DEV Community

Avery Li
Avery Li

Posted on

A Pairing Manifest That Stops Generated Edits Outside One Module

A Pairing Manifest That Stops Generated Edits Outside One Module

A generated patch should stay on the laptop until a pairing names one rewrite set and one owner. The decision kept in this worked example is a manifest that rejects every changed path outside that set. A free model may draft only after the manifest exists, and a free server may receive only a later dry run. The local checker runs first, so an over-wide edit never becomes a remote experiment on a shared host.

What the session was protecting

Shared modules fail in quiet ways when a generated draft helps by touching neighboring files that nobody planned to change. A retry helper, a package initializer, and a sample config can look related while carrying different rollback costs. This worked example starts from a narrow bug in the helper and a tempting offer to clean the whole package. The senior refused that expansion before any remote host entered the plan or received a copy of the tree.

Questions the senior placed on the note

The senior did not ask for a longer prompt or a broader cleanup pass across the package. The note recorded which paths were in scope, who would roll them back, and which evidence would show the patch had not grown. Those three items stayed beside the terminal for the whole session and were not replaced by a chat log. The note became the rewrite set, rather than a second design document that nobody would reread.

  1. Which paths may change in this pairing, and which paths stay frozen for later work?
  2. Who owns the rollback if a later dry run on a free server fails after the check?
  3. Which repeated diff shows that a redraft did not add paths after the first local check?

The pair answered with a file list, a named owner, and a second diff, then stopped adding process to the note. A vague answer, such as a claim that the model would know, sent the session back to the dead ends below. The note was accepted only when each answer pointed at a file, a person, or a command.

Dead ends the pair discarded

The first dead end was a draft that rewrote the helper, the package init, and a sample config together. The prompt had asked for a consistent change, and the model treated consistency as permission to wander. The second dead end proposed a live test on a free server before the diff was bounded. The third treated a green unit test as permission to include a migration in the same patch.

Each discarded option hid a different owner behind a convenient story about saving time in the session. The cleanup mixed a bug fix with style edits that another person might already be reviewing. The early server run would have spent a shared host on an unbounded working tree with no named owner. The migration idea would have coupled a data change to a retry tweak, so the pair dropped all three before the manifest.

Steps that remained after the dead ends

The workflow below is a proposal for the same kind of pairing, labeled so nobody mistakes it for a measured case study. Each step has a visible artifact, and a missing artifact stops the session rather than inviting a workaround. The free model and the free server appear late on purpose, after the file boundary is already written down. A missing owner name stops the session even when the path list already looks narrow enough.

  1. Write rewrite-set.txt with one allowed path per line and a comment that names the rollback owner.
  2. Run the checker against the working tree before any model is asked to redraft the helper or its tests.
  3. If the checker prints an extra path, restore that path and shrink the prompt instead of widening the manifest.
  4. Request a draft only inside the allowed paths, then run the checker again on the resulting diff.
  5. Point a dry run at a free server only after the second checker exits with status zero.
  6. Record one rollback command the owner can run, and stop the session if that command is unclear.

The checker the pairing kept

The script below is an unexecuted example for review, not a claim that a repository already enforces this gate. It reads the manifest, lists changed paths, and fails when any path is absent from the allowed set. It does not judge whether an allowed file is semantically correct, safe to ship, or free of secrets. It only preserves the boundary the pairing already chose in writing and can reverse by hand.

#!/usr/bin/env python3
"""Unexecuted example: reject Git paths outside a kept rewrite set."""

import subprocess
import sys
from pathlib import Path

MANIFEST = Path("rewrite-set.txt")


def load_allowed(path: Path) -> set[str]:
    allowed = set()
    for line in path.read_text(encoding="utf-8").splitlines():
        stripped = line.strip()
        if not stripped or stripped.startswith("#"):
            continue
        allowed.add(stripped)
    return allowed


def collect_paths(command: list[str]) -> list[str]:
    result = subprocess.run(
        command,
        check=True,
        capture_output=True,
        text=True,
    )
    return [line.strip() for line in result.stdout.splitlines() if line.strip()]


def changed_paths() -> list[str]:
    groups = [
        ["git", "diff", "--name-only", "--", "."],
        ["git", "diff", "--cached", "--name-only", "--", "."],
        ["git", "ls-files", "--others", "--exclude-standard"],
    ]
    found = []
    seen = set()
    for command in groups:
        for path in collect_paths(command):
            if path not in seen:
                seen.add(path)
                found.append(path)
    return found


def main() -> int:
    if not MANIFEST.is_file():
        print("missing rewrite-set.txt", file=sys.stderr)
        return 2
    allowed = load_allowed(MANIFEST)
    extra = [path for path in changed_paths() if path not in allowed]
    if extra:
        print("paths outside the kept rewrite set:")
        for path in extra:
            print(f"  {path}")
        return 1
    print("rewrite set holds")
    return 0


if __name__ == "__main__":
    raise SystemExit(main())
Enter fullscreen mode Exit fullscreen mode

