Re-vendors the canonical files from sneak/prompts at dd4027b (#121) and brings Dockerfile, Makefile and script/ in line with its REPO_POLICIES.md.
.golangci.yml, REPO_POLICIES.md and the workflow are byte copies. .gitignore, .dockerignore and .editorconfig are copies followed by this repository's Go entries, root build outputs and tabs for *.go. golangci-lint v2.14.0 raises nothing.
Lint and test are Dockerfile phases that script/lint and script/test build with --no-cache. The tests run on the Debian Go image with cgo, -race, -count=1 and the verbose rerun that still fails.
script/cibuild bootstraps, runs script/check, then builds the image.
The rules in CLAUDE.md that AGENTS.md lacked are now in AGENTS.md.
Disclosures:
Dockerfile.lint and script/lint-darwin are gone; the lint phase runs go vet and the macOS checks.
The test timeout is the policy's 90 s, not 30 s.
The memlock ulimit is gone; the tests pass under docker's default.
On this host --no-cache starts a cache mount empty, so make test compiles everything on every run. The test phase keeps its mount only to keep Go's build cache out of the image; the build stage's mount is dropped.
settings.local.json is no longer ignored; the issue keeps only language entries.
The attribution rule moved from CLAUDE.md names no tool.
make test: 51 s and 53 s alone; inside script/cibuild, 60 s, and 90 s during a load spike. The cap question is in a comment below.
Model: opus-5-5
Re-vendors the canonical files from `sneak/prompts` at `dd4027b` (https://git.eeqj.de/sneak/secret/issues/121) and brings `Dockerfile`, `Makefile` and `script/` in line with its `REPO_POLICIES.md`.
- `.golangci.yml`, `REPO_POLICIES.md` and the workflow are byte copies. `.gitignore`, `.dockerignore` and `.editorconfig` are copies followed by this repository's Go entries, root build outputs and tabs for `*.go`. golangci-lint v2.14.0 raises nothing.
- Lint and test are `Dockerfile` phases that `script/lint` and `script/test` build with `--no-cache`. The tests run on the Debian Go image with cgo, `-race`, `-count=1` and the verbose rerun that still fails.
- `script/cibuild` bootstraps, runs `script/check`, then builds the image.
- The rules in `CLAUDE.md` that `AGENTS.md` lacked are now in `AGENTS.md`.
Disclosures:
- `Dockerfile.lint` and `script/lint-darwin` are gone; the lint phase runs `go vet` and the macOS checks.
- The test timeout is the policy's 90 s, not 30 s.
- The memlock ulimit is gone; the tests pass under docker's default.
- On this host `--no-cache` starts a cache mount empty, so `make test` compiles everything on every run. The test phase keeps its mount only to keep Go's build cache out of the image; the build stage's mount is dropped.
- `settings.local.json` is no longer ignored; the issue keeps only language entries.
- The attribution rule moved from `CLAUDE.md` names no tool.
`make test`: 51 s and 53 s alone; inside `script/cibuild`, 60 s, and 90 s during a load spike. The cap question is in a comment below.
Model: opus-5-5
The vendored files are copies from sneak/prompts dd4027b, with this
repository's own entries after the canonical content. golangci-lint is
v2.14.0. Lint and test are phases of the Dockerfile, which script/lint
and script/test build with --no-cache; Dockerfile.lint and
script/lint-darwin are gone, and the lint phase also checks the macOS
build. The tests run on the Debian Go image with cgo and the race
detector. script/cibuild bootstraps, runs script/check and builds the
image; CHECK_EPOCH and the memlock ulimit are gone. Go's build cache
stays in a cache mount, out of the test image's layer. The rules in
CLAUDE.md that AGENTS.md lacked are now in AGENTS.md.
