Spec: Bundled Baseline Update Guard
Spec: Bundled Baseline Update Guard
Initial Situation
Harness distributes scaffold content through stable baseline releases, while the npm CLI package also includes a bundled baseline for offline use. Issue 43 showed a hazardous interaction: after a newer stable baseline was published, global dp update --yes could resolve to the older bundled baseline and produce managed-file changes that downgraded repo guidance.
Issue
Bundled fallback is useful for offline diagnosis and intentional recovery, but dp update --write and dp update --yes are write paths. When the repo's .devpunks/scaffold-manifest.json records a different baseline version, applying implicit bundled fallback is unsafe because the command cannot know whether it is refreshing or downgrading.
Solution
Keep fallback resolution intact, but add a write guard inside runUpdate:
- allow check/json mode to report baseline drift
- block apply mode when active baseline source is
bundledand manifest baseline drift exists - allow explicit bundled application when the operator passes
--baseline bundledor setsDP_BASELINE=bundled
This keeps offline visibility while requiring an explicit decision before old bundled assets can replace newer managed scaffold files.
Non-Goals
- Removing bundled fallback.
- Changing baseline publish mechanics.
- Changing pack drift behavior.
- Rewriting control-plane or GitHub release resolution.
Acceptance Criteria
dp update --yesrefuses to write from implicit bundled fallback when manifest baseline drift exists.dp update --checkcan still report baseline drift without writing.- Explicit bundled mode can still apply managed-file changes.
- Operator docs explain the guard and the explicit override.
- Focused update tests cover blocked and explicit bundled write paths.