diff --git a/docs/why-gates-are-code.md b/docs/why-gates-are-code.md index 69fa398..be75e16 100644 --- a/docs/why-gates-are-code.md +++ b/docs/why-gates-are-code.md @@ -83,6 +83,14 @@ that every instruction would then have to know which provider an instance runs. gap belongs where the capability is, and reaches the session as an exit code rather than as a paragraph it has to remember to apply. +The preflight is the second such case, and the one closest to this page's own argument. A machine +without Python or ripgrep is not something the tool can fix, and an install that met that gap +with only a setup instruction to go on showed what follows: the agent worked around each missing +piece - another environment, a hand-made configuration - and kept going. So `tools/preflight.sh` +exits 42 with the command a human has to run, and the launcher in front of every `wikitool` call +exits 42 until the preflight has passed. "Check first, stop, let the user act" lives in two places +a session cannot read past, not in a step it can skip. + ## A gate in code still has to be reachable Code beats prose for the reason above, but on its own it buys less than it looks like: a check