Re-vendor the canonical files from sneak/prompts at dd4027b #112

Open
opened 2026-10-06 01:29:56 +02:00 by clawbot · 1 comment
Collaborator

sneak/prompts#78: sneak/prompts has changed the canonical files this repository vendors. Re-vendor them once, from sneak/prompts commit dd4027b (dd4027b907), fetching each file from https://git.eeqj.de/sneak/prompts/raw/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc/<path>.

Files this repository vendors now: .dockerignore .editorconfig .gitea/workflows/check.yml .gitignore .golangci.yml REPO_POLICIES.md. REPO_POLICIES.md comes from prompts/REPO_POLICIES.md at that commit: the root REPO_POLICIES.md there is a symlink, and its raw URL returns only the link's target path. That repository's own .gitattributes and TODO.md are not canonical.

What changed that matters here:

  • golangci-lint is v2.14.0 (golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f). The lint phase digest and .golangci.yml change in one commit, since v2.12.2 rejects the new file; the go directive may name at most Go 1.27.
  • The Go Dockerfile example: the test phase uses the Debian Go image so -race works; the stage that compiles installs git, trusts /src with git config --system --add safe.directory /src, and fails when .git is present but no version comes out.
  • Host Go tools are installed with go install pinned to a commit, never as go.mod tool dependencies.
  • The image version comes from git describe inside the build: .dockerignore sends .git without its own or any submodule's config. CHECK_EPOCH is gone; every docker build in script/ passes --no-cache.
  • .gitignore and .dockerignore keep out more secret files, hardware-backed SSH keys included.
  • Agent guidance lives in one root AGENTS.md; a committed file or directory named for one agent tool has its content moved there and is deleted.

Definition of done

  1. Every vendored canonical file is its copy at that commit, fetched rather than hand-edited, plus only the entries item 3 keeps. A canonical file the policies require and this repository lacks is added the same way.
  2. Dockerfile, Makefile and script/ follow REPO_POLICIES.md as of that commit, including the gate phases and the version step.
  3. This repository's own entries are carried forward: the deny entries of the test-support depguard rule in .golangci.yml, anchored host-built artifacts in .dockerignore, and its language's entries in .gitignore and .editorconfig, kept after the canonical content. .gitignore is a base each repository extends for its language: a Go repository keeps at least *.log, *.out, *.test and its binaries (prompts/CODE_STYLEGUIDE_GO.md), and its .editorconfig keeps tabs for *.go. (Corrected 2026-10-06: the first version of this item dropped those entries.)
  4. Findings the new files raise are fixed in the code in the same PR; no vendored file is loosened.
  5. make lint runs with no deprecation warnings, and make check passes.
  6. One reviewed PR against next. Closing this issue ticks this repository on sneak/prompts#78.

Model: opus-5-5

https://git.eeqj.de/sneak/prompts/issues/78: `sneak/prompts` has changed the canonical files this repository vendors. Re-vendor them once, from `sneak/prompts` commit `dd4027b` (https://git.eeqj.de/sneak/prompts/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc), fetching each file from `https://git.eeqj.de/sneak/prompts/raw/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc/<path>`. Files this repository vendors now: `.dockerignore .editorconfig .gitea/workflows/check.yml .gitignore .golangci.yml REPO_POLICIES.md`. `REPO_POLICIES.md` comes from `prompts/REPO_POLICIES.md` at that commit: the root `REPO_POLICIES.md` there is a symlink, and its raw URL returns only the link's target path. That repository's own `.gitattributes` and `TODO.md` are not canonical. What changed that matters here: - golangci-lint is v2.14.0 (`golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f`). The lint phase digest and `.golangci.yml` change in one commit, since v2.12.2 rejects the new file; the `go` directive may name at most Go 1.27. - The Go `Dockerfile` example: the test phase uses the Debian Go image so `-race` works; the stage that compiles installs `git`, trusts `/src` with `git config --system --add safe.directory /src`, and fails when `.git` is present but no version comes out. - Host Go tools are installed with `go install` pinned to a commit, never as `go.mod` tool dependencies. - The image version comes from `git describe` inside the build: `.dockerignore` sends `.git` without its own or any submodule's `config`. `CHECK_EPOCH` is gone; every `docker build` in `script/` passes `--no-cache`. - `.gitignore` and `.dockerignore` keep out more secret files, hardware-backed SSH keys included. - Agent guidance lives in one root `AGENTS.md`; a committed file or directory named for one agent tool has its content moved there and is deleted. ## Definition of done 1. Every vendored canonical file is its copy at that commit, fetched rather than hand-edited, plus only the entries item 3 keeps. A canonical file the policies require and this repository lacks is added the same way. 2. `Dockerfile`, `Makefile` and `script/` follow `REPO_POLICIES.md` as of that commit, including the gate phases and the version step. 3. This repository's own entries are carried forward: the `deny` entries of the `test-support` depguard rule in `.golangci.yml`, anchored host-built artifacts in `.dockerignore`, and its language's entries in `.gitignore` and `.editorconfig`, kept after the canonical content. `.gitignore` is a base each repository extends for its language: a Go repository keeps at least `*.log`, `*.out`, `*.test` and its binaries (`prompts/CODE_STYLEGUIDE_GO.md`), and its `.editorconfig` keeps tabs for `*.go`. (Corrected 2026-10-06: the first version of this item dropped those entries.) 4. Findings the new files raise are fixed in the code in the same PR; no vendored file is loosened. 5. `make lint` runs with no deprecation warnings, and `make check` passes. 6. One reviewed PR against `next`. Closing this issue ticks this repository on https://git.eeqj.de/sneak/prompts/issues/78. Model: opus-5-5
clawbot self-assigned this 2026-10-06 01:29:56 +02:00
Author
Collaborator

Plan, for one worker, one PR against next. Dispatched once #101 has landed, since both change the Makefile test target.

What this repository needs beyond the issue text:

  1. Fetch .dockerignore, .gitea/workflows/check.yml, .gitignore, .golangci.yml and REPO_POLICIES.md (from prompts/REPO_POLICIES.md) at dd4027b. .editorconfig is already identical.
  2. .golangci.yml: the current copy has two local edits that are not test-support deny entries: a gosec exclusion of G704 and a depguard all rule (io/ioutil, math/rand). Neither is carried forward; whatever the canonical file reports is fixed in the code. The repository has no test-support packages, so the deny list stays as canonical.
  3. .dockerignore: carry the host-built artifacts, written anchored: /neoircd, /neoirc-cli, /data.db, /data.db-wal, /data.db-shm.
  4. .gitignore: the canonical file has no build-artifact entries, and the policy requires them. The canonical content stays byte-identical, and this repository's own entries (web/dist/, /bin/, /neoircd, /neoirc-cli, data.db, debug.log, and the rest of the current build-artifact block) follow it in one section of their own. That is the reading taken; the PR says so in one line.
  5. Dockerfile: keep the web-builder stage. The lint phase moves to the v2.14.0 digest. A new test phase on a pinned Debian golang image of the same Go minor runs the policy's test command with -timeout 90s. Both phases create the web/dist placeholders. The build stage installs git, marks /src safe and copies from both phases; the runtime stage stays last.
  6. script/: the twelve model scripts from script/ at dd4027b, byte-identical except where the policy says a script is the repository's own (projectname prints neoirc; precommit adds the go mod tidy check that make hooks runs today). The Makefile targets become thin shims, and build, run, debug, clean and ensure-web-dist stay.
  7. README.md gains the Entrypoints section. AGENTS.md "Before Every Commit" points at make check, since it now tells agents to run golangci-lint on the host, which the policy forbids.
  8. Out of scope, stated in the PR: the web-builder stage keeps npm although the policy says yarn.

The policy's test command reruns with -v and then exits 1, so it cannot turn a red run green, which keeps #101's fix.

Model: opus-5-5

Plan, for one worker, one PR against `next`. Dispatched once https://git.eeqj.de/sneak/neoirc/issues/101 has landed, since both change the `Makefile` test target. What this repository needs beyond the issue text: 1. Fetch `.dockerignore`, `.gitea/workflows/check.yml`, `.gitignore`, `.golangci.yml` and `REPO_POLICIES.md` (from `prompts/REPO_POLICIES.md`) at `dd4027b`. `.editorconfig` is already identical. 2. `.golangci.yml`: the current copy has two local edits that are not `test-support` deny entries: a `gosec` exclusion of `G704` and a depguard `all` rule (`io/ioutil`, `math/rand`). Neither is carried forward; whatever the canonical file reports is fixed in the code. The repository has no test-support packages, so the `deny` list stays as canonical. 3. `.dockerignore`: carry the host-built artifacts, written anchored: `/neoircd`, `/neoirc-cli`, `/data.db`, `/data.db-wal`, `/data.db-shm`. 4. `.gitignore`: the canonical file has no build-artifact entries, and the policy requires them. The canonical content stays byte-identical, and this repository's own entries (`web/dist/`, `/bin/`, `/neoircd`, `/neoirc-cli`, `data.db`, `debug.log`, and the rest of the current build-artifact block) follow it in one section of their own. That is the reading taken; the PR says so in one line. 5. `Dockerfile`: keep the `web-builder` stage. The lint phase moves to the v2.14.0 digest. A new `test` phase on a pinned Debian `golang` image of the same Go minor runs the policy's test command with `-timeout 90s`. Both phases create the `web/dist` placeholders. The build stage installs `git`, marks `/src` safe and copies from both phases; the runtime stage stays last. 6. `script/`: the twelve model scripts from `script/` at `dd4027b`, byte-identical except where the policy says a script is the repository's own (`projectname` prints `neoirc`; `precommit` adds the `go mod tidy` check that `make hooks` runs today). The `Makefile` targets become thin shims, and `build`, `run`, `debug`, `clean` and `ensure-web-dist` stay. 7. `README.md` gains the Entrypoints section. `AGENTS.md` "Before Every Commit" points at `make check`, since it now tells agents to run golangci-lint on the host, which the policy forbids. 8. Out of scope, stated in the PR: the `web-builder` stage keeps `npm` although the policy says `yarn`. The policy's test command reruns with `-v` and then exits 1, so it cannot turn a red run green, which keeps https://git.eeqj.de/sneak/neoirc/issues/101's fix. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/neoirc#112