All checks were successful
check / check (push) Successful in 4s
## The question this answers Is the 60-second test-time cap the new **org-wide** ceiling, or an approved **dnswatcher-only** divergence? - Question: #41 - Origin: sneak/dnswatcher#93 This PR implements **org-wide**. ## The ruling On sneak/dnswatcher#93 (comment) (2026-08-09), verbatim: > make the cap 60s in both and never use mocking, always use live resolvers and > assume the build and run environments have full unmodified unrestricted > internet access. it is ok if they fail due to a bad build environment that > alters dns packets. And on #41 (comment), disambiguating the scope: > org wide. the hard cap is 60 for ci/green, but over 20s should be filed as an > improvement bug. That second comment landed after this work was started, and it confirms the option implemented here. The two-tier shape it describes (60s hard, 20s target, overage filed as a bug) is encoded in the policy text. ## What changed, and the number chosen The backstop moves from `30s` to **`90s`**. The old pairing was incoherent under the new cap: a 60-second ceiling with a 30-second `-timeout` means the timeout kills the suite long before the ceiling is reached, so the ceiling would never be the thing that fails. The backstop has to sit above the cap, where it does its actual job of catching a hung test rather than a merely slow one. `90s` preserves the 1.5x backstop-to-cap ratio the old `20s`/`30s` pair already had, so the relationship between the two numbers is unchanged and only the scale moves. Every place a number changed: | File | What | | --- | --- | | `prompts/REPO_POLICIES.md` | Prose ceiling: `20 seconds` to `60 seconds`, plus the new 20s target / improvement-bug tier | | `prompts/REPO_POLICIES.md` | Backstop prose: `30-second timeout` to `90-second timeout`, with the rationale for why it exceeds the cap | | `prompts/REPO_POLICIES.md` | Go example Makefile snippet, first run: `go test -timeout 30s` to `-timeout 90s` | | `prompts/REPO_POLICIES.md` | Go example Makefile snippet, verbose rerun: `go test -timeout 30s` to `-timeout 90s` | | `prompts/EXISTING_REPO_CHECKLIST.md` | `make test` has a `30-second` timeout, to `90-second` timeout plus the 60s hard cap and the 20s filing rule | | `prompts/NEW_REPO_CHECKLIST.md` | `script/test` / `make test` entrypoint line: `30-second timeout` to `90-second timeout, 60-second hard cap on wall time` | I swept the whole repo for `20 second`, `30-second`, `20s`, `30s`, `timeout 20`, `timeout 30`, and `under 20`/`under 30`. After this change the only remaining occurrences of `20` in a test-timing context are the two intentional references to the new 20-second target. The other `timeout` hits in the repo are unrelated (`.golangci.yml` lint timeout, HTTP server `ReadTimeout`/`WriteTimeout` examples, `middleware.Timeout`) and were left alone. One deliberate non-change: the Python example Makefile snippet in `prompts/REPO_POLICIES.md` carries no timeout flag today and still carries none. `pytest` has no built-in timeout, so adding one would mean mandating the `pytest-timeout` plugin org-wide, which is a new dependency requirement rather than a renumbering, and outside what was ruled on. It is a pre-existing gap between the prose and that snippet, not one this PR introduces. Happy to file it separately or add `--timeout=90` here if you want it in scope. ## The alternative that was not implemented **Keep canonical at 20s and let `sneak/dnswatcher` carry a documented per-repo divergence.** That was the recommendation originally written up in #41, on the reasoning that the 20s ceiling is doing real work in repos with fast deterministic suites and only dnswatcher needs the headroom. Org-wide was chosen instead for two reasons. First, the pressure is not specific to DNS: any repo whose tests exercise real infrastructure over the network inherits the same variance, and there is no principled line that admits dnswatcher and excludes the next such repo. Second, and more decisively, `REPO_POLICIES.md` is a vendored file. A sanctioned per-repo divergence in a vendored file is indistinguishable, on inspection, from a stale vendored copy: the next re-vendoring silently reverts the divergence, and nobody reading a consuming repo can tell whether the number they are looking at is an intentional exception or drift. That is the bidirectional-drift problem already tracked in #31. The two-tier cap gets the same outcome without the drift, since a fast repo that regresses from 4s to 45s still generates an improvement bug. ## Status This PR was opened speculatively, ahead of a decision, on the standing "open it rather than wait" instruction. The scope question has since been answered org-wide in the issue, but the specific backstop value of `90s` and the two-tier wording are still my proposals rather than anything ruled on, so closing this or sending it back for a different number is a perfectly fine outcome. `make check` passes; `make fmt` was run and the result is included (it was a no-op, the edits were already prettier-conformant). `sneak/dnswatcher` is landing the matching 60s edit to its vendored copy in parallel, and will match whichever way this is decided. Co-authored-by: clawbot <clawbot@eeqj.de> Reviewed-on: #42 Co-authored-by: clawbot <clawbot@noreply.example.org> Co-committed-by: clawbot <clawbot@noreply.example.org>
4.9 KiB
4.9 KiB
title, last_modified
| title | last_modified |
|---|---|
| Existing Repo Checklist | 2026-07-06 |
Use this checklist when beginning work in a repo that may not yet conform to our
repository policies
(https://git.eeqj.de/sneak/prompts/raw/branch/main/prompts/REPO_POLICIES.md).
Work on a feature branch. Check each item and fix any gaps before proceeding with your task.
Formatting (do this first)
- If the repo has never been formatted to our standards, run
make fmtand commit the result as a standalone branch/commit/PR before any other changes. Formatting diffs can be large and should not be mixed with functional changes.
Required Files
README.mdexists with all required sections (Description, Getting Started, Rationale, Design, TODO, License, Author)LICENSEfile exists and matches the READMEREPO_POLICIES.mdexists and version date is current — fetch fromhttps://git.eeqj.de/sneak/prompts/raw/branch/main/prompts/REPO_POLICIES.md.gitignoreis comprehensive (OS, editor, language artifacts, secrets) — fetch fromhttps://git.eeqj.de/sneak/prompts/raw/branch/main/.gitignoreif missing.editorconfigexists — fetch fromhttps://git.eeqj.de/sneak/prompts/raw/branch/main/.editorconfigDockerfileand.dockerignoreexist; Dockerfile runsmake checkas a build step — fetch.dockerignorefromhttps://git.eeqj.de/sneak/prompts/raw/branch/main/.dockerignore- Gitea Actions workflow in
.gitea/workflows/runsdocker build .on push — referencehttps://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml - Language-specific config:
- Go:
go.mod,go.sum,.golangci.yml(fetch fromhttps://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml) - JS:
package.json,yarn.lock,.prettierrc,.prettierignore(fetch fromhttps://git.eeqj.de/sneak/prompts/raw/branch/main/.prettierrcandhttps://git.eeqj.de/sneak/prompts/raw/branch/main/.prettierignore) - Python:
pyproject.toml - Docs/writing:
.prettierrc,.prettierignore(same URLs as above)
- Go:
Makefile and script/ Entrypoints
Makefileexists in root — referencehttps://git.eeqj.de/sneak/prompts/raw/branch/main/Makefile- Has targets:
test,lint,fmt,fmt-check,check,docker,hooks - Target implementations live in
script/(scripts-to-rule-them-all); Makefile targets are thin shims calling them — model scripts athttps://git.eeqj.de/sneak/prompts/raw/branch/main/script/<name> script/precommitexists and the pre-commit hook (installed byscript/install-precommit, shimmed bymake hooks) runs it- README has an Entrypoints section documenting the
script/entrypoints and linking the standard make checkdoes not modify any files in the repomake testhas a 90-second timeout and completes within the 60-second hard cap (over 20 seconds is green but must be filed as an improvement bug)make testruns real tests, not a no-op (at minimum, import/compile check)make checkpasses on current branch
Formatting
- Platform-standard formatter is configured (
black,prettier,go fmt) - Default formatter config, only exception: four-space indents (except Go)
- All files pass
make fmt-check
Git Hygiene
- Pre-commit hook is installed (
make hooks) - No secrets in the repo (
.env, keys, credentials) - No mutable references in Dockerfiles or scripts (tags,
@latest) — all pinned by cryptographic hash with version/date comment - Using
yarn, notnpm(JS projects)
Directory Structure
- No unnecessary files in repo root
- Files organized into canonical subdirectories (
bin/,cmd/,docs/,internal/,static/, etc.) - Go migrations in
internal/db/migrations/and embedded in binary
HTTP Service Hardening (if targeting 1.0 and the repo is an HTTP/web service)
- Security headers set on all responses (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy)
- Request body size limits enforced on all endpoints
- Read/write/idle timeouts configured on the HTTP server (slowloris defense)
- Per-handler execution time limits in place
- Password-based auth endpoints are rate-limited
- CSRF tokens on all state-mutating HTML forms
- Passwords hashed with bcrypt, scrypt, or argon2
- Session cookies use HttpOnly, Secure, and SameSite attributes
- True client IP correctly detected behind reverse proxy (trusted proxy allowlist configured)
- CORS restricted to explicit origin allowlist for authenticated endpoints
- Error responses do not leak stack traces, SQL queries, or internal paths
Final
make checkpassesdocker buildsucceeds- Commit and merge fixes before starting your actual task