check / check (push) Waiting to run
Every PR adds an entry at the top of Completed Steps in TODO.md, so each merge to next left every other open PR conflicting there. A root .gitattributes now marks TODO.md merge=union, so two branches inserting at the same place merge without a conflict. Git now never reports a conflict in TODO.md: a real conflict elsewhere keeps both versions of the line, and two new entries that share an identical line end up one inside the other. The .gitattributes comment and the TODO.md entry say to read the merged entries after every merge or rebase. This applies to this repository only; nothing canonical changes. Model: opus-5-5
11 KiB
11 KiB
Workflow
- branch (from
main) - do the work in Next Step
- move Next Step to the top of Completed Steps
- move the top item of Future Steps into Next Step
- commit (
TODO.mdchanges in the same commit as the work) - merge to
mainif the branch is not protected, otherwise open a PR - push
Status
pre-1.0
Next Step
Finish the two draft prompt documents in the working tree and commit them:
prompts/FIXUP_CLEAN.md (currently a near-empty stub) and prompts/FIXUP_REPORT.md
(a rough draft). Write the missing content, run make fmt so they pass
fmt-check, and commit.
Completed Steps
- 2026-10-04: Added a root
.gitattributesthat mergesTODO.mdwith git's union merge (issue 98), so two branches that each add an entry at the top of Completed Steps merge without a conflict. Git now never reports a conflict inTODO.md: a real conflict elsewhere keeps both versions of the line, and when two new entries share an identical line, one is inserted into the middle of the other, which a rebase can do to an entry already onnext. Read the merged entries after every merge or rebase. This applies to this repository only; no canonical file changed. - 2026-10-04: The note under the canonical Go
Dockerfileexample inREPO_POLICIES.mdnow installs lint-phase system libraries withapt-getunder their Debian package names (issue 83). Thegolangci/golangci-lintimage is Debian-based and has noapk, so the oldapk addinstruction failed as written. Nothing is pinned or unpinned; that is still open on issue 72. - 2026-10-04: Fixed the server lifecycle example in
prompts/GO_HTTP_SERVER_CONVENTIONS.md(issue 86). Only fx handles SIGINT and SIGTERM, andRun()inmainexits with the shutdown's exit code. A listen error asks fx to shut down with exit code 1 throughfx.Shutdowner; a Sentry start failure is returned from the server's start hook instead of callingos.Exitfrom a goroutine, so the stop hooks of what had started still run. The server's stop hook shuts the HTTP server down within 5 seconds and fails when requests are still running. A new paragraph says who owns signals and the exit code. - 2026-10-04:
REPO_POLICIES.mdnow says how a Go tool a repo needs on the host is pinned (issue 37): installed withgo installpinned to a commit hash, never tracked as ago.modtool dependency or through atools.gofile. golangci-lint is unaffected, since no repo installs it on the host. - 2026-10-04: The canonical
.gitignoreand.dockerignorenow also keep outid_ecdsa_skandid_ed25519_sk, the private key filesssh-keygenwrites for keys backed by a hardware security key (issue 81). Their.pubhalves stay trackable. - 2026-10-04:
package.jsonnow has"license": "MIT", matchingLICENSE, so yarn no longer prints "No license field" whenscript/bootstrapruns it inside the Docker phases (issue 76). That was the only yarn warning there. - 2026-10-04:
REPO_POLICIES.mdnow states that guidance for coding agents lives in oneAGENTS.mdat the repository root, never under a file or directory named after one agent tool and never in separate memory files (issue 31). This retires the rule, still present in older vendored copies, that kept agent memory as committed files under.claude/memory/.AGENTS.mdjoins the list of files allowed in the root, and both checklists say so. - 2026-10-04: Rewrote the note under the canonical Go
make testexample inREPO_POLICIES.md(issue 77), which still named the cache-busting build argument that--no-cachereplaced. It now says where Go's test result cache can replay a pass: on a developer's machine, where the Makefile target runs, and not in thetestphase of theDockerfile, whose base image and earlier steps hold no result for the repo's tests. - 2026-10-04: The Makefile examples in the Go styleguide and the HTTP server
conventions now fall back to
devwhengit describeprints nothing (outside a git checkout, or where git is missing or refuses the checkout), instead of stamping an empty version (issue 74). The canonicalDockerfilealready fails on adevversion when.gitis in the build context. - 2026-10-04: The canonical
.dockerignorenow also keeps out each submodule'sconfig(issue 75). A submodule's git directory lives under.git/modules/, nested again for its own submodules, and itsconfigcan hold a credential just like.git/config. The pattern.git/modules/**/configcovers every depth and leaves the top-level.gitthatgit describereads untouched.REPO_POLICIES.mdand both checklists say so in the same words. - 2026-10-03: Fixed two defects in the canonical Go
Dockerfileexample (issue 73). The test phase now uses the Debian Go image, since-raceneeds cgo and the alpine image has no C compiler, so the phase failed before running a test. The stage that compiles runsgit config --system --add safe.directory /src, because a context sent as a tar stream keeps the sender's file owners and git refuses that checkout, leaving the version empty. Both checklists state that step in the same words. - 2026-10-03: Moved the canonical golangci-lint to v2.14.0, built with go1.27,
because v2.12.2 refuses to lint a module whose
