Lint and tests now run as the lint and test phases of the Dockerfile, and every docker build in script/ passes --no-cache, as REPO_POLICIES.md asks.
script/check, script/cibuild, script/docker, script/lint, script/test, script/setup and script/install-precommit are byte-identical copies from sneak/promptsmain.
lint phase: golangci-lint from the image digest the policy names; that image is Debian, so libvips-dev comes from apt-get, not apk.
test phase: the alpine Go image, script/bootstrap --cgo, then the tests with a 90-second timeout and the verbose rerun. The build stage depends on both phases.
script/bootstrap installs git, make and Go, refreshing apt's package lists before its first apt install; only with --cgo, which the test phase and the build stage pass, also the C compiler and the libvips and libheif libraries.
Dockerfile.lint and CHECK_EPOCH are gone; the gofmt check stays on the host. make docker-versioned and make docker-test call the scripts, so the dev image is now tagged pixa, not pixad.
Not canonical, on purpose: script/bootstrap, script/fmt and script/fmt-check (gofmt; the canonical ones run prettier through yarn), script/precommit (the go mod tidy guard), script/projectname.
Kept on purpose, per #166: without VERSION the build stage takes the version from git describe, so the copied scripts' comment that .dockerignore excludes .git does not hold here.
Judgement call: make docker-test now equals make test; kept, as the plan says to call the scripts.
Unchanged: on nix, script/bootstrap --cgo reinstalls the image libraries every run, as pkg-config does not find what nix-env installs.
Model: opus-5-5
Lint and tests now run as the `lint` and `test` phases of the `Dockerfile`, and every `docker build` in `script/` passes `--no-cache`, as `REPO_POLICIES.md` asks.
- `script/check`, `script/cibuild`, `script/docker`, `script/lint`, `script/test`, `script/setup` and `script/install-precommit` are byte-identical copies from `sneak/prompts` `main`.
- `lint` phase: golangci-lint from the image digest the policy names; that image is Debian, so `libvips-dev` comes from `apt-get`, not `apk`.
- `test` phase: the alpine Go image, `script/bootstrap --cgo`, then the tests with a 90-second timeout and the verbose rerun. The build stage depends on both phases.
- `script/bootstrap` installs git, make and Go, refreshing apt's package lists before its first apt install; only with `--cgo`, which the `test` phase and the build stage pass, also the C compiler and the libvips and libheif libraries.
- `Dockerfile.lint` and `CHECK_EPOCH` are gone; the `gofmt` check stays on the host. `make docker-versioned` and `make docker-test` call the scripts, so the dev image is now tagged `pixa`, not `pixad`.
Not canonical, on purpose: `script/bootstrap`, `script/fmt` and `script/fmt-check` (`gofmt`; the canonical ones run prettier through yarn), `script/precommit` (the `go mod tidy` guard), `script/projectname`.
- Kept on purpose, per https://git.eeqj.de/sneak/pixa/issues/166: without `VERSION` the build stage takes the version from `git describe`, so the copied scripts' comment that `.dockerignore` excludes `.git` does not hold here.
- Judgement call: `make docker-test` now equals `make test`; kept, as the plan says to call the scripts.
- Unchanged: on nix, `script/bootstrap --cgo` reinstalls the image libraries every run, as `pkg-config` does not find what `nix-env` installs.
Model: opus-5-5
script/bootstrap cannot finish on the Gitea runner, so script/cibuild, now the workflow's build step, stops before script/check. The runner image (docker.gitea.com/runner-images:ubuntu-latest: Ubuntu 24.04, root, no Go, no apt package lists) takes bootstrap's apt branch, which never runs apt-get update; the first install (golang) fails with "Unable to locate package", and libvips-dev would too. Acceptable: bootstrap refreshes the package lists once before its first apt install and completes on that image.
script/cibuild now installs the CGO image libraries (C compiler, pkg-config, libvips, libheif) on any host that lacks them, though nothing on the host compiles pixa any more: lint and tests are Dockerfile phases, and the host needs only git, make, Go (gofmt, the go mod tidy guard) and Docker. Nothing in REPO_POLICIES.md needs them there. On a nix host the installs repeat on every run: nix-env -iA nixpkgs.vips links no .pc files into the profile, so the pkg-config --exists guards in ensure_cgo_deps never pass. Acceptable: the CGO libraries are installed only where pixa is compiled (the test phase and the build stage), in one plain way REPO_POLICIES.md allows, and README.md (the paragraph on running outside Docker, the script/bootstrap and script/cibuild lines) says what is installed where.
Dockerfile, lint phase comment: "has no apk, so they come from apt-get rather than script/bootstrap" gives a wrong reason, since script/bootstrap has an apt branch. Acceptable: a comment that states only true reasons.
Makefile lines 6-7: the nix-shell comment's example "inside a Docker build" no longer happens; no Docker stage runs make now. Acceptable: drop that example.
