fleetd #148 (point 2): drop .envrc from the default parityOverlay #250

Closed
agent wants to merge 0 commits from worker/cb148-envrc-default-fa6c82-12 into main
Member

fleetd #148, point 2 only: drop .envrc from the default parityOverlay

.env is data — a copy of it can only carry values. .envrc is executable shell that direnv
runs on every cd, so a copy of it can carry behaviour into a worker. Those are different risks
and should not share a default.

Change: the default parityOverlay is now [".env"] (was [".env", ".envrc"]). The knob
itself is unchanged — an operator who wants .envrc copied still writes
parityOverlay: [".env", ".envrc"] explicitly and owns that choice.

Files changed

  • fleetd/src/main/java/dev/ltms/fleet/config/FleetConfig.java — the default (List.of(".env"))
    and its javadoc, which now explains why .envrc is excluded (executable shell direnv runs on
    cd) and keeps the existing gitignore/refs/wip warnings.
  • fleetd/fleetd.example.yaml — both mentions of the default (key-doc block + commented example),
    each now also noting the .envrc opt-in escape hatch.
  • fleetd/src/test/java/dev/ltms/fleet/config/FleetConfigTest.java — renamed
    parityOverlayDefaultsToEnvFilesOnly → parityOverlayDefaultsToDotEnvOnly with the updated
    assertion, and added parityOverlayExplicitEnvrcOptInStillWorks to prove the explicit
    [".env", ".envrc"] escape hatch still works verbatim.
  • fleetd/src/test/java/dev/ltms/fleet/session/WorktreeSessionManagerTest.java — outside the
    named scope but directly the same defect
    : worktreeAcquireRunsParityOverlayWithProfileDefaults
    also hardcoded the old [".env", ".envrc"] default and broke the full build; fixed it to track
    .env (mirroring what the fake previously tracked as .envrc) so it still exercises the
    copied/skip-worktree behaviour under the new default.

Mutation test (production code only, never a test)

Step Result
Backup FleetConfig.java (md5 5721cdae16b791361d98498e069b6bae) done
Revert default to List.of(".env", ".envrc") applied
Run parityOverlayDefaultsToDotEnvOnly RED — Tests run: 1, Failures: 1, Errors: 0 (expected: <[.env]> but was: <[.env, .envrc]>)
Compile-error count (`grep -cE 'COMPILATION ERROR cannot find symbol'`)
Revert mutation, diff -q against backup identical — clean revert confirmed

Full build

cd fleetd && mvn clean install — unpiped, full output read.

Tests run: 1216, Failures: 0, Errors: 0, Skipped: 0
BUILD SUCCESS

Out of scope (noted only, not investigated)

docs/CB-301-ext-Worktree-Provisioning.md and docs/Worker-Git-Workflow.md also mention the old
[".env", ".envrc"] default pair — not touched, since the ticket scoped only FleetConfig.java,
fleetd.example.yaml, and the config test.

## fleetd #148, point 2 only: drop `.envrc` from the default `parityOverlay` `.env` is data — a copy of it can only carry values. `.envrc` is executable shell that `direnv` runs on every `cd`, so a copy of it can carry behaviour into a worker. Those are different risks and should not share a default. **Change:** the default `parityOverlay` is now `[".env"]` (was `[".env", ".envrc"]`). The knob itself is unchanged — an operator who wants `.envrc` copied still writes `parityOverlay: [".env", ".envrc"]` explicitly and owns that choice. ### Files changed - `fleetd/src/main/java/dev/ltms/fleet/config/FleetConfig.java` — the default (`List.of(".env")`) and its javadoc, which now explains *why* `.envrc` is excluded (executable shell direnv runs on `cd`) and keeps the existing gitignore/`refs/wip` warnings. - `fleetd/fleetd.example.yaml` — both mentions of the default (key-doc block + commented example), each now also noting the `.envrc` opt-in escape hatch. - `fleetd/src/test/java/dev/ltms/fleet/config/FleetConfigTest.java` — renamed `parityOverlayDefaultsToEnvFilesOnly` → `parityOverlayDefaultsToDotEnvOnly` with the updated assertion, and added `parityOverlayExplicitEnvrcOptInStillWorks` to prove the explicit `[".env", ".envrc"]` escape hatch still works verbatim. - `fleetd/src/test/java/dev/ltms/fleet/session/WorktreeSessionManagerTest.java` — **outside the named scope but directly the same defect**: `worktreeAcquireRunsParityOverlayWithProfileDefaults` also hardcoded the old `[".env", ".envrc"]` default and broke the full build; fixed it to track `.env` (mirroring what the fake previously tracked as `.envrc`) so it still exercises the copied/skip-worktree behaviour under the new default. ### Mutation test (production code only, never a test) | Step | Result | |---|---| | Backup `FleetConfig.java` (md5 5721cdae16b791361d98498e069b6bae) | done | | Revert default to `List.of(".env", ".envrc")` | applied | | Run `parityOverlayDefaultsToDotEnvOnly` | **RED** — `Tests run: 1, Failures: 1, Errors: 0` (`expected: <[.env]> but was: <[.env, .envrc]>`) | | Compile-error count (`grep -cE 'COMPILATION ERROR|cannot find symbol'`) | **0** (separate from the 1 test failure — no compile failure masking a false "no failures") | | Revert mutation, `diff -q` against backup | **identical** — clean revert confirmed | ### Full build `cd fleetd && mvn clean install` — unpiped, full output read. ``` Tests run: 1216, Failures: 0, Errors: 0, Skipped: 0 BUILD SUCCESS ``` ### Out of scope (noted only, not investigated) `docs/CB-301-ext-Worktree-Provisioning.md` and `docs/Worker-Git-Workflow.md` also mention the old `[".env", ".envrc"]` default pair — not touched, since the ticket scoped only `FleetConfig.java`, `fleetd.example.yaml`, and the config test.
agent added 1 commit 2026-09-03 07:00:39 +02:00
fleetd #148 (point 2): drop .envrc from the default parityOverlay
CI / contract (pull_request) Successful in 1m20s
CI / build (pull_request) Successful in 1m32s
8bba3a8184
.env is data; .envrc is executable shell that direnv runs on every cd, so
copying it into a worker moves behaviour, not just values. The default
parityOverlay is now [.env] only. The knob is unchanged: an operator who
wants .envrc copied can still write parityOverlay: [.env, .envrc]
explicitly.

Updates FleetConfig's default and javadoc, fleetd.example.yaml's two
mentions of the default, and the FleetConfigTest coverage: renamed the
default test, added parityOverlayExplicitEnvrcOptInStillWorks to prove
the .envrc opt-in escape hatch still works, and fixed
WorktreeSessionManagerTest#worktreeAcquireRunsParityOverlayWithProfileDefaults
which also hardcoded the old default.
ltms closed this pull request 2026-09-03 07:05:29 +02:00
Some checks are pending
CI / contract (pull_request) Successful in 1m20s
CI / build (pull_request) Successful in 1m32s

Pull request closed

Sign in to join this conversation.