Fold the August fleet findings into the policies, or drop them (closes #62) #99

Merged
clawbot merged 1 commits from issue-62-fold-fleet-findings into next 2026-10-04 15:14:45 +02:00
Collaborator

Implements #62. Of the findings recorded on 2026-08-09, two were rules a repository must follow that prompts/REPO_POLICIES.md did not yet state. Each is added to the paragraph a reader would already be in:

  • --no-cache paragraph: a new or changed check is proven by planting a defect it must catch and watching the run fail. A green run alone does not show that the check ran or that it covers what it should.
  • Gitea Actions workflow paragraph: a separate workflow limited to main by a branches list under on: push cannot be checked by review. To try a change to it, the feature branch is added to that list and removed again before merging, with any job that publishes kept behind if: github.ref_name == 'main'.

Nothing else in the policies changes. The disposition comment on the issue gives each dropped finding its reason. The warning against golangci-lint config verify is dropped because sneak ruled on #40 (2026-08-10) that there is no config check step and the config is assumed valid; a vendored .golangci.yml stays byte-identical to the canonical copy. TODO.md gets a Completed Steps entry.

The root REPO_POLICIES.md is a symlink to prompts/REPO_POLICIES.md, so it shows no change of its own. last_modified was already today's date.

Judgement call: the finding about the upload-artifact version bump is folded only as the rule about a workflow limited to main. I did not add a separate "pin the version already in use" rule, because the bump broke production only because nothing could run that workflow before merge.

Model: opus-5-5

Implements https://git.eeqj.de/sneak/prompts/issues/62. Of the findings recorded on 2026-08-09, two were rules a repository must follow that `prompts/REPO_POLICIES.md` did not yet state. Each is added to the paragraph a reader would already be in: - `--no-cache` paragraph: a new or changed check is proven by planting a defect it must catch and watching the run fail. A green run alone does not show that the check ran or that it covers what it should. - Gitea Actions workflow paragraph: a separate workflow limited to `main` by a `branches` list under `on: push` cannot be checked by review. To try a change to it, the feature branch is added to that list and removed again before merging, with any job that publishes kept behind `if: github.ref_name == 'main'`. Nothing else in the policies changes. The disposition comment on the issue gives each dropped finding its reason. The warning against `golangci-lint config verify` is dropped because sneak ruled on https://git.eeqj.de/sneak/prompts/issues/40 (2026-08-10) that there is no config check step and the config is assumed valid; a vendored `.golangci.yml` stays byte-identical to the canonical copy. `TODO.md` gets a Completed Steps entry. The root `REPO_POLICIES.md` is a symlink to `prompts/REPO_POLICIES.md`, so it shows no change of its own. `last_modified` was already today's date. Judgement call: the finding about the `upload-artifact` version bump is folded only as the rule about a workflow limited to `main`. I did not add a separate "pin the version already in use" rule, because the bump broke production only because nothing could run that workflow before merge. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 11:36:09 +02:00
clawbot self-assigned this 2026-10-04 11:36:09 +02:00
Author
Collaborator

FAIL, needs rework.

  1. prompts/REPO_POLICIES.md, the sentence added at the end of the .golangci.yml paragraph: the reason it gives is false for the release the policies pin. golangci-lint v2.14.0 checks config verify against a schema built into the binary and fetches nothing: run with networking turned off, it still rejects a config written in the old layout. The sentence therefore bans the one command that catches a config golangci-lint otherwise ignores without a word (golangci-lint run still reports 0 issues. on such a file). The same false reason is repeated in the TODO.md entry, the commit message, the PR body and line 1 of the disposition comment on #62. Acceptable: remove the sentence and record finding 1 as a drop, because the pinned release no longer fetches its schema, and correct the other four places to match. Whether config verify should then run in the lint phase is a question for the owner, not for this PR.

  2. prompts/REPO_POLICIES.md, the two sentences added at the end of the Gitea Actions workflow paragraph: they do not fit the workflow that paragraph describes. The canonical workflow is triggered by on: [push], which has no branch list, so it already runs on every branch. The paragraph also says the workflow has only two steps: the checkout and script/cibuild. So it has no step that runs only on main, and its trigger has no list to add a branch to. In a workflow triggered this way, a step can be limited to main only by an if: condition, and adding the branch to the trigger would not make that step run. The wording adds to the confusion: a step has no trigger of its own (the workflow has one), and the text never says to remove the branch again before merging. Acceptable: name the case the rule covers, which is a separate workflow (or a job) limited to main by a branches list under on: push. Say to add the feature branch to that list and to remove it before merging, and keep any job that publishes behind if: github.ref_name == 'main'. Keep it to at most two plain sentences, and update line 12 of the disposition comment to match.

Model: opus-5-5

FAIL, needs rework. 1. `prompts/REPO_POLICIES.md`, the sentence added at the end of the `.golangci.yml` paragraph: the reason it gives is false for the release the policies pin. golangci-lint v2.14.0 checks `config verify` against a schema built into the binary and fetches nothing: run with networking turned off, it still rejects a config written in the old layout. The sentence therefore bans the one command that catches a config golangci-lint otherwise ignores without a word (`golangci-lint run` still reports `0 issues.` on such a file). The same false reason is repeated in the `TODO.md` entry, the commit message, the PR body and line 1 of the disposition comment on https://git.eeqj.de/sneak/prompts/issues/62. Acceptable: remove the sentence and record finding 1 as a drop, because the pinned release no longer fetches its schema, and correct the other four places to match. Whether `config verify` should then run in the lint phase is a question for the owner, not for this PR. 2. `prompts/REPO_POLICIES.md`, the two sentences added at the end of the Gitea Actions workflow paragraph: they do not fit the workflow that paragraph describes. The canonical workflow is triggered by `on: [push]`, which has no branch list, so it already runs on every branch. The paragraph also says the workflow has only two steps: the checkout and `script/cibuild`. So it has no step that runs only on `main`, and its trigger has no list to add a branch to. In a workflow triggered this way, a step can be limited to `main` only by an `if:` condition, and adding the branch to the trigger would not make that step run. The wording adds to the confusion: a step has no trigger of its own (the workflow has one), and the text never says to remove the branch again before merging. Acceptable: name the case the rule covers, which is a separate workflow (or a job) limited to `main` by a `branches` list under `on: push`. Say to add the feature branch to that list and to remove it before merging, and keep any job that publishes behind `if: github.ref_name == 'main'`. Keep it to at most two plain sentences, and update line 12 of the disposition comment to match. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-04 11:54:33 +02:00
Author
Collaborator

For finding 1: whether to run golangci-lint config verify is already decided. sneak ruled on #40 (2026-08-10): "Don't do the config check step. That's not necessary. We can assume the config is valid." The drop reason should cite that ruling, not the schema fetch.

Model: opus-5-5

For finding 1: whether to run `golangci-lint config verify` is already decided. sneak ruled on https://git.eeqj.de/sneak/prompts/issues/40 (2026-08-10): "Don't do the config check step. That's not necessary. We can assume the config is valid." The drop reason should cite that ruling, not the schema fetch. Model: opus-5-5
clawbot force-pushed issue-62-fold-fleet-findings from 8451b38159 to 6d7c39cdd8 2026-10-04 12:05:33 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-04 12:06:17 +02:00
Author
Collaborator

Rework pushed.

  1. Done: sentence removed, finding 1 recorded as a drop, and the TODO.md entry, commit message, PR body and disposition comment on #62 corrected.
  2. Done in two sentences, with line 12 of the disposition comment updated to match. Judgement call: they name a separate workflow, not a job, since only a workflow's on: push can carry a branches list.

Model: opus-5-5

Rework pushed. 1. Done: sentence removed, finding 1 recorded as a drop, and the `TODO.md` entry, commit message, PR body and disposition comment on https://git.eeqj.de/sneak/prompts/issues/62 corrected. 2. Done in two sentences, with line 12 of the disposition comment updated to match. Judgement call: they name a separate workflow, not a job, since only a workflow's `on: push` can carry a `branches` list. Model: opus-5-5
Author
Collaborator

FAIL, needs rework.

  1. The reason given for dropping finding 1, in four places: line 1 of the disposition comment on #62 (#62 (comment)), the TODO.md Completed Steps entry ("no longer true (the pinned golangci-lint checks config verify against a schema built into it and fetches nothing)"), the commit message, and the PR body. Each says the warning against golangci-lint config verify is dropped because the pinned release fetches nothing. That reads as clearing the way to add a config verify step. The owner has already ruled that there is no such step, on #40 (2026-08-10): "Don't do the config check step. That's not necessary. We can assume the config is valid." This was pointed out on this PR before the rework, and the rework did not take it up. Acceptable: in all four places, give that ruling as the reason the warning is dropped, with a link to it. There is no config check step, and the vendored .golangci.yml is assumed valid because it stays byte-identical to the canonical copy. Leave out the point about the schema being built in.

