Current templates: safe.directory, golangci-lint v2.14.0, fetch-depth 0, the policy's last stage #50

Closed
opened 2026-10-04 06:27:14 +02:00 by clawbot · 1 comment
Collaborator

From the whole-branch review of #28 (#28 (comment)), findings 3, 6 and 7, and one point the reviewer left to the manager:

  • A build whose context is sent as a tar stream (docker build - < context.tar, or the Docker Engine API) fails: the files keep the sender's owner, git refuses /src as dubious ownership, the version comes out empty and the version check stops the build. The canonical Dockerfile on the next branch of sneak/prompts now runs git config --system --add safe.directory /src in the build stage.
  • The templates moved on 2026-10-04: REPO_POLICIES.md, .golangci.yml (golangci-lint v2.14.0, exhaustruct_v5), .dockerignore (.git/modules/**/config) and the lint-phase image digest.
  • .gitea/workflows/check.yml checks out without tags, while REPO_POLICIES.md requires fetch-depth: 0 on the checkout step of a repo that stamps a version from git describe --tags.
  • REPO_POLICIES.md says the last stage of a non-server repo's Dockerfile brings up a development environment; keyfunc's last stage is the binary on alpine.

Work, on a branch cut from next, PR to next:

  • REPO_POLICIES.md, .golangci.yml, script/lint, script/test, script/docker and script/cibuild: byte-identical to the current next copies in sneak/prompts. .dockerignore and .gitignore: the current templates plus keyfunc's own lines, as now.
  • Dockerfile: the lint phase on the digest the template now pins; safe.directory in the build stage as the template has it; the last stage follows the policy for a non-server repo, with keyfunc installed in it on the PATH. The README says what the image is.
  • .gitea/workflows/check.yml: with: fetch-depth: 0 on the checkout step, with the action still pinned by commit.
  • Fix by hand every finding the new linter configuration raises. More than about two dozen, or one that needs a design decision: report them on this issue instead.

Definition of done

  • The copied files equal the sneak/prompts next copies; .dockerignore and .gitignore equal them plus keyfunc's lines.
  • docker build - < context.tar of a fresh clone (made with git archive plus .git, or tar of the clone) succeeds and the version is the tag or short commit.
  • make check and script/cibuild pass on a fresh clone; the Gitea run of the branch passes.

Model: opus-5-5

From the whole-branch review of https://git.eeqj.de/sneak/keyfunc/pulls/28 (https://git.eeqj.de/sneak/keyfunc/pulls/28#issuecomment-120217), findings 3, 6 and 7, and one point the reviewer left to the manager: - A build whose context is sent as a tar stream (`docker build - < context.tar`, or the Docker Engine API) fails: the files keep the sender's owner, git refuses `/src` as dubious ownership, the version comes out empty and the version check stops the build. The canonical `Dockerfile` on the `next` branch of `sneak/prompts` now runs `git config --system --add safe.directory /src` in the build stage. - The templates moved on 2026-10-04: `REPO_POLICIES.md`, `.golangci.yml` (golangci-lint v2.14.0, `exhaustruct_v5`), `.dockerignore` (`.git/modules/**/config`) and the lint-phase image digest. - `.gitea/workflows/check.yml` checks out without tags, while `REPO_POLICIES.md` requires `fetch-depth: 0` on the checkout step of a repo that stamps a version from `git describe --tags`. - `REPO_POLICIES.md` says the last stage of a non-server repo's `Dockerfile` brings up a development environment; keyfunc's last stage is the binary on alpine. Work, on a branch cut from `next`, PR to `next`: - `REPO_POLICIES.md`, `.golangci.yml`, `script/lint`, `script/test`, `script/docker` and `script/cibuild`: byte-identical to the current `next` copies in `sneak/prompts`. `.dockerignore` and `.gitignore`: the current templates plus keyfunc's own lines, as now. - `Dockerfile`: the lint phase on the digest the template now pins; `safe.directory` in the build stage as the template has it; the last stage follows the policy for a non-server repo, with `keyfunc` installed in it on the `PATH`. The README says what the image is. - `.gitea/workflows/check.yml`: `with: fetch-depth: 0` on the checkout step, with the action still pinned by commit. - Fix by hand every finding the new linter configuration raises. More than about two dozen, or one that needs a design decision: report them on this issue instead. ## Definition of done - The copied files equal the `sneak/prompts` `next` copies; `.dockerignore` and `.gitignore` equal them plus keyfunc's lines. - `docker build - < context.tar` of a fresh clone (made with `git archive` plus `.git`, or `tar` of the clone) succeeds and the version is the tag or short commit. - `make check` and `script/cibuild` pass on a fresh clone; the Gitea run of the branch passes. Model: opus-5-5
clawbot self-assigned this 2026-10-04 06:27:14 +02:00
Author
Collaborator

Built in #56: the template copies, golangci-lint v2.14.0 with its finding fixed, safe.directory in the stage that compiles, a development environment as the last stage, and fetch-depth: 0 on the CI checkout. The PR body lists two judgement calls and one deviation.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/keyfunc/pulls/56: the template copies, golangci-lint v2.14.0 with its finding fixed, `safe.directory` in the stage that compiles, a development environment as the last stage, and `fetch-depth: 0` on the CI checkout. The PR body lists two judgement calls and one deviation. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/keyfunc#50