The canonical files are fetched whole from sneak/prompts at dd4027b. Kept after the canonical content: the internal/livednstest deny entry in .golangci.yml, /bin in .dockerignore, this repo's own .gitignore lines (*.log, *.out, *.test, bin/, vendor/, data/, *.exe, /dnswatcher; the canonical content already covers .env), and tabs for *.go in .editorconfig.
Lint and test are phases of the Dockerfile: golangci-lint v2.14.0, and the tests on the Debian Go 1.25.7 image with the same flags as before, as an ordinary user, because the file permission tests skip themselves as root. The build stage depends on both, takes the version the canonical way and builds a static, stripped binary.
script/lint, script/test, script/docker and script/cibuild are the model scripts from that commit. script/cibuild runs bootstrap, script/check, then the image build, so lint and tests run twice.
script/fmt-check takes in script/fmt-check-go and script/fmt-check-markdown.
No Go code changes.
Worth knowing: make test now needs Docker, and GOFLAGS set on the host no longer reaches the tests.
Disclosures:
Deviation: the workflow keeps this repo's concurrency block and persist-credentials: false from #216 until sneak/prompts#107 adds them to the canonical file.
Deviation: prettier still runs in Docker rather than on the host, per #119; its stages moved from Dockerfile.fmt into the Dockerfile, so script/fmt and script/fmt-check also build, uncached.
Judgement call: goimports still runs with go run at its pinned commit rather than go install; it never enters go.mod.
Judgement call: no /node_modules line in .dockerignore; the canonical **/node_modules already covers it.
Model: opus-5-5
Part of https://git.eeqj.de/sneak/prompts/issues/78, for https://git.eeqj.de/sneak/dnswatcher/issues/257.
- The canonical files are fetched whole from `sneak/prompts` at `dd4027b`. Kept after the canonical content: the `internal/livednstest` deny entry in `.golangci.yml`, `/bin` in `.dockerignore`, this repo's own `.gitignore` lines (`*.log`, `*.out`, `*.test`, `bin/`, `vendor/`, `data/`, `*.exe`, `/dnswatcher`; the canonical content already covers `.env`), and tabs for `*.go` in `.editorconfig`.
- Lint and test are phases of the `Dockerfile`: golangci-lint v2.14.0, and the tests on the Debian Go 1.25.7 image with the same flags as before, as an ordinary user, because the file permission tests skip themselves as root. The build stage depends on both, takes the version the canonical way and builds a static, stripped binary.
- `script/lint`, `script/test`, `script/docker` and `script/cibuild` are the model scripts from that commit. `script/cibuild` runs bootstrap, `script/check`, then the image build, so lint and tests run twice.
- `script/fmt-check` takes in `script/fmt-check-go` and `script/fmt-check-markdown`.
- No Go code changes.
Worth knowing: `make test` now needs Docker, and `GOFLAGS` set on the host no longer reaches the tests.
Disclosures:
- Deviation: the workflow keeps this repo's `concurrency` block and `persist-credentials: false` from https://git.eeqj.de/sneak/dnswatcher/issues/216 until https://git.eeqj.de/sneak/prompts/issues/107 adds them to the canonical file.
- Deviation: prettier still runs in Docker rather than on the host, per https://git.eeqj.de/sneak/dnswatcher/issues/119; its stages moved from `Dockerfile.fmt` into the `Dockerfile`, so `script/fmt` and `script/fmt-check` also build, uncached.
- Judgement call: goimports still runs with `go run` at its pinned commit rather than `go install`; it never enters `go.mod`.
- Judgement call: no `/node_modules` line in `.dockerignore`; the canonical `**/node_modules` already covers it.
Model: opus-5-5
Manager's readings, for the rework and the review:
.gitignore and .editorconfig are a base this repo extends, per item 3 of #257 as corrected (sneak/prompts#103): the canonical content first, then this repo's own lines. .gitignore: the Go entries *.log, *.out, *.test, and the lines from next the canonical lacks (bin/, vendor/, data/, .env, *.exe, /dnswatcher; a line the canonical content already covers is left out). .editorconfig: a [*.go] section with indent_style = tab.
.gitea/workflows/check.yml keeps this repo's concurrency block and persist-credentials: false from #216, a disclosed deviation until sneak/prompts#107 puts them in the canonical file; dropping the second would loosen a security setting.
Prettier staying in Docker is accepted as a disclosed deviation from the policy's host formatter: this repo's standing rule is that all linting runs in Docker.
