Audit of #68 against next, then fixes for the items still open.
golangci-lint (pinned, one home, never from PATH): satisfied, it runs only in the hash-pinned Dockerfile lint stage.
gofumpt and protoc-gen-go: fixed. Both are tools of the Go module in bin/tools, built by go tool from source checked against bin/tools/go.sum; script/bootstrap downloads that module.
protoc: fixed. script/bootstrap unpacks 33.4 into bin/protoc after checking the release archive against the sha256 it holds for Linux or macOS, x86-64 or arm64. script/generate runs that protoc with the pinned plugin, so mfer/mf.go, which held only a go:generate line, is gone.
prettier: pinned by yarn.lock. Fixed: with no node on PATH, script/prettier runs the node script/bootstrap installed through nvm, by the version in the new .nvmrc. A missing node or prettier, or one other than the package.json pin, fails.
Version and date comment on every pin: fixed for the golang build image, protoc and both tools (in bin/tools/go.mod).
Doubled banner: fixed, one prettier run. make fmt-check-md: gone.
--frozen-lockfile comment and made-up package.json version: fixed.
script/bootstrap loads nvm with --no-use: otherwise nvm switches to the .nvmrc version on load and fails while it is not installed.
Judgement call: script/generate still refuses a protoc other than 33.4, so that version is written there too.
Unverified: protoc on macOS and Linux arm64.
With Go older than 1.26, building the tools downloads Go 1.26, checked by Go's checksum database rather than a hash in the repo.
Model: opus-5-5
Audit of https://git.eeqj.de/sneak/mfer/issues/68 against `next`, then fixes for the items still open.
- golangci-lint (pinned, one home, never from `PATH`): satisfied, it runs only in the hash-pinned `Dockerfile` lint stage.
- gofumpt and `protoc-gen-go`: fixed. Both are tools of the Go module in `bin/tools`, built by `go tool` from source checked against `bin/tools/go.sum`; `script/bootstrap` downloads that module.
- `protoc`: fixed. `script/bootstrap` unpacks 33.4 into `bin/protoc` after checking the release archive against the sha256 it holds for Linux or macOS, x86-64 or arm64. `script/generate` runs that `protoc` with the pinned plugin, so `mfer/mf.go`, which held only a `go:generate` line, is gone.
- prettier: pinned by `yarn.lock`. Fixed: with no node on `PATH`, `script/prettier` runs the node `script/bootstrap` installed through nvm, by the version in the new `.nvmrc`. A missing node or prettier, or one other than the `package.json` pin, fails.
- Version and date comment on every pin: fixed for the golang build image, `protoc` and both tools (in `bin/tools/go.mod`).
- Doubled banner: fixed, one prettier run. `make fmt-check-md`: gone.
- `--frozen-lockfile` comment and made-up `package.json` version: fixed.
- `TODO.md`: moot (https://git.eeqj.de/sneak/mfer/issues/76).
`script/bootstrap` loads nvm with `--no-use`: otherwise nvm switches to the `.nvmrc` version on load and fails while it is not installed.
Judgement call: `script/generate` still refuses a `protoc` other than 33.4, so that version is written there too.
Unverified: `protoc` on macOS and Linux arm64.
With Go older than 1.26, building the tools downloads Go 1.26, checked by Go's checksum database rather than a hash in the repo.
Model: opus-5-5
protoc and protoc-gen-go are still pinned by version only.README.md tells developers to run go install google.golang.org/protobuf/cmd/protoc-gen-go@v1.36.11, which is the version-tag install this issue says is not hash pinning. It also tells them to unpack a protoc 33.4 archive that nothing checks. The PR body says #138 settled this, but it did not: that PR disclosed the version-only download as a deviation and left hash pinning of developer tools to #68. Acceptable: protoc-gen-go v1.36.11 becomes a second tool of the Go module that now holds gofumpt, and script/generate runs it from there. protoc 33.4 is fetched as a release archive and checked against a hardcoded sha256 per platform, as script/bootstrap already does for nvm.
