Skip to content

TRACKING: guards-that-do-not-guard epic (#241) — implementation order and completion criteria #251

Description

@Polichinel

Rewritten 2026-08-12. Tracking issue for #241.

The shape

This is an MVP with one maintainer and a product that has not shipped in eight days. The epic was re-scoped so that PR #240 merges after three issues, and those three are almost entirely deletion.

The test for every item: does this make the thing smaller, or does it add a second product to maintain?

Gate 1 — blocks PR #240. Do these, then ship.

Then: PR #240 green → merge → FAO has the work. Nothing below blocks the release.

Gate 2 — cheap, same week. Each makes the code smaller or truer.

Gate 3 — the two paragraphs that stop the next round

Closing out

  • Independent review pass finds nothing above suggestion severity
  • C-89 … C-96 resolved or amended with a measured residual and a trigger
  • wc -l tests/*.py is lower than when this epic started — if it is higher, the epic did the opposite of its purpose

Deferred, with triggers — not built, on purpose

Deferred Trigger to revisit
Read-only findability preflight (C-94) A delivery is reported empty, or APPWRITE_READ_API_KEY is provisioned for the launcher
Adopt [edition].obliges_consumers The drift check fires again on something we do not care about
Extract a platform/ module (C-88) A third consumer needs one of these declarations
GitHub push protection / secret scanning The cost is known, or GHAS is available
Split test_env_declaration.py (1,145 lines) The file grows again after this epic, or a second contributor arrives
Write-path integration test A non-production Appwrite project exists (þing-01 D2, an open operator assignment)

Order and why

#242 before #243 — get the no-print invariant in place before the matcher moves under it. #243 absorbs #244 — both are "what the scanner hunts and how", and splitting them was an artefact of reviewing them separately. #246 after #245 — the tautology sits on the code #245 changes. #249 late — several of its sentences describe behaviour #245 and #247 change. #250 last — writing the rule before doing the work would draw it from the same imagination that caused the problem.

#248's cross-repo half — the issues on views-faoapi and views-crafdapi — should be filed on day one. Their response time is not ours.

Completion criteria

The epic is done when all of the following hold, each demonstrated rather than asserted:

  1. PR Sync development → main: the sibling-CI arc, three ADRs, and a drift check that matches on the right thing #240 is merged. A product that does not ship is a broken product; this is criterion one for that reason.
  2. No test in this repository parses another repository's source. Verified by grep.
  3. The drift check fires on exactly one condition — a row we name moved between the pin and their main — and its stopping rule is written above it.
  4. The no-copy scan's stopping rule is derived from this repository's own documents, is mechanical, and is a test.
  5. No branch of that scan can print a coordinate value, asserted about the guard as a whole.
  6. Every proof fails under mutation of the thing it names.
  7. Every deferral above is in the register with an owner and a trigger (ADR-014 §4).
  8. The guard surface is smaller than when this epic started.

What would mean this was the wrong plan

Worth writing down now, while it is cheap. If Gate 2 turns the no-copy scan into something that fires on ordinary documentation, do not narrow it quietly — say so, keep the pair-matching core, and record why. And if this epic's diff comes out net positive in test lines, stop and re-read the epic: the whole argument is that these guards got big because they were guarding facts this repository does not own, and the remedy was supposed to be subtraction.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    epicA large capability spanning multiple storiesplanningInvestigation/spike/decision work

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions