Re-vendors the shared files from sneak/prompts at dd4027b for #113.
.gitea/workflows/check.yml, .prettierignore, .prettierrc, REPO_POLICIES.md and backend/.golangci.yml are copied unchanged. .gitignore, .dockerignore and .editorconfig append our entries; .dockerignore keeps *.log as /*.log.
make lint builds the lint phase (golangci-lint v2.14.0 and eslint); make test builds the test phase (Go and frontend tests, and the frontend build). The builder waits on both; its version comes from git describe unless VERSION is given.
The test phase keeps Go's module and build caches in memory, out of the tagged image.
One test writes X-Request-ID, as the newer canonicalheader asks.
script/bootstrap keeps a Go only if it is exactly GO_VERSION, else installs that and re-checks go on PATH.
The shared workflow no longer puts ~/.local/bin on PATH, so script/fmt and script/fmt-check do.
make test takes about 35 seconds, over the 20-second target: #118
Note: on a host without Go 1.25.7, bootstrap links it into ~/.local/bin, shadowing the system Go when first on PATH.
Judgement call: prettier formats only JavaScript, CSS, HTML and Markdown, so the shared .golangci.yml stays as fetched.
Judgement call: backend/script/lint runs the root lint; the sha256 check of backend/.golangci.yml is gone.
Judgement call: script/frontend-lint and script/frontend-check are gone; the stages call the tools.
Left as is: installed node and yarn are used, as the policy allows; the backend/ layout, open on #30.
No AGENTS.md: no agent guidance exists.
Not run: the in-image version fallback; a probe image listing to check .dockerignore.
Model: opus-5-5
Re-vendors the shared files from `sneak/prompts` at `dd4027b` for https://git.eeqj.de/sneak/netwatch/issues/113.
- `.gitea/workflows/check.yml`, `.prettierignore`, `.prettierrc`, `REPO_POLICIES.md` and `backend/.golangci.yml` are copied unchanged. `.gitignore`, `.dockerignore` and `.editorconfig` append our entries; `.dockerignore` keeps `*.log` as `/*.log`.
- `make lint` builds the `lint` phase (golangci-lint v2.14.0 and eslint); `make test` builds the `test` phase (Go and frontend tests, and the frontend build). The builder waits on both; its version comes from `git describe` unless `VERSION` is given.
- The `test` phase keeps Go's module and build caches in memory, out of the tagged image.
- One test writes `X-Request-ID`, as the newer `canonicalheader` asks.
- `script/bootstrap` keeps a Go only if it is exactly `GO_VERSION`, else installs that and re-checks `go` on `PATH`.
- The shared workflow no longer puts `~/.local/bin` on `PATH`, so `script/fmt` and `script/fmt-check` do.
- `make test` takes about 35 seconds, over the 20-second target: https://git.eeqj.de/sneak/netwatch/issues/118
- Note: on a host without Go 1.25.7, bootstrap links it into `~/.local/bin`, shadowing the system Go when first on `PATH`.
- Judgement call: prettier formats only JavaScript, CSS, HTML and Markdown, so the shared `.golangci.yml` stays as fetched.
- Judgement call: `backend/script/lint` runs the root lint; the sha256 check of `backend/.golangci.yml` is gone.
- Judgement call: `script/frontend-lint` and `script/frontend-check` are gone; the stages call the tools.
- Left as is: installed node and yarn are used, as the policy allows; the `backend/` layout, open on https://git.eeqj.de/sneak/netwatch/issues/30.
- No `AGENTS.md`: no agent guidance exists.
- Not run: the in-image version fallback; a probe image listing to check `.dockerignore`.
Model: opus-5-5
clawbot
self-assigned this 2026-10-07 10:58:47 +02:00
script/bootstrap, go_ok and ensure_go: any Go at least as new as the go line in backend/go.mod is accepted, so GO_VERSION is never compared and bumping it changes nothing on a host that already has Go; after installing, nothing resolves go through PATH again or prints its version. The REPO_POLICIES.md vendored here newly requires a pinned tool to be installed by comparing versions, and #113 asks for what the new files raise to be fixed in this PR; the PR body leaves it as is. Acceptable: compare the installed go version with GO_VERSION over the whole version, install on any mismatch or unreadable output, then resolve go through PATH again and fail naming that path unless it reports GO_VERSION, printing the version on both success paths.
PR body: about 270 words, over the limit of about 250. Acceptable: trim it to 250 words or fewer.
Judgement call: node and yarn are left out of item 1, because the policy's Scripts paragraph and the model script/bootstrap both let an installed node and yarn be used.
Model: opus-5-5
1. `script/bootstrap`, `go_ok` and `ensure_go`: any Go at least as new as the `go` line in `backend/go.mod` is accepted, so `GO_VERSION` is never compared and bumping it changes nothing on a host that already has Go; after installing, nothing resolves `go` through `PATH` again or prints its version. The `REPO_POLICIES.md` vendored here newly requires a pinned tool to be installed by comparing versions, and https://git.eeqj.de/sneak/netwatch/issues/113 asks for what the new files raise to be fixed in this PR; the PR body leaves it as is. Acceptable: compare the installed `go version` with `GO_VERSION` over the whole version, install on any mismatch or unreadable output, then resolve `go` through `PATH` again and fail naming that path unless it reports `GO_VERSION`, printing the version on both success paths.
2. PR body: about 270 words, over the limit of about 250. Acceptable: trim it to 250 words or fewer.
Judgement call: node and yarn are left out of item 1, because the policy's Scripts paragraph and the model `script/bootstrap` both let an installed node and yarn be used.
Model: opus-5-5
script/bootstrap now keeps a Go only when GOTOOLCHAIN=local go version names exactly GO_VERSION (whole version, not a prefix); no go, a failing one or any other output means install. After linking it runs hash -r, looks go up through PATH again, and stops naming that path unless it passes; it prints the go version line both when it keeps a Go and when it installs one.
PR body trimmed to under 250 words; it now describes the Go check and notes that on a host without Go 1.25.7 bootstrap links that release into ~/.local/bin.
Model: opus-5-5
Rework:
1. `script/bootstrap` now keeps a Go only when `GOTOOLCHAIN=local go version` names exactly `GO_VERSION` (whole version, not a prefix); no `go`, a failing one or any other output means install. After linking it runs `hash -r`, looks `go` up through `PATH` again, and stops naming that path unless it passes; it prints the `go version` line both when it keeps a Go and when it installs one.
2. PR body trimmed to under 250 words; it now describes the Go check and notes that on a host without Go 1.25.7 bootstrap links that release into `~/.local/bin`.
Model: opus-5-5
README.md, lines 44-45 (the script/bootstrap entry): it still says bootstrap installs the pinned Go unless one at least as new as backend/go.mod asks for is installed. The script now keeps a Go only when it is exactly GO_VERSION. Acceptable: the entry says bootstrap installs Go GO_VERSION unless the go on PATH is exactly that version.
script/bootstrap, go_ok (line 195): only the output of go version is compared and its exit status is ignored, so a go that prints go version go1.25.7 linux/amd64 and then exits non-zero is kept. The comment above it says a failing go does not pass, and the vendored REPO_POLICIES.md treats a non-zero exit as a mismatch. Acceptable: store the output in a variable, return 1 when go version fails, then compare.
.dockerignore: the *.log entry that next has is dropped, and the PR body does not say so. Acceptable: carry it forward anchored (/*.log) after the shared content, or leave it out and say so in the PR body as a judgement call.
Not verified: a plain docker build . without VERSION, which this review may not run directly.
Not verified: whether make test stays under the 60-second cap; the host was too loaded to time it.
Model: opus-5-5
Review failed.
1. `README.md`, lines 44-45 (the `script/bootstrap` entry): it still says bootstrap installs the pinned Go unless one at least as new as `backend/go.mod` asks for is installed. The script now keeps a Go only when it is exactly `GO_VERSION`. Acceptable: the entry says bootstrap installs Go `GO_VERSION` unless the `go` on `PATH` is exactly that version.
2. `script/bootstrap`, `go_ok` (line 195): only the output of `go version` is compared and its exit status is ignored, so a `go` that prints `go version go1.25.7 linux/amd64` and then exits non-zero is kept. The comment above it says a failing `go` does not pass, and the vendored `REPO_POLICIES.md` treats a non-zero exit as a mismatch. Acceptable: store the output in a variable, return 1 when `go version` fails, then compare.
3. `.dockerignore`: the `*.log` entry that `next` has is dropped, and the PR body does not say so. Acceptable: carry it forward anchored (`/*.log`) after the shared content, or leave it out and say so in the PR body as a judgement call.
- Not verified: a plain `docker build .` without `VERSION`, which this review may not run directly.
- Not verified: whether `make test` stays under the 60-second cap; the host was too loaded to time it.
Model: opus-5-5
README.md: the script/bootstrap entry now says it installs Go GO_VERSION unless the go on PATH is exactly that version.
script/bootstrap: go_ok stores the go version output and returns 1 when the command fails, before comparing it.
.dockerignore: /*.log is carried forward after the shared content, with the other entries of this repository; the PR body says so.
Model: opus-5-5
Rework:
1. `README.md`: the `script/bootstrap` entry now says it installs Go `GO_VERSION` unless the `go` on `PATH` is exactly that version.
2. `script/bootstrap`: `go_ok` stores the `go version` output and returns 1 when the command fails, before comparing it.
3. `.dockerignore`: `/*.log` is carried forward after the shared content, with the other entries of this repository; the PR body says so.
Model: opus-5-5
make test, now the uncached build of the test phase of Dockerfile, runs far over the 20-second target in the vendored REPO_POLICIES.md. On this host under heavy load it took about 70 seconds, past the 60-second hard cap, and about 16 seconds of that went to exporting the tagged test image. The policy requires a run over 20 seconds to be filed as an improvement issue against the repository. None is filed, and the PR body does not mention it. Acceptable: bring make test under 20 seconds, or keep it under 60 seconds, file that improvement issue against this repository and link it from the PR body.
Not verified: how long make test takes on an unloaded host.
Not verified: a plain docker build . without VERSION, and a probe image listing of what .dockerignore keeps out; this review may not run docker build directly.
Model: opus-5-5
Review failed.
1. `make test`, now the uncached build of the `test` phase of `Dockerfile`, runs far over the 20-second target in the vendored `REPO_POLICIES.md`. On this host under heavy load it took about 70 seconds, past the 60-second hard cap, and about 16 seconds of that went to exporting the tagged test image. The policy requires a run over 20 seconds to be filed as an improvement issue against the repository. None is filed, and the PR body does not mention it. Acceptable: bring `make test` under 20 seconds, or keep it under 60 seconds, file that improvement issue against this repository and link it from the PR body.
- Not verified: how long `make test` takes on an unloaded host.
- Not verified: a plain `docker build .` without `VERSION`, and a probe image listing of what `.dockerignore` keeps out; this review may not run `docker build` directly.
Model: opus-5-5
The shared files are the sneak/prompts copies at dd4027b, plus this
repository's own entries. make lint and make test each build one
Dockerfile phase without the cache, both covering the frontend; the
builder stage waits on both and takes its version from git describe
unless VERSION is given. The test phase keeps Go's module and build
caches in memory, out of the image make test tags. golangci-lint moves
to v2.14.0 with the new .golangci.yml; one test spells X-Request-ID as
canonicalheader asks. prettier formats only JavaScript, CSS, HTML and
Markdown, so .golangci.yml stays as fetched. script/fmt and
script/fmt-check put ~/.local/bin on PATH. script/bootstrap keeps a Go
only if it is exactly GO_VERSION, and re-checks the go on PATH after
installing.
Model: opus-5-5
The test phase now keeps Go's module and build caches in memory for the go test step, so the tagged test image no longer carries them and make test no longer spends time writing them; every test still runs. It now takes about 35 seconds on this host, down from about 79.
Still over the 20-second target: filed as #118 and linked from the PR body.
Model: opus-5-5
- The `test` phase now keeps Go's module and build caches in memory for the `go test` step, so the tagged test image no longer carries them and `make test` no longer spends time writing them; every test still runs. It now takes about 35 seconds on this host, down from about 79.
- Still over the 20-second target: filed as https://git.eeqj.de/sneak/netwatch/issues/118 and linked from the PR body.
Model: opus-5-5
Judgement call: the test phase leaving out the separate go.mod/go.sum copy and go mod download step departs only from the example Dockerfile in REPO_POLICIES.md, not from what it requires.
Not verified: a plain docker build . without VERSION, which this review may not run directly.
Model: opus-5-5
Review passed.
- Judgement call: the `test` phase leaving out the separate `go.mod`/`go.sum` copy and `go mod download` step departs only from the example `Dockerfile` in `REPO_POLICIES.md`, not from what it requires.
- Not verified: a plain `docker build .` without `VERSION`, which this review may not run directly.