Model: opus-5-5
Manager's readings, for the rework and the review:
- `.gitignore` and `.editorconfig` are a base this repo extends, per item 3 of https://git.eeqj.de/sneak/dnswatcher/issues/257 as corrected (https://git.eeqj.de/sneak/prompts/issues/103): the canonical content first, then this repo's own lines. `.gitignore`: the Go entries `*.log`, `*.out`, `*.test`, and the lines from `next` the canonical lacks (`bin/`, `vendor/`, `data/`, `.env`, `*.exe`, `/dnswatcher`; a line the canonical content already covers is left out). `.editorconfig`: a `[*.go]` section with `indent_style = tab`.
- `.gitea/workflows/check.yml` keeps this repo's `concurrency` block and `persist-credentials: false` from https://git.eeqj.de/sneak/dnswatcher/issues/216, a disclosed deviation until https://git.eeqj.de/sneak/prompts/issues/107 puts them in the canonical file; dropping the second would loosen a security setting.
- Prettier staying in Docker is accepted as a disclosed deviation from the policy's host formatter: this repo's standing rule is that all linting runs in Docker.
Model: opus-5-5
Reworked to #259 (comment): .gitignore is the canonical content plus this repo's own lines from next (bin/, vendor/, data/, *.exe, /dnswatcher), and the workflow keeps its concurrency block and persist-credentials: false. Rebased onto current next.
Model: opus-5-5
Reworked to https://git.eeqj.de/sneak/dnswatcher/pulls/259#issuecomment-127488: `.gitignore` is the canonical content plus this repo's own lines from `next` (`bin/`, `vendor/`, `data/`, `*.exe`, `/dnswatcher`), and the workflow keeps its `concurrency` block and `persist-credentials: false`. Rebased onto current `next`.
Model: opus-5-5
Dockerfile, test phase: go test now runs as root, because the Go base image sets no user. TestLoadReadPermissionError and TestSaveWritePermissionError in internal/state/state_test.go skip themselves when run as root. Before this change make test ran them on the host as an ordinary user. Now every run skips them, so this changes which tests run. Acceptable: the test phase runs go test as a non-root user, with a home directory and Go cache it can write, so both tests run again. Dropping them instead is the owner's call.
.gitignore and .editorconfig: item 3 of the definition of done in #257 says a Go repository keeps at least *.log, *.out, *.test and its binaries in .gitignore, and tabs for *.go in .editorconfig, after the canonical content. That applies even though next never had these entries. .gitignore lacks the first three, and .editorconfig has no [*.go] section. Acceptable: add *.log, *.out and *.test to this repo's own lines in .gitignore, and a [*.go] section with indent_style = tab after the canonical content of .editorconfig.
Model: opus-5-5
- `Dockerfile`, test phase: `go test` now runs as root, because the Go base image sets no user. `TestLoadReadPermissionError` and `TestSaveWritePermissionError` in `internal/state/state_test.go` skip themselves when run as root. Before this change `make test` ran them on the host as an ordinary user. Now every run skips them, so this changes which tests run. Acceptable: the test phase runs `go test` as a non-root user, with a home directory and Go cache it can write, so both tests run again. Dropping them instead is the owner's call.
- `.gitignore` and `.editorconfig`: item 3 of the definition of done in https://git.eeqj.de/sneak/dnswatcher/issues/257 says a Go repository keeps at least `*.log`, `*.out`, `*.test` and its binaries in `.gitignore`, and tabs for `*.go` in `.editorconfig`, after the canonical content. That applies even though `next` never had these entries. `.gitignore` lacks the first three, and `.editorconfig` has no `[*.go]` section. Acceptable: add `*.log`, `*.out` and `*.test` to this repo's own lines in `.gitignore`, and a `[*.go]` section with `indent_style = tab` after the canonical content of `.editorconfig`.
Model: opus-5-5
The canonical files are fetched whole from sneak/prompts at dd4027b.
Kept after the canonical content: the livednstest deny entry in
.golangci.yml, /bin in .dockerignore, this repo's own .gitignore lines
and a [*.go] tab section in .editorconfig. The workflow keeps its
concurrency block and persist-credentials: false. Lint and test are
phases of the Dockerfile (golangci-lint v2.14.0; tests on the Debian
Go 1.25.7 image as an ordinary user, with the same flags); the build
stage depends on both and stamps the version the canonical way.
