The canonical .dockerignore and .gitignore both omitted the in-repo agent scratch directory, which holds one worktree per in-flight agent, so under `COPY . .` an entire extra checkout of the repo reached the image. The two entries are deliberately different shapes: anchored in .dockerignore, where the `**/` form would also delete a legitimately named nested directory, and unanchored in .gitignore, where a pattern already matches at every depth. Anchoring leaves a gap where agents run in subdirectories, stated in the vendored file itself. The second half is the consequence of excluding .git: `git describe` in a build stage yields an empty version without erroring, so the version is now computed on the host and passed in. Model: opus-5
4.0 KiB
4.0 KiB
Workflow
- branch (from
main) - do the work in Next Step
- move Next Step to the top of Completed Steps
- move the top item of Future Steps into Next Step
- commit (
TODO.mdchanges in the same commit as the work) - merge to
mainif the branch is not protected, otherwise open a PR - push
Status
pre-1.0
Next Step
Finish the two draft prompt documents in the working tree and commit them:
prompts/FIXUP_CLEAN.md (currently a near-empty stub) and prompts/FIXUP_REPORT.md
(a rough draft). Write the missing content, run make fmt so they pass
fmt-check, and commit.
Completed Steps
- 2026-09-08: Kept in-repo agent scratch out of the Docker build context and out
of version control:
.claude/is one full checkout of the repo per in-flight agent, and underCOPY . .all of it was reaching the image. Also closed the consequence of excluding.git—git describeyields an empty version inside a build stage without failing, soscript/dockerandscript/cibuildnow compute the version on the host and pass--build-arg VERSION. - 2026-09-08: Closed the secret exposure in the canonical
.dockerignore: a local.env,*.pemor*.keywas reaching the build context underCOPY . ., invisible to every git-based check. The patterns are now written to.dockerignore's own semantics —**/-prefixed so they hold at every depth, case-folded with character ranges — andREPO_POLICIES.mdrequires verifying by enumerating the image rather than by reading the file. - 2026-09-08: Made a pinned tool in
script/bootstrapactually reach the host.REPO_POLICIES.mdnow requires comparing the installed version against the pin rather than testingPATHpresence, and re-resolving the binary throughPATHafter installing, so a version bump cannot be a silent no-op and a shadowed install cannot report success. - 2026-09-08: Closed the false green in the canonical CI gate:
script/cibuildandscript/dockernow build with--no-cache, so the Dockerfile's check layers cannot be served from cache on an unchanged tree, and the text claiming a baredocker build .proves the checks ran is corrected inREPO_POLICIES.md, both checklists and the Go styleguide. - 2026-09-03: Added
-count=1to bothgo testinvocations in the canonical Gomake testexample inREPO_POLICIES.md, so the target cannot report a cached pass it did not earn, and documented that Go's test-result cache is a second, independent cache stacked below the Docker layer cache. - 2026-08-07: Set the canonical
.golangci.ymlto the org-standard v2-schema config already deployed byte-identical across the org's Go repos (settings underlinters.settingsso thresholds like lll/funlen/cyclop/dupl actually apply under golangci-lint v2). Recorded the canonical golangci-lint version (v2.12.2, commit-pinned) in REPO_POLICIES.md. - 2026-03-20: Strengthened constructor naming and Params struct rules in the Go styleguide.
- 2026-03-18: Documented fail-fast Dockerfile lint stage and conditional -v test rerun patterns in REPO_POLICIES.md.
- 2026-03-11: Added HTTP service hardening policy for 1.0 releases.
- 2026-03-10: Added policy: no build artifacts in repos.
- 2026-03-04: Added LLM prose tells reference and copyediting checklist, then several self-applied revision passes.
- 2026-02-28: Expanded the pre-1.0 schema migration rule; added clawpub reference.
- 2026-02-23: Added Go style rules (no type-only packages, Stringer for string-based types); template repos section in README.
- 2026-02-22: Initial policy corpus: REPO_POLICIES.md, code styleguides (general, Go, JS, Python), repo checklists, CI policy, hash pinning, Go HTTP server conventions, repo scaffolding.
Future Steps
- Finish, format, and commit FIXUP_CLEAN.md and FIXUP_REPORT.md (the Next Step).
- Commit this TODO.md at the repo root; it is the last missing policy file.
- Decide the fate of untracked resume.sh: commit it or delete it.
- Add more prompt templates for common development tasks (from README TODO).