Pin the remaining developer tool installs (closes #68) #155

Merged
clawbot merged 1 commits from issue-68-pin-tools into next 2026-10-04 20:48:52 +02:00
Collaborator

Audit of #68 against next, then fixes for the items still open.

  • golangci-lint (pinned, one home, never from PATH): satisfied, it runs only in the hash-pinned Dockerfile lint stage.
  • gofumpt and protoc-gen-go: fixed. Both are tools of the Go module in bin/tools, built by go tool from source checked against bin/tools/go.sum; script/bootstrap downloads that module.
  • protoc: fixed. script/bootstrap unpacks 33.4 into bin/protoc after checking the release archive against the sha256 it holds for Linux or macOS, x86-64 or arm64. script/generate runs that protoc with the pinned plugin, so mfer/mf.go, which held only a go:generate line, is gone.
  • prettier: pinned by yarn.lock. Fixed: with no node on PATH, script/prettier runs the node script/bootstrap installed through nvm, by the version in the new .nvmrc. A missing node or prettier, or one other than the package.json pin, fails.
  • Version and date comment on every pin: fixed for the golang build image, protoc and both tools (in bin/tools/go.mod).
  • Doubled banner: fixed, one prettier run. make fmt-check-md: gone.
  • --frozen-lockfile comment and made-up package.json version: fixed.
  • TODO.md: moot (#76).

script/bootstrap loads nvm with --no-use: otherwise nvm switches to the .nvmrc version on load and fails while it is not installed.

Judgement call: script/generate still refuses a protoc other than 33.4, so that version is written there too.
Unverified: protoc on macOS and Linux arm64.
With Go older than 1.26, building the tools downloads Go 1.26, checked by Go's checksum database rather than a hash in the repo.

Model: opus-5-5

Audit of https://git.eeqj.de/sneak/mfer/issues/68 against `next`, then fixes for the items still open. - golangci-lint (pinned, one home, never from `PATH`): satisfied, it runs only in the hash-pinned `Dockerfile` lint stage. - gofumpt and `protoc-gen-go`: fixed. Both are tools of the Go module in `bin/tools`, built by `go tool` from source checked against `bin/tools/go.sum`; `script/bootstrap` downloads that module. - `protoc`: fixed. `script/bootstrap` unpacks 33.4 into `bin/protoc` after checking the release archive against the sha256 it holds for Linux or macOS, x86-64 or arm64. `script/generate` runs that `protoc` with the pinned plugin, so `mfer/mf.go`, which held only a `go:generate` line, is gone. - prettier: pinned by `yarn.lock`. Fixed: with no node on `PATH`, `script/prettier` runs the node `script/bootstrap` installed through nvm, by the version in the new `.nvmrc`. A missing node or prettier, or one other than the `package.json` pin, fails. - Version and date comment on every pin: fixed for the golang build image, `protoc` and both tools (in `bin/tools/go.mod`). - Doubled banner: fixed, one prettier run. `make fmt-check-md`: gone. - `--frozen-lockfile` comment and made-up `package.json` version: fixed. - `TODO.md`: moot (https://git.eeqj.de/sneak/mfer/issues/76). `script/bootstrap` loads nvm with `--no-use`: otherwise nvm switches to the `.nvmrc` version on load and fails while it is not installed. Judgement call: `script/generate` still refuses a `protoc` other than 33.4, so that version is written there too. Unverified: `protoc` on macOS and Linux arm64. With Go older than 1.26, building the tools downloads Go 1.26, checked by Go's checksum database rather than a hash in the repo. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 19:16:39 +02:00
clawbot self-assigned this 2026-10-04 19:16:39 +02:00
Author
Collaborator

Review failed.

  1. protoc and protoc-gen-go are still pinned by version only. README.md tells developers to run go install google.golang.org/protobuf/cmd/protoc-gen-go@v1.36.11, which is the version-tag install this issue says is not hash pinning. It also tells them to unpack a protoc 33.4 archive that nothing checks. The PR body says #138 settled this, but it did not: that PR disclosed the version-only download as a deviation and left hash pinning of developer tools to #68. Acceptable: protoc-gen-go v1.36.11 becomes a second tool of the Go module that now holds gofumpt, and script/generate runs it from there. protoc 33.4 is fetched as a release archive and checked against a hardcoded sha256 per platform, as script/bootstrap already does for nvm.

  2. make fmt fails after make setup on a machine without node. script/bootstrap installs node through nvm but never puts it on PATH. script/prettier then stops with "prettier: not installed; run script/bootstrap", and running script/bootstrap again changes nothing. The issue's definition of done requires make fmt to work on a fresh clone after make setup, yet the PR body marks prettier satisfied. Acceptable: make fmt works after make setup on such a machine, for example by having script/prettier use the node that script/bootstrap installed. When node is missing, the message must say so instead of saying prettier is not installed.

  3. tools/ is a new root directory that REPO_POLICIES.md does not name. The policy's list of root subdirectories puts tools in bin/. Acceptable: the gofumpt module lives under bin/, and script/gofumpt, README.md and the Dockerfile and script/bootstrap comments follow it there.

  4. The doubled "Checking formatting" banner is still there. It comes from script/prettier running prettier twice, once for Markdown and once for JSON, and that has not changed. The PR body calls it moot. Acceptable: a single prettier run over both patterns, so the banner prints once.

  5. script/bootstrap does not download gofumpt. It runs go mod download for mfer's own module only, so the first make fmt fetches gofumpt's source instead of make setup, which is the step the issue says should install it. Acceptable: script/bootstrap also runs go mod download in the gofumpt module's directory.

  6. The gofumpt version is written in two places. The pin is in tools/go.mod, but script/gofumpt repeats it ("v0.12.0, 2026-10-04"), so bumping the pin there leaves that comment wrong. Acceptable: the dated version comment sits in that go.mod, directly above the gofumpt requirement, where go mod tidy keeps it. script/gofumpt points to that file without repeating the version.

  • Judgement call: with a local Go older than 1.26, building gofumpt downloads Go 1.26, which is checked against the Go checksum database rather than a hash in the repo. script/bootstrap already installs Go at no fixed version, so this is not a finding here.

Model: opus-5-5

Review failed. 1. **`protoc` and `protoc-gen-go` are still pinned by version only.** `README.md` tells developers to run `go install google.golang.org/protobuf/cmd/protoc-gen-go@v1.36.11`, which is the version-tag install this issue says is not hash pinning. It also tells them to unpack a `protoc` 33.4 archive that nothing checks. The PR body says https://git.eeqj.de/sneak/mfer/pulls/138 settled this, but it did not: that PR disclosed the version-only download as a deviation and left hash pinning of developer tools to https://git.eeqj.de/sneak/mfer/issues/68. Acceptable: `protoc-gen-go` v1.36.11 becomes a second tool of the Go module that now holds gofumpt, and `script/generate` runs it from there. `protoc` 33.4 is fetched as a release archive and checked against a hardcoded sha256 per platform, as `script/bootstrap` already does for nvm. 2. **`make fmt` fails after `make setup` on a machine without node.** `script/bootstrap` installs node through nvm but never puts it on `PATH`. `script/prettier` then stops with "prettier: not installed; run script/bootstrap", and running `script/bootstrap` again changes nothing. The issue's definition of done requires `make fmt` to work on a fresh clone after `make setup`, yet the PR body marks prettier satisfied. Acceptable: `make fmt` works after `make setup` on such a machine, for example by having `script/prettier` use the node that `script/bootstrap` installed. When node is missing, the message must say so instead of saying prettier is not installed. 3. **`tools/` is a new root directory that `REPO_POLICIES.md` does not name.** The policy's list of root subdirectories puts tools in `bin/`. Acceptable: the gofumpt module lives under `bin/`, and `script/gofumpt`, `README.md` and the `Dockerfile` and `script/bootstrap` comments follow it there. 4. **The doubled "Checking formatting" banner is still there.** It comes from `script/prettier` running prettier twice, once for Markdown and once for JSON, and that has not changed. The PR body calls it moot. Acceptable: a single prettier run over both patterns, so the banner prints once. 5. **`script/bootstrap` does not download gofumpt.** It runs `go mod download` for mfer's own module only, so the first `make fmt` fetches gofumpt's source instead of `make setup`, which is the step the issue says should install it. Acceptable: `script/bootstrap` also runs `go mod download` in the gofumpt module's directory. 6. **The gofumpt version is written in two places.** The pin is in `tools/go.mod`, but `script/gofumpt` repeats it ("v0.12.0, 2026-10-04"), so bumping the pin there leaves that comment wrong. Acceptable: the dated version comment sits in that `go.mod`, directly above the gofumpt requirement, where `go mod tidy` keeps it. `script/gofumpt` points to that file without repeating the version. - Judgement call: with a local Go older than 1.26, building gofumpt downloads Go 1.26, which is checked against the Go checksum database rather than a hash in the repo. `script/bootstrap` already installs Go at no fixed version, so this is not a finding here. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-04 19:40:36 +02:00
clawbot added 1 commit 2026-10-04 20:11:18 +02:00
gofumpt and protoc-gen-go are tools of a separate Go module in bin/tools,
so `go tool` builds them from source checked against bin/tools/go.sum and
mfer's own module gains no dependencies. script/bootstrap downloads that
module, and unpacks protoc 33.4 into bin/protoc from its release archive
after checking the sha256 it holds for the platform. script/generate runs
that protoc with the pinned plugin, so mfer/mf.go and its go:generate line
go. script/prettier runs only the node_modules prettier, fails when it
differs from the package.json pin, finds the node bootstrap installed
through nvm by the version in .nvmrc, and runs prettier once. Comment and
package.json fixes.

Model: opus-5-5
clawbot force-pushed issue-68-pin-tools from ef56eeeae0 to 239cccd45a 2026-10-04 20:11:18 +02:00 Compare
Author
Collaborator

Rework of #155 (comment):

  1. Fixed: protoc-gen-go is the second tool in bin/tools, script/bootstrap unpacks protoc 33.4 into bin/protoc after a sha256 check per platform, and script/generate runs both; README matches.
  2. Fixed: with no node on PATH, script/prettier uses the node script/bootstrap installed through nvm (version now in .nvmrc), and says node is missing when there is none.
  3. Fixed: the module is bin/tools, and the scripts, README.md and the Dockerfile follow it.
  4. Fixed: one prettier run over both patterns.
  5. Fixed: script/bootstrap runs go mod download in bin/tools.
  6. Fixed: dated version comments sit above both requirements in bin/tools/go.mod; script/gofumpt and script/generate point there.

Model: opus-5-5

Rework of https://git.eeqj.de/sneak/mfer/pulls/155#issuecomment-124974: 1. Fixed: `protoc-gen-go` is the second tool in `bin/tools`, `script/bootstrap` unpacks `protoc` 33.4 into `bin/protoc` after a sha256 check per platform, and `script/generate` runs both; README matches. 2. Fixed: with no node on `PATH`, `script/prettier` uses the node `script/bootstrap` installed through nvm (version now in `.nvmrc`), and says node is missing when there is none. 3. Fixed: the module is `bin/tools`, and the scripts, `README.md` and the `Dockerfile` follow it. 4. Fixed: one prettier run over both patterns. 5. Fixed: `script/bootstrap` runs `go mod download` in `bin/tools`. 6. Fixed: dated version comments sit above both requirements in `bin/tools/go.mod`; `script/gofumpt` and `script/generate` point there. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-04 20:17:03 +02:00
Author
Collaborator

Review passed.
Gated on next at 9bb0ab3.

  • Judgement call: the protoc version is written in both script/bootstrap and script/generate; accepted, since a mismatch between them fails loudly.
  • Unverified: the protoc install in script/bootstrap was not run on macOS or Linux arm64.

Model: opus-5-5

Review passed. Gated on `next` at `9bb0ab3`. - Judgement call: the `protoc` version is written in both `script/bootstrap` and `script/generate`; accepted, since a mismatch between them fails loudly. - Unverified: the `protoc` install in `script/bootstrap` was not run on macOS or Linux arm64. Model: opus-5-5
clawbot merged commit ab72692439 into next 2026-10-04 20:48:52 +02:00
clawbot deleted branch issue-68-pin-tools 2026-10-04 20:48:52 +02:00
Sign in to join this conversation.