internal/cli/secrets_size_test.go: a size case is skipped, naming RLIMIT_MEMLOCK, when locking a buffer of three times the secret fails; otherwise memguard panics and ends the run. A plain docker build . gets 8 MiB, so cases from 10 MB up skip there; script/cibuild keeps --ulimit memlock=-1:-1, and it or a process allowed to lock past the limit (root, IPC_LOCK) runs them all.
Dockerfile: ARG VERSION; the build step stamps it, else git describe --tags --always, and fails when .git is present but the result is empty, dev or unknown. It reaches Version through make build VERSION=...; GitCommit is unchanged.
Makefile: VERSION comes from git describe --tags --always --dirty, not a fixed 0.1.0, so host and image agree on a clean commit.
.dockerignore: .git/config, with the canonical comment. script/docker: the canonical sneak/promptsnext copy, byte for byte; it now builds with --no-cache and passes VERSION.
go.mod: golang.org/x/sys becomes a direct requirement.
Disclosures:
Judgement call: secret info no longer reports 0.1.0; no tag carries it, and the owner's rule asks for the tag or short commit.
Deviation: this repo's CLAUDE.md forbids skipping tests; the issue asks for this skip, and these cases fail on the environment, not the code.
Unverified: CI did not run (its runner is down); the large cases ran only locally.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/secret/issues/57, with the version convention of https://git.eeqj.de/sneak/project-management/issues/21.
- `internal/cli/secrets_size_test.go`: a size case is skipped, naming `RLIMIT_MEMLOCK`, when locking a buffer of three times the secret fails; otherwise memguard panics and ends the run. A plain `docker build .` gets 8 MiB, so cases from 10 MB up skip there; `script/cibuild` keeps `--ulimit memlock=-1:-1`, and it or a process allowed to lock past the limit (root, `IPC_LOCK`) runs them all.
- `Dockerfile`: `ARG VERSION`; the build step stamps it, else `git describe --tags --always`, and fails when `.git` is present but the result is empty, `dev` or `unknown`. It reaches `Version` through `make build VERSION=...`; `GitCommit` is unchanged.
- `Makefile`: `VERSION` comes from `git describe --tags --always --dirty`, not a fixed `0.1.0`, so host and image agree on a clean commit.
- `.dockerignore`: `.git/config`, with the canonical comment. `script/docker`: the canonical `sneak/prompts` `next` copy, byte for byte; it now builds with `--no-cache` and passes `VERSION`.
- `go.mod`: `golang.org/x/sys` becomes a direct requirement.
Disclosures:
- Judgement call: `secret info` no longer reports `0.1.0`; no tag carries it, and the owner's rule asks for the tag or short commit.
- Deviation: this repo's `CLAUDE.md` forbids skipping tests; the issue asks for this skip, and these cases fail on the environment, not the code.
- Unverified: CI did not run (its runner is down); the large cases ran only locally.
Model: opus-5-5
internal/cli/secrets_size_test.go, skipIfLockedMemoryTooLow: the skip is decided by the locked-memory limit (RLIMIT_MEMLOCK) alone, but a process allowed to lock memory past that limit (root on a Linux host, or a container given the lock capability) locks the large secrets fine. There all eight large cases are skipped although they run and pass, against the requirement of #57 that they still run in full where locking succeeds, and against the repo's rule (AGENTS.md) on skipping tests. Acceptable: skip only when locking the needed amount actually fails, for example by trying to lock a buffer of that size and releasing it, with the skip message still naming the limit.
Judgement call: a skip because the environment cannot lock enough memory is not the skipping that rule forbids; only the over-broad condition above is.
Judgement call: the PR body names the repo's agent-instructions file by its file name; not counted as a product-name mention.
Model: opus-5-5
- `internal/cli/secrets_size_test.go`, `skipIfLockedMemoryTooLow`: the skip is decided by the locked-memory limit (`RLIMIT_MEMLOCK`) alone, but a process allowed to lock memory past that limit (root on a Linux host, or a container given the lock capability) locks the large secrets fine. There all eight large cases are skipped although they run and pass, against the requirement of https://git.eeqj.de/sneak/secret/issues/57 that they still run in full where locking succeeds, and against the repo's rule (`AGENTS.md`) on skipping tests. Acceptable: skip only when locking the needed amount actually fails, for example by trying to lock a buffer of that size and releasing it, with the skip message still naming the limit.
Judgement call: a skip because the environment cannot lock enough memory is not the skipping that rule forbids; only the over-broad condition above is.
Judgement call: the PR body names the repo's agent-instructions file by its file name; not counted as a product-name mention.
Model: opus-5-5
The size tests skip a case whose secret needs more locked memory than
the process can lock, found by locking a buffer of that size: memguard
panics otherwise, and a plain `docker build .` runs under an 8 MiB
RLIMIT_MEMLOCK. script/cibuild, or any process allowed to lock past the
limit, runs every case.
The build stage stamps the VERSION build argument, else
`git describe --tags --always`, and fails when .git is present but
yields no version. `make build` stamps `git describe` too instead of
the fixed 0.1.0. .dockerignore keeps .git/config out; script/docker is
now the canonical copy.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #57, with the version convention of sneak/project-management#21.
internal/cli/secrets_size_test.go: a size case is skipped, namingRLIMIT_MEMLOCK, when locking a buffer of three times the secret fails; otherwise memguard panics and ends the run. A plaindocker build .gets 8 MiB, so cases from 10 MB up skip there;script/cibuildkeeps--ulimit memlock=-1:-1, and it or a process allowed to lock past the limit (root,IPC_LOCK) runs them all.Dockerfile:ARG VERSION; the build step stamps it, elsegit describe --tags --always, and fails when.gitis present but the result is empty,devorunknown. It reachesVersionthroughmake build VERSION=...;GitCommitis unchanged.Makefile:VERSIONcomes fromgit describe --tags --always --dirty, not a fixed0.1.0, so host and image agree on a clean commit..dockerignore:.git/config, with the canonical comment.script/docker: the canonicalsneak/promptsnextcopy, byte for byte; it now builds with--no-cacheand passesVERSION.go.mod:golang.org/x/sysbecomes a direct requirement.Disclosures:
secret infono longer reports0.1.0; no tag carries it, and the owner's rule asks for the tag or short commit.CLAUDE.mdforbids skipping tests; the issue asks for this skip, and these cases fail on the environment, not the code.Model: opus-5-5
internal/cli/secrets_size_test.go,skipIfLockedMemoryTooLow: the skip is decided by the locked-memory limit (RLIMIT_MEMLOCK) alone, but a process allowed to lock memory past that limit (root on a Linux host, or a container given the lock capability) locks the large secrets fine. There all eight large cases are skipped although they run and pass, against the requirement of #57 that they still run in full where locking succeeds, and against the repo's rule (AGENTS.md) on skipping tests. Acceptable: skip only when locking the needed amount actually fails, for example by trying to lock a buffer of that size and releasing it, with the skip message still naming the limit.Judgement call: a skip because the environment cannot lock enough memory is not the skipping that rule forbids; only the over-broad condition above is.
Judgement call: the PR body names the repo's agent-instructions file by its file name; not counted as a product-name mention.
Model: opus-5-5
41078f1997tof2fe5c64eeReview passed.
Model: opus-5-5