config

package
v1.55.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 11, 2026 License: MIT Imports: 23 Imported by: 0

Documentation

Index

Constants

View Source
const (
	// BlockingSeverityWarning preserves the historical gate policy: errors and
	// warnings require a decision, while informational findings are advisory.
	BlockingSeverityWarning = "warning"
	// BlockingSeverityError makes warnings advisory for repositories that opt in.
	BlockingSeverityError = "error"
	// DefaultBlockingSeverity is intentionally strict for compatibility.
	DefaultBlockingSeverity = BlockingSeverityWarning

	// DefaultCITimeout is the monitor's idle timeout when ci_timeout is unset.
	DefaultCITimeout = 7 * 24 * time.Hour
	// DefaultStepQuietWarning is how long a running/fixing step can go without
	// a new log or lifecycle activity before AXI status marks it quiet.
	DefaultStepQuietWarning = 10 * time.Minute
	// DefaultDaemonConnectTimeout bounds client IPC connection attempts to a
	// daemon socket that exists but is not accepting connections.
	DefaultDaemonConnectTimeout = 3 * time.Second
	// CITimeoutUnlimited is the sentinel meaning "monitor until the PR is
	// merged, closed, or the run is aborted - never self-terminate".
	// Any non-positive ci_timeout, or the keywords "unlimited", "none",
	// "off", and "never", resolves to this.
	CITimeoutUnlimited = time.Duration(-1)
	// DefaultCIRerunTransient is the per-check rerun budget the CI step uses
	// when ci.rerun_transient is unset. It is 0 because GitHub's CANCELLED
	// conclusion does not carry a cause: the same value covers a provider
	// aborting its own infrastructure, a maintainer stopping a runaway or
	// unsafe job, and repository concurrency with cancel-in-progress. Until a
	// reliable cause signal exists, restarting on that ambiguity risks
	// re-running work a person deliberately stopped, so rerunning cancelled
	// checks is an explicit opt-in rather than a default.
	DefaultCIRerunTransient = 0
	// MaxCIRerunTransient caps ci.rerun_transient. Reruns are cheap compared
	// with an agent round, but they are not free: each one keeps the monitor
	// polling the same commit, so the budget stays small by construction.
	MaxCIRerunTransient = 5
	// DefaultEvalMaxCases caps the auto-captured local eval corpus. Cases
	// share one object pool per repository, so the marginal cost of a case is
	// its JSON records plus the objects its commits actually introduced, not a
	// copy of the repository. The cap exists to bound that JSON and to keep
	// the corpus a recent, representative window rather than an archive.
	DefaultEvalMaxCases = 200
	// DefaultEvalDiversifiedSize caps the official gold-only eval set.
	// 0 means one gold case per stratum with no Hamilton bound.
	DefaultEvalDiversifiedSize = 32
	// DefaultEvidenceRetention is how long a run's on-disk evidence survives
	// before the daemon reaps it. It is comfortably longer than typical PR
	// review latency because a PR body references these artifacts by local path
	// whenever publishing is off or the provider has no derivable links. This
	// is no-mistakes' own budget: the point of owning it is that no OS temp
	// timer decides when a user's screenshots disappear.
	DefaultEvidenceRetention = 14 * 24 * time.Hour
	// DefaultEvidenceMaxRuns caps how many run directories survive regardless
	// of age, so a burst of parallel runs that all land inside the retention
	// window still cannot grow the directory without bound.
	DefaultEvidenceMaxRuns = 200
)

CI monitor timeout constants.

CITimeout is interpreted by the CI step as the maximum time to babysit an open PR with no base-branch movement before giving up. The monitor re-arms this timer every time the base branch advances (see internal/pipeline/steps ci.go), so an actively-rebased PR keeps its monitor. The value is deliberately long because a green PR can legitimately wait days on a dependency PR or on review; a torn-down or abandoned run is reaped explicitly via `no-slop axi abort --run <id>` rather than by a short timeout.

View Source
const (
	DefaultReviewConvergenceNonDecreasingRounds = 3
	DefaultReviewConvergenceRecurringRounds     = 3
	DefaultReviewConvergenceBudgetMinutes       = 120
)

Default review convergence guard thresholds. These are the documented defaults in docs/src/content/docs/reference/repo-config.md; change both together.

View Source
const (
	ReviewPathInstructionsHeading    = "" /* 190-byte string literal not displayed */
	ReviewPathInstructionsPathLabel  = "path: "
	ReviewPathInstructionsFilesLabel = "matched files: "
	ReviewPathInstructionsRulesLabel = "instructions:"
	// ReviewPathInstructionsMaxFilesBytes bounds the matched-file list a single
	// block may print. A broad glob can match hundreds of files, so the review
	// step truncates the list deterministically and states the remaining count;
	// the accounting charges every entry this full allowance so the cap holds
	// for any diff rather than only for small ones.
	ReviewPathInstructionsMaxFilesBytes = 192
)

Review-prompt block frame for review.path_instructions.

The review step renders every matched entry as

path: <path>
matched files: <files>
instructions:
<instructions>

so each rule travels with the scope it was selected for and no block can read as a global instruction. The labels live here rather than in the review step because the byte accounting below has to measure the real assembled section, not an estimate of it; internal/pipeline/steps builds its blocks from these same constants and TestReviewPathInstructionsSectionStaysWithinAccountedBytes is the drift check.

View Source
const (
	// MaxReviewPathInstructions is the largest number of path_instructions
	// entries a repository may configure.
	MaxReviewPathInstructions = 32
	// MaxReviewPathInstructionsBytes is the largest review-prompt section
	// path_instructions may produce, measured by ReviewPathInstructionsBytes.
	// It leaves room for the entry cap to be reached with a rule of ordinary
	// length, so neither cap makes the other unusable.
	MaxReviewPathInstructionsBytes = 16384
)

Bounds on review.path_instructions.

The injected text lands in the review prompt, which is already the largest gate prompt no-slop builds, and an oversized prompt fails the agent invocation outright instead of degrading. The budget is therefore validated when the config is parsed - before a run starts - rather than truncated silently at review time.

View Source
const DefaultFixMessageTemplate = "no-slop({{.Step}}): {{.Summary}}"

DefaultFixMessageTemplate preserves the built-in auto-fix commit subject.

View Source
const MaxFixMessageSummaryBytes = 4096

MaxFixMessageSummaryBytes bounds agent-provided fix summaries before rendering.

Variables

This section is empty.

Functions

func EnsureDefaultGlobalConfig

func EnsureDefaultGlobalConfig(path string)

EnsureDefaultGlobalConfig writes the default config file at path if it does not already exist. Failures are logged at debug level and silently ignored.

func ParseLogLevel

func ParseLogLevel(level string) slog.Level

ParseLogLevel converts a log level string to slog.Level. Accepted values: "debug", "info", "warn", "error". Defaults to slog.LevelInfo.

func RenderedInstructions

func RenderedInstructions(instructions string) string

RenderedInstructions is the emptiness-agreement helper for instruction text, not a second copy of the prompt renderer. The real renderer is sanitizePromptMultilineText in internal/pipeline/steps, which additionally normalizes CR and collapses each line's runs of whitespace; internal/config cannot import that package, which is why the conflict-marker replacer above is duplicated here at all. Two invariants tie the two together, and the rest of this feature silently depends on both:

  • Emptiness agrees exactly. This returns "" for precisely the inputs the prompt renderer reduces to "", so validation can reject a value that would otherwise reach the reviewer as an empty block.
  • The prompt renderer never lengthens text, so the rendered instructions are no longer than strings.TrimSpace of the raw value and ReviewPathInstructionsBytes stays an upper bound on the assembled section.

A change to sanitizePromptMultilineText that can lengthen text (escaping, wrapping) or that strips a token this replacer keeps breaks one of them; TestPathInstructionRenderingAgreesWithConfigValidation is the drift check.

func ReviewPathInstructionsBytes

func ReviewPathInstructionsBytes(entries []PathInstruction) int

ReviewPathInstructionsBytes returns the largest review-prompt section these entries can produce: the leading blank line, the heading, and for every entry its labels, its path, its instructions, its full matched-file allowance, and the separator before it. Instruction text can only shrink on its way into the prompt (conflict markers are removed and whitespace is collapsed), and the matched-file list is truncated to its allowance, so the result is an upper bound on the real section for any diff.

Types

type AutoFix

type AutoFix struct {
	Lint     int
	Test     int
	Review   int
	Document int
	CI       int
	Rebase   int
}

AutoFix holds resolved per-step auto-fix attempt limits. A value of 0 means auto-fix is disabled (requires manual approval).

type AutoFixRaw

type AutoFixRaw struct {
	Lint     *int `yaml:"lint"`
	Test     *int `yaml:"test"`
	Review   *int `yaml:"review"`
	Document *int `yaml:"document"`
	CI       *int `yaml:"ci"`
	Babysit  *int `yaml:"babysit"`
	Rebase   *int `yaml:"rebase"`
}

AutoFixRaw is the YAML representation of auto-fix config. Pointer fields distinguish "not set" (nil) from "set to 0" (disabled).

type CI

type CI struct {
	// RerunTransient is how many times the CI step may re-run a single check
	// the provider reported as cancelled - the one terminal outcome it
	// attributes to itself rather than to the job - before that check reaches
	// an approval gate. 0 disables reruns and restores the behavior of
	// escalating every failure on sight.
	RerunTransient int
}

CI holds the resolved CI-step settings.

type CIRaw

type CIRaw struct {
	RerunTransient *int `yaml:"rerun_transient"`
}

CIRaw is the YAML representation of CI-step settings. Pointer fields distinguish "not set" (nil) from "set to 0" (disabled).

type Commands

type Commands struct {
	Lint   string `yaml:"lint"`
	Test   string `yaml:"test"`
	Format string `yaml:"format"`
}

Commands holds optional per-repo command overrides.

type Commit

type Commit struct {
	FixMessage string
}

Commit is the resolved auto-fix commit configuration.

func (Commit) RenderFixMessage

func (c Commit) RenderFixMessage(step types.StepName, summary string) (string, error)

RenderFixMessage renders and validates a single-line auto-fix commit subject.

type CommitRaw

type CommitRaw struct {
	FixMessage *string `yaml:"fix_message"`
}

CommitRaw is the YAML representation of auto-fix commit settings.

type Concurrency added in v1.55.0

type Concurrency struct {
	Reviews int `yaml:"reviews"`
	Suites  int `yaml:"suites"`
}

Concurrency is host-daemon capacity, never contributor-controlled repo policy.

func DefaultConcurrency added in v1.55.0

func DefaultConcurrency() Concurrency

DefaultConcurrency limits executing reviews and suites independently. Suite commands may parallelize internally; these limits do not reserve CPUs.

type Config

type Config struct {
	Concurrency           Concurrency
	ReplayGlobalYAML      []byte
	ReplayRepoYAML        []byte
	TrustedConfigSHA      string
	CaptureEvalProvenance bool
	Agent                 types.AgentName
	Agents                []types.AgentName
	ACPXPath              string
	ACPRegistryOverrides  map[string]string
	AgentPathOverride     map[string]string
	AgentArgsOverride     map[string][]string
	CITimeout             time.Duration
	StepQuietWarning      time.Duration
	LogLevel              string
	SessionReuse          bool
	Eval                  Eval
	Commands              Commands
	IgnorePatterns        []string
	BlockingSeverity      string
	AutoFix               AutoFix
	CI                    CI
	Commit                Commit
	Intent                Intent
	Test                  Test
	Quartermaster         Quartermaster
	Document              Document
	Review                Review
	Slop                  Slop
	// DisableProjectSettings is the resolved, trusted-only opt-out (see the
	// RepoConfig field). When true, gate agents are launched with their
	// project-level settings/instructions suppressed; the daemon fails the run
	// closed if the resolved harness has no verified suppression knob.
	DisableProjectSettings bool
	// NoCI is the resolved, trusted-only declaration that this repository
	// intentionally has no CI (see the RepoConfig field). When true and the
	// forge reports zero checks, the CI monitor treats that as all-checks-passed.
	NoCI bool
}

Config is the merged result of global + per-repo configuration.

func Merge

func Merge(global *GlobalConfig, repo *RepoConfig) *Config

Merge combines global and per-repo config. Per-repo agent values, including ordered fallback lists, override global agent values when non-empty. Commands and ignore patterns come from repo config only.

func (*Config) AgentArgs

func (c *Config) AgentArgs() []string

AgentArgs returns extra CLI args for the configured native agent, as declared in agent_args_override. Returns nil when no override is set for this agent.

func (*Config) AgentArgsFor

func (c *Config) AgentArgsFor(name types.AgentName) []string

func (*Config) AgentPath

func (c *Config) AgentPath() string

AgentPath returns the binary path for the configured agent. ACP agents and ACP aliases use acpx_path if set, otherwise acpx. Native agents use agent_path_override if set, otherwise the default binary name.

func (*Config) AgentPathFor

func (c *Config) AgentPathFor(name types.AgentName) string

func (*Config) AutoFixLimit

func (c *Config) AutoFixLimit(step types.StepName) int

AutoFixLimit returns the max auto-fix attempts for a given step. Steps without auto-fix support return 0.

func (*Config) EnableEvalProvenance

func (c *Config) EnableEvalProvenance(global *GlobalConfig, repo *RepoConfig) error

EnableEvalProvenance pins the exact configuration this run reviews under so a later replay grades a candidate against identical conditions.

func (*Config) ResolveAgent

func (c *Config) ResolveAgent(ctx context.Context, lookPath func(string) (string, error)) error

ResolveAgent resolves configured agent names to available agents. A single explicit agent must be runnable; auto probes native agents, then ACP aliases; an ordered list is filtered to available agents, deduplicated by resolved identity, and kept as fallbacks. The lookPath function should behave like exec.LookPath.

type Convergence

type Convergence struct {
	// NonDecreasingRounds trips the guard when the review findings count has
	// not decreased across this many trailing consecutive rounds.
	NonDecreasingRounds int
	// RecurringRounds trips the guard when one finding class recurs in this
	// many distinct review rounds.
	RecurringRounds int
	// BudgetMinutes trips the guard when cumulative review execution time
	// reaches this budget.
	BudgetMinutes int
}

Convergence holds the resolved review convergence guard thresholds. A zero value for a field disables that trigger.

type ConvergenceRaw

type ConvergenceRaw struct {
	NonDecreasingRounds *int `yaml:"non_decreasing_rounds"`
	RecurringRounds     *int `yaml:"recurring_rounds"`
	BudgetMinutes       *int `yaml:"budget_minutes"`
}

ConvergenceRaw is the YAML representation of the review convergence guard thresholds. Pointer fields distinguish "not set" (default applies) from an explicit 0 (that trigger disabled).

type Document

type Document struct {
	Instructions string
}

Document is the resolved document-step config. Instructions come from the trusted default-branch repo config and augment the built-in placement policy in the document prompt.

type DocumentRaw

type DocumentRaw struct {
	// Instructions augment (never replace) the built-in documentation
	// placement policy with the repository's ownership map or extra
	// placement rules.
	Instructions string `yaml:"instructions"`
}

DocumentRaw is the YAML representation of document-step settings.

type Eval

type Eval struct {
	CaptureProvenance bool
	AutoCapture       bool
	// MaxCases caps the auto-captured corpus. 0 keeps every case. Pruning is
	// oldest-first and never removes a case that already has recorded
	// candidate replays, so a corpus you have spent tokens on is never
	// silently reclaimed underneath a comparison.
	MaxCases int
	// DiversifiedSize caps the official gold-only eval set. 0 means one gold
	// case per stratum (no Hamilton bound). Unlabeled cases never fill it.
	DiversifiedSize int
}

Eval is the resolved local evaluation-corpus config. It is deliberately a first-class configuration key rather than an environment variable: the daemon is a long-lived launchd/systemd service whose unit file is re-rendered on install and update, and only proxy variables survive that re-render, so an environment-gated corpus would silently stop collecting after an update.

CaptureProvenance is the upstream half: it makes every review round record the exact commit and configuration inputs a replay needs. A round written with it off can never be captured afterwards, because the pinned global configuration is a point-in-time snapshot that no longer exists anywhere.

AutoCapture is the downstream half: it freezes each finished run's review passes into the local corpus without anyone running a command. It has no effect while CaptureProvenance is off, since there is nothing to freeze.

type EvalRaw

type EvalRaw struct {
	CaptureProvenance *bool `yaml:"capture_provenance"`
	AutoCapture       *bool `yaml:"auto_capture"`
	MaxCases          *int  `yaml:"max_cases"`
	DiversifiedSize   *int  `yaml:"diversified_size"`
}

EvalRaw is the YAML representation of local evaluation-corpus settings. Pointer fields distinguish "not set" (nil) from explicit zero/false values.

type Evidence

type Evidence struct {
	StoreInRepo bool
	Dir         string
	Branch      string
	// LocalRoot overrides the app-root default for on-disk evidence; empty
	// means paths.EvidenceDir(). Retention and MaxRuns bound how much of it
	// survives: no-mistakes reaps its own evidence rather than leaving that to
	// an OS temp-directory timer. Zero disables the corresponding bound.
	LocalRoot string
	Retention time.Duration
	MaxRuns   int
}

Evidence is the resolved test-evidence config. When StoreInRepo is true, the run publishes its evidence artifacts to the orphan Branch of the same repository, under Dir, and links them from the pull request body. Evidence never enters the pushed code branch, so it never reaches the default branch's history. Otherwise evidence stays on local disk under LocalRoot, referenced only by local path.

type EvidenceRaw

type EvidenceRaw struct {
	StoreInRepo *bool   `yaml:"store_in_repo"`
	Dir         *string `yaml:"dir"`
	// Branch selects the orphan evidence branch. It names a git ref the
	// daemon pushes to with the maintainer's credentials, so it is honored
	// ONLY from the trusted default-branch copy of .no-mistakes.yaml (see
	// EffectiveRepoConfig): a contributor's pushed branch must not be able to
	// aim evidence commits at another branch of the repository.
	Branch *string `yaml:"branch"`
	// LocalRoot, Retention, and MaxRuns describe this MACHINE's evidence
	// storage: where the daemon writes artifacts on local disk and how long it
	// keeps them. They are global-only - Merge resolves them straight from
	// GlobalConfig and never from a repository, trusted copy included. A
	// repository does not get to name a filesystem path the daemon writes to,
	// nor to set the retention budget for a resource every other repository on
	// the machine shares. (Contrast Branch, which is trusted-repo-settable
	// because a branch genuinely is per-repository state.)
	//
	// LocalRoot must be absolute; see validateTestRaw.
	LocalRoot *string `yaml:"local_root"`
	Retention *string `yaml:"retention"`
	MaxRuns   *int    `yaml:"max_runs"`
}

EvidenceRaw is the YAML representation of test-evidence settings. Pointer fields distinguish "not set" (nil) from explicit zero/false values.

type GlobalConfig

type GlobalConfig struct {
	Concurrency          Concurrency         `yaml:"concurrency"`
	SourceYAML           []byte              `yaml:"-"`
	Agent                types.AgentName     `yaml:"agent"`
	Agents               []types.AgentName   `yaml:"-"`
	ACPXPath             string              `yaml:"acpx_path"`
	ACPRegistryOverrides map[string]string   `yaml:"acp_registry_overrides"`
	AgentPathOverride    map[string]string   `yaml:"agent_path_override"`
	AgentArgsOverride    map[string][]string `yaml:"agent_args_override"`
	CITimeout            time.Duration       `yaml:"-"`
	StepQuietWarning     time.Duration       `yaml:"-"`
	DaemonConnectTimeout time.Duration       `yaml:"-"`
	LogLevel             string              `yaml:"log_level"`
	// SessionReuse controls per-run agent session reuse in the review loop:
	// one durable fixer session across review-fix turns. Review turns always
	// run session-free so the rereview never resumes the session whose
	// findings prescribed the fixes it certifies. Default true; set
	// session_reuse: false to force every invocation cold.
	SessionReuse bool `yaml:"-"`
	AutoFix      AutoFixRaw
	// CI is the operator's own CI-step floor. It is the only place the rerun
	// budget can be set for a repository whose default branch this machine's
	// user does not control (the common case when contributing to someone
	// else's project), and a trusted repo value still wins over it.
	CI            CIRaw
	Commit        CommitRaw
	Intent        IntentRaw
	Test          TestRaw
	Quartermaster Quartermaster
	// Eval is resolved at load time because it is global-only: it describes
	// this machine's local eval corpus (disk, retention, whether review rounds
	// record replay provenance), never a repository policy. Keeping it out of
	// RepoConfig means no pushed branch can enable, disable, or resize it.
	Eval Eval
}

