be
    narrowed with [override.<id>], and a moved or missing rev is exit 2.
  • Whether such a file may declare a [[shim]] is a separate decision from
    ADR 0006. An org file is chosen by the repository, which is the property
    ADR 0006 cites for keeping shims out of bundled sets, so it may be the
    right place.
  • uphold init: write a minimal policy/ with the recommended sets, the
    shim block, and the hook entries at the current pin, refusing to touch a
    tree that already has a policy.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions