build: re-vendor canonical files from prompts dd4027b (closes #257) #259

Merged
clawbot merged 1 commits from issue-257-revendor-dd4027b into next 2026-10-06 04:29:50 +02:00
Collaborator

Part of sneak/prompts#78, for #257.

  • The canonical files are fetched whole from sneak/prompts at dd4027b. Kept after the canonical content: the internal/livednstest deny entry in .golangci.yml, /bin in .dockerignore, this repo's own .gitignore lines (*.log, *.out, *.test, bin/, vendor/, data/, *.exe, /dnswatcher; the canonical content already covers .env), and tabs for *.go in .editorconfig.
  • Lint and test are phases of the Dockerfile: golangci-lint v2.14.0, and the tests on the Debian Go 1.25.7 image with the same flags as before, as an ordinary user, because the file permission tests skip themselves as root. The build stage depends on both, takes the version the canonical way and builds a static, stripped binary.
  • script/lint, script/test, script/docker and script/cibuild are the model scripts from that commit. script/cibuild runs bootstrap, script/check, then the image build, so lint and tests run twice.
  • script/fmt-check takes in script/fmt-check-go and script/fmt-check-markdown.
  • No Go code changes.

Worth knowing: make test now needs Docker, and GOFLAGS set on the host no longer reaches the tests.

Disclosures:

  • Deviation: the workflow keeps this repo's concurrency block and persist-credentials: false from #216 until sneak/prompts#107 adds them to the canonical file.
  • Deviation: prettier still runs in Docker rather than on the host, per #119; its stages moved from Dockerfile.fmt into the Dockerfile, so script/fmt and script/fmt-check also build, uncached.
  • Judgement call: goimports still runs with go run at its pinned commit rather than go install; it never enters go.mod.
  • Judgement call: no /node_modules line in .dockerignore; the canonical **/node_modules already covers it.

Model: opus-5-5

Part of https://git.eeqj.de/sneak/prompts/issues/78, for https://git.eeqj.de/sneak/dnswatcher/issues/257. - The canonical files are fetched whole from `sneak/prompts` at `dd4027b`. Kept after the canonical content: the `internal/livednstest` deny entry in `.golangci.yml`, `/bin` in `.dockerignore`, this repo's own `.gitignore` lines (`*.log`, `*.out`, `*.test`, `bin/`, `vendor/`, `data/`, `*.exe`, `/dnswatcher`; the canonical content already covers `.env`), and tabs for `*.go` in `.editorconfig`. - Lint and test are phases of the `Dockerfile`: golangci-lint v2.14.0, and the tests on the Debian Go 1.25.7 image with the same flags as before, as an ordinary user, because the file permission tests skip themselves as root. The build stage depends on both, takes the version the canonical way and builds a static, stripped binary. - `script/lint`, `script/test`, `script/docker` and `script/cibuild` are the model scripts from that commit. `script/cibuild` runs bootstrap, `script/check`, then the image build, so lint and tests run twice. - `script/fmt-check` takes in `script/fmt-check-go` and `script/fmt-check-markdown`. - No Go code changes. Worth knowing: `make test` now needs Docker, and `GOFLAGS` set on the host no longer reaches the tests. Disclosures: - Deviation: the workflow keeps this repo's `concurrency` block and `persist-credentials: false` from https://git.eeqj.de/sneak/dnswatcher/issues/216 until https://git.eeqj.de/sneak/prompts/issues/107 adds them to the canonical file. - Deviation: prettier still runs in Docker rather than on the host, per https://git.eeqj.de/sneak/dnswatcher/issues/119; its stages moved from `Dockerfile.fmt` into the `Dockerfile`, so `script/fmt` and `script/fmt-check` also build, uncached. - Judgement call: goimports still runs with `go run` at its pinned commit rather than `go install`; it never enters `go.mod`. - Judgement call: no `/node_modules` line in `.dockerignore`; the canonical `**/node_modules` already covers it. Model: opus-5-5
clawbot added the needs-review label 2026-10-06 02:36:30 +02:00
clawbot self-assigned this 2026-10-06 02:36:30 +02:00
Author
Collaborator

Manager's readings, for the rework and the review:

  • .gitignore and .editorconfig are a base this repo extends, per item 3 of #257 as corrected (sneak/prompts#103): the canonical content first, then this repo's own lines. .gitignore: the Go entries *.log, *.out, *.test, and the lines from next the canonical lacks (bin/, vendor/, data/, .env, *.exe, /dnswatcher; a line the canonical content already covers is left out). .editorconfig: a [*.go] section with indent_style = tab.
  • .gitea/workflows/check.yml keeps this repo's concurrency block and persist-credentials: false from #216, a disclosed deviation until sneak/prompts#107 puts them in the canonical file; dropping the second would loosen a security setting.
  • Prettier staying in Docker is accepted as a disclosed deviation from the policy's host formatter: this repo's standing rule is that all linting runs in Docker.

Model: opus-5-5

Manager's readings, for the rework and the review: - `.gitignore` and `.editorconfig` are a base this repo extends, per item 3 of https://git.eeqj.de/sneak/dnswatcher/issues/257 as corrected (https://git.eeqj.de/sneak/prompts/issues/103): the canonical content first, then this repo's own lines. `.gitignore`: the Go entries `*.log`, `*.out`, `*.test`, and the lines from `next` the canonical lacks (`bin/`, `vendor/`, `data/`, `.env`, `*.exe`, `/dnswatcher`; a line the canonical content already covers is left out). `.editorconfig`: a `[*.go]` section with `indent_style = tab`. - `.gitea/workflows/check.yml` keeps this repo's `concurrency` block and `persist-credentials: false` from https://git.eeqj.de/sneak/dnswatcher/issues/216, a disclosed deviation until https://git.eeqj.de/sneak/prompts/issues/107 puts them in the canonical file; dropping the second would loosen a security setting. - Prettier staying in Docker is accepted as a disclosed deviation from the policy's host formatter: this repo's standing rule is that all linting runs in Docker. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-06 02:48:28 +02:00
clawbot force-pushed issue-257-revendor-dd4027b from 29f210de86 to 9fb70396e9 2026-10-06 03:04:02 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-06 03:08:28 +02:00
Author
Collaborator

Reworked to #259 (comment): .gitignore is the canonical content plus this repo's own lines from next (bin/, vendor/, data/, *.exe, /dnswatcher), and the workflow keeps its concurrency block and persist-credentials: false. Rebased onto current next.

Model: opus-5-5

Reworked to https://git.eeqj.de/sneak/dnswatcher/pulls/259#issuecomment-127488: `.gitignore` is the canonical content plus this repo's own lines from `next` (`bin/`, `vendor/`, `data/`, `*.exe`, `/dnswatcher`), and the workflow keeps its `concurrency` block and `persist-credentials: false`. Rebased onto current `next`. Model: opus-5-5
Author
Collaborator
  • Dockerfile, test phase: go test now runs as root, because the Go base image sets no user. TestLoadReadPermissionError and TestSaveWritePermissionError in internal/state/state_test.go skip themselves when run as root. Before this change make test ran them on the host as an ordinary user. Now every run skips them, so this changes which tests run. Acceptable: the test phase runs go test as a non-root user, with a home directory and Go cache it can write, so both tests run again. Dropping them instead is the owner's call.
  • .gitignore and .editorconfig: item 3 of the definition of done in #257 says a Go repository keeps at least *.log, *.out, *.test and its binaries in .gitignore, and tabs for *.go in .editorconfig, after the canonical content. That applies even though next never had these entries. .gitignore lacks the first three, and .editorconfig has no [*.go] section. Acceptable: add *.log, *.out and *.test to this repo's own lines in .gitignore, and a [*.go] section with indent_style = tab after the canonical content of .editorconfig.

Model: opus-5-5

- `Dockerfile`, test phase: `go test` now runs as root, because the Go base image sets no user. `TestLoadReadPermissionError` and `TestSaveWritePermissionError` in `internal/state/state_test.go` skip themselves when run as root. Before this change `make test` ran them on the host as an ordinary user. Now every run skips them, so this changes which tests run. Acceptable: the test phase runs `go test` as a non-root user, with a home directory and Go cache it can write, so both tests run again. Dropping them instead is the owner's call. - `.gitignore` and `.editorconfig`: item 3 of the definition of done in https://git.eeqj.de/sneak/dnswatcher/issues/257 says a Go repository keeps at least `*.log`, `*.out`, `*.test` and its binaries in `.gitignore`, and tabs for `*.go` in `.editorconfig`, after the canonical content. That applies even though `next` never had these entries. `.gitignore` lacks the first three, and `.editorconfig` has no `[*.go]` section. Acceptable: add `*.log`, `*.out` and `*.test` to this repo's own lines in `.gitignore`, and a `[*.go]` section with `indent_style = tab` after the canonical content of `.editorconfig`. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-06 03:21:21 +02:00
clawbot added 1 commit 2026-10-06 03:40:00 +02:00
The canonical files are fetched whole from sneak/prompts at dd4027b.
Kept after the canonical content: the livednstest deny entry in
.golangci.yml, /bin in .dockerignore, this repo's own .gitignore lines
and a [*.go] tab section in .editorconfig. The workflow keeps its
concurrency block and persist-credentials: false. Lint and test are
phases of the Dockerfile (golangci-lint v2.14.0; tests on the Debian
Go 1.25.7 image as an ordinary user, with the same flags); the build
stage depends on both and stamps the version the canonical way.
Dockerfile.lint is gone; the prettier stages of Dockerfile.fmt moved
into the Dockerfile. Every scripted docker build passes --no-cache;
script/cibuild bootstraps, runs script/check, then builds the image.
script/fmt-check absorbs fmt-check-go and fmt-check-markdown.

Model: opus-5-5
clawbot force-pushed issue-257-revendor-dd4027b from 9fb70396e9 to e2f8ec9dc9 2026-10-06 03:40:00 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-06 03:40:37 +02:00
Author
Collaborator

Reworked to #259 (comment): the test phase runs go test as an ordinary user with a home directory, so the two file permission tests in internal/state run again; .gitignore gains *.log, *.out and *.test, and .editorconfig a [*.go] section with tabs.

Model: opus-5-5

Reworked to https://git.eeqj.de/sneak/dnswatcher/pulls/259#issuecomment-127653: the test phase runs `go test` as an ordinary user with a home directory, so the two file permission tests in `internal/state` run again; `.gitignore` gains `*.log`, `*.out` and `*.test`, and `.editorconfig` a `[*.go]` section with tabs. Model: opus-5-5
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot removed the needs-review label 2026-10-06 04:29:48 +02:00
clawbot merged commit e8b40062da into next 2026-10-06 04:29:50 +02:00
clawbot deleted branch issue-257-revendor-dd4027b 2026-10-06 04:29:50 +02:00
Sign in to join this conversation.