Skip to content

Estate drift: estate-rules content scanners false-positive on policy ADRs (check-no-vlang / check-no-project-identifiers) #84

Description

@hyperpolymath

Sub-issue of #66. Discovered 2026-05-17 while fixing #83 (root-allow.txt) — a separate, independent cause of the estate-rules job staying red.

Symptom

On rsr-template-repo (and any consumer carrying the doc), after #83's root-shape fix, the estate-rules job still fails at later steps:

  • No V-lang references (check-no-vlang.sh): 4 hits, all in docs/decisions/0002-estate-tech-debt-compounding-fixes.adoc.
  • Neutral template (no project identifiers) (check-no-project-identifiers.sh): hits at 0002-…adoc:114,136 (affinescript, "AffineScript, not ReScript").

Root cause

The scanners do substring/identifier matching with no exemption for governance decision-records that legitimately discuss banned tech / project policy. ADR 0002-estate-tech-debt-compounding-fixes.adoc documents the V-lang ban and the AffineScript-over-ReScript decision — citing those names is the content's purpose, not drift. The checks are therefore false-positive on policy docs. The hardcoded remediation pointer in check-no-project-identifiers.sh ("see hyperpolymath/rsr-template-repo#45") is stale — #45 is CLOSED and was a different concern, so this is currently untracked.

Fix options (decide at source)

  • A. Exempt docs/decisions/** (ADRs) from check-no-vlang / check-no-project-identifiers (decision-records are meta-policy, not template body) — narrowest, principled.
  • B. Add justified rows to .machine_readable/identifier-allow.txt (+ a vlang equivalent) for ADR 0002 — per the checks' own escape hatch; more entries to maintain.
  • C. Reword ADR 0002 to avoid the literal tokens — rejected: mutilates a governance record to satisfy a scanner (anti-pattern; violates truth-in-tooling / Explicit-Escape).
  • Also: update the stale #45 pointer in check-no-project-identifiers.sh to this issue.

Recommend A (+ pointer fix). Canonical scripts live in rsr-template-repo scripts/; fix there + consumer sweep.

Refs #66

Activity

  1. hyperpolymath commented on May 19, 2026

    @hyperpolymath
    OwnerAuthor

    Closed as completed.

    Root-cause fix landed in rsr-template-repo#55 (commit 34b6d7a, merged 2026-05-17) — Option A from this issue: both scripts/check-no-vlang.sh and scripts/check-no-project-identifiers.sh now exempt docs/decisions/** from substring matching (ADRs legitimately discuss banned tech / project policy as their content), and the stale rsr-template-repo#45 pointer was updated to reference this issue.

    Re-verified at root 2026-05-19:

    BEFORE → AFTER on rsr-template-repo against docs/decisions/0002-estate-tech-debt-compounding-fixes.adoc:

    • check-no-vlang.sh: 4 V-lang hits → PASS (0 hits in ADRs)
    • check-no-project-identifiers.sh: 7 project-identifier hits (lines 66,67,70,72,83,114,136) → PASS in ADRs

    Regression guard (planted tokens OUTSIDE docs/decisions/):

    • src/REGRESSION_GUARD_TEST_DELETE_ME.txt with literal vlang → correctly caught (FAIL: 1 V-lang reference(s) found)
    • src/REGRESSION_GUARD_TEST_SLUG.txt with affinescript → correctly caught (FAIL[C]: project identifier leaked)

    Scanners are exempt for ADRs only and remain fully effective everywhere else. Test artifacts cleaned up.

    Consumer propagation: 3 RSR consumers (bofj-kitt, npm-avoidant, the-nash-equilibrium) carry the old scripts but lack a triggering ADR today — false-positive latent, not active. Recommended to roll on normal RSR sync rather than mass auto-mutation (estate guardrail).

    Refs #66, hyperpolymath/rsr-template-repo#55.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions