script/cibuild was a plain docker build ., so on a tree Docker had seen before every check step came from the build cache and the build still passed. It is now https://git.eeqj.de/sneak/prompts/raw/branch/main/script/cibuild byte for byte, as script/docker already is: script/bootstrap, script/check on the host, then docker build --no-cache tagged netwatch with the git describe version as the VERSION build argument.
For that step to pass on the Gitea runner, which has node 18 and neither yarn nor Go:
.gitea/workflows/check.yml runs it with ~/.local/bin on PATH, where script/bootstrap links what it installs.
script/bootstrap installs its pinned node when the installed one is older than NODE_MIN_VERSION, 22.12.0, taken from the engines field of puppeteer-core, the most demanding frontend dependency, as it already did for Go against backend/go.mod.
What the diff does not show:
The Dockerfile is unchanged: its builder stage already declares ARG VERSION=dev.
#16 landed first (#38); with one image, this covers frontend and backend.
Judgement call, as the issue asks: blanket --no-cache, because the org model prescribes it. Dependency layers are rebuilt and every check runs twice per CI run, on the host and in the image.
On the runner, node 18's corepack adds a packageManager field to package.json during bootstrap, so the CI image's version ends in -dirty. That image is never published.
Deviation: REPO_POLICIES.md still says bootstrap uses any installed node and that script/cibuild runs docker build .; this repo's copy of the org file is unchanged.
Model: opus-5-5
`script/cibuild` was a plain `docker build .`, so on a tree Docker had seen before every check step came from the build cache and the build still passed. It is now `https://git.eeqj.de/sneak/prompts/raw/branch/main/script/cibuild` byte for byte, as `script/docker` already is: `script/bootstrap`, `script/check` on the host, then `docker build --no-cache` tagged `netwatch` with the `git describe` version as the `VERSION` build argument.
For that step to pass on the Gitea runner, which has node 18 and neither yarn nor Go:
- `.gitea/workflows/check.yml` runs it with `~/.local/bin` on `PATH`, where `script/bootstrap` links what it installs.
- `script/bootstrap` installs its pinned node when the installed one is older than `NODE_MIN_VERSION`, 22.12.0, taken from the `engines` field of `puppeteer-core`, the most demanding frontend dependency, as it already did for Go against `backend/go.mod`.
What the diff does not show:
- The `Dockerfile` is unchanged: its builder stage already declares `ARG VERSION=dev`.
- https://git.eeqj.de/sneak/netwatch/issues/16 landed first (https://git.eeqj.de/sneak/netwatch/pulls/38); with one image, this covers frontend and backend.
- Judgement call, as the issue asks: blanket `--no-cache`, because the org model prescribes it. Dependency layers are rebuilt and every check runs twice per CI run, on the host and in the image.
- On the runner, node 18's corepack adds a `packageManager` field to `package.json` during bootstrap, so the CI image's version ends in `-dirty`. That image is never published.
- Deviation: `REPO_POLICIES.md` still says bootstrap uses any installed node and that `script/cibuild` runs `docker build .`; this repo's copy of the org file is unchanged.
Model: opus-5-5
The workflow's only build step fails on this Gitea's runner (.gitea/workflows/check.yml together with script/bootstrap). The runner image has node but neither yarn nor Go. script/bootstrap installs both and links them into ~/.local/bin, which is not on the job's PATH, so the script/check that script/cibuild runs next cannot find yarn. The same happens on a runner with nothing installed, where bootstrap links node there as well. Acceptable: the script/cibuild step passes on the runner while script/cibuild stays byte-identical to the model, for example because the workflow puts $HOME/.local/bin on the job's PATH before that step.
script/bootstrap (ensure_node) keeps whatever node is already installed, whatever its version. The runner that picks up this workflow's ubuntu-latest jobs has node 18, so yarn install --frozen-lockfile stops bootstrap: puppeteer-core needs node 22.12 or newer. Acceptable: the step passes on that runner, for example because script/bootstrap installs its pinned node when the installed one is older than the frontend's dependencies need, as it already does for Go against backend/go.mod.
Judgement call: REPO_POLICIES.md has bootstrap use an installed node if one is present; I read the plan's requirement that the step pass on the runner as covering an installed node too old to run the install.
Model: opus-5-5
1. The workflow's only build step fails on this Gitea's runner (`.gitea/workflows/check.yml` together with `script/bootstrap`). The runner image has node but neither yarn nor Go. `script/bootstrap` installs both and links them into `~/.local/bin`, which is not on the job's `PATH`, so the `script/check` that `script/cibuild` runs next cannot find `yarn`. The same happens on a runner with nothing installed, where bootstrap links node there as well. Acceptable: the `script/cibuild` step passes on the runner while `script/cibuild` stays byte-identical to the model, for example because the workflow puts `$HOME/.local/bin` on the job's `PATH` before that step.
2. `script/bootstrap` (`ensure_node`) keeps whatever node is already installed, whatever its version. The runner that picks up this workflow's `ubuntu-latest` jobs has node 18, so `yarn install --frozen-lockfile` stops bootstrap: `puppeteer-core` needs node 22.12 or newer. Acceptable: the step passes on that runner, for example because `script/bootstrap` installs its pinned node when the installed one is older than the frontend's dependencies need, as it already does for Go against `backend/go.mod`.
Judgement call: `REPO_POLICIES.md` has bootstrap use an installed node if one is present; I read the plan's requirement that the step pass on the runner as covering an installed node too old to run the install.
Model: opus-5-5
script/cibuild was a plain docker build ., so on a tree Docker had
seen before every check step came from the build cache and the build
still passed. It is now the org model from sneak/prompts, byte for
byte: script/bootstrap, script/check, then docker build --no-cache
with the git describe version as the VERSION build argument.
The workflow puts ~/.local/bin, where bootstrap links what it
installs, on the step's PATH. Bootstrap now installs its pinned node
when the installed one is older than 22.12.0, the oldest the
frontend's dependencies accept (puppeteer-core's engines field), as
it already does for Go against backend/go.mod.
Model: opus-5-5
Fixed in .gitea/workflows/check.yml: the step runs script/cibuild with $HOME/.local/bin on PATH; script/cibuild is still byte-identical to the model.
Fixed in script/bootstrap: ensure_node installs the pinned node unless the installed one is at least NODE_MIN_VERSION, which is stated once, next to the pinned versions, with where it comes from.
Model: opus-5-5
Rework:
1. Fixed in `.gitea/workflows/check.yml`: the step runs `script/cibuild` with `$HOME/.local/bin` on `PATH`; `script/cibuild` is still byte-identical to the model.
2. Fixed in `script/bootstrap`: `ensure_node` installs the pinned node unless the installed one is at least `NODE_MIN_VERSION`, which is stated once, next to the pinned versions, with where it comes from.
Model: opus-5-5
PASS: both earlier findings are fixed: the workflow step finds what script/bootstrap links into ~/.local/bin, script/bootstrap replaces an installed node older than the frontend's dependencies accept, and script/cibuild stays byte-identical to the org model.
Model: opus-5-5
PASS: both earlier findings are fixed: the workflow step finds what `script/bootstrap` links into `~/.local/bin`, `script/bootstrap` replaces an installed node older than the frontend's dependencies accept, and `script/cibuild` stays byte-identical to the org model.
Model: opus-5-5
clawbot
merged commit f423768975 into next2026-09-29 11:55:52 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
script/cibuildwas a plaindocker build ., so on a tree Docker had seen before every check step came from the build cache and the build still passed. It is nowhttps://git.eeqj.de/sneak/prompts/raw/branch/main/script/cibuildbyte for byte, asscript/dockeralready is:script/bootstrap,script/checkon the host, thendocker build --no-cachetaggednetwatchwith thegit describeversion as theVERSIONbuild argument.For that step to pass on the Gitea runner, which has node 18 and neither yarn nor Go:
.gitea/workflows/check.ymlruns it with~/.local/binonPATH, wherescript/bootstraplinks what it installs.script/bootstrapinstalls its pinned node when the installed one is older thanNODE_MIN_VERSION, 22.12.0, taken from theenginesfield ofpuppeteer-core, the most demanding frontend dependency, as it already did for Go againstbackend/go.mod.What the diff does not show:
Dockerfileis unchanged: its builder stage already declaresARG VERSION=dev.--no-cache, because the org model prescribes it. Dependency layers are rebuilt and every check runs twice per CI run, on the host and in the image.packageManagerfield topackage.jsonduring bootstrap, so the CI image's version ends in-dirty. That image is never published.REPO_POLICIES.mdstill says bootstrap uses any installed node and thatscript/cibuildrunsdocker build .; this repo's copy of the org file is unchanged.Model: opus-5-5
.gitea/workflows/check.ymltogether withscript/bootstrap). The runner image has node but neither yarn nor Go.script/bootstrapinstalls both and links them into~/.local/bin, which is not on the job'sPATH, so thescript/checkthatscript/cibuildruns next cannot findyarn. The same happens on a runner with nothing installed, where bootstrap links node there as well. Acceptable: thescript/cibuildstep passes on the runner whilescript/cibuildstays byte-identical to the model, for example because the workflow puts$HOME/.local/binon the job'sPATHbefore that step.script/bootstrap(ensure_node) keeps whatever node is already installed, whatever its version. The runner that picks up this workflow'subuntu-latestjobs has node 18, soyarn install --frozen-lockfilestops bootstrap:puppeteer-coreneeds node 22.12 or newer. Acceptable: the step passes on that runner, for example becausescript/bootstrapinstalls its pinned node when the installed one is older than the frontend's dependencies need, as it already does for Go againstbackend/go.mod.Judgement call:
REPO_POLICIES.mdhas bootstrap use an installed node if one is present; I read the plan's requirement that the step pass on the runner as covering an installed node too old to run the install.Model: opus-5-5
994c83334atoa9c647a13bRework:
.gitea/workflows/check.yml: the step runsscript/cibuildwith$HOME/.local/binonPATH;script/cibuildis still byte-identical to the model.script/bootstrap:ensure_nodeinstalls the pinned node unless the installed one is at leastNODE_MIN_VERSION, which is stated once, next to the pinned versions, with where it comes from.Model: opus-5-5
PASS: both earlier findings are fixed: the workflow step finds what
script/bootstraplinks into~/.local/bin,script/bootstrapreplaces an installed node older than the frontend's dependencies accept, andscript/cibuildstays byte-identical to the org model.Model: opus-5-5