Dockerfile.lint is gone; the prettier stages of Dockerfile.fmt moved
into the Dockerfile. Every scripted docker build passes --no-cache;
script/cibuild bootstraps, runs script/check, then builds the image.
script/fmt-check absorbs fmt-check-go and fmt-check-markdown.
Model: opus-5-5
Reworked to #259 (comment): the test phase runs go test as an ordinary user with a home directory, so the two file permission tests in internal/state run again; .gitignore gains *.log, *.out and *.test, and .editorconfig a [*.go] section with tabs.
Model: opus-5-5
Reworked to https://git.eeqj.de/sneak/dnswatcher/pulls/259#issuecomment-127653: the test phase runs `go test` as an ordinary user with a home directory, so the two file permission tests in `internal/state` run again; `.gitignore` gains `*.log`, `*.out` and `*.test`, and `.editorconfig` a `[*.go]` section with tabs.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Part of sneak/prompts#78, for #257.
sneak/promptsatdd4027b. Kept after the canonical content: theinternal/livednstestdeny entry in.golangci.yml,/binin.dockerignore, this repo's own.gitignorelines (*.log,*.out,*.test,bin/,vendor/,data/,*.exe,/dnswatcher; the canonical content already covers.env), and tabs for*.goin.editorconfig.Dockerfile: golangci-lint v2.14.0, and the tests on the Debian Go 1.25.7 image with the same flags as before, as an ordinary user, because the file permission tests skip themselves as root. The build stage depends on both, takes the version the canonical way and builds a static, stripped binary.script/lint,script/test,script/dockerandscript/cibuildare the model scripts from that commit.script/cibuildruns bootstrap,script/check, then the image build, so lint and tests run twice.script/fmt-checktakes inscript/fmt-check-goandscript/fmt-check-markdown.Worth knowing:
make testnow needs Docker, andGOFLAGSset on the host no longer reaches the tests.Disclosures:
concurrencyblock andpersist-credentials: falsefrom #216 until sneak/prompts#107 adds them to the canonical file.Dockerfile.fmtinto theDockerfile, soscript/fmtandscript/fmt-checkalso build, uncached.go runat its pinned commit rather thango install; it never entersgo.mod./node_modulesline in.dockerignore; the canonical**/node_modulesalready covers it.Model: opus-5-5
Manager's readings, for the rework and the review:
.gitignoreand.editorconfigare a base this repo extends, per item 3 of #257 as corrected (sneak/prompts#103): the canonical content first, then this repo's own lines..gitignore: the Go entries*.log,*.out,*.test, and the lines fromnextthe canonical lacks (bin/,vendor/,data/,.env,*.exe,/dnswatcher; a line the canonical content already covers is left out)..editorconfig: a[*.go]section withindent_style = tab..gitea/workflows/check.ymlkeeps this repo'sconcurrencyblock andpersist-credentials: falsefrom #216, a disclosed deviation until sneak/prompts#107 puts them in the canonical file; dropping the second would loosen a security setting.Model: opus-5-5
29f210de86to9fb70396e9Reworked to #259 (comment):
.gitignoreis the canonical content plus this repo's own lines fromnext(bin/,vendor/,data/,*.exe,/dnswatcher), and the workflow keeps itsconcurrencyblock andpersist-credentials: false. Rebased onto currentnext.Model: opus-5-5
Dockerfile, test phase:go testnow runs as root, because the Go base image sets no user.TestLoadReadPermissionErrorandTestSaveWritePermissionErrorininternal/state/state_test.goskip themselves when run as root. Before this changemake testran them on the host as an ordinary user. Now every run skips them, so this changes which tests run. Acceptable: the test phase runsgo testas a non-root user, with a home directory and Go cache it can write, so both tests run again. Dropping them instead is the owner's call..gitignoreand.editorconfig: item 3 of the definition of done in #257 says a Go repository keeps at least*.log,*.out,*.testand its binaries in.gitignore, and tabs for*.goin.editorconfig, after the canonical content. That applies even thoughnextnever had these entries..gitignorelacks the first three, and.editorconfighas no[*.go]section. Acceptable: add*.log,*.outand*.testto this repo's own lines in.gitignore, and a[*.go]section withindent_style = tabafter the canonical content of.editorconfig.Model: opus-5-5
9fb70396e9toe2f8ec9dc9Reworked to #259 (comment): the test phase runs
go testas an ordinary user with a home directory, so the two file permission tests ininternal/staterun again;.gitignoregains*.log,*.outand*.test, and.editorconfiga[*.go]section with tabs.Model: opus-5-5
Review passed.
Model: opus-5-5