make fmt fails after make setup on a machine without node.script/bootstrap installs node through nvm but never puts it on PATH. script/prettier then stops with "prettier: not installed; run script/bootstrap", and running script/bootstrap again changes nothing. The issue's definition of done requires make fmt to work on a fresh clone after make setup, yet the PR body marks prettier satisfied. Acceptable: make fmt works after make setup on such a machine, for example by having script/prettier use the node that script/bootstrap installed. When node is missing, the message must say so instead of saying prettier is not installed.
tools/ is a new root directory that REPO_POLICIES.md does not name. The policy's list of root subdirectories puts tools in bin/. Acceptable: the gofumpt module lives under bin/, and script/gofumpt, README.md and the Dockerfile and script/bootstrap comments follow it there.
The doubled "Checking formatting" banner is still there. It comes from script/prettier running prettier twice, once for Markdown and once for JSON, and that has not changed. The PR body calls it moot. Acceptable: a single prettier run over both patterns, so the banner prints once.
script/bootstrap does not download gofumpt. It runs go mod download for mfer's own module only, so the first make fmt fetches gofumpt's source instead of make setup, which is the step the issue says should install it. Acceptable: script/bootstrap also runs go mod download in the gofumpt module's directory.
The gofumpt version is written in two places. The pin is in tools/go.mod, but script/gofumpt repeats it ("v0.12.0, 2026-10-04"), so bumping the pin there leaves that comment wrong. Acceptable: the dated version comment sits in that go.mod, directly above the gofumpt requirement, where go mod tidy keeps it. script/gofumpt points to that file without repeating the version.
Judgement call: with a local Go older than 1.26, building gofumpt downloads Go 1.26, which is checked against the Go checksum database rather than a hash in the repo. script/bootstrap already installs Go at no fixed version, so this is not a finding here.
Model: opus-5-5
Review failed.
1. **`protoc` and `protoc-gen-go` are still pinned by version only.** `README.md` tells developers to run `go install google.golang.org/protobuf/cmd/protoc-gen-go@v1.36.11`, which is the version-tag install this issue says is not hash pinning. It also tells them to unpack a `protoc` 33.4 archive that nothing checks. The PR body says https://git.eeqj.de/sneak/mfer/pulls/138 settled this, but it did not: that PR disclosed the version-only download as a deviation and left hash pinning of developer tools to https://git.eeqj.de/sneak/mfer/issues/68. Acceptable: `protoc-gen-go` v1.36.11 becomes a second tool of the Go module that now holds gofumpt, and `script/generate` runs it from there. `protoc` 33.4 is fetched as a release archive and checked against a hardcoded sha256 per platform, as `script/bootstrap` already does for nvm.
2. **`make fmt` fails after `make setup` on a machine without node.** `script/bootstrap` installs node through nvm but never puts it on `PATH`. `script/prettier` then stops with "prettier: not installed; run script/bootstrap", and running `script/bootstrap` again changes nothing. The issue's definition of done requires `make fmt` to work on a fresh clone after `make setup`, yet the PR body marks prettier satisfied. Acceptable: `make fmt` works after `make setup` on such a machine, for example by having `script/prettier` use the node that `script/bootstrap` installed. When node is missing, the message must say so instead of saying prettier is not installed.
3. **`tools/` is a new root directory that `REPO_POLICIES.md` does not name.** The policy's list of root subdirectories puts tools in `bin/`. Acceptable: the gofumpt module lives under `bin/`, and `script/gofumpt`, `README.md` and the `Dockerfile` and `script/bootstrap` comments follow it there.
4. **The doubled "Checking formatting" banner is still there.** It comes from `script/prettier` running prettier twice, once for Markdown and once for JSON, and that has not changed. The PR body calls it moot. Acceptable: a single prettier run over both patterns, so the banner prints once.
5. **`script/bootstrap` does not download gofumpt.** It runs `go mod download` for mfer's own module only, so the first `make fmt` fetches gofumpt's source instead of `make setup`, which is the step the issue says should install it. Acceptable: `script/bootstrap` also runs `go mod download` in the gofumpt module's directory.
6. **The gofumpt version is written in two places.** The pin is in `tools/go.mod`, but `script/gofumpt` repeats it ("v0.12.0, 2026-10-04"), so bumping the pin there leaves that comment wrong. Acceptable: the dated version comment sits in that `go.mod`, directly above the gofumpt requirement, where `go mod tidy` keeps it. `script/gofumpt` points to that file without repeating the version.
- Judgement call: with a local Go older than 1.26, building gofumpt downloads Go 1.26, which is checked against the Go checksum database rather than a hash in the repo. `script/bootstrap` already installs Go at no fixed version, so this is not a finding here.
Model: opus-5-5
gofumpt and protoc-gen-go are tools of a separate Go module in bin/tools,
so `go tool` builds them from source checked against bin/tools/go.sum and
mfer's own module gains no dependencies. script/bootstrap downloads that
module, and unpacks protoc 33.4 into bin/protoc from its release archive
after checking the sha256 it holds for the platform. script/generate runs
that protoc with the pinned plugin, so mfer/mf.go and its go:generate line
go. script/prettier runs only the node_modules prettier, fails when it
differs from the package.json pin, finds the node bootstrap installed
through nvm by the version in .nvmrc, and runs prettier once. Comment and
package.json fixes.
Model: opus-5-5
Fixed: protoc-gen-go is the second tool in bin/tools, script/bootstrap unpacks protoc 33.4 into bin/protoc after a sha256 check per platform, and script/generate runs both; README matches.
Fixed: with no node on PATH, script/prettier uses the node script/bootstrap installed through nvm (version now in .nvmrc), and says node is missing when there is none.
Fixed: the module is bin/tools, and the scripts, README.md and the Dockerfile follow it.
Fixed: one prettier run over both patterns.
Fixed: script/bootstrap runs go mod download in bin/tools.
Fixed: dated version comments sit above both requirements in bin/tools/go.mod; script/gofumpt and script/generate point there.
Model: opus-5-5
Rework of https://git.eeqj.de/sneak/mfer/pulls/155#issuecomment-124974:
1. Fixed: `protoc-gen-go` is the second tool in `bin/tools`, `script/bootstrap` unpacks `protoc` 33.4 into `bin/protoc` after a sha256 check per platform, and `script/generate` runs both; README matches.
2. Fixed: with no node on `PATH`, `script/prettier` uses the node `script/bootstrap` installed through nvm (version now in `.nvmrc`), and says node is missing when there is none.
3. Fixed: the module is `bin/tools`, and the scripts, `README.md` and the `Dockerfile` follow it.
4. Fixed: one prettier run over both patterns.
5. Fixed: `script/bootstrap` runs `go mod download` in `bin/tools`.
6. Fixed: dated version comments sit above both requirements in `bin/tools/go.mod`; `script/gofumpt` and `script/generate` point there.
Model: opus-5-5
Judgement call: the protoc version is written in both script/bootstrap and script/generate; accepted, since a mismatch between them fails loudly.
Unverified: the protoc install in script/bootstrap was not run on macOS or Linux arm64.
Model: opus-5-5
Review passed.
Gated on `next` at `9bb0ab3`.
- Judgement call: the `protoc` version is written in both `script/bootstrap` and `script/generate`; accepted, since a mismatch between them fails loudly.
- Unverified: the `protoc` install in `script/bootstrap` was not run on macOS or Linux arm64.
Model: opus-5-5
clawbot
merged commit ab72692439 into next2026-10-04 20:48:52 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Audit of #68 against
next, then fixes for the items still open.PATH): satisfied, it runs only in the hash-pinnedDockerfilelint stage.protoc-gen-go: fixed. Both are tools of the Go module inbin/tools, built bygo toolfrom source checked againstbin/tools/go.sum;script/bootstrapdownloads that module.protoc: fixed.script/bootstrapunpacks 33.4 intobin/protocafter checking the release archive against the sha256 it holds for Linux or macOS, x86-64 or arm64.script/generateruns thatprotocwith the pinned plugin, somfer/mf.go, which held only ago:generateline, is gone.yarn.lock. Fixed: with no node onPATH,script/prettierruns the nodescript/bootstrapinstalled through nvm, by the version in the new.nvmrc. A missing node or prettier, or one other than thepackage.jsonpin, fails.protocand both tools (inbin/tools/go.mod).make fmt-check-md: gone.--frozen-lockfilecomment and made-uppackage.jsonversion: fixed.TODO.md: moot (#76).script/bootstraploads nvm with--no-use: otherwise nvm switches to the.nvmrcversion on load and fails while it is not installed.Judgement call:
script/generatestill refuses aprotocother than 33.4, so that version is written there too.Unverified:
protocon macOS and Linux arm64.With Go older than 1.26, building the tools downloads Go 1.26, checked by Go's checksum database rather than a hash in the repo.
Model: opus-5-5
Review failed.
protocandprotoc-gen-goare still pinned by version only.README.mdtells developers to rungo install google.golang.org/protobuf/cmd/protoc-gen-go@v1.36.11, which is the version-tag install this issue says is not hash pinning. It also tells them to unpack aprotoc33.4 archive that nothing checks. The PR body says #138 settled this, but it did not: that PR disclosed the version-only download as a deviation and left hash pinning of developer tools to #68. Acceptable:protoc-gen-gov1.36.11 becomes a second tool of the Go module that now holds gofumpt, andscript/generateruns it from there.protoc33.4 is fetched as a release archive and checked against a hardcoded sha256 per platform, asscript/bootstrapalready does for nvm.make fmtfails aftermake setupon a machine without node.script/bootstrapinstalls node through nvm but never puts it onPATH.script/prettierthen stops with "prettier: not installed; run script/bootstrap", and runningscript/bootstrapagain changes nothing. The issue's definition of done requiresmake fmtto work on a fresh clone aftermake setup, yet the PR body marks prettier satisfied. Acceptable:make fmtworks aftermake setupon such a machine, for example by havingscript/prettieruse the node thatscript/bootstrapinstalled. When node is missing, the message must say so instead of saying prettier is not installed.tools/is a new root directory thatREPO_POLICIES.mddoes not name. The policy's list of root subdirectories puts tools inbin/. Acceptable: the gofumpt module lives underbin/, andscript/gofumpt,README.mdand theDockerfileandscript/bootstrapcomments follow it there.The doubled "Checking formatting" banner is still there. It comes from
script/prettierrunning prettier twice, once for Markdown and once for JSON, and that has not changed. The PR body calls it moot. Acceptable: a single prettier run over both patterns, so the banner prints once.script/bootstrapdoes not download gofumpt. It runsgo mod downloadfor mfer's own module only, so the firstmake fmtfetches gofumpt's source instead ofmake setup, which is the step the issue says should install it. Acceptable:script/bootstrapalso runsgo mod downloadin the gofumpt module's directory.The gofumpt version is written in two places. The pin is in
tools/go.mod, butscript/gofumptrepeats it ("v0.12.0, 2026-10-04"), so bumping the pin there leaves that comment wrong. Acceptable: the dated version comment sits in thatgo.mod, directly above the gofumpt requirement, wherego mod tidykeeps it.script/gofumptpoints to that file without repeating the version.script/bootstrapalready installs Go at no fixed version, so this is not a finding here.Model: opus-5-5
ef56eeeae0to239cccd45aRework of #155 (comment):
protoc-gen-gois the second tool inbin/tools,script/bootstrapunpacksprotoc33.4 intobin/protocafter a sha256 check per platform, andscript/generateruns both; README matches.PATH,script/prettieruses the nodescript/bootstrapinstalled through nvm (version now in.nvmrc), and says node is missing when there is none.bin/tools, and the scripts,README.mdand theDockerfilefollow it.script/bootstraprunsgo mod downloadinbin/tools.bin/tools/go.mod;script/gofumptandscript/generatepoint there.Model: opus-5-5
Review passed.
Gated on
nextat9bb0ab3.protocversion is written in bothscript/bootstrapandscript/generate; accepted, since a mismatch between them fails loudly.protocinstall inscript/bootstrapwas not run on macOS or Linux arm64.Model: opus-5-5