Model: opus-5-5

FAIL, needs rework. 1. The reason given for dropping finding 1, in four places: line 1 of the disposition comment on https://git.eeqj.de/sneak/prompts/issues/62 (https://git.eeqj.de/sneak/prompts/issues/62#issuecomment-122443), the `TODO.md` Completed Steps entry ("no longer true (the pinned golangci-lint checks `config verify` against a schema built into it and fetches nothing)"), the commit message, and the PR body. Each says the warning against `golangci-lint config verify` is dropped because the pinned release fetches nothing. That reads as clearing the way to add a `config verify` step. The owner has already ruled that there is no such step, on https://git.eeqj.de/sneak/prompts/issues/40 (2026-08-10): "Don't do the config check step. That's not necessary. We can assume the config is valid." This was pointed out on this PR before the rework, and the rework did not take it up. Acceptable: in all four places, give that ruling as the reason the warning is dropped, with a link to it. There is no config check step, and the vendored `.golangci.yml` is assumed valid because it stays byte-identical to the canonical copy. Leave out the point about the schema being built in. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-04 12:18:51 +02:00
clawbot force-pushed issue-62-fold-fleet-findings from 6d7c39cdd8 to ad0e9bfc3c 2026-10-04 12:34:59 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-04 12:35:04 +02:00
Author
Collaborator

Rework pushed.

  1. Done: the reason for dropping finding 1 is now sneak's ruling on #40, plus the byte-identical vendored .golangci.yml, in the disposition comment on #62, the TODO.md entry, the commit message and the PR body.

Model: opus-5-5

Rework pushed. 1. Done: the reason for dropping finding 1 is now sneak's ruling on https://git.eeqj.de/sneak/prompts/issues/40, plus the byte-identical vendored `.golangci.yml`, in the disposition comment on https://git.eeqj.de/sneak/prompts/issues/62, the `TODO.md` entry, the commit message and the PR body. Model: opus-5-5
Author
Collaborator

FAIL, needs rebase. The substance passed.

  1. TODO.md, Completed Steps: Gitea reports the branch as conflicting with current next, which has since added the entries for #98 and #88 at the top. Acceptable: rebase onto current next and push, with the entry for this change at the top of Completed Steps, above those two. The union merge that next now applies to TODO.md puts it below them during a rebase, so move it up by hand.

Model: opus-5-5

FAIL, needs rebase. The substance passed. 1. `TODO.md`, Completed Steps: Gitea reports the branch as conflicting with current `next`, which has since added the entries for https://git.eeqj.de/sneak/prompts/issues/98 and https://git.eeqj.de/sneak/prompts/issues/88 at the top. Acceptable: rebase onto current `next` and push, with the entry for this change at the top of Completed Steps, above those two. The union merge that `next` now applies to `TODO.md` puts it below them during a rebase, so move it up by hand. Model: opus-5-5
clawbot added needs-rebase and removed needs-review labels 2026-10-04 14:19:50 +02:00
clawbot force-pushed issue-62-fold-fleet-findings from ad0e9bfc3c to 4928c6a890 2026-10-04 14:35:13 +02:00 Compare
clawbot added needs-review and removed needs-rebase labels 2026-10-04 14:35:25 +02:00
Author
Collaborator

Rebased onto next: in TODO.md this branch's Completed Steps entry is moved back to the top, above the two entries that landed since; nothing else changed.

Model: opus-5-5

Rebased onto `next`: in `TODO.md` this branch's Completed Steps entry is moved back to the top, above the two entries that landed since; nothing else changed. Model: opus-5-5
clawbot added 1 commit 2026-10-04 14:51:26 +02:00
Two findings from 2026-08-09 were rules a repository must follow that
`prompts/REPO_POLICIES.md` did not yet state, and are now added where a
reader would look: a new or changed check is proven by planting a defect
it must catch; and a change to a separate workflow limited to `main` by
a `branches` list is first run from the feature branch, added to that
list and removed again before merging. The issue records why every
other finding was dropped. The warning against `golangci-lint config
verify` is dropped because sneak ruled on
#40 (2026-08-10) that there is
no config check step and the config is assumed valid; a vendored
`.golangci.yml` stays byte-identical to the canonical copy.

Model: opus-5-5
clawbot force-pushed issue-62-fold-fleet-findings from 4928c6a890 to f61b2084c7 2026-10-04 14:51:26 +02:00 Compare
Author
Collaborator

Rebased onto next; resolved TODO.md by keeping every Completed Steps entry, with this branch's entry moved back to the top above the one from #90. Nothing else changed.

Model: opus-5-5

Rebased onto `next`; resolved `TODO.md` by keeping every Completed Steps entry, with this branch's entry moved back to the top above the one from https://git.eeqj.de/sneak/prompts/issues/90. Nothing else changed. Model: opus-5-5
Author
Collaborator

PASS: the rebase changed only TODO.md, where every Completed Steps entry is kept whole and newest first with this change on top, and the change itself still meets the plan on #62.

Model: opus-5-5

PASS: the rebase changed only `TODO.md`, where every Completed Steps entry is kept whole and newest first with this change on top, and the change itself still meets the plan on https://git.eeqj.de/sneak/prompts/issues/62. Model: opus-5-5
clawbot merged commit dd4027b907 into next 2026-10-04 15:14:45 +02:00
clawbot deleted branch issue-62-fold-fleet-findings 2026-10-04 15:14:46 +02:00
Sign in to join this conversation.