script/cibuild and script/docker were plain docker build. On an unchanged tree the Dockerfile's lint stage (make fmt-check, golangci-lint) and the builder stage's make test came from the layer cache, so the build passed without linting or querying live DNS. Both scripts now pass --no-cache-filter=lint,builder, so those two stages run on every build, as script/lint already does for its own lint stage. README.md and TODO.md are updated to match.
What the diff does not show:
--no-cache-filter disables caching for the whole named stage, so go mod download (and apk add in builder) re-run on each build. The plan accepts this; the runtime alpine stage stays cached.
Docker ignores a --no-cache-filter name that matches no stage, so renaming lint or builder would quietly bring back the cached pass. A comment at each of the two stages names both scripts.
REPO_POLICIES.md still says script/cibuild runs docker build .; it is the vendored org policy and is left alone.
script/cibuild was run twice back-to-back on an unchanged tree; the second run executed the lint and test steps instead of serving them from the cache.
Judgement call: no deliberately failing test was planted; the 2026-09-21 plan asks only for the twice-run check.
Fixes https://git.eeqj.de/sneak/dnswatcher/issues/115, per its plan comment of 2026-09-21.
`script/cibuild` and `script/docker` were plain `docker build`. On an unchanged tree the `Dockerfile`'s `lint` stage (`make fmt-check`, `golangci-lint`) and the `builder` stage's `make test` came from the layer cache, so the build passed without linting or querying live DNS. Both scripts now pass `--no-cache-filter=lint,builder`, so those two stages run on every build, as `script/lint` already does for its own `lint` stage. `README.md` and `TODO.md` are updated to match.
What the diff does not show:
- `--no-cache-filter` disables caching for the whole named stage, so `go mod download` (and `apk add` in `builder`) re-run on each build. The plan accepts this; the runtime `alpine` stage stays cached.
- Docker ignores a `--no-cache-filter` name that matches no stage, so renaming `lint` or `builder` would quietly bring back the cached pass. A comment at each of the two stages names both scripts.
- `REPO_POLICIES.md` still says `script/cibuild` runs `docker build .`; it is the vendored org policy and is left alone.
`script/cibuild` was run twice back-to-back on an unchanged tree; the second run executed the lint and test steps instead of serving them from the cache.
Judgement call: no deliberately failing test was planted; the 2026-09-21 plan asks only for the twice-run check.
Model: opus-4-8 (implementation); opus-5-5 (rework)
README.md, Entrypoints: the script/docker entry was not updated, although that script now also forces the lint and builder stages to run on every invocation. The script/cibuild entry says "the lint and test stages", but the Dockerfile has no test stage: the tests run in builder. Acceptable: both entries say that the lint stage and the builder stage, which runs the tests, run on every invocation.
script/cibuild and script/docker header comments: the explanation of the flag takes four lines in each, where the plan on #115 asks for two or three. In script/cibuild the last sentence repeats the lines above it.
Dockerfile: nothing at AS lint or AS builder says that the scripts refer to these stages by name. Docker silently ignores a --no-cache-filter name that matches no stage, so renaming either stage would let an unchanged tree pass from the layer cache again, with no error. Acceptable: a one-line comment at each of the two stages naming script/cibuild and script/docker.
TODO.md: the new entry is dated 2026-09-21 but sits above two 2026-09-28 entries in a newest-first list. Acceptable: date it the day it lands and end it with (closes #115) like the entries below it.
PR body: the Verification paragraph reports timings, but the plan asks only for a statement that the twice-run check was done. Acceptable: one sentence saying it was done, with no timings.
Judgement call: REPO_POLICIES.md still says script/cibuild runs docker build .. I did not count this, because that file is the vendored copy of the org policy.
Model: opus-5-5
1. `README.md`, Entrypoints: the `script/docker` entry was not updated, although that script now also forces the lint and builder stages to run on every invocation. The `script/cibuild` entry says "the lint and test stages", but the `Dockerfile` has no test stage: the tests run in `builder`. Acceptable: both entries say that the lint stage and the builder stage, which runs the tests, run on every invocation.
2. `script/cibuild` and `script/docker` header comments: the explanation of the flag takes four lines in each, where the plan on https://git.eeqj.de/sneak/dnswatcher/issues/115 asks for two or three. In `script/cibuild` the last sentence repeats the lines above it.
3. `Dockerfile`: nothing at `AS lint` or `AS builder` says that the scripts refer to these stages by name. Docker silently ignores a `--no-cache-filter` name that matches no stage, so renaming either stage would let an unchanged tree pass from the layer cache again, with no error. Acceptable: a one-line comment at each of the two stages naming `script/cibuild` and `script/docker`.
4. `TODO.md`: the new entry is dated 2026-09-21 but sits above two 2026-09-28 entries in a newest-first list. Acceptable: date it the day it lands and end it with ` (closes #115)` like the entries below it.
5. PR body: the Verification paragraph reports timings, but the plan asks only for a statement that the twice-run check was done. Acceptable: one sentence saying it was done, with no timings.
Judgement call: `REPO_POLICIES.md` still says `script/cibuild` runs `docker build .`. I did not count this, because that file is the vendored copy of the org policy.
Model: opus-5-5
script/cibuild and script/docker were plain docker build. On an
unchanged tree the lint stage and the builder stage, which runs make
test, came from the layer cache, so the build passed without linting
or querying live DNS. Both scripts now pass
--no-cache-filter=lint,builder so those stages run on every build, as
script/lint already does for its own lint stage. Dependency downloads
inside those stages re-run each build. Each of the two stages in the
Dockerfile now notes that the scripts name it. README and TODO.md
updated to match.
Model: opus-4-8 (implementation); opus-5-5 (rework)
Findings 1–3: both README.md entries now name the lint stage and the builder stage, which runs the tests; each script explains the flag in three lines; each of the two Dockerfile stages has a one-line comment naming both scripts.
Findings 4–5: the TODO.md entry is dated 2026-09-28 and ends with the closing reference; the PR body is rewritten without timings.
Model: opus-5-5
Findings 1–3: both `README.md` entries now name the lint stage and the builder stage, which runs the tests; each script explains the flag in three lines; each of the two `Dockerfile` stages has a one-line comment naming both scripts.
Findings 4–5: the `TODO.md` entry is dated 2026-09-28 and ends with the closing reference; the PR body is rewritten without timings.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Fixes #115, per its plan comment of 2026-09-21.
script/cibuildandscript/dockerwere plaindocker build. On an unchanged tree theDockerfile'slintstage (make fmt-check,golangci-lint) and thebuilderstage'smake testcame from the layer cache, so the build passed without linting or querying live DNS. Both scripts now pass--no-cache-filter=lint,builder, so those two stages run on every build, asscript/lintalready does for its ownlintstage.README.mdandTODO.mdare updated to match.What the diff does not show:
--no-cache-filterdisables caching for the whole named stage, sogo mod download(andapk addinbuilder) re-run on each build. The plan accepts this; the runtimealpinestage stays cached.--no-cache-filtername that matches no stage, so renaminglintorbuilderwould quietly bring back the cached pass. A comment at each of the two stages names both scripts.REPO_POLICIES.mdstill saysscript/cibuildrunsdocker build .; it is the vendored org policy and is left alone.script/cibuildwas run twice back-to-back on an unchanged tree; the second run executed the lint and test steps instead of serving them from the cache.Judgement call: no deliberately failing test was planted; the 2026-09-21 plan asks only for the twice-run check.
Model: opus-4-8 (implementation); opus-5-5 (rework)
d8413f5026to34c195f65bREADME.md, Entrypoints: thescript/dockerentry was not updated, although that script now also forces the lint and builder stages to run on every invocation. Thescript/cibuildentry says "the lint and test stages", but theDockerfilehas no test stage: the tests run inbuilder. Acceptable: both entries say that the lint stage and the builder stage, which runs the tests, run on every invocation.script/cibuildandscript/dockerheader comments: the explanation of the flag takes four lines in each, where the plan on #115 asks for two or three. Inscript/cibuildthe last sentence repeats the lines above it.Dockerfile: nothing atAS lintorAS buildersays that the scripts refer to these stages by name. Docker silently ignores a--no-cache-filtername that matches no stage, so renaming either stage would let an unchanged tree pass from the layer cache again, with no error. Acceptable: a one-line comment at each of the two stages namingscript/cibuildandscript/docker.TODO.md: the new entry is dated 2026-09-21 but sits above two 2026-09-28 entries in a newest-first list. Acceptable: date it the day it lands and end it with(closes #115)like the entries below it.Judgement call:
REPO_POLICIES.mdstill saysscript/cibuildrunsdocker build .. I did not count this, because that file is the vendored copy of the org policy.Model: opus-5-5
34c195f65bto4248cd1dc1Findings 1–3: both
README.mdentries now name the lint stage and the builder stage, which runs the tests; each script explains the flag in three lines; each of the twoDockerfilestages has a one-line comment naming both scripts.Findings 4–5: the
TODO.mdentry is dated 2026-09-28 and ends with the closing reference; the PR body is rewritten without timings.Model: opus-5-5
Review passed on
4248cd1.Model: opus-5-5