GlobalConfig represents ~/.no-mistakes/config.yaml.

func DefaultGlobalConfig

func DefaultGlobalConfig() *GlobalConfig

DefaultGlobalConfig returns the built-in global defaults.

func LoadGlobal

func LoadGlobal(path string) (*GlobalConfig, error)

LoadGlobal reads global config from path. Returns defaults if file doesn't exist.

func LoadGlobalFromBytes

func LoadGlobalFromBytes(data []byte) (*GlobalConfig, error)

type Intent

type Intent struct {
	Enabled         bool
	Threshold       float64
	SlackDays       int
	DisabledReaders map[string]bool
}

Intent is the resolved user-intent extraction config.

type IntentRaw

type IntentRaw struct {
	Enabled         *bool    `yaml:"enabled"`
	Threshold       *float64 `yaml:"threshold"`
	SlackDays       *int     `yaml:"slack_days"`
	DisabledReaders []string `yaml:"disabled_readers"`
}

IntentRaw is the YAML representation of user-intent extraction settings. Pointer fields distinguish "not set" (nil) from explicit zero/false values.

type PathInstruction

type PathInstruction struct {
	Path         string `yaml:"path"`
	Instructions string `yaml:"instructions"`
}

PathInstruction is one glob-scoped block of review guidance. Path follows the same match rules as ignore_patterns: no slash matches by basename, a trailing "/**" matches an entire subtree, and anything else is a full-path glob.

type Quartermaster

type Quartermaster struct {
	Enabled bool
	Bin     string
	TTL     time.Duration
	Weight  int
}

type QuartermasterRaw

type QuartermasterRaw struct {
	Enabled *bool  `yaml:"enabled"`
	Bin     string `yaml:"bin"`
	TTL     string `yaml:"ttl"`
	Weight  int    `yaml:"weight"`
}

