Commit Graph
4 Commits
Author SHA1 Message Date
sneak f7bae92768 Bring every copied template file to sneak/prompts next at dd4027b9 (closes #67)
check / check (push) Failing after 2s
REPO_POLICIES.md is the sneak/prompts next copy at commit
dd4027b907ef99cdc3187c215cc4d610b7a11efc. .gitignore and .dockerignore
are that commit's copies plus keyfunc's own /keyfunc entry: both now
ignore id_ecdsa_sk and id_ed25519_sk, the private key files ssh-keygen
writes for hardware-backed keys, and .dockerignore keeps out a
.git/config at any depth. The other copied files already matched that
commit. The template Dockerfile, scripts, Makefile and workflow have not
changed since keyfunc adapted them, and the new policy text asks nothing
new of keyfunc's Dockerfile: its gate phases install nothing and its
last stage already runs script/bootstrap.

Model: opus-5-5
2026-10-04 19:45:31 +00:00
clawbot 1d1c8182be Current templates: safe.directory, golangci-lint v2.14.0, fetch-depth 0, the policy's last stage (closes #50)
check / check (push) Failing after 2s
Brings keyfunc to the current sneak/prompts templates: REPO_POLICIES.md and .golangci.yml are the template copies, the lint phase runs golangci-lint v2.14.0 on the template digest (its one new finding fixed), and .dockerignore gains the template line for submodule configs. The stage that compiles keyfunc marks /src safe for git, so a context sent as a tar stream still stamps the tag or short commit. The last stage is now a development environment, as the policy asks of a non-server repo: run the tool as docker run IMAGE keyfunc .... The CI checkout fetches tags.

Deviation: .gitea/workflows/check.yml differs from the template copy by fetch-depth: 0, which REPO_POLICIES.md requires.

Model: opus-5-5
2026-10-04 08:59:08 +02:00
clawbot 90596de901 Lint and test as phases of the Dockerfile (closes #38)
check / check (push) Failing after 3s
Lint and test are now phases of the one Dockerfile, as the current repo policy requires: a lint phase on the pinned golangci-lint image and a test phase on the pinned Go image, and the build stage depends on both, so a plain docker build . fails when either fails. Dockerfile.lint is gone. REPO_POLICIES.md and script/lint, test, docker and cibuild are byte-identical to the current sneak/prompts copies, so every docker build in script/ is uncached and tagged. make test now needs Docker on the host; formatting is checked on the host only.

Judgement calls: the test phase installs gcc and musl-dev unpinned for -race; no -count=1, since a build stage holds no earlier result.

Model: opus-5-5
2026-10-04 02:59:03 +02:00
clawbot 279cba6bcf Skeleton, mnemonic input, derivation, and the ssh pub and priv commands (closes #1)
check / check (push) Successful in 5s
The module, the script entrypoints and Makefile, Docker-only linting, the mnemonic sources in the specified order with their refusals, the BIP-85 derivation, and keyfunc ssh pub and priv with the README test vectors as tests. Two review rounds; the second passed with no findings.

Model: opus-5 (implementation and review); fable-5-1 (landing)
2026-09-07 17:34:54 +02:00