1 Commits
Author SHA1 Message Date
sneak 6d7c39cdd8 Fold the August fleet findings into the policies, or drop them (closes #62)
check / check (push) Failing after 1s
Two findings from 2026-08-09 were rules a repository must follow that
`prompts/REPO_POLICIES.md` did not yet state, and are now added where a
reader would look: a new or changed check is proven by planting a defect
it must catch; and a change to a separate workflow limited to `main` by
a `branches` list is first run from the feature branch, added to that
list and removed again before merging. The issue records why every
other finding was dropped, including the warning against
`golangci-lint config verify`: the pinned release checks against a
schema built into it and fetches nothing.

Model: opus-5-5
2026-10-04 10:04:31 +00:00
2 changed files with 14 additions and 13 deletions
+8 -6
View File
@@ -22,12 +22,14 @@ fmt-check, and commit.
# Completed Steps # Completed Steps
- 2026-10-04: Went through the fleet findings recorded on 2026-08-09 (issue 62) - 2026-10-04: Went through the fleet findings recorded on 2026-08-09 (issue 62)
and added the three rules `REPO_POLICIES.md` did not yet state: and added the two rules `REPO_POLICIES.md` did not yet state: a new or changed
`golangci-lint config verify` is never run from `make lint`, the lint phase or check is proven by planting a defect it must catch; and a change to a separate
CI; a new or changed check is proven by planting a defect it must catch; and a workflow limited to `main` is first run from the feature branch, added to that
workflow step that runs only on `main` is first run from the feature branch. workflow's `branches` list and removed again before merging. The other
The other findings were already stated, replaced by `--no-cache`, about git findings were already stated, replaced by `--no-cache`, about git worktrees,
worktrees, or about how agents work together; the issue gives each reason. about how agents work together, or no longer true (the pinned golangci-lint
checks `config verify` against a schema built into it and fetches nothing);
the issue gives each reason.
- 2026-10-04: The note under the canonical Go `Dockerfile` example in - 2026-10-04: The note under the canonical Go `Dockerfile` example in
`REPO_POLICIES.md` now installs lint-phase system libraries with `apt-get` `REPO_POLICIES.md` now installs lint-phase system libraries with `apt-get`
under their Debian package names (issue 83). The `golangci/golangci-lint` under their Debian package names (issue 83). The `golangci/golangci-lint`
+6 -7
View File
@@ -277,10 +277,12 @@ style conventions are in separate documents:
carry the same guarantee, because its gate phases may come from the cache. The carry the same guarantee, because its gate phases may come from the cache. The
image build is uncached and so runs the gate phases a second time. That is the image build is uncached and so runs the gate phases a second time. That is the
price of the rule above, and it is worth paying: the image that ships is built price of the rule above, and it is worth paying: the image that ships is built
from a run of its own gates rather than from a cache entry. A workflow step from a run of its own gates rather than from a cache entry. A separate
that runs only on `main` cannot be checked by review. Before merging it, workflow limited to `main` by a `branches` list under `on: push` cannot be
temporarily add the feature branch to its trigger and push, keeping any job checked by review: to try a change to it, add the feature branch to that list
that publishes behind `if: github.ref_name == 'main'`. and push, then remove the branch from the list again before merging. Keep any
job in it that publishes behind `if: github.ref_name == 'main'`, so the run
from the feature branch publishes nothing.
- Use platform-standard formatters: `black` for Python, `prettier` for - Use platform-standard formatters: `black` for Python, `prettier` for
JS/CSS/Markdown/HTML, `go fmt` for Go. Always use default configuration with JS/CSS/Markdown/HTML, `go fmt` for Go. Always use default configuration with
@@ -488,9 +490,6 @@ style conventions are in separate documents:
the two prompted the change: the canonical copy can name linters that an older the two prompted the change: the canonical copy can name linters that an older
golangci-lint rejects, and a newer golangci-lint can add linters that golangci-lint rejects, and a newer golangci-lint can add linters that
`default: all` switches on until the canonical copy disables them. `default: all` switches on until the canonical copy disables them.
`golangci-lint config verify` is never run from `make lint`, the lint phase or
CI: it fetches the schema it checks against over the network, unpinned, on
every run.
- **`script/bootstrap` installs a pinned tool by comparing versions, never by - **`script/bootstrap` installs a pinned tool by comparing versions, never by
testing presence.** An `if ! command -v <tool>; then install; fi` guard tests testing presence.** An `if ! command -v <tool>; then install; fi` guard tests