next into main. Everything on next is fit for main; merging takes all of it.
On the branch:
backend/.golangci.yml is the current org-standard file from sneak/prompts: gomodguard_v2 in place of the deprecated gomodguard, plus the org's depguard test-support rule; the backend needed no source change.
script/cibuild is the org model: script/bootstrap, script/check, then an uncached image build, so CI can no longer pass on checks it did not run. The workflow puts ~/.local/bin on its PATH, and bootstrap replaces an installed node older than 22.12.0.
Coming next: the container setting up its own data directory before start (#75), in rework after review; it joins this PR when it lands. The main to prod deploy, #74, waits for it to reach main.
To deploy what is here: nothing changes in the running image.
Model: opus-5-5
`next` into `main`. Everything on `next` is fit for `main`; merging takes all of it.
**On the branch:**
- `backend/.golangci.yml` is the current org-standard file from `sneak/prompts`: `gomodguard_v2` in place of the deprecated `gomodguard`, plus the org's `depguard` test-support rule; the backend needed no source change.
- `script/cibuild` is the org model: `script/bootstrap`, `script/check`, then an uncached image build, so CI can no longer pass on checks it did not run. The workflow puts `~/.local/bin` on its `PATH`, and bootstrap replaces an installed node older than 22.12.0.
**Coming next:** the container setting up its own data directory before start (https://git.eeqj.de/sneak/netwatch/issues/75), in rework after review; it joins this PR when it lands. The `main` to `prod` deploy, https://git.eeqj.de/sneak/netwatch/pulls/74, waits for it to reach `main`.
**To deploy what is here:** nothing changes in the running image.
Model: opus-5-5
golangci-lint v2.12 deprecates gomodguard, which the org .golangci.yml
reached through "default: all", so every lint run printed a
deprecation warning. backend/.golangci.yml is now the current copy
from sneak/prompts, fetched unedited: gomodguard is disabled and
gomodguard_v2 enabled with the org block list. The new file also
turns depguard on with its test-support rule, which forbids
net/http/httptest outside test code. netwatch has no test-support
packages of its own to add to that rule, so the file is identical to
the canonical one. backend/script/lint checks the new sha256. The
backend raises no findings under the new rules.
Model: opus-5-5
clawbot
removed their assignment 2026-09-29 11:45:49 +02:00
sneak
was assigned by clawbot2026-09-29 11:45:49 +02:00
script/cibuild was a plain docker build ., so on a tree Docker had
seen before every check step came from the build cache and the build
still passed. It is now the org model from sneak/prompts, byte for
byte: script/bootstrap, script/check, then docker build --no-cache
with the git describe version as the VERSION build argument.
The workflow puts ~/.local/bin, where bootstrap links what it
installs, on the step's PATH. Bootstrap now installs its pinned node
when the installed one is older than 22.12.0, the oldest the
frontend's dependencies accept (puppeteer-core's engines field), as
it already does for Go against backend/go.mod.
Model: opus-5-5
Closes #75.
`bin/entrypoint.sh`, which already runs as root, now makes the data directory usable before the backend starts: it creates `DATA_DIR` if missing, gives it and `/data` to the `netwatch` user (`chown -R`), and sets mode 750 on both, the mode the backend gives a directory it creates. The backend still runs as `netwatch`. The README "Running under upaas" section loses its first-run step that created and chowned the host directory and names only the path to mount. The Dockerfile's build-time `mkdir` and `chown` of `/data` are gone, since the entrypoint now does this on every start.
What the diff does not show:
- The host directory mounted at `/data` ends up owned by uid 1000 with mode 750, and everything under `DATA_DIR` is chowned to uid 1000 on every start.
- If the directory cannot be created or chowned, the container stops with that tool's error before either process starts.
Recorded runs with `--mount type=bind`: an empty directory owned by root (mode 755, and again mode 700), and one holding a `reports` directory and report file owned by uid 1001 with mode 700. Each time the container turned healthy, `netwatch-server` ran as `netwatch`, and a posted report was written to `DATA_DIR`; a second start on the root-owned and the uid 1001 directories did the same.
Judgement call: `/data` itself is given to `netwatch` as well as `DATA_DIR`, so the backend can reach `DATA_DIR` inside a host directory with mode 700.
Model: opus-5-5
Reviewed-on: #76
Co-authored-by: clawbot <35+clawbot@noreply.example.org>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
nextintomain. Everything onnextis fit formain; merging takes all of it.On the branch:
backend/.golangci.ymlis the current org-standard file fromsneak/prompts:gomodguard_v2in place of the deprecatedgomodguard, plus the org'sdepguardtest-support rule; the backend needed no source change.script/cibuildis the org model:script/bootstrap,script/check, then an uncached image build, so CI can no longer pass on checks it did not run. The workflow puts~/.local/binon itsPATH, and bootstrap replaces an installed node older than 22.12.0.Coming next: the container setting up its own data directory before start (#75), in rework after review; it joins this PR when it lands. The
maintoproddeploy, #74, waits for it to reachmain.To deploy what is here: nothing changes in the running image.
Model: opus-5-5