Files
prompts/TODO.md
clawbot ed5ed236b1
All checks were successful
check / check (push) Successful in 27s
Migrate canonical .golangci.yml to gomodguard_v2, with a block list (#55)
Option-2 answer to sneak's ruling of 2026-08-19 on
sneak/homoicon#4: migrate to the successor, with
settings. Closes #25.

## The change

`golangci-lint` v2.12.0 deprecated `gomodguard`, and this config sets
`linters.default: all`, so it is enabled everywhere and warns on every run.

- `gomodguard` joins `wsl` in `linters.disable` under a shared "deprecated"
  comment. The warning is attached to the old name, so disabling it is what
  silences it.
- `gomodguard_v2` is named in `linters.enable`, a no-op under `default: all`
  that gives the settings block a visible owner.
- Blocked, each restating a decision already recorded in the Go package
  defaults: `rs/zerolog` → `log/slog`; the pre-fork `go-redis/redis` →
  `redis/go-redis/v9`; `sergi/go-diff` and `hexops/gotextdiff` → `go-udiff`.
  Every entry matches the module path exactly, so the pre-fork go-redis takes
  three: `go-redis/redis`, `/v7`, `/v8`. A prefix would also cover
  `go-redis/redismock`, the test double for the successor recommended here.

Deliberately absent: recorded rejections that vendoring repos still require
(`mattn/go-sqlite3`, `gorm.io/gorm`, `pmezard/go-difflib`), plus `urfave/cli`
and unversioned `go-chi/chi`. Blocking those would redden repos mid-migration
on their next re-vendor.

## After merge

The file's sha256 moves from
`d10f47ef5e0d8620efd62275b016a7de8fd5abedf333922eec86fe4abc06176e` to
`a79b63a254602a5318db5d0e9a06bc71b84bf0c1d896305229d8bfed1d1b1776`, so every
vendoring repo mismatches. #60 is the
propagation brief; it and the record on
#25 carry this value.

## Disclosures

- Judgement call: `wsl` moved two lines down to share the "deprecated" comment.
  No behaviour change, but it widens the diff.
- The `go.mod` survey and the settings-block probe are on
  #25.
- Unverified: the linter was not run against each vendoring repo; the per-repo
  claim rests on reading their `go.mod` files.
- `make check` exit 0.

Model: opus-5
Co-authored-by: Jeffrey Paul <sneak@noreply.example.org>
Reviewed-on: #55
Co-authored-by: clawbot <clawbot@noreply.example.org>
Co-committed-by: clawbot <clawbot@noreply.example.org>
2026-09-09 14:04:18 +02:00

5.1 KiB

Workflow

  • branch (from main)
  • do the work in Next Step
  • move Next Step to the top of Completed Steps
  • move the top item of Future Steps into Next Step
  • commit (TODO.md changes in the same commit as the work)
  • merge to main if the branch is not protected, otherwise open a PR
  • push

Status

pre-1.0

Next Step

Finish the two draft prompt documents in the working tree and commit them: prompts/FIXUP_CLEAN.md (currently a near-empty stub) and prompts/FIXUP_REPORT.md (a rough draft). Write the missing content, run make fmt so they pass fmt-check, and commit.

Completed Steps

  • 2026-09-08: Moved linting and testing into Docker as phases of the main Dockerfile, per the owner ruling on issue 40. script/lint and script/test build one phase each by name with --no-cache — the same answer issue 26 got, so no separate cache-busting mechanism survives — and the final stage copies a harmless file from both, so the image cannot be built unless they pass. This also closes issue 30: a container has its own result cache and its own lock, so a lint verdict can no longer belong to another checkout. No separate lint Dockerfile, and no golangci-lint config verify step. script/check runs the gates and nothing else, and script/cibuild bootstraps first, since it is all CI runs and script/fmt-check is native.
  • 2026-09-08: Kept in-repo agent scratch out of the Docker build context and out of version control: .claude/ is one full checkout of the repo per in-flight agent, and under COPY . . all of it was reaching the image. Also closed the consequence of excluding .gitgit describe yields an empty version inside a build stage without failing, so script/docker and script/cibuild now compute the version on the host and pass --build-arg VERSION.
  • 2026-09-08: Closed the secret exposure in the canonical .dockerignore: a local .env, *.pem or *.key was reaching the build context under COPY . ., invisible to every git-based check. The patterns are now written to .dockerignore's own semantics — **/-prefixed so they hold at every depth, case-folded with character ranges — and REPO_POLICIES.md requires verifying by enumerating the image rather than by reading the file.
  • 2026-09-08: Made a pinned tool in script/bootstrap actually reach the host. REPO_POLICIES.md now requires comparing the installed version against the pin rather than testing PATH presence, and re-resolving the binary through PATH after installing, so a version bump cannot be a silent no-op and a shadowed install cannot report success.
  • 2026-09-08: Closed the false green in the canonical CI gate: script/cibuild and script/docker now build with --no-cache, so the Dockerfile's check layers cannot be served from cache on an unchanged tree, and the text claiming a bare docker build . proves the checks ran is corrected in REPO_POLICIES.md, both checklists and the Go styleguide.
  • 2026-09-03: Added -count=1 to both go test invocations in the canonical Go make test example in REPO_POLICIES.md, so the target cannot report a cached pass it did not earn, and documented that Go's test-result cache is a second, independent cache stacked below the Docker layer cache.
  • 2026-08-31: Migrated the canonical .golangci.yml from the deprecated gomodguard to gomodguard_v2: the old linter is disabled by name (which is what silences the deprecation warning), the successor is named explicitly in linters.enable, and it carries a blocked module list drawn only from decisions already recorded in the Go package defaults.
  • 2026-08-07: Set the canonical .golangci.yml to the org-standard v2-schema config already deployed byte-identical across the org's Go repos (settings under linters.settings so thresholds like lll/funlen/cyclop/dupl actually apply under golangci-lint v2). Recorded the canonical golangci-lint version (v2.12.2, commit-pinned) in REPO_POLICIES.md.
  • 2026-03-20: Strengthened constructor naming and Params struct rules in the Go styleguide.
  • 2026-03-18: Documented fail-fast Dockerfile lint stage and conditional -v test rerun patterns in REPO_POLICIES.md.
  • 2026-03-11: Added HTTP service hardening policy for 1.0 releases.
  • 2026-03-10: Added policy: no build artifacts in repos.
  • 2026-03-04: Added LLM prose tells reference and copyediting checklist, then several self-applied revision passes.
  • 2026-02-28: Expanded the pre-1.0 schema migration rule; added clawpub reference.
  • 2026-02-23: Added Go style rules (no type-only packages, Stringer for string-based types); template repos section in README.
  • 2026-02-22: Initial policy corpus: REPO_POLICIES.md, code styleguides (general, Go, JS, Python), repo checklists, CI policy, hash pinning, Go HTTP server conventions, repo scaffolding.

Future Steps

  • Finish, format, and commit FIXUP_CLEAN.md and FIXUP_REPORT.md (the Next Step).
  • Commit this TODO.md at the repo root; it is the last missing policy file.
  • Decide the fate of untracked resume.sh: commit it or delete it.
  • Add more prompt templates for common development tasks (from README TODO).