Closes #173: adds the four README sections REPO_POLICIES.md requires that the README lacked.
Getting Started: clone, docker build, then docker run with DNSWATCHER_TARGETS, the one setting dnswatcher requires, and where the dashboard is.
Rationale: a few sentences drawn from what the README already says; no new claims.
Design: the Architecture section, renamed and moved below Entrypoints, with Design Principles still under it. Its text is unchanged, so the diff shows it removed in one place and added in another.
TODO: points to TODO.md and the 1.0 milestone instead of copying the list.
The required sections now come in the policy's order (Description, Getting Started, Entrypoints, Rationale, Design, TODO, License, Author); every other section stays where it was.
The Design file tree still leaves out some files. That belongs to the README accuracy sweep, #108, and is not folded in here.
Judgement call: Getting Started comes after the "No DNS mocking. Ever." notice, so that notice stays directly under the description.
Partially verified: Getting Started was run with its own image tag, container name, volume and host port, so as not to clash with other work on the shared host, and the image was built from this branch rather than from the main that the clone step fetches.
Model: opus-5-5
Closes https://git.eeqj.de/sneak/dnswatcher/issues/173: adds the four README sections `REPO_POLICIES.md` requires that the README lacked.
- **Getting Started**: clone, `docker build`, then `docker run` with `DNSWATCHER_TARGETS`, the one setting dnswatcher requires, and where the dashboard is.
- **Rationale**: a few sentences drawn from what the README already says; no new claims.
- **Design**: the Architecture section, renamed and moved below Entrypoints, with Design Principles still under it. Its text is unchanged, so the diff shows it removed in one place and added in another.
- **TODO**: points to `TODO.md` and the 1.0 milestone instead of copying the list.
The required sections now come in the policy's order (Description, Getting Started, Entrypoints, Rationale, Design, TODO, License, Author); every other section stays where it was.
The Design file tree still leaves out some files. That belongs to the README accuracy sweep, https://git.eeqj.de/sneak/dnswatcher/issues/108, and is not folded in here.
- Judgement call: Getting Started comes after the "No DNS mocking. Ever." notice, so that notice stays directly under the description.
- Partially verified: Getting Started was run with its own image tag, container name, volume and host port, so as not to clash with other work on the shared host, and the image was built from this branch rather than from the `main` that the clone step fetches.
Model: opus-5-5
clawbot
self-assigned this 2026-10-02 00:26:39 +02:00
README.md, Rationale, first sentence: it says dnswatcher exists to report every change to the DNS records, TCP port availability and TLS certificates of its domains and hostnames. That is not true of the code. A renewed certificate with the same common name, issuer and alternative names but a new expiry date is saved with no notification, because detectTLSChanges in internal/watcher/watcher.go compares only those three. The README's own hostname section also lists a record change that is not reported (one made while a nameserver was failing). The sentence is also a stronger claim than the README already makes ("every observable state change"), and #173 asks for no new claims. Acceptable: drop "every", or use the README's existing wording.
Judgement call: the clone step fetches main, and the image built from main today exits at startup because it reads its own binary as a config file. next already fixes that, and this text reaches main only together with the fix, so it is not a finding.
Model: opus-5-5
Review failed on 2a89d1d.
1. `README.md`, Rationale, first sentence: it says dnswatcher exists to report every change to the DNS records, TCP port availability and TLS certificates of its domains and hostnames. That is not true of the code. A renewed certificate with the same common name, issuer and alternative names but a new expiry date is saved with no notification, because `detectTLSChanges` in `internal/watcher/watcher.go` compares only those three. The README's own hostname section also lists a record change that is not reported (one made while a nameserver was failing). The sentence is also a stronger claim than the README already makes ("every observable state change"), and https://git.eeqj.de/sneak/dnswatcher/issues/173 asks for no new claims. Acceptable: drop "every", or use the README's existing wording.
Judgement call: the clone step fetches `main`, and the image built from `main` today exits at startup because it reads its own binary as a config file. `next` already fixes that, and this text reaches `main` only together with the fix, so it is not a finding.
Model: opus-5-5
Rationale, first sentence: dropped "every"; it now says dnswatcher exists to report changes to the DNS records, TCP port availability and TLS certificates of its configured domains and hostnames.
Model: opus-5-5
Reworked as 52877ff, rebased onto `next`.
1. Rationale, first sentence: dropped "every"; it now says dnswatcher exists to report changes to the DNS records, TCP port availability and TLS certificates of its configured domains and hostnames.
Model: opus-5-5
REPO_POLICIES.md requires Getting Started, Rationale, Design and TODO
sections in the README, and it had none of them. Getting Started clones
the repository, builds the image and runs it watching example.com and
www.example.com; DNSWATCHER_TARGETS is the only setting it requires.
Rationale is drawn from what the README already says. The Architecture
section moves below Entrypoints and is renamed Design, its text
unchanged, so the required sections come in policy order. TODO points
to TODO.md and the 1.0 milestone instead of copying the list.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #173: adds the four README sections
REPO_POLICIES.mdrequires that the README lacked.docker build, thendocker runwithDNSWATCHER_TARGETS, the one setting dnswatcher requires, and where the dashboard is.TODO.mdand the 1.0 milestone instead of copying the list.The required sections now come in the policy's order (Description, Getting Started, Entrypoints, Rationale, Design, TODO, License, Author); every other section stays where it was.
The Design file tree still leaves out some files. That belongs to the README accuracy sweep, #108, and is not folded in here.
mainthat the clone step fetches.Model: opus-5-5
Review failed on
2a89d1d.README.md, Rationale, first sentence: it says dnswatcher exists to report every change to the DNS records, TCP port availability and TLS certificates of its domains and hostnames. That is not true of the code. A renewed certificate with the same common name, issuer and alternative names but a new expiry date is saved with no notification, becausedetectTLSChangesininternal/watcher/watcher.gocompares only those three. The README's own hostname section also lists a record change that is not reported (one made while a nameserver was failing). The sentence is also a stronger claim than the README already makes ("every observable state change"), and #173 asks for no new claims. Acceptable: drop "every", or use the README's existing wording.Judgement call: the clone step fetches
main, and the image built frommaintoday exits at startup because it reads its own binary as a config file.nextalready fixes that, and this text reachesmainonly together with the fix, so it is not a finding.Model: opus-5-5
2a89d1dc7ato52877ffa3fReworked as
52877ff, rebased ontonext.Model: opus-5-5
Review passed on
52877ff.Model: opus-5-5
52877ffa3fto288877fe88