Skip to content

Deferred: first-party quality rules and agent workflow calibration (preserve TSGo and Ultracite) #867

Description

@BleedingDev

Deferred first-party quality-policy improvements

Decision and scope

Deferred for later approval, not implementation authorization and not a DAG.
The approved first wave is S1–S4, A9, B1 and B2: separate our blocking/advisory
quality gates, assess bot findings rather than automatically obey them, remove
blanket zero-clone/complexity gating, keep feature scope narrow, repair our
analyzers instead of distorting valid code, offer focused local checks, and
remove implicit formatting from installation.

Do not weaken, override, filter or disable upstream Effect TSGo or Ultracite.
preferSucceedSomeOrNone and preferTypedSchemaDecoder are upstream Effect TSGo
rules, not OntOS rules. The earlier proposal to downgrade them is withdrawn,
not deferred. Sources:

Only first-party rules/tooling are eligible below. Existing custom Oxlint
severities remain unchanged pending separate approval. No test should merely
copy configuration or severity maps; validate observable behavior and actual
regressions. Do not rewrite already-correct application code just because a
rule is relaxed.

Deferred A proposals

Proposal Candidate policy Medium-term impact Long-term impact Risks and required protection
A1: first-party syntax/constructor preferences only Warning, or off for a proven preference with no useful signal. No upstream TSGo changes. Fewer behavior-preserving rewrites. Less coupling to one stylistic idiom. Verify ownership first; missing input validation is never a syntax preference.
A2: custom no-manual-tag-comparison in test assertions Warning; consider off only for that narrow scope. Less assertion-matcher migration churn. Less bespoke detector maintenance. Preserve assertions of variant and content; do not conflate with no-raw-effect-adt-tag-check.
A3: custom no-literal-union-type-alias Warning for internal types; consider narrow off. Avoid runtime schemas for purely static types. Simpler internal models. Keep real runtime validation at API/persistence boundaries.
A4: custom require-context-service-for-service-interface Warning. Avoid dependency-injection reshaping solely for local heuristics. Fewer artificial services/layers. Keep runtime provisioning and integration tests; absence of local tag evidence is not proof of a missing service.
A5: custom require-concurrency-option Missing explicit option advisory; demonstrated unbounded fan-out remains blocking. Avoid mechanical concurrency options. Capacity and ordering drive policy. Preserve resource bounds, transaction order and timeout behavior; never mechanically parallelize writes.
A6: custom no-native-json-parse / no-native-json-stringify Warning for trusted internal use, narrow off only with provenance; boundary contracts remain hard. Simpler tooling/reporting. Fewer schemas without a contract purpose. Scripts can ingest hostile data; protect identity/hash/signature and persisted-document semantics.
A7: custom no-native-error-construction Warning/narrow off for synchronous validators; real error-channel contract violations remain hard. Fewer lint-only adapters. Clearer synchronous/Effect boundaries. Expected failures must not turn into unhandled defects; test conversion at the boundary.
A8: custom no-unmanaged-mutable-state Mere module let/Map/WeakMap advisory; proven isolation violations blocking. Avoid unnecessary cache/registry rewrites. Explicit state ownership/lifetime. Verify cross-request/tenant isolation, invalidation and capacity where shared state exists.

Deferred B proposals

Proposal Implementation direction Medium-term impact Long-term impact Risks and protection
B3: deduplicate repeated review/warnings Reuse disposition for the same finding until relevant code or assumptions change. Less repeated agent work and comment noise. Attention stays on new defects. Exceptions can become stale; bind them to scope and assumptions, not permanent blanket suppression.
B4: impact-select expensive tooling checks Run selection in shadow mode beside the full suite before reducing CI work. Potentially shorter CI. Lower tooling maintenance/runtime cost. Indirect dependency misses; rules/generators/lockfile/shared-contract changes require wider checks and safe fallback.
B5: stronger targeted deployment proofs Fresh DB/migrations, relocated artifact, actual CLI argument forwarding. Catch deployment errors missed by green PR checks. Better alignment of tested and deployed behavior. Avoid another generic test platform; add scenarios demonstrated by historical failures.

Evidence motivating reconsideration

Audit window: 2026-08-17 through 2026-09-16; census of 134 updated PRs and
589 unique main-history commits. It does not establish hours lost or a causal
false-positive percentage. This issue intentionally contains the proposals,
trade-offs and primary evidence without depending on local report files.

Conditions for any later change

  • Obtain separate approval; confirm each rule is first-party.
  • Keep known real defects detectable and legitimate cases nonblocking.
  • Do not add configuration snapshots or tests that just duplicate constants.
  • Preserve compiler, authorization, tenant isolation, transaction, secret-handling
    and module-ownership protections. No blanket exclusions for tests/scripts.
  • Measure actual repair loops, confirmed false positives, CI wait and escaped
    defects. A short incident-free period is not proof of safety.
  • Do not automatically extract shared cross-deployment abstractions to satisfy
    clone metrics. Do not change TSGo or Ultracite enforcement.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions