Skip to content

Add worktree-local Intent policy overlays #228

Description

@LadyBluenotes

Problem

Intent policy is currently shared through package.json. A user cannot add worktree-local grants or denials without changing committed repository policy. Local state also needs strict Git safety rules so it cannot be silently tracked or hide .intent/hooks.

User outcome

A user can manually create a valid .intent/config.local.json beside the nearest owning package.json. Intent applies it automatically as personal worktree state: local skills can broaden shared defaults, local excludes can add denials, and shared excludes remain final.

Example:

{
  "skills": [
    "@acme/private-skill"
  ],
  "exclude": [
    "@acme/unsafe-skill"
  ]
}

In scope

  • Add .intent/config.local.json discovery beside the nearest owning package.json as the sole local policy source. Keep package.json as the sole shared committed source.
  • Provide reusable guarded local resolver and storage behavior that future installer or review work may consume.
  • Require local policy operations to run in a Git worktree. Use only the exact sidecar path in $GIT_COMMON_DIR/info/exclude; do not ignore .intent/, and preserve .intent/hooks.
  • Check that the exact local path is untracked on every local read and write. Reject tracked paths even when info/exclude contains the path.
  • Support a top-level JSON object with optional skills and exclude fields, where at least one field is present. Parse present fields strictly as arrays of valid strings under the existing selector and exclusion grammars.
  • Activate a manually created valid local file automatically. Fail closed when a present local file is tracked, unreadable, malformed, or not exactly ignored.
  • Compile shared and local skill selectors independently. For declared shared policy, grant a candidate when either predicate matches. Preserve existing package, exact-skill, wildcard, npm, and workspace semantics.
  • Preserve migration behavior when shared intent.skills is absent and local skills is omitted or []. A non-empty local skills, including ["*"], ends that migration mode.
  • Apply shared and local exclusions as final additive denials. Local policy must never restore a skill denied by shared policy.
  • Make all policy consumers use the same effective-policy resolver: list, load, stale, support diagnostics, install --map, and hooks.

Acceptance criteria

  • A valid manual .intent/config.local.json beside the nearest owning package.json is discovered and applied automatically in a Git worktree.
  • The local file is accepted only when the exact path is untracked and exactly ignored through $GIT_COMMON_DIR/info/exclude; the check applies to both reads and writes.
  • .intent/hooks remains usable, and the implementation never ignores .intent/ as a whole directory.
  • A tracked, unreadable, malformed, or not-exactly-ignored present local file fails closed with actionable diagnostics.
  • The local object rejects unknown top-level fields, accepts only optional skills and exclude, requires at least one of them, and validates each present array under existing selector or exclusion rules.
  • Shared and local selector sets are compiled independently. For declared shared policy, a candidate is granted when either set matches without changing package, exact-skill, wildcard, npm, or workspace semantics.
  • Shared and local exclusions both deny matching candidates after grant selection. A shared exclusion cannot be bypassed locally.
  • When shared intent.skills is absent, omitted or empty local skills preserves current migration behavior. A non-empty local skills, including ["*"], ends it.
  • list, load, stale, support diagnostics, install --map, and hooks resolve the same effective policy and report local-source provenance where they already report policy diagnostics.
  • The work introduces no .intent/config.json, global local-policy store, new dependency, destination-selection UI, preview, confirmation, package writing, content delivery, locks, hashes, or Git skill-source support.

Related work

Blocked by: None. #219 is completed prior behavior. #220 and #221 may integrate local policy when available but can proceed independently with package.json-only behavior. #222 independent.

#220 owns interactive destination selection if and when it integrates local configuration. #221 owns repeat review if and when it integrates local configuration.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions