From dd4027b907ef99cdc3187c215cc4d610b7a11efc Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Sun, 4 Oct 2026 15:14:44 +0200 Subject: [PATCH] Fold the August fleet findings into the policies, or drop them (closes #62) Of the cross-repository findings recorded on 2026-08-09, two were rules a repository must follow that `prompts/REPO_POLICIES.md` did not yet state, and each now sits in the paragraph a reader would be in. A new or changed check is proven by planting a defect it must catch and watching the run fail, since a green run alone does not show the check ran. A separate workflow limited to `main` by a `branches` list is first run from the feature branch by adding that branch to the list and removing it before merging, with any publishing job kept behind `if: github.ref_name == 'main'`. The other findings are dropped, each with its reason on the issue; the `config verify` warning goes by sneak's ruling on https://git.eeqj.de/sneak/prompts/issues/40 that there is no config check step. Model: opus-5-5 --- TODO.md | 11 +++++++++++ prompts/REPO_POLICIES.md | 10 +++++++++- 2 files changed, 20 insertions(+), 1 deletion(-) diff --git a/TODO.md b/TODO.md index 0717a5f..1434757 100644 --- a/TODO.md +++ b/TODO.md @@ -21,6 +21,17 @@ fmt-check, and commit. # Completed Steps +- 2026-10-04: Went through the fleet findings recorded on 2026-08-09 (issue 62) + and added the two rules `REPO_POLICIES.md` did not yet state: a new or changed + check is proven by planting a defect it must catch; and a change to a separate + workflow limited to `main` is first run from the feature branch, added to that + workflow's `branches` list and removed again before merging. The other + findings were already stated, replaced by `--no-cache`, about git worktrees, + or about how agents work together. The warning against + `golangci-lint config verify` is dropped because sneak ruled on + https://git.eeqj.de/sneak/prompts/issues/40 (2026-08-10) that there is no + config check step and the config is assumed valid; a vendored `.golangci.yml` + stays byte-identical to the canonical copy. The issue gives each reason. - 2026-10-04: `REPO_POLICIES.md` now says which `Dockerfile` stages run `script/bootstrap` (issue 90). The gate phases and the build stage start from their pinned base images and install what those images lack either inline, as diff --git a/prompts/REPO_POLICIES.md b/prompts/REPO_POLICIES.md index 8c72a7b..20382d1 100644 --- a/prompts/REPO_POLICIES.md +++ b/prompts/REPO_POLICIES.md @@ -160,6 +160,9 @@ style conventions are in separate documents: not evidence that anything ran: a sub-second build reporting success is a cache hit, not a result. Never invalidate by pruning — `docker builder prune` and friends destroy a build cache shared with every other build on the host. + When a check is added or changed, prove it works by planting a defect it must + catch and watching the run fail on it, then revert the defect. A green run + alone shows neither that the check ran nor that it covers what it should. - **The gate phases are separate stages, and the build stage depends on both.** The lint phase is based on the `golangci/golangci-lint` image (pinned by @@ -283,7 +286,12 @@ style conventions are in separate documents: carry the same guarantee, because its gate phases may come from the cache. The image build is uncached and so runs the gate phases a second time. That is the price of the rule above, and it is worth paying: the image that ships is built - from a run of its own gates rather than from a cache entry. + from a run of its own gates rather than from a cache entry. A separate + workflow limited to `main` by a `branches` list under `on: push` cannot be + checked by review: to try a change to it, add the feature branch to that list + and push, then remove the branch from the list again before merging. Keep any + job in it that publishes behind `if: github.ref_name == 'main'`, so the run + from the feature branch publishes nothing. - Use platform-standard formatters: `black` for Python, `prettier` for JS/CSS/Markdown/HTML, `go fmt` for Go. Always use default configuration with