type RepoConfig

type RepoConfig struct {
	Agent          types.AgentName   `yaml:"agent"`
	Agents         []types.AgentName `yaml:"-"`
	Commands       Commands          `yaml:"commands"`
	IgnorePatterns []string          `yaml:"ignore_patterns"`
	// BlockingSeverity is the minimum recognized severity that parks a gate.
	// It is trusted-only so a pushed branch cannot make its own warnings advisory.
	BlockingSeverity string `yaml:"blocking_severity"`
	// AllowRepoCommands opts in to honoring the code-executing selection
	// fields (commands.{test,lint,format} and agent) from a contributor's
	// pushed branch instead of the trusted default-branch copy. It is read
	// ONLY from the trusted default-branch copy of .no-slop.yaml (never
	// the pushed SHA), so a contributor cannot self-enable. Default false:
	// the pushed branch controls nothing that executes.
	AllowRepoCommands bool       `yaml:"allow_repo_commands"`
	AutoFix           AutoFixRaw `yaml:"auto_fix"`
	CI                CIRaw      `yaml:"ci"`
	Commit            CommitRaw  `yaml:"commit"`
	Intent            IntentRaw  `yaml:"intent"`
	Test              TestRaw    `yaml:"test"`
	// Document carries the repository's documentation placement policy. It
	// steers the document step's gate prompt, so it is honored ONLY from the
	// trusted default-branch copy of .no-slop.yaml (see
	// EffectiveRepoConfig): a contributor's pushed branch must not be able to
	// weaken documentation rules for its own review.
	Document DocumentRaw `yaml:"document"`
	// Review carries the repository's review-step settings. Its
	// path_instructions steer the review gate prompt, so they are honored
	// ONLY from the trusted default-branch copy of .no-slop.yaml (see
	// EffectiveRepoConfig), regardless of allow_repo_commands: a contributor's
	// pushed branch must not be able to inject or weaken the guidance that
	// reviews it.
	Review ReviewRaw `yaml:"review"`
	// DisableProjectSettings opts the repository out of loading project-level
	// agent settings/instructions (AGENTS.md/CLAUDE.md and the equivalent
	// per-harness project settings) into gate agents. It exists for
	// agent-orchestration repos (e.g. firstmate) whose project instructions
	// would otherwise install a fleet-captain identity on a gate agent. It is a
	// SECURITY boundary honored ONLY from the trusted default-branch copy of
	// .no-slop.yaml (see EffectiveRepoConfig and the daemon's
	// assertGateTrustedConfigReadable): a contributor's pushed branch must not be
	// able to turn it off (or on). Default false; a plain bool so a missing key
	// or a YAML/JSON null is falsy and preserves current loading.
	DisableProjectSettings bool `yaml:"disable_project_settings"`
	// NoCI declares that this repository intentionally has no CI. When true and
	// the forge reports zero checks, the CI monitor treats that empty result as
	// all-checks-passed. It is a readiness boundary honored ONLY from the trusted
	// default-branch copy of .no-slop.yaml (see EffectiveRepoConfig): a
	// contributor's pushed branch must not self-declare no-CI and bypass checks.
	// Default false - absence means CI is expected, and an unproven empty check
	// list remains not-ready regardless of elapsed time. If checks still appear,
	// their actual states are processed normally; the declaration never waives a
	// registered pending or failing check. No inference from workflow files,
	// prior history, branch names, or grace-period expiry.
	NoCI bool `yaml:"no_ci"`
	// Slop configures the NoSlop front-stage classifier and artifact oracles.
	// It controls validation depth, so EffectiveRepoConfig treats it as
	// trusted-only when the daemon evaluates a pushed branch.
	Slop SlopRaw `yaml:"slop"`
}

RepoConfig represents .no-slop.yaml in a repo root.

func EffectiveRepoConfig

func EffectiveRepoConfig(pushed, trusted *RepoConfig, allowRepoCommands bool) *RepoConfig

EffectiveRepoConfig returns the repo config that should drive the pipeline given a pushed-branch copy and the trusted default-branch copy.

The code-executing selection fields - Commands (run verbatim via sh -c on the daemon host) and Agent/Agents (select which processes launch with the maintainer's credentials, including fallback lists and acp: targets) - are taken only from the trusted copy when it is present, so a contributor's pushed branch cannot inject shell or pick an agent. Document (the documentation placement policy injected into the document gate prompt) is trusted-only for the same reason: a pushed branch must not weaken the documentation rules that gate itself. Review (the path-scoped guidance injected into the review gate prompt) is trusted-only for the same reason: a pushed branch must not steer the reviewer that gates it. DisableProjectSettings is also trusted-only so a pushed branch cannot enable or defeat the gate-agent project-instruction boundary. NoCI is trusted-only so a pushed branch cannot self-declare no-CI and bypass its own checks, and CI (the transient-rerun budget) is trusted-only because every rerun it authorizes is another provider-side workflow run billed to the repository. BlockingSeverity is trusted-only as well, because lowering it would let a contributor make its own warning findings advisory. These fields ignore allowRepoCommands, which scopes only the code-executing selection fields. When allowRepoCommands is true the maintainer has explicitly opted in (via allow_repo_commands on the TRUSTED default-branch copy) to honoring the pushed branch's commands and agent selection. When there is no trusted copy and the maintainer has not opted in, both fields are forced empty (Agent "" and nil Agents inherit the global agent; Commands{} yields built-in defaults) rather than falling back to the pushed branch - this blocks the supply-chain vector for repos that ship .no-slop.yaml only on feature branches.

