@mjg59 It seems like one problem is it would be legitimately difficult to validate this without introducing some sort of uniform build/packaging process to audit in the first place.
(I guess you could look at effects, and specifically test whether the tarball/thing in package repo is different from the source, and compare against an approved list of intentional, inspected late patches for the cases where you want behavior like this?)