Defuse the clone-and-run trap: tracked pipeline data warns loudly

Eric spotted it: the README told people to clone this repo, rm the
committed data, and run — which writes THEIR pipeline artifacts at
git-TRACKED paths. The next `git pull` (this repo commits data every
session) refuses to merge, and the internet's standard remedies for
that error — reset --hard, checkout ., stash, clean -fdx — destroy
their review decisions, hand-written games, upload log, and photos.

Two layers. The README's "Bring your own shelves" now leads with
`uv tool install git+…` and running in a directory of your own: data
lands untracked by construction and a bug fix is `uv tool upgrade`,
which cannot touch it. And because nobody re-reads a README, Config
gains tracked_data_warning(): if artifacts under data_dir are
git-tracked, `bggpipe init` and the web dashboard both warn in plain
words. The owner's exemption is data/.own_repo — a GITIGNORED marker,
so the author's checkout is silent while a fresh clone of the same
repo still gets the warning (a committed marker or config key would
have shipped the exemption to exactly the people who need warning).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jXZFSTZQKzAC8fqpWSz9g
This commit is contained in:
Eric Wagoner
2026-08-06 00:43:35 -04:00
co-authored by Claude Fable 5
parent 77d330748d
commit dec2bfc7b6
7 changed files with 94 additions and 5 deletions
+42
View File
@@ -2,6 +2,7 @@
from __future__ import annotations
import os
from pathlib import Path
import pytest
@@ -96,3 +97,44 @@ model = "claude-sonnet-5"
pytest.warns(UserWarning, match="anthorpic"),
):
load_config(p)
def _git(tmp_path, *args):
import subprocess
subprocess.run(
["git", *args],
cwd=tmp_path,
check=True,
capture_output=True,
env={
"PATH": os.environ["PATH"],
"HOME": str(tmp_path),
"GIT_AUTHOR_NAME": "t",
"GIT_AUTHOR_EMAIL": "t@t",
"GIT_COMMITTER_NAME": "t",
"GIT_COMMITTER_EMAIL": "t@t",
},
)
def test_tracked_data_warning_fires_only_inside_a_repo(tmp_path):
"""The clone-and-run trap: data at git-tracked paths is one panicked
`git reset --hard` from destruction. Outside a repo, silence."""
data = tmp_path / "data"
data.mkdir()
(data / "matches.csv").write_text("x")
cfg = Config(data_dir=data)
assert cfg.tracked_data_warning() is None # no repo, no trap
_git(tmp_path, "init")
assert cfg.tracked_data_warning() is None # repo, but nothing tracked
_git(tmp_path, "add", "data/matches.csv")
_git(tmp_path, "commit", "-m", "seed")
warning = cfg.tracked_data_warning()
assert warning and "git-TRACKED" in warning and ".own_repo" in warning
# the owner's exemption is a gitignored marker: a fresh clone of this
# repo would NOT carry it, so only the author's checkout is silenced
(data / ".own_repo").touch()
assert cfg.tracked_data_warning() is None
+1 -1
View File
@@ -20,8 +20,8 @@ from bggpipe.upload import (
_scrub,
annotate_queue,
build_queue,
stale_jobs,
run_upload,
stale_jobs,
verify_uploads,
)