What consumers copy today
inherit.paths reads only files inside the repository, and a bundled set is
the only thing shared across repositories. A rule that one org wants in all
of its repositories, and that does not belong in a bundled set, has no home,
so it is pasted. From a fleet sweep against 1.21.0:
- A pacing rule pair pasted byte-identical into 13 connector
repositories, plus a rule in that org's root whose only job is to
police that the copies still match.
no-device-model-names in four repositories of another org with four
different regexes, because nothing made them one rule.
- The
[[shim]] block for gh and git copied into every consumer. ADR
0006 says a set may not declare a shim, which is the right call for a
bundled set, but it leaves the one-line-per-repo decision with no shared
spelling either.
Onboarding has the same shape: there is no uphold init, and three
repositories in the sweep were set up by hand-copying another repository's
policy, hook config and shim block.
What would close it
- An org-level source for
inherit: a policy file fetched from another
repository at a pinned revision (the way hook configs pin a rev), for
example inherit.remote = [{ repo = "<org>/<policy-repo>", rev = "<tag>", path = "policy/org.toml" }]. Rules from it carry that provenance, can be
narrowed with [override.<id>], and a moved or missing rev is exit 2.
- Whether such a file may declare a
[[shim]] is a separate decision from
ADR 0006. An org file is chosen by the repository, which is the property
ADR 0006 cites for keeping shims out of bundled sets, so it may be the
right place.
uphold init: write a minimal policy/ with the recommended sets, the
shim block, and the hook entries at the current pin, refusing to touch a
tree that already has a policy.
What consumers copy today
inherit.pathsreads only files inside the repository, and a bundled set isthe only thing shared across repositories. A rule that one org wants in all
of its repositories, and that does not belong in a bundled set, has no home,
so it is pasted. From a fleet sweep against 1.21.0:
repositories, plus a rule in that org's root whose only job is to
police that the copies still match.
no-device-model-namesin four repositories of another org with fourdifferent regexes, because nothing made them one rule.
[[shim]]block forghandgitcopied into every consumer. ADR0006 says a set may not declare a shim, which is the right call for a
bundled set, but it leaves the one-line-per-repo decision with no shared
spelling either.
Onboarding has the same shape: there is no
uphold init, and threerepositories in the sweep were set up by hand-copying another repository's
policy, hook config and shim block.
What would close it
inherit: a policy file fetched from anotherrepository at a pinned revision (the way hook configs pin a
rev), forexample
inherit.remote = [{ repo = "<org>/<policy-repo>", rev = "<tag>", path = "policy/org.toml" }]. Rules from it carry that provenance, can benarrowed with
[override.<id>], and a moved or missing rev is exit 2.[[shim]]is a separate decision fromADR 0006. An org file is chosen by the repository, which is the property
ADR 0006 cites for keeping shims out of bundled sets, so it may be the
right place.
uphold init: write a minimalpolicy/with the recommended sets, theshim block, and the hook entries at the current pin, refusing to touch a
tree that already has a policy.