godirective is 1.27 (issue 65). Releases from v2.13.0 deprecateexhaustructin favour ofexhaustruct_v5, whichdefault: allswitches on, so the canonical.golangci.ymlnow disablesexhaustruct_v5besideexhaustruct. v2.12.2 rejects that file, soREPO_POLICIES.mdand both repo checklists now say a repo sets the lint phase digest and re-vendors.golangci.ymlin one commit. - 2026-10-03: Brought the canonical
.gitignorelevel with.dockerignoreon secrets (issue 38): it now also ignoresprod.env-style*.envfiles,.envrc,*.p12,*.pfxand the extensionless SSH private keys, written to.gitignore's own rules (no**/prefix) and case-folded with character ranges.example.envandsample.envstay trackable through negations. - 2026-10-02: The image version now comes from git inside the build (issues 69
and 71), superseding the 2026-09-08 entry that excluded
.git. The canonical.dockerignoresends.gitbut keeps out.git/config, which can hold a credential. The Dockerfile example inREPO_POLICIES.mdinstallsgit, takes theVERSIONbuild argument when one is given and otherwisegit describe --tags --always, and fails when.gitexists but the version is empty,devorunknown; a plaindocker build .with no build arguments must succeed. This repo'sscript/dockerandscript/cibuildstill pass--build-arg VERSION, since its ownDockerfilecompiles nothing. - 2026-09-08: Moved linting and testing into Docker as phases of the main
Dockerfile, per the owner ruling on issue 40.script/lintandscript/testbuild one phase each by name with--no-cache— the same answer issue 26 got, so no separate cache-busting mechanism survives — and the final stage copies a harmless file from both, so the image cannot be built unless they pass. This also closes issue 30: a container has its own result cache and its own lock, so a lint verdict can no longer belong to another checkout. No separate lint Dockerfile, and nogolangci-lint config verifystep.script/checkruns the gates and nothing else, andscript/cibuildbootstraps first, since it is all CI runs andscript/fmt-checkis native. - 2026-09-08: Kept in-repo agent scratch out of the Docker build context and out
of version control:
.claude/is one full checkout of the repo per in-flight agent, and underCOPY . .all of it was reaching the image. Also closed the consequence of excluding.git—git describeyields an empty version inside a build stage without failing, soscript/dockerandscript/cibuildnow compute the version on the host and pass--build-arg VERSION. - 2026-09-08: Closed the secret exposure in the canonical
.dockerignore: a local.env,*.pemor*.keywas reaching the build context underCOPY . ., invisible to every git-based check. The patterns are now written to.dockerignore's own semantics —**/-prefixed so they hold at every depth, case-folded with character ranges — andREPO_POLICIES.mdrequires verifying by enumerating the image rather than by reading the file. - 2026-09-08: Made a pinned tool in
script/bootstrapactually reach the host.REPO_POLICIES.mdnow requires comparing the installed version against the pin rather than testingPATHpresence, and re-resolving the binary throughPATHafter installing, so a version bump cannot be a silent no-op and a shadowed install cannot report success. - 2026-09-08: Closed the false green in the canonical CI gate:
script/cibuildandscript/dockernow build with--no-cache, so the Dockerfile's check layers cannot be served from cache on an unchanged tree, and the text claiming a baredocker build .proves the checks ran is corrected inREPO_POLICIES.md, both checklists and the Go styleguide. - 2026-09-03: Added
-count=1to bothgo testinvocations in the canonical Gomake testexample inREPO_POLICIES.md, so the target cannot report a cached pass it did not earn, and documented that Go's test-result cache is a second, independent cache stacked below the Docker layer cache. - 2026-08-31: Migrated the canonical
.golangci.ymlfrom the deprecatedgomodguardtogomodguard_v2: the old linter is disabled by name (which is what silences the deprecation warning), the successor is named explicitly inlinters.enable, and it carries ablockedmodule list drawn only from decisions already recorded in the Go package defaults. - 2026-08-07: Set the canonical
.golangci.ymlto the org-standard v2-schema config already deployed byte-identical across the org's Go repos (settings underlinters.settingsso thresholds like lll/funlen/cyclop/dupl actually apply under golangci-lint v2). Recorded the canonical golangci-lint version (v2.12.2, commit-pinned) in REPO_POLICIES.md. - 2026-03-20: Strengthened constructor naming and Params struct rules in the Go styleguide.
- 2026-03-18: Documented fail-fast Dockerfile lint stage and conditional -v test rerun patterns in REPO_POLICIES.md.
- 2026-03-11: Added HTTP service hardening policy for 1.0 releases.
- 2026-03-10: Added policy: no build artifacts in repos.
- 2026-03-04: Added LLM prose tells reference and copyediting checklist, then several self-applied revision passes.
- 2026-02-28: Expanded the pre-1.0 schema migration rule; added clawpub reference.
- 2026-02-23: Added Go style rules (no type-only packages, Stringer for string-based types); template repos section in README.
- 2026-02-22: Initial policy corpus: REPO_POLICIES.md, code styleguides (general, Go, JS, Python), repo checklists, CI policy, hash pinning, Go HTTP server conventions, repo scaffolding.
Future Steps
- Finish, format, and commit FIXUP_CLEAN.md and FIXUP_REPORT.md (the Next Step).
- Commit this TODO.md at the repo root; it is the last missing policy file.
- Decide the fate of untracked resume.sh: commit it or delete it.
- Add more prompt templates for common development tasks (from README TODO).