Non-executing fields (ignore patterns, auto-fix, commit, intent, test) are always taken from the pushed copy, matching prior behavior, since they cannot run arbitrary shell, select a process, or spend the maintainer's CI minutes. The single exception inside test is evidence.branch, which names a git ref the daemon pushes to and is therefore trusted-only.

func LoadRepo

func LoadRepo(dir string) (*RepoConfig, error)

LoadRepo reads per-repo config from the canonical .no-slop.yaml name or the legacy .no-mistakes.yaml alias. Returns zero-value config if file doesn't exist.

func LoadRepoFromAliasBytes

func LoadRepoFromAliasBytes(canonicalData []byte, canonicalExists bool, legacyData []byte, legacyExists bool) (*RepoConfig, bool, error)

func LoadRepoFromBytes

func LoadRepoFromBytes(data []byte) (*RepoConfig, error)

LoadRepoFromBytes parses per-repo config from raw YAML bytes. It is the trusted-config entry point: callers that read .no-slop.yaml from a specific git ref (e.g. the default branch) use this to avoid honoring a contributor's checked-out copy.

func (*RepoConfig) UnmarshalYAML

func (c *RepoConfig) UnmarshalYAML(value *yaml.Node) error

type Review

type Review struct {
	PathInstructions []PathInstruction
	Convergence      Convergence
}

Review is the resolved review-step config. PathInstructions come from the trusted default-branch repo config and scope extra review guidance to the changed paths each glob matches. Convergence carries the resolved review-loop ladder guard thresholds from the same trusted section.

type ReviewRaw

type ReviewRaw struct {
	// PathInstructions scope extra review guidance to the paths a change
	// actually touches. The review step appends the blocks whose glob matches
	// at least one changed file; a run that touches nothing matching leaves
	// the review prompt exactly as it is without this setting.
	PathInstructions []PathInstruction `yaml:"path_instructions"`
	// Convergence configures the review-loop ladder guard thresholds. It
	// rides the Review section's trust boundary: honored only from the
	// trusted default-branch copy, so a pushed branch cannot widen or
	// disable the guard on its own run.
	Convergence ConvergenceRaw `yaml:"convergence"`
}

ReviewRaw is the YAML representation of review-step settings.

type Slop

type Slop struct {
	DataDir        string
	Risk           SlopRisk
	LeakScan       SlopLeakScan
	Prose          SlopProse
	TestCountFloor bool
	TestCommand    string
}

Slop is the resolved NoSlop front-stage configuration.

type SlopLeakScan

type SlopLeakScan struct {
	BlocklistFile   string
	AllowExemptions bool
}

type SlopLeakScanRaw

type SlopLeakScanRaw struct {
	BlocklistFile   string `yaml:"blocklist_file"`
	AllowExemptions *bool  `yaml:"allow_exemptions"`
}

SlopLeakScanRaw controls the optional private-name blocklist file.

type SlopProse

type SlopProse struct {
	OutboundPaths []string
	AITellWords   []string
}

type SlopProseRaw

type SlopProseRaw struct {
	OutboundPaths []string `yaml:"outbound_paths"`
	AITellWords   []string `yaml:"ai_tell_words"`
}

SlopProseRaw controls outbound artifact recognition and vocabulary checks.

type SlopRaw

type SlopRaw struct {
	DataDir        string          `yaml:"data_dir"`
	Risk           SlopRiskRaw     `yaml:"risk"`
	LeakScan       SlopLeakScanRaw `yaml:"leak_scan"`
	Prose          SlopProseRaw    `yaml:"prose"`
	TestCountFloor *bool           `yaml:"test_count_floor"`
	TestCommand    string          `yaml:"test_command"`
}

SlopRaw is the YAML representation of NoSlop front-stage settings.

type SlopRisk

type SlopRisk struct {
	SingleReviewThreshold    int
	FullAdversarialThreshold int
	HighRiskPaths            []string
}

type SlopRiskRaw

type SlopRiskRaw struct {
	SingleReviewThreshold    int      `yaml:"single_review_threshold"`
	FullAdversarialThreshold int      `yaml:"full_adversarial_threshold"`
	HighRiskPaths            []string `yaml:"high_risk_paths"`
}

SlopRiskRaw controls the risk classifier's numeric cutoffs and path hints.

type Test

type Test struct {
	Evidence Evidence
}

Test is the resolved test-step config.

type TestRaw

type TestRaw struct {
	Evidence EvidenceRaw `yaml:"evidence"`
}

TestRaw is the YAML representation of test-step settings.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL