chore: re-vendor canonical files from prompts at dd4027b (closes #472)
check / check (push) Successful in 5m41s
e2e / e2e-chrome (push) Successful in 4m57s
e2e / e2e-firefox (push) Successful in 2m36s

Copies .dockerignore, .gitignore, .prettierignore, check.yml and
REPO_POLICIES.md from sneak/prompts at dd4027b. The repo's own entries
(dist/, release/, yarn files) are kept after the canonical content.

The Dockerfile gets separate lint and test phases. Its last stage
depends on both, checks the git describe version and runs make build.
script/lint, test, check, cibuild and docker are the canonical models.
check-censored moves into the lint phase and test-verify-build into the
test phase. fmt and fmt-check fall back to the nvm-installed node. The
e2e image builds are uncached. Comments that cited the old 20-second
test cap now say 60.

Model: opus-5-5
This commit is contained in:
2026-10-06 02:23:57 +00:00
parent 25ead55eac
commit 4e25d90529
26 changed files with 708 additions and 279 deletions
+42 -33
View File
@@ -222,31 +222,32 @@ provide:
- `script/setup` — make a fresh clone ready for development: bootstrap plus the
git pre-commit hook
- `script/projectname` — print the project name (used for the Docker image tag)
- `script/test` — run the test suite (jest)
- `script/test` — build the Dockerfile's `test` phase, uncached: the jest suite,
stopped after 90 seconds and rerun verbose if it fails, then
`script/test-verify-build`
- `script/test-e2e` — run the Chrome browser end-to-end suite (docker is the
only prerequisite: it builds a pinned image that carries the repo and a fresh
extension build, see [End-to-End Tests](#end-to-end-tests))
- `script/test-e2e-firefox` — run the Firefox browser end-to-end suite (same,
against an image with a pinned Firefox and geckodriver, see
[End-to-End Tests](#end-to-end-tests))
- `script/lint` — run ESLint (`eslint.config.js`) and then `prettier --check`,
failing on either. It never writes: `--fix` is not in this path, so
`make check` stays non-mutating. Linting runs in the container — the script
builds the Dockerfile's `lint` stage — because an ESLint result that depends
on whichever ESLint the host happens to have is not a result. Docker is
therefore required to lint; inside that image `AUTISTMASK_LINT_NATIVE=1` makes
the same script lint in place instead of recursing.
- `script/fmt` — format all files (writes)
- `script/fmt-check` — check formatting (read-only)
- `script/check` — run test, test-verify-build, check-censored, lint, and
fmt-check
- `script/lint` — build the Dockerfile's `lint` phase, uncached: ESLint
(`eslint.config.js`), `prettier --check`, then `script/check-censored`,
failing on any of them. It never writes: `--fix` is not in this path, so
`make check` stays non-mutating. Linting runs only in the container, because
an ESLint result that depends on whichever ESLint the host happens to have is
not a result, so docker is required to lint.
- `script/fmt` — format all files (writes), on the host
- `script/fmt-check` — check formatting (read-only), on the host
- `script/check` — run `script/test`, `script/lint` and `script/fmt-check`
- `script/check-censored` — assert the competitor name RULES.md bars appears
nowhere in the working tree or under `dist/` outside its documented
exceptions: the pinned source reference in `script/vendor-blocklist`, the two
provider-shim identifiers in `src/content/inpage.js`, and one ERC-20's
on-chain name in `src/shared/tokenList.js`. Each is scoped to that path and
fails anywhere else. Part of `make check`, which inspects `dist/` when there
is one and says loudly when there is not; `make build` re-runs it with
fails anywhere else. Run by the `lint` phase, so part of `make check`; it
inspects `dist/` when there is one and says loudly when there is not, and the
build context of that phase never has one. `make build` re-runs it with
`--require-dist`, so a build artifact is always covered
- `script/package` — produce the release artifacts: `make build` first, so the
archives can only ever be made from a `dist/` that has been verified against
@@ -281,14 +282,20 @@ provide:
failing and a succeeding release build step, and read the `make build` and
`make build-debug` recipes back out of `make -n` to check that they pass the
mode as an argument on a scrubbed environment and wrap only the release path.
Part of `make check`; it reads no build artifacts and writes nothing under
`dist/`. The cases that depend on file permissions cannot mean anything for a
process that is not subject to them, so the harness proves its runner against
a mode-000 file before counting them, dropping to an unprivileged user when
run as root; if it cannot, it skips those cases and says so in a banner rather
than passing them.
- `script/docker` — build the Docker image tagged via `script/projectname`
- `script/cibuild` — CI entrypoint: plain `docker build .`
Run by the `test` phase, so part of `make check`; it reads no build artifacts
and writes nothing under `dist/`. The cases that depend on file permissions
cannot mean anything for a process that is not subject to them, so the harness
proves its runner against a mode-000 file before counting them, dropping to an
unprivileged user when run as root; if it cannot, it skips those cases and
says so in a banner rather than passing them.
- `script/docker` — build the Docker image, uncached and tagged via
`script/projectname`: the `lint` and `test` phases, then `make build` in the
last stage. It passes the version `git describe --tags --always --dirty` gives
on the host; without one, the build runs `git describe` on the `.git` in the
build context, which `.dockerignore` sends without its `config`, and fails if
git cannot read it
- `script/cibuild` — CI entrypoint: `script/bootstrap`, `script/check`, then the
same image build as `script/docker`
- `script/precommit` — run by the git pre-commit hook; runs `script/check`
- `script/install-precommit` — install the git pre-commit hook
@@ -617,7 +624,7 @@ Two limits are worth knowing, both real differences from the Chrome suite:
out, but it cannot report which requests were attempted.
Neither `make test-e2e` nor `make test-e2e-firefox` is part of `make check` or
`make test`. `REPO_POLICIES.md` caps `make test` at 20 seconds and a browser
`make test`. `REPO_POLICIES.md` caps `make test` at 60 seconds and a browser
suite does not fit; nothing in `tests/e2e/` is named `*.test.js`, so jest cannot
pick it up either. Run them locally before changing anything under
`src/popup/views/`.
@@ -626,7 +633,7 @@ pick it up either. Run them locally before changing anything under
`.gitea/workflows/e2e.yml` runs both suites on every push, as two jobs —
`e2e-chrome` and `e2e-firefox` — separate from the `check` workflow, so the
20-second `make test` cap and the local fast path are untouched. Each job is a
60-second `make test` cap and the local fast path are untouched. Each job is a
checkout and the matching `script/` entrypoint, nothing else.
Docker is the only thing either job needs from the runner, and that is not an
@@ -652,19 +659,21 @@ build fails, and when the browser fails to start; the Chrome harness aborts the
suite outright if its network interception is not in effect.
Measured on this repo's runner in the green runs of early October 2026, from a
warm docker cache to a cold one: `check` 49s to 3m37s, `e2e-chrome` 1m44s to
4m48s, and `e2e-firefox` 31s to 4m07s. A cold cache adds three to four minutes
to each job, spent rebuilding its image: reinstalling dependencies and, for
`e2e-firefox`, installing Firefox, geckodriver and their system libraries. Those
warm docker cache to a cold one: `e2e-chrome` 1m44s to 4m48s, and `e2e-firefox`
31s to 4m07s. A cold cache adds three to four minutes to each job, spent
rebuilding its image: reinstalling dependencies and, for `e2e-firefox`,
installing Firefox, geckodriver and their system libraries. Both scripts now
build their image with `--no-cache`, so every run pays the cold figure. Those
`e2e-chrome` runs predate the cases that wait in real time for a receipt to end
in error. `make test-e2e` now takes 3m51s locally with its image cached, so a
cold `e2e-chrome` run comes to about seven minutes.
in error. `make test-e2e` took 3m51s locally with its image cached, so with the
image rebuilt every run, an `e2e-chrome` run comes to about seven minutes.
Every job has a `timeout-minutes` cap, so a hung build or browser ends the job
instead of holding the shared runner: `check` 10 minutes, `e2e-firefox` 15 and
Each e2e job has a `timeout-minutes` cap, so a hung build or browser ends the
job instead of holding the shared runner: `e2e-firefox` 15 minutes and
`e2e-chrome` 20, each over two and a half times the job's slowest cold run. A
job that reaches its cap has hung; read it as a hang, not as a slow run to
retry.
retry. The `check` job has no cap: `.gitea/workflows/check.yml` is the canonical
copy from `sneak/prompts`, kept byte-identical.
### Element id guard (part of `make check`)