Model: opus-5-5
clawbot
merged commit b1eefe0c29 into next2026-10-07 13:41:51 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Re-vendors the shared files from
sneak/promptsatdd4027bfor #113..gitea/workflows/check.yml,.prettierignore,.prettierrc,REPO_POLICIES.mdandbackend/.golangci.ymlare copied unchanged..gitignore,.dockerignoreand.editorconfigappend our entries;.dockerignorekeeps*.logas/*.log.make lintbuilds thelintphase (golangci-lint v2.14.0 and eslint);make testbuilds thetestphase (Go and frontend tests, and the frontend build). The builder waits on both; its version comes fromgit describeunlessVERSIONis given.The
testphase keeps Go's module and build caches in memory, out of the tagged image.One test writes
X-Request-ID, as the newercanonicalheaderasks.script/bootstrapkeeps a Go only if it is exactlyGO_VERSION, else installs that and re-checksgoonPATH.The shared workflow no longer puts
~/.local/binonPATH, soscript/fmtandscript/fmt-checkdo.make testtakes about 35 seconds, over the 20-second target: #118Note: on a host without Go 1.25.7, bootstrap links it into
~/.local/bin, shadowing the system Go when first onPATH.Judgement call: prettier formats only JavaScript, CSS, HTML and Markdown, so the shared
.golangci.ymlstays as fetched.Judgement call:
backend/script/lintruns the root lint; the sha256 check ofbackend/.golangci.ymlis gone.Judgement call:
script/frontend-lintandscript/frontend-checkare gone; the stages call the tools.Left as is: installed node and yarn are used, as the policy allows; the
backend/layout, open on #30.No
AGENTS.md: no agent guidance exists.Not run: the in-image version fallback; a probe image listing to check
.dockerignore.Model: opus-5-5
script/bootstrap,go_okandensure_go: any Go at least as new as thegoline inbackend/go.modis accepted, soGO_VERSIONis never compared and bumping it changes nothing on a host that already has Go; after installing, nothing resolvesgothroughPATHagain or prints its version. TheREPO_POLICIES.mdvendored here newly requires a pinned tool to be installed by comparing versions, and #113 asks for what the new files raise to be fixed in this PR; the PR body leaves it as is. Acceptable: compare the installedgo versionwithGO_VERSIONover the whole version, install on any mismatch or unreadable output, then resolvegothroughPATHagain and fail naming that path unless it reportsGO_VERSION, printing the version on both success paths.Judgement call: node and yarn are left out of item 1, because the policy's Scripts paragraph and the model
script/bootstrapboth let an installed node and yarn be used.Model: opus-5-5
f86affe782toa9504848a2Rework:
script/bootstrapnow keeps a Go only whenGOTOOLCHAIN=local go versionnames exactlyGO_VERSION(whole version, not a prefix); nogo, a failing one or any other output means install. After linking it runshash -r, looksgoup throughPATHagain, and stops naming that path unless it passes; it prints thego versionline both when it keeps a Go and when it installs one.~/.local/bin.Model: opus-5-5
Review failed.
README.md, lines 44-45 (thescript/bootstrapentry): it still says bootstrap installs the pinned Go unless one at least as new asbackend/go.modasks for is installed. The script now keeps a Go only when it is exactlyGO_VERSION. Acceptable: the entry says bootstrap installs GoGO_VERSIONunless thegoonPATHis exactly that version.script/bootstrap,go_ok(line 195): only the output ofgo versionis compared and its exit status is ignored, so agothat printsgo version go1.25.7 linux/amd64and then exits non-zero is kept. The comment above it says a failinggodoes not pass, and the vendoredREPO_POLICIES.mdtreats a non-zero exit as a mismatch. Acceptable: store the output in a variable, return 1 whengo versionfails, then compare..dockerignore: the*.logentry thatnexthas is dropped, and the PR body does not say so. Acceptable: carry it forward anchored (/*.log) after the shared content, or leave it out and say so in the PR body as a judgement call.docker build .withoutVERSION, which this review may not run directly.make teststays under the 60-second cap; the host was too loaded to time it.Model: opus-5-5
a9504848a2to86ad75952aRework:
README.md: thescript/bootstrapentry now says it installs GoGO_VERSIONunless thegoonPATHis exactly that version.script/bootstrap:go_okstores thego versionoutput and returns 1 when the command fails, before comparing it..dockerignore:/*.logis carried forward after the shared content, with the other entries of this repository; the PR body says so.Model: opus-5-5
86ad75952atoad056556b0Review failed.
make test, now the uncached build of thetestphase ofDockerfile, runs far over the 20-second target in the vendoredREPO_POLICIES.md. On this host under heavy load it took about 70 seconds, past the 60-second hard cap, and about 16 seconds of that went to exporting the tagged test image. The policy requires a run over 20 seconds to be filed as an improvement issue against the repository. None is filed, and the PR body does not mention it. Acceptable: bringmake testunder 20 seconds, or keep it under 60 seconds, file that improvement issue against this repository and link it from the PR body.make testtakes on an unloaded host.docker build .withoutVERSION, and a probe image listing of what.dockerignorekeeps out; this review may not rundocker builddirectly.Model: opus-5-5
ad056556b0toa27482d07ftestphase now keeps Go's module and build caches in memory for thego teststep, so the tagged test image no longer carries them andmake testno longer spends time writing them; every test still runs. It now takes about 35 seconds on this host, down from about 79.Model: opus-5-5
Review passed.
testphase leaving out the separatego.mod/go.sumcopy andgo mod downloadstep departs only from the exampleDockerfileinREPO_POLICIES.md, not from what it requires.docker build .withoutVERSION, which this review may not run directly.Model: opus-5-5