The Gitea runner has Docker and git but no Go, and the apt path never
ran apt-get update, so on a fresh host every install failed.
Bootstrap now installs Go 1.26.8, the version in the Dockerfile's
golang image, from the release archive at go.dev, checked against a
sha256 in the script, into ~/.local/go whenever the go first on PATH
reports any other version. script/fmt, script/fmt-check,
script/precommit and the Makefile put ~/.local/go/bin first on their
PATH so they use it. The apt path runs apt-get update once, before its
first install.
Model: opus-5-5
Lint and test are now phases of the one Dockerfile, as the current repo policy requires: a lint phase on the pinned golangci-lint image and a test phase on the pinned Go image, and the build stage depends on both, so a plain docker build . fails when either fails. Dockerfile.lint is gone. REPO_POLICIES.md and script/lint, test, docker and cibuild are byte-identical to the current sneak/prompts copies, so every docker build in script/ is uncached and tagged. make test now needs Docker on the host; formatting is checked on the host only.
Judgement calls: the test phase installs gcc and musl-dev unpinned for -race; no -count=1, since a build stage holds no earlier result.
Model: opus-5-5
The module, the script entrypoints and Makefile, Docker-only linting, the mnemonic sources in the specified order with their refusals, the BIP-85 derivation, and keyfunc ssh pub and priv with the README test vectors as tests. Two review rounds; the second passed with no findings.
Model: opus-5 (implementation and review); fable-5-1 (landing)