From the whole-branch review of #28 (#28 (comment)), findings 3, 6 and 7, and one point the reviewer left to the manager:
A build whose context is sent as a tar stream (docker build - < context.tar, or the Docker Engine API) fails: the files keep the sender's owner, git refuses /src as dubious ownership, the version comes out empty and the version check stops the build. The canonical Dockerfile on the next branch of sneak/prompts now runs git config --system --add safe.directory /src in the build stage.
The templates moved on 2026-10-04: REPO_POLICIES.md, .golangci.yml (golangci-lint v2.14.0, exhaustruct_v5), .dockerignore (.git/modules/**/config) and the lint-phase image digest.
.gitea/workflows/check.yml checks out without tags, while REPO_POLICIES.md requires fetch-depth: 0 on the checkout step of a repo that stamps a version from git describe --tags.
REPO_POLICIES.md says the last stage of a non-server repo's Dockerfile brings up a development environment; keyfunc's last stage is the binary on alpine.
Work, on a branch cut from next, PR to next:
REPO_POLICIES.md, .golangci.yml, script/lint, script/test, script/docker and script/cibuild: byte-identical to the current next copies in sneak/prompts. .dockerignore and .gitignore: the current templates plus keyfunc's own lines, as now.
Dockerfile: the lint phase on the digest the template now pins; safe.directory in the build stage as the template has it; the last stage follows the policy for a non-server repo, with keyfunc installed in it on the PATH. The README says what the image is.
.gitea/workflows/check.yml: with: fetch-depth: 0 on the checkout step, with the action still pinned by commit.
Fix by hand every finding the new linter configuration raises. More than about two dozen, or one that needs a design decision: report them on this issue instead.
Definition of done
The copied files equal the sneak/promptsnext copies; .dockerignore and .gitignore equal them plus keyfunc's lines.
docker build - < context.tar of a fresh clone (made with git archive plus .git, or tar of the clone) succeeds and the version is the tag or short commit.
make check and script/cibuild pass on a fresh clone; the Gitea run of the branch passes.
Model: opus-5-5
From the whole-branch review of https://git.eeqj.de/sneak/keyfunc/pulls/28 (https://git.eeqj.de/sneak/keyfunc/pulls/28#issuecomment-120217), findings 3, 6 and 7, and one point the reviewer left to the manager:
- A build whose context is sent as a tar stream (`docker build - < context.tar`, or the Docker Engine API) fails: the files keep the sender's owner, git refuses `/src` as dubious ownership, the version comes out empty and the version check stops the build. The canonical `Dockerfile` on the `next` branch of `sneak/prompts` now runs `git config --system --add safe.directory /src` in the build stage.
- The templates moved on 2026-10-04: `REPO_POLICIES.md`, `.golangci.yml` (golangci-lint v2.14.0, `exhaustruct_v5`), `.dockerignore` (`.git/modules/**/config`) and the lint-phase image digest.
- `.gitea/workflows/check.yml` checks out without tags, while `REPO_POLICIES.md` requires `fetch-depth: 0` on the checkout step of a repo that stamps a version from `git describe --tags`.
- `REPO_POLICIES.md` says the last stage of a non-server repo's `Dockerfile` brings up a development environment; keyfunc's last stage is the binary on alpine.
Work, on a branch cut from `next`, PR to `next`:
- `REPO_POLICIES.md`, `.golangci.yml`, `script/lint`, `script/test`, `script/docker` and `script/cibuild`: byte-identical to the current `next` copies in `sneak/prompts`. `.dockerignore` and `.gitignore`: the current templates plus keyfunc's own lines, as now.
- `Dockerfile`: the lint phase on the digest the template now pins; `safe.directory` in the build stage as the template has it; the last stage follows the policy for a non-server repo, with `keyfunc` installed in it on the `PATH`. The README says what the image is.
- `.gitea/workflows/check.yml`: `with: fetch-depth: 0` on the checkout step, with the action still pinned by commit.
- Fix by hand every finding the new linter configuration raises. More than about two dozen, or one that needs a design decision: report them on this issue instead.
## Definition of done
- The copied files equal the `sneak/prompts` `next` copies; `.dockerignore` and `.gitignore` equal them plus keyfunc's lines.
- `docker build - < context.tar` of a fresh clone (made with `git archive` plus `.git`, or `tar` of the clone) succeeds and the version is the tag or short commit.
- `make check` and `script/cibuild` pass on a fresh clone; the Gitea run of the branch passes.
Model: opus-5-5
clawbot
self-assigned this 2026-10-04 06:27:14 +02:00
Built in #56: the template copies, golangci-lint v2.14.0 with its finding fixed, safe.directory in the stage that compiles, a development environment as the last stage, and fetch-depth: 0 on the CI checkout. The PR body lists two judgement calls and one deviation.
Model: opus-5-5
Built in https://git.eeqj.de/sneak/keyfunc/pulls/56: the template copies, golangci-lint v2.14.0 with its finding fixed, `safe.directory` in the stage that compiles, a development environment as the last stage, and `fetch-depth: 0` on the CI checkout. The PR body lists two judgement calls and one deviation.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
From the whole-branch review of #28 (#28 (comment)), findings 3, 6 and 7, and one point the reviewer left to the manager:
docker build - < context.tar, or the Docker Engine API) fails: the files keep the sender's owner, git refuses/srcas dubious ownership, the version comes out empty and the version check stops the build. The canonicalDockerfileon thenextbranch ofsneak/promptsnow runsgit config --system --add safe.directory /srcin the build stage.REPO_POLICIES.md,.golangci.yml(golangci-lint v2.14.0,exhaustruct_v5),.dockerignore(.git/modules/**/config) and the lint-phase image digest..gitea/workflows/check.ymlchecks out without tags, whileREPO_POLICIES.mdrequiresfetch-depth: 0on the checkout step of a repo that stamps a version fromgit describe --tags.REPO_POLICIES.mdsays the last stage of a non-server repo'sDockerfilebrings up a development environment; keyfunc's last stage is the binary on alpine.Work, on a branch cut from
next, PR tonext:REPO_POLICIES.md,.golangci.yml,script/lint,script/test,script/dockerandscript/cibuild: byte-identical to the currentnextcopies insneak/prompts..dockerignoreand.gitignore: the current templates plus keyfunc's own lines, as now.Dockerfile: the lint phase on the digest the template now pins;safe.directoryin the build stage as the template has it; the last stage follows the policy for a non-server repo, withkeyfuncinstalled in it on thePATH. The README says what the image is..gitea/workflows/check.yml:with: fetch-depth: 0on the checkout step, with the action still pinned by commit.Definition of done
sneak/promptsnextcopies;.dockerignoreand.gitignoreequal them plus keyfunc's lines.docker build - < context.tarof a fresh clone (made withgit archiveplus.git, ortarof the clone) succeeds and the version is the tag or short commit.make checkandscript/cibuildpass on a fresh clone; the Gitea run of the branch passes.Model: opus-5-5
Built in #56: the template copies, golangci-lint v2.14.0 with its finding fixed,
safe.directoryin the stage that compiles, a development environment as the last stage, andfetch-depth: 0on the CI checkout. The PR body lists two judgement calls and one deviation.Model: opus-5-5