The checker unions unstaged names, staged names, and untracked names that Git does not already ignore. A path that matches the manifest is still unread by this script, so a bad change inside an allowed file can pass. Renames can hide the old path, and ignored files never appear, so those cases need a human look at the tree. The script is a boundary reminder for a pairing, not a policy engine for a regulated release train.

A sample manifest stays short so the owner line remains visible to a human reviewer during the session. The checker ignores comments, which means a person can record the rollback without changing the allow logic. Adding a path is a new pairing decision, not a convenience edit made during a redraft of the helper. A wide manifest recreates the dead end the senior already rejected when the package cleanup appeared.

# owner: platform pairing, rollback: git checkout -- src/retry.py
src/retry.py
tests/test_retry.py
Enter fullscreen mode Exit fullscreen mode

The local commands are ordinary and do not call a model or a remote host at any point. A failing run should print the extra paths and return a nonzero status before anyone opens a draft tool. A passing run only means the names match the note that the senior kept beside the terminal. Reviewers still read the diff inside those names before any dry run is scheduled on a shared host.

python3 check_rewrite_set.py
git diff -- src/retry.py tests/test_retry.py
Enter fullscreen mode Exit fullscreen mode

How to rehearse the three exit codes

A rehearsal stays local and uses a temporary repository so the example cannot touch a shared host. The steps below are unexecuted instructions for a reviewer who wants to see the three exit codes. They do not prove that a passing tree is behaviorally correct or ready for any shared host. They only show that the path boundary fails closed when the manifest is missing or exceeded.

  1. Create a temporary Git repository, commit the two allowed files, and add the sample manifest beside them.
  2. Run the checker on a clean tree and expect status zero, since an empty change list cannot violate the set.
  3. Add an untracked note outside the set, run the checker, and expect status one with that path printed.
  4. Remove the manifest, run the checker, and expect status two before any drafting tool is opened.

How the pair compared the options

The comparison table is a review aid for the session, not a benchmark of tools or hosts. No timing figure, token total, or hardware result belongs in the rows of this session comparison. The only passing row is the one whose failure mode the pair can explain in a single sentence. Other rows stay as rejected alternatives so a later reader does not revive them by habit.

Option Boundary it kept Why it lost or stayed
Whole-package cleanup No single owner Style edits mixed with the bug fix
Free-server test first A realistic host only The diff was still unbounded
Green unit test as a wide pass Local behavior of one helper A migration has a different rollback
Manifest plus a second diff check The agreed file list Failure prints the extra path

Where a free model and a free server fit

Disclosure: This article was prepared as part of MonkeyCode's product outreach. MonkeyCode enters the method only after the rewrite set exists, as a drafting aid inside the operator-described free model access. The same operator note describes a free server option, which fits the dry-run step after the checker exits cleanly. This draft does not name models, quotas, hardware, or a duration, because those terms were not verified here and can change.

Readers should confirm the current product terms before they treat either free option as available for their own work. A free server remains a shared convenience, not a production stand-in and not a substitute for the named owner. A dry run can still reveal a bad retry loop, a missing fixture, or a log line that should never have left the laptop. If that run fails, the owner uses the recorded rollback and does not widen the manifest to satisfy the host.

A later draft starts again from the same allowed paths and the same owner note beside the terminal. Nothing in the free option changes the rule that an extra path is a failed pairing rather than a prompt problem. The drafting tool should receive the manifest text in the task notes so the requested edit stays narrow. If the tool cannot accept that constraint, the pairing stops on the laptop and does not open the server.

Who should skip this boundary

This boundary should not be used for a production incident, a secret rotation, or a change that already sits with a formal control board. It also fits poorly when the real risk lives inside one allowed file, because a correct path list can still hide a bad permission check. Teams that cannot name a rollback owner should not send the patch to any shared host, free or otherwise. A zero exit from the checker is a boundary result, not an approval to deploy the change.

The worked example is a method, not a report of avoided outages or saved hours for any team. No customer outcome is claimed, and the script is not presented as an executed suite from this account. Adapt the manifest to the real repository layout before a zero exit is treated as permission to continue. Readers who draft with MonkeyCode can keep this manifest as the gate, and use the free server only after the checker exits cleanly.

Top comments (0)