Files
netwatch/TODO.md
clawbot 4baf2a1c78
All checks were successful
check / check (push) Successful in 23s
build: unify the gate so root make check covers the backend (closes #16)
Root `make check` only ever ran the frontend, so the "main is always
green" policy was satisfied vacuously: the Go backend could be entirely
broken and the root gate stayed green.

- The backend moves onto scripts-to-rule-them-all. Its test, lint, fmt,
  fmt-check, build, run and clean implementations now live in
  `backend/script/`, and `backend/Makefile` is thin shims. The backend
  is its own project (own module, README, LICENSE, linter config,
  Dockerfile stage), and `Dockerfile.backend` only copies `backend/`
  into its builder, so its scripts have to live under `backend/`.
- The root `script/test`, `script/lint`, `script/fmt` and
  `script/fmt-check` now run the frontend step and then the matching
  `backend/script/*` step, so `script/check` — and therefore the
  pre-commit hook — gates both halves. The frontend-only steps moved
  into `script/frontend-*` so nothing is duplicated.
- `script/bootstrap` now provisions the backend's toolchain as well,
  because widening the gate without widening bootstrap left the
  documented fresh-clone path (`make setup`) installing a pre-commit
  hook that rejected every commit with `golangci-lint: not found`.
  golangci-lint is installed at exactly `2.7.2`, the version
  `Dockerfile.backend` pins, so local findings match CI. Go is reused
  only when the installed version falls inside a window — at least
  `backend/go.mod`'s floor, and no newer in major.minor than the Go the
  pinned linter was built with — otherwise `go1.25.7` is installed. The
  upper bound is load-bearing: golangci-lint links `go/types` from its
  own build toolchain, so the pinned `2.7.2` (built with `go1.25.4`)
  panics with "file requires newer Go version go1.26" against a host Go
  1.26, which would leave `make setup` exiting 0 and every commit
  rejected. Both tools come from a specific release archive whose sha256
  is hardcoded here and verified before anything is unpacked — never an
  install script piped to a shell — and both are symlinked onto `PATH`,
  since nvm-style activation does not reach `make` or the git hook.
- `script/bootstrap` links only into `~/.local/bin` and never into a
  system-wide prefix. `/usr/local/bin` is shared with other users and
  with a package manager — on an Intel Mac it is the Homebrew prefix —
  and pointing an entry there at one user's `$HOME` breaks it for
  everyone else. It also refuses, non-zero, to replace anything it did
  not create: only a symlink already pointing into its own toolchain
  directory is overwritten, so a pre-existing binary is reported rather
  than deleted. `corepack enable` is given `--install-directory` so its
  four shims (`yarn`, `yarnpkg`, `pnpm`, `pnpx`) land inside that same
  toolchain directory instead of beside the corepack binary, and only
  `yarn` is linked onto `PATH`.
- `script/bootstrap` exits non-zero when it cannot guarantee the pinned
  toolchain is the one the gate will run. Reporting success while
  knowing a different linter or a newer Go precedes `~/.local/bin` is
  the same defect this commit exists to remove, so the final step
  re-resolves `go`, `gofmt`, `golangci-lint`, `node` and `yarn` against
  the caller's own `PATH` and fails with what it found and how to fix
  it.
- `script/frontend-check` is the frontend half of the gate, exposed as
  the `frontend-check` target, for the frontend Dockerfile: its build
  stage is a node image with no Go toolchain. The backend half is gated
  by `Dockerfile.backend`, and `script/cibuild` builds both images, so
  the two Dockerfiles together still gate the whole repo. The
  `backend-check` target is the mirror of it. Both targets are named
  after the script they shim, like every other target.
- `script/cibuild` builds both images through one `build_image` helper,
  and the Gitea workflow's only build step is `script/cibuild`; the raw
  `docker build -f Dockerfile.backend .` is gone from the workflow.
  `script/docker` likewise builds and tags both images.
- `backend/Makefile`'s `hooks` target is removed. It wrote the same
  `.git/hooks/pre-commit` as `script/install-precommit`, so the two
  clobbered each other and the developer silently ended up gating on
  only one half of the repo. `script/install-precommit` is now the only
  installer, and the hook it writes runs the repo-wide `script/check`.
- `backend/Makefile`'s `docker` target is removed too: the backend image
  builds from the repo root with a root-level Dockerfile, so it belongs
  to the root `script/docker` and `script/cibuild` rather than to a
  backend script that would have to reach outside `backend/`.
- `backend/script/lint` verifies that `.golangci.yml` still matches its
  pinned sha256 before running the linter. Offline hash comparison, no
  network. The pin is marked provisional in the file: it is the config
  currently on `main`, and the comment names PR #31 and the canonical
  hash that must replace it when #31 lands.
- Every script locates the repo root with the mandated
  `$(cd "$(dirname "$0")/.." && pwd -P)` idiom, `cd`s there, and calls
  siblings as `"$ROOT/script/<name>"`; the `SCRIPT_DIR` variant is gone.