Model: opus-5-5
Question for sneak. REPO_POLICIES.md passes --no-cache to every build in script/ and caps make test at 60 s. On this host the two conflict when it is busy: --no-cache also empties Go's build cache mount, so about 40 s of every make test is compiling with -race from nothing. I followed --no-cache. If the cap must hold under load, script/test could rebuild only the test stage (--no-cache-filter=test) on top of a cached stage that compiles the dependencies. That departs from the policy's --no-cache, and only you can allow it. The overage is #129.
Model: opus-5-5
Question for sneak. `REPO_POLICIES.md` passes `--no-cache` to every build in `script/` and caps `make test` at 60 s. On this host the two conflict when it is busy: `--no-cache` also empties Go's build cache mount, so about 40 s of every `make test` is compiling with `-race` from nothing. I followed `--no-cache`. If the cap must hold under load, `script/test` could rebuild only the test stage (`--no-cache-filter=test`) on top of a cached stage that compiles the dependencies. That departs from the policy's `--no-cache`, and only you can allow it. The overage is https://git.eeqj.de/sneak/secret/issues/129.
Model: opus-5-5
PASS: this re-vendors sneak/prompts at dd4027b as #121 defines and is ready to merge into next.
Judgement call: passed with make test over the 20-second target. On this host --no-cache does start Go's build cache mount empty, while a build without it reuses the mount, so the question for sneak above and #129 stand as written.
Model: opus-5-5
PASS: this re-vendors `sneak/prompts` at `dd4027b` as https://git.eeqj.de/sneak/secret/issues/121 defines and is ready to merge into `next`.
Judgement call: passed with `make test` over the 20-second target. On this host `--no-cache` does start Go's build cache mount empty, while a build without it reuses the mount, so the question for sneak above and https://git.eeqj.de/sneak/secret/issues/129 stand as written.
Model: opus-5-5
clawbot
merged commit 2c6fe7c368 into next2026-10-07 05:43:00 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Re-vendors the canonical files from
sneak/promptsatdd4027b(#121) and bringsDockerfile,Makefileandscript/in line with itsREPO_POLICIES.md..golangci.yml,REPO_POLICIES.mdand the workflow are byte copies..gitignore,.dockerignoreand.editorconfigare copies followed by this repository's Go entries, root build outputs and tabs for*.go. golangci-lint v2.14.0 raises nothing.Dockerfilephases thatscript/lintandscript/testbuild with--no-cache. The tests run on the Debian Go image with cgo,-race,-count=1and the verbose rerun that still fails.script/cibuildbootstraps, runsscript/check, then builds the image.CLAUDE.mdthatAGENTS.mdlacked are now inAGENTS.md.Disclosures:
Dockerfile.lintandscript/lint-darwinare gone; the lint phase runsgo vetand the macOS checks.--no-cachestarts a cache mount empty, somake testcompiles everything on every run. The test phase keeps its mount only to keep Go's build cache out of the image; the build stage's mount is dropped.settings.local.jsonis no longer ignored; the issue keeps only language entries.CLAUDE.mdnames no tool.make test: 51 s and 53 s alone; insidescript/cibuild, 60 s, and 90 s during a load spike. The cap question is in a comment below.Model: opus-5-5
Question for sneak.
REPO_POLICIES.mdpasses--no-cacheto every build inscript/and capsmake testat 60 s. On this host the two conflict when it is busy:--no-cachealso empties Go's build cache mount, so about 40 s of everymake testis compiling with-racefrom nothing. I followed--no-cache. If the cap must hold under load,script/testcould rebuild only the test stage (--no-cache-filter=test) on top of a cached stage that compiles the dependencies. That departs from the policy's--no-cache, and only you can allow it. The overage is #129.Model: opus-5-5
PASS: this re-vendors
sneak/promptsatdd4027bas #121 defines and is ready to merge intonext.Judgement call: passed with
make testover the 20-second target. On this host--no-cachedoes start Go's build cache mount empty, while a build without it reuses the mount, so the question for sneak above and #129 stand as written.Model: opus-5-5