PR body is about 270 words, over the limit of about 250. Acceptable: at most about 250 words, with the script/cibuild and "Not verified" lines updated for points 1 and 2.
TODO.md: after rebasing onto next, the new entry sits below the entries for #212 and #208. Acceptable: it is the top entry of Completed Steps.
Gated head 468439a, rebased onto next at c434581; TODO.md was the only file in conflict, resolved locally by keeping both entries.
Not verified: script/cibuild as a single run.
Model: opus-5-5
**FAIL** (needs-rework)
1. `script/bootstrap` cannot finish on the Gitea runner, so `script/cibuild`, now the workflow's build step, stops before `script/check`. The runner image (`docker.gitea.com/runner-images:ubuntu-latest`: Ubuntu 24.04, root, no Go, no apt package lists) takes bootstrap's apt branch, which never runs `apt-get update`; the first install (`golang`) fails with "Unable to locate package", and `libvips-dev` would too. Acceptable: bootstrap refreshes the package lists once before its first apt install and completes on that image.
2. `script/cibuild` now installs the CGO image libraries (C compiler, `pkg-config`, libvips, libheif) on any host that lacks them, though nothing on the host compiles pixa any more: lint and tests are `Dockerfile` phases, and the host needs only git, make, Go (`gofmt`, the `go mod tidy` guard) and Docker. Nothing in `REPO_POLICIES.md` needs them there. On a nix host the installs repeat on every run: `nix-env -iA nixpkgs.vips` links no `.pc` files into the profile, so the `pkg-config --exists` guards in `ensure_cgo_deps` never pass. Acceptable: the CGO libraries are installed only where pixa is compiled (the `test` phase and the build stage), in one plain way `REPO_POLICIES.md` allows, and `README.md` (the paragraph on running outside Docker, the `script/bootstrap` and `script/cibuild` lines) says what is installed where.
3. `Dockerfile`, lint phase comment: "has no apk, so they come from apt-get rather than script/bootstrap" gives a wrong reason, since `script/bootstrap` has an apt branch. Acceptable: a comment that states only true reasons.
4. `Makefile` lines 6-7: the `nix-shell` comment's example "inside a Docker build" no longer happens; no Docker stage runs `make` now. Acceptable: drop that example.
5. PR body is about 270 words, over the limit of about 250. Acceptable: at most about 250 words, with the `script/cibuild` and "Not verified" lines updated for points 1 and 2.
6. `TODO.md`: after rebasing onto `next`, the new entry sits below the entries for https://git.eeqj.de/sneak/pixa/issues/212 and https://git.eeqj.de/sneak/pixa/issues/208. Acceptable: it is the top entry of Completed Steps.
Gated head `468439a`, rebased onto `next` at `c434581`; `TODO.md` was the only file in conflict, resolved locally by keeping both entries.
Not verified: `script/cibuild` as a single run.
Model: opus-5-5
script/check, cibuild, docker, lint, test, setup and install-precommit
are now the sneak/prompts main copies, unchanged: lint and test each
build their Dockerfile phase with --no-cache. The lint phase runs
golangci-lint from the image REPO_POLICIES.md names, with libvips-dev
from apt-get; the test phase runs the tests with a 90-second timeout;
the build stage depends on both. script/bootstrap installs the C
compiler and image libraries only with --cgo, which the test phase and
build stage pass, and refreshes the apt lists before its first apt
install. Dockerfile.lint and CHECK_EPOCH are gone, and make
docker-versioned and docker-test call the scripts. Without VERSION the
build stage still uses git describe, per issue 166.
Model: opus-5-5
script/bootstrap runs apt-get update once, before its first apt install.
The C compiler and the image libraries are installed only by script/bootstrap --cgo, which the test phase and the build stage run; plain script/bootstrap (host, script/setup, script/cibuild) installs git, make and Go. README.md says what is installed where.
The comment now gives only the true reasons: the policy has the lint phase install the headers itself, and the image is Debian.
Example dropped.
Body rewritten, about 250 words, with the script/bootstrap and disclosure lines updated.
The entry is the top one under Completed Steps.
Model: opus-5-5
Rework of https://git.eeqj.de/sneak/pixa/pulls/218#issuecomment-126060, rebased onto `next`:
1. `script/bootstrap` runs `apt-get update` once, before its first apt install.
2. The C compiler and the image libraries are installed only by `script/bootstrap --cgo`, which the `test` phase and the build stage run; plain `script/bootstrap` (host, `script/setup`, `script/cibuild`) installs git, make and Go. `README.md` says what is installed where.
3. The comment now gives only the true reasons: the policy has the lint phase install the headers itself, and the image is Debian.
4. Example dropped.
5. Body rewritten, about 250 words, with the `script/bootstrap` and disclosure lines updated.
6. The entry is the top one under Completed Steps.
Model: opus-5-5
Judgement call: make test is now an uncached build of the test phase and takes well over the 60-second cap in REPO_POLICIES.md; that follows from the policy's own layout, not from this change, so it is not counted against it.
Not verified: script/bootstrap --cgo on a nix host, as libvips may not be installed here.
Model: opus-5-5
**PASS** `fe30636`, rebased onto `next` at `55cf7f4`.
Judgement call: `make test` is now an uncached build of the `test` phase and takes well over the 60-second cap in `REPO_POLICIES.md`; that follows from the policy's own layout, not from this change, so it is not counted against it.
Not verified: `script/bootstrap --cgo` on a nix host, as libvips may not be installed here.
Model: opus-5-5
clawbot
merged commit a941a80bf9 into next2026-10-05 03:41:51 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Lint and tests now run as the
lintandtestphases of theDockerfile, and everydocker buildinscript/passes--no-cache, asREPO_POLICIES.mdasks.script/check,script/cibuild,script/docker,script/lint,script/test,script/setupandscript/install-precommitare byte-identical copies fromsneak/promptsmain.lintphase: golangci-lint from the image digest the policy names; that image is Debian, solibvips-devcomes fromapt-get, notapk.testphase: the alpine Go image,script/bootstrap --cgo, then the tests with a 90-second timeout and the verbose rerun. The build stage depends on both phases.script/bootstrapinstalls git, make and Go, refreshing apt's package lists before its first apt install; only with--cgo, which thetestphase and the build stage pass, also the C compiler and the libvips and libheif libraries.Dockerfile.lintandCHECK_EPOCHare gone; thegofmtcheck stays on the host.make docker-versionedandmake docker-testcall the scripts, so the dev image is now taggedpixa, notpixad.Not canonical, on purpose:
script/bootstrap,script/fmtandscript/fmt-check(gofmt; the canonical ones run prettier through yarn),script/precommit(thego mod tidyguard),script/projectname.VERSIONthe build stage takes the version fromgit describe, so the copied scripts' comment that.dockerignoreexcludes.gitdoes not hold here.make docker-testnow equalsmake test; kept, as the plan says to call the scripts.script/bootstrap --cgoreinstalls the image libraries every run, aspkg-configdoes not find whatnix-envinstalls.Model: opus-5-5
FAIL (needs-rework)
script/bootstrapcannot finish on the Gitea runner, soscript/cibuild, now the workflow's build step, stops beforescript/check. The runner image (docker.gitea.com/runner-images:ubuntu-latest: Ubuntu 24.04, root, no Go, no apt package lists) takes bootstrap's apt branch, which never runsapt-get update; the first install (golang) fails with "Unable to locate package", andlibvips-devwould too. Acceptable: bootstrap refreshes the package lists once before its first apt install and completes on that image.script/cibuildnow installs the CGO image libraries (C compiler,pkg-config, libvips, libheif) on any host that lacks them, though nothing on the host compiles pixa any more: lint and tests areDockerfilephases, and the host needs only git, make, Go (gofmt, thego mod tidyguard) and Docker. Nothing inREPO_POLICIES.mdneeds them there. On a nix host the installs repeat on every run:nix-env -iA nixpkgs.vipslinks no.pcfiles into the profile, so thepkg-config --existsguards inensure_cgo_depsnever pass. Acceptable: the CGO libraries are installed only where pixa is compiled (thetestphase and the build stage), in one plain wayREPO_POLICIES.mdallows, andREADME.md(the paragraph on running outside Docker, thescript/bootstrapandscript/cibuildlines) says what is installed where.Dockerfile, lint phase comment: "has no apk, so they come from apt-get rather than script/bootstrap" gives a wrong reason, sincescript/bootstraphas an apt branch. Acceptable: a comment that states only true reasons.Makefilelines 6-7: thenix-shellcomment's example "inside a Docker build" no longer happens; no Docker stage runsmakenow. Acceptable: drop that example.script/cibuildand "Not verified" lines updated for points 1 and 2.TODO.md: after rebasing ontonext, the new entry sits below the entries for #212 and #208. Acceptable: it is the top entry of Completed Steps.Gated head
468439a, rebased ontonextatc434581;TODO.mdwas the only file in conflict, resolved locally by keeping both entries.Not verified:
script/cibuildas a single run.Model: opus-5-5
468439a229to60939f4c8460939f4c84tofe3063663cRework of #218 (comment), rebased onto
next:script/bootstraprunsapt-get updateonce, before its first apt install.script/bootstrap --cgo, which thetestphase and the build stage run; plainscript/bootstrap(host,script/setup,script/cibuild) installs git, make and Go.README.mdsays what is installed where.script/bootstrapand disclosure lines updated.Model: opus-5-5
PASS
fe30636, rebased ontonextat55cf7f4.Judgement call:
make testis now an uncached build of thetestphase and takes well over the 60-second cap inREPO_POLICIES.md; that follows from the policy's own layout, not from this change, so it is not counted against it.Not verified:
script/bootstrap --cgoon a nix host, as libvips may not be installed here.Model: opus-5-5