READMEs at the root and in `backend/` document every script, the
backend's Getting Started separates commands run from `backend/` from
those run at the repo root, and `TODO.md` records the change.
2026-08-09 07:22:25 +00:00

60 lines
2.8 KiB
Markdown

# Workflow
- branch (from `main`)
- do the work in Next Step
- move Next Step to the top of Completed Steps
- move the top item of Future Steps into Next Step
- commit (`TODO.md` changes in the same commit as the work)
- merge to `main` if the branch is not protected, otherwise open a PR
- push
# Status
pre-1.0. No git tags. Backend work in flight on feat/reportbuf-storage (dirty:
src/main.js). Frontend is functional; backend is new and unmerged.
# Next Step
Land feat/reportbuf-storage: finish the in-progress src/main.js change, get make
check green, and merge the branch to main. The branch adds the backend (buffered
zstd-compressed report storage), the CI workflow, and backend repo standard
files, so merging it also closes most compliance gaps.
# Completed Steps
- 2026-08-09: unified the gate: the root `make check` now covers the Go backend
as well as the frontend, the backend moved onto scripts-to-rule-them-all
(`backend/script/*` with `backend/Makefile` as thin shims), the duplicate
pre-commit hook installer in `backend/Makefile` was removed, `script/cibuild`
now builds both images as the workflow's only build step, and
`script/bootstrap` provisions the backend toolchain (pinned, hash-verified Go
and golangci-lint) so a fresh clone can pass the widened gate. Bootstrap
matches the Go pin rather than treating it as a floor, because the pinned
golangci-lint cannot analyse packages built by a newer Go; it links only into
`~/.local/bin`, never a system-wide prefix, and refuses to replace anything it
did not create; and it exits non-zero rather than reporting success when the
tools on the caller's `PATH` are not the pinned ones
- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints, Makefile
shims, README Entrypoints section
- 2026-02-27: backend with buffered zstd-compressed report storage; CI workflow
and backend repo standard files; backend Dockerfile fixed (Go 1.25,
golangci-lint) and moved to repo root (feat/reportbuf-storage, unmerged)
- 2026-02-26: host row layout redesigned with CSS grid; overflow and spacing
fixes; nginx config extracted; port hardcoded to 8080
- 2026-02-26: debug log panel, median stats, recovery probe, Docker build fix,
S3 Singapore endpoint added
- 2026-02-23: summary box redesign, host pinning, local and UTC clocks, checks
counter
- 2026-02-23: hosts sorted by latency; GET instead of HEAD for latency; timeout
derived from interval; Hetzner regional endpoints; 3s interval
- 2026-01-29: initial NetWatch network latency monitor
# Future Steps
- Compliance top-up as one small commit: add .editorconfig and add the hooks
target to the Makefile
- After merge, confirm .gitea/workflows/check.yml is on main and CI is green
(main always green policy)
- Decide what to do with untracked resume.sh: commit it, gitignore it, or delete
it