All checks were successful
check / check (push) Successful in 37s
script/fmt ran prettier with default settings over root-level *.md and *.json, swallowing every failure with `|| true`, while script/fmt-check checked gofmt only. The formatter and the gate therefore disagreed silently: `make fmt` rewrote markdown that `make check` never looked at, including REPO_POLICIES.md, which is a verbatim copy of an authoritative upstream document that local tooling must not touch. Configuration: - .prettierrc pins the two policy deviations from prettier defaults, four-space indents and proseWrap: always. Nothing else. - .prettierignore excludes REPO_POLICIES.md so no local run can drift it from upstream again, plus .golangci.yml (user-owned, and listed even though the current file set does not reach it) and node_modules, vendor, bin. One canonical file set: - New script/prettier takes --write or --check and applies the same patterns in both modes, so script/fmt and script/fmt-check cannot drift apart by construction. The patterns are repo-wide (**/*.md, **/*.json) rather than root-only, so markdown in subdirectories such as a future docs/ is covered. - No `|| true` anywhere, and no --no-error-on-unmatched-pattern: both patterns always match tracked files, so an empty match means the glob broke and prettier should say so instead of passing vacuously. A missing prettier is a hard error naming script/bootstrap, not a silent skip. Pinned prettier: - package.json/yarn.lock pin prettier 3.9.6; the lockfile carries the integrity hash, and --frozen-lockfile enforces it. script/prettier prefers node_modules/.bin/prettier and warns on stderr when it has to fall back to a PATH prettier of unknown version. - script/bootstrap now installs node, yarn, and the locked JS deps. Its NODE_VERSION and YARN_VERSION pins already existed. Docker gate: - The golangci-lint image has no node, so the lint stage runs the new script/fmt-check-go (the Go half of fmt-check, extracted) instead of the whole thing. - The markdown half gets its own stage on a digest-pinned node image shipping exactly the node and yarn versions bootstrap pins. The builder stage takes a COPY --from dependency on it, so BuildKit cannot skip it and a markdown violation fails `docker build .` rather than being skipped somewhere nobody looks. Markdown files other than REPO_POLICIES.md are reformatted here for the first time under the policy settings.
5.1 KiB
5.1 KiB
Workflow
- branch (from
main) - do the work in Next Step
- move Next Step to the top of Completed Steps
- move the top item of Future Steps into Next Step
- commit (
TODO.mdchanges in the same commit as the work) - merge to
mainif the branch is not protected, otherwise open a PR - push
Status
pre-1.0. No git tags. README section "TODO: Remaining Work for 1.0" lists open design questions and implementation tasks; policy compliance work is in flight and unmerged.
Next Step
Land the in-flight compliance branch chore/align-repo-policies: finish and
commit the uncommitted work (32 modified Go files, new untracked .golangci.yml
and TODO.md), confirm make check is green, merge the branch (one commit ahead
of main as of 2026-07-03) to main, and push.
Completed Steps
- 2026-08-09: added
.prettierrc/.prettierignore, gavescript/fmtandscript/fmt-checkone shared prettier file set viascript/prettier, dropped the|| truethat hid prettier failures, and added a node-based Dockerfile stage so a markdown formatting violation failsdocker build .(#69) - 2026-07-07 Adopted scripts-to-rule-them-all:
script/entrypoints, Makefile shims, README Entrypoints section - 2026-07-03: aligned repo tooling, docs, and config with standardized policies (7d9a138, on chore/align-repo-policies, unmerged)
- 2026-06-28: moved to standardized repo policies (#56, on main)
- 2026-04-07: added 1.0 roadmap as README TODO section, removed old TODO.md (#54)
- 2026-03-20: added Gitea Actions CI workflow (#53)
- 2026-03-17: added REPO_POLICIES.md, renamed CLAUDE.md to AGENTS.md (#51); removed committed .index.mf (#52)
- 2026-03-15: split Dockerfile with pre-built golangci-lint stage for faster CI (#45)
- 2026-03-01: 1.0 quality polish: code review, tests, bug fixes, docs (#32)
- 2026-02-20: deterministic file ordering in Builder.Build() (#28); removed committed vendor/modcache archives (#35)
- 2026-02-08: added --seed flag for deterministic manifest UUID
Future Steps
- Compliance (fold of TODO.md audit 2026-07-02; verify which items the in-flight
branch already closes, then check off):
- Add .editorconfig (canonical copy from sneak/prompts)
- Add standardized .golangci.yml (present untracked on the branch; user-owned, copy verbatim)
- Make .gitignore cover secrets (.env, _.key, .pem), OS files (.DS_Store), and editor files (.swp, _~)
- Make fmt-check/lint verify with gofumpt, not gofmt -l, so
make checkmatches whatmake fmtwrites - Add README "Getting Started" section with copy-pasteable install/usage block
- Move FORMAT.md from repo root to docs/ and update the AGENTS.md reference
- Pin Makefile-installed Go tools (protoc-gen-go@v1.28.1, golangci-lint@v2.0.2) by module hash, not mutable tag
- Set
make testtimeout to 30s (currently 10s) - Add explicit README "Rationale" heading (content exists under other names); name the author in the README Description first line
- Reconcile root-level AGENTS.md with directory-hygiene policy (keep or relocate)
- Add a
make buildtarget - Rewrite
make hooksto use printf or a heredoc instead of non-portableecho '...\n...'
- Answer the 14 owner design questions in the README 1.0 roadmap:
- Format: simplify MFFileChecksum; store file mode; drop atime; specify path normalization rules; version byte after magic; length-prefix after magic
- Signatures: hash covers compressed or uncompressed data; sign raw bytes vs hex canonical string; detached .mf.sig support; GPG subprocess vs pure-Go crypto
- Implementation: deterministic manifests by default; consolidate duplicate scanner/checker implementations; export the manifest type; canonical Go module path for 1.0
- Format and correctness:
- Resolve proto go_package vs go.mod module path inconsistency
- Specify and validate path invariants (UTF-8, forward-slash, relative, no .., no leading /)
- Remove or deprecate atime; reserve mode field; add version byte (all pending design answers)
- Write a standalone format specification document
- Library:
- Delete internal/scanner and internal/checker; consolidate on the mfer/ package versions (pending design answer)
- Add decompression size limit via io.LimitReader in deserializeInner()
- Fix errors.Is dead code in checker; make AddFile verify totalRead == size
- Export manifest type or define a public interface (pending)
- Replace GPG subprocess with pure-Go crypto (pending); add timeouts to remaining subprocess calls
- CLI:
- Kebab-case primary flag names; fix fetch URL construction with url.JoinPath; add http.Client timeout and retry with backoff to fetch; rate-limit Checker progress output; add --deterministic flag or default; wire top-level --version properly
- Testing:
- Fuzz NewManifestFromReader; end-to-end tests for freshen and fetch
- Documentation:
- Promote docs/FORMAT.md as primary spec reference; audit error messages; document the signature scheme fully
- Release:
- Finalize module path, bump version constant, SemVer --version output, tag v1.0.0