`next` waits for sneak to merge it to `main`; the upaas setup and deploy
and the run under a real 5 GiB limit follow and are his. Meanwhile the
`.dockerignore` issue is next on `next`; nothing orders the stats issue.
Model: opus-5-5
The 2026-09-29 Completed Steps line now says the README License section
says MIT and links LICENSE, and that an Author section was added.
Model: opus-5-5
REPO_POLICIES.md asks the README's first line to name the license and the
author, and for License and Author sections; the README had neither up
front, its License section only said "See LICENSE file.", and it had no
Author section.
TODO.md's Status, Next Step and Future Steps still described the unmerged
repo-policies-compliance branch and a missing CI workflow. They now say
what is true of next, and Completed Steps gains a line for each issue that
landed from 2026-09-21 on without one. The next step is not decided, and
Next Step says so.
Model: opus-5-5
Stopping the daemon while the RIS Live feed was flowing could panic with "send on closed channel" and skip the rest of the shutdown. Stop cancels the stream and closes the handler queues under the streamer's write lock, but the read loop checked for a stop only before parsing each line. It now checks again under the read lock it already takes just before handing a message to the queues, so it never sends to a closed queue. Stop also clears its cancel function and returns early when there is none, so a second call no longer closes the queues again. A test forces both cases.
Behaviour change: Stop before Start now does nothing.
Model: opus-5-5
entrypoint.sh now switches to the routewatch user (UID 1000) with setpriv instead of runuser. setpriv replaces itself with the daemon, so the daemon is the container's main process and receives docker stop's signal itself. runuser stayed in between, passed the signal on and killed the daemon 2 seconds later, so every stop ended with exit 143. The daemon now gets the whole wait the caller allows, up to its own 60-second limit, and a clean stop exits 0. Taking ownership of the state directory and the MALLOC_ARENA_MAX check still run as root first.
Not fixed here: a stop while the feed is flowing can still panic (#34).
Model: opus-5-5
A set but invalid PORT (anything but plain digits from 1 to 65535) or a relative XDG_DATA_HOME now stops the start before the database opens; before, a bad PORT left the daemon running without HTTP. entrypoint.sh refuses a MALLOC_ARENA_MAX that is not a positive whole number, since glibc ignores a bad one silently. The HEALTHCHECK probes the port PORT names, 8080 when unset. PORT is now read in internal/config, so server.New takes the config.
The README gives the real Linux state directory, lists XDG_DATA_HOME, and adds "Running under upaas": port, volume, environment, the 5g memory limit and the health check.
Unverified: the 5g memory limit could not be exercised on the build host.
Model: opus-5-5
Realtime in-memory counters seeded at startup and adjusted on every insert, update and delete; no periodic recompute. Independent review passed: #29 (comment)
model: claude-opus-4-8 (implementation and review); merged by claude-fable-5