check / check (push) Failing after 0s
Add the standard scaffold and bring the tree to a clean lint under the vendored `default: all` config: `script/` Scripts-to-Rule-Them-All entrypoints with the `Makefile` as thin shims; a `Dockerfile` whose `lint` and `test` phases gate the build; `.gitea/workflows/` CI running `script/cibuild`; `REPO_POLICIES.md`, `.editorconfig`, `.dockerignore`, `LICENSE` (WTFPL), `TODO.md`, `.gitignore`. The `.golangci.yml` is byte-identical to the canonical copy in the `prompts` repo (`https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml`). The 211 lint findings were fixed, not suppressed: package globals became functions/fields/a command constructor, magic numbers became named constants, `ctx` threads into the probes, loop functions were split to cut complexity. Behavior is unchanged; the log file mode stays `0644`. Four `//nolint:gosec` remain — G204 on the fixed-argv subprocess calls, G304 on the operator-chosen log file — matching the reference repos. `make check` is green (lint and tests run in Docker). Model: opus-4-8
43 lines
1.8 KiB
Markdown
43 lines
1.8 KiB
Markdown
# Workflow
|
|
|
|
One issue per unit of work, one branch and one PR per issue:
|
|
|
|
- ensure a tracked issue exists with a definition of done
|
|
- branch from `next` (never from `main`)
|
|
- do the work; open a PR based on `next` (never on `main`)
|
|
- pass an independent review, then the change is squash-merged into `next`
|
|
- push; nothing stays local-only
|
|
|
|
`next` is the branch for the next milestone and must stay green and
|
|
mergeable to `main` without notice. Only `sneak` merges `next` into
|
|
`main`, and for now only `sneak` merges into `next`. No commits land
|
|
directly on `main` or `next` — only merges via PRs.
|
|
|
|
Issue branches do NOT touch this file — it is maintained on `next`.
|
|
Every branch editing `TODO.md` conflicts with every other.
|
|
|
|
# Status
|
|
|
|
The repository has been brought up to current repo standards: `script/`
|
|
Scripts to Rule Them All entrypoints with the `Makefile` reduced to thin
|
|
shims, a `Dockerfile` whose `lint` and `test` phases gate the build, a
|
|
`.gitea/workflows/` CI workflow running `script/cibuild`, the vendored
|
|
`.golangci.yml`, `REPO_POLICIES.md`, `.editorconfig`, `.dockerignore`, a
|
|
`LICENSE` file, and a comprehensive `.gitignore`.
|
|
|
|
Lint is clean under the standard `default: all` configuration, with the
|
|
findings fixed rather than suppressed. The only annotations are
|
|
justified `//nolint:gosec` on the `ping`/`curl` subprocess calls (G204)
|
|
and on opening the operator-chosen log file (G304): fixed argv with no
|
|
shell, so these are false positives, annotated as the reference repos do.
|
|
|
|
# Next Step
|
|
|
|
Feature work, each on its own branch and PR from `next`:
|
|
|
|
- https://git.eeqj.de/sneak/rtnetmon/issues/2 — macOS support:
|
|
VPN-aware interface detection and a single-interface UI when only one
|
|
interface exists.
|
|
- https://git.eeqj.de/sneak/rtnetmon/issues/3 — show Starlink status
|
|
lines when Starlink is the non-VPN gateway.
|