1 Commits
Author SHA1 Message Date
sneak 8451b38159 Fold the August fleet findings into the policies, or drop them (closes #62)
check / check (push) Failing after 1s
Three findings from 2026-08-09 were rules a repository must follow that
`prompts/REPO_POLICIES.md` did not yet state, and are now added where a
reader would look: `golangci-lint config verify` is never run from
`make lint`, the lint phase or CI, since it fetches its schema over the
network; a new or changed check is proven by planting a defect it must
catch; and a workflow step that runs only on `main` is first run from
the feature branch. The issue records why every other finding was
dropped.

Model: opus-5-5
2026-10-04 09:34:26 +00:00
2 changed files with 13 additions and 14 deletions
+6 -8
View File
@@ -22,14 +22,12 @@ fmt-check, and commit.
# Completed Steps # Completed Steps
- 2026-10-04: Went through the fleet findings recorded on 2026-08-09 (issue 62) - 2026-10-04: Went through the fleet findings recorded on 2026-08-09 (issue 62)
and added the two rules `REPO_POLICIES.md` did not yet state: a new or changed and added the three rules `REPO_POLICIES.md` did not yet state:
check is proven by planting a defect it must catch; and a change to a separate `golangci-lint config verify` is never run from `make lint`, the lint phase or
workflow limited to `main` is first run from the feature branch, added to that CI; a new or changed check is proven by planting a defect it must catch; and a
workflow's `branches` list and removed again before merging. The other workflow step that runs only on `main` is first run from the feature branch.
findings were already stated, replaced by `--no-cache`, about git worktrees, The other findings were already stated, replaced by `--no-cache`, about git
about how agents work together, or no longer true (the pinned golangci-lint worktrees, or about how agents work together; the issue gives each reason.
checks `config verify` against a schema built into it and fetches nothing);
the issue gives each reason.
- 2026-10-04: The note under the canonical Go `Dockerfile` example in - 2026-10-04: The note under the canonical Go `Dockerfile` example in
`REPO_POLICIES.md` now installs lint-phase system libraries with `apt-get` `REPO_POLICIES.md` now installs lint-phase system libraries with `apt-get`
under their Debian package names (issue 83). The `golangci/golangci-lint` under their Debian package names (issue 83). The `golangci/golangci-lint`
+7 -6
View File
@@ -277,12 +277,10 @@ style conventions are in separate documents:
carry the same guarantee, because its gate phases may come from the cache. The carry the same guarantee, because its gate phases may come from the cache. The
image build is uncached and so runs the gate phases a second time. That is the image build is uncached and so runs the gate phases a second time. That is the
price of the rule above, and it is worth paying: the image that ships is built price of the rule above, and it is worth paying: the image that ships is built
from a run of its own gates rather than from a cache entry. A separate from a run of its own gates rather than from a cache entry. A workflow step
workflow limited to `main` by a `branches` list under `on: push` cannot be that runs only on `main` cannot be checked by review. Before merging it,
checked by review: to try a change to it, add the feature branch to that list temporarily add the feature branch to its trigger and push, keeping any job
and push, then remove the branch from the list again before merging. Keep any that publishes behind `if: github.ref_name == 'main'`.
job in it that publishes behind `if: github.ref_name == 'main'`, so the run
from the feature branch publishes nothing.
- Use platform-standard formatters: `black` for Python, `prettier` for - Use platform-standard formatters: `black` for Python, `prettier` for
JS/CSS/Markdown/HTML, `go fmt` for Go. Always use default configuration with JS/CSS/Markdown/HTML, `go fmt` for Go. Always use default configuration with
@@ -490,6 +488,9 @@ style conventions are in separate documents:
the two prompted the change: the canonical copy can name linters that an older the two prompted the change: the canonical copy can name linters that an older
golangci-lint rejects, and a newer golangci-lint can add linters that golangci-lint rejects, and a newer golangci-lint can add linters that
`default: all` switches on until the canonical copy disables them. `default: all` switches on until the canonical copy disables them.
`golangci-lint config verify` is never run from `make lint`, the lint phase or
CI: it fetches the schema it checks against over the network, unpinned, on
every run.
- **`script/bootstrap` installs a pinned tool by comparing versions, never by - **`script/bootstrap` installs a pinned tool by comparing versions, never by
testing presence.** An `if ! command -v <tool>; then install; fi` guard tests testing presence.** An `if ! command -v <tool>; then install; fi` guard tests