The review of #37 (merged for #34, the image built on the latest Ubuntu LTS with nixpkgs) and its worker noticed points to settle in SPEC.md or when milestone 2 (#14) builds the image. None blocked the merge.
Nix and runit are installed from Ubuntu's archive by package name, checked by the archive's signature but not pinned by hash or version. The repo policy pins every external reference by hash, with no exceptions, so the spec should install them pinned: from a dated Ubuntu snapshot (apt --snapshot), or runit from the pinned nixpkgs, where it is packaged, and Nix from a hash-checked release.
The Ubuntu 26.04 base image has no CA certificates; today they arrive only as a recommended package of nix-bin and runit. The image should install ca-certificates explicitly, or a build without recommended packages breaks Nix downloads and GeoJS lookups, and with a country list set every visitor counts as an unknown country.
The example run scripts follow the style guide's shebang and set -euo pipefail, but not its rule to put all code in functions, even a main function.
The nixpkgs in the image adds several hundred MiB (about 800 MiB unpacked, about 1.5 GiB with git added); the spec does not say so.
Nix from nix-bin needs build-users-group = in /etc/nix/nix.conf before root can use it without a daemon.
A GitHub archive of a nixpkgs commit can change bytes over time: hash the unpacked contents, or use the release file from releases.nixos.org.
runsvinit has been archived upstream since 2015; its last tag is v2.0.0 and it has no go.mod.
Model: opus-5-5
The review of https://git.eeqj.de/sneak/smallwebwaf/pulls/37 (merged for https://git.eeqj.de/sneak/smallwebwaf/issues/34, the image built on the latest Ubuntu LTS with nixpkgs) and its worker noticed points to settle in `SPEC.md` or when milestone 2 (https://git.eeqj.de/sneak/smallwebwaf/issues/14) builds the image. None blocked the merge.
- Nix and runit are installed from Ubuntu's archive by package name, checked by the archive's signature but not pinned by hash or version. The repo policy pins every external reference by hash, with no exceptions, so the spec should install them pinned: from a dated Ubuntu snapshot (`apt --snapshot`), or runit from the pinned nixpkgs, where it is packaged, and Nix from a hash-checked release.
- The Ubuntu 26.04 base image has no CA certificates; today they arrive only as a recommended package of `nix-bin` and `runit`. The image should install `ca-certificates` explicitly, or a build without recommended packages breaks Nix downloads and GeoJS lookups, and with a country list set every visitor counts as an unknown country.
- The example `run` scripts follow the style guide's shebang and `set -euo pipefail`, but not its rule to put all code in functions, even a `main` function.
- The nixpkgs in the image adds several hundred MiB (about 800 MiB unpacked, about 1.5 GiB with `git` added); the spec does not say so.
- Nix from `nix-bin` needs `build-users-group =` in `/etc/nix/nix.conf` before root can use it without a daemon.
- A GitHub archive of a nixpkgs commit can change bytes over time: hash the unpacked contents, or use the release file from releases.nixos.org.
- `runsvinit` has been archived upstream since 2015; its last tag is v2.0.0 and it has no `go.mod`.
Model: opus-5-5
clawbot
self-assigned this 2026-09-29 02:44:07 +02:00
Plan. Docs only, one PR to next changing SPEC.md (and README.md where it repeats the same text), after #33 is on next, since both change "Deployment". Each point, decided:
Ubuntu packages (nix-bin, runit, ca-certificates) are installed from a dated Ubuntu snapshot (apt-get --snapshot <date>), so the same image build always gets the same files. Ubuntu's own runit stays, since it looks in /etc/service.
ca-certificates is installed by name, not left to come in as a recommended package.
The example run scripts put their code in a main function, as the style guide asks.
The spec says the nixpkgs in the image adds about 800 MiB unpacked.
The spec says the image sets build-users-group = in /etc/nix/nix.conf, so that root can use Nix without a daemon.
nixpkgs comes from the release file on releases.nixos.org for the chosen commit, checked against its SHA-256 hash, not from a GitHub archive.
runsvinit stays, since the org style guide names it for service containers. The spec says it has been archived upstream since 2015, that the image builds it at a fixed commit hash, and that, having no go.mod, it is built with one made for the build.
Model: opus-5-5
Plan. Docs only, one PR to `next` changing `SPEC.md` (and `README.md` where it repeats the same text), after https://git.eeqj.de/sneak/smallwebwaf/issues/33 is on `next`, since both change "Deployment". Each point, decided:
- Ubuntu packages (`nix-bin`, `runit`, `ca-certificates`) are installed from a dated Ubuntu snapshot (`apt-get --snapshot <date>`), so the same image build always gets the same files. Ubuntu's own `runit` stays, since it looks in `/etc/service`.
- `ca-certificates` is installed by name, not left to come in as a recommended package.
- The example `run` scripts put their code in a `main` function, as the style guide asks.
- The spec says the nixpkgs in the image adds about 800 MiB unpacked.
- The spec says the image sets `build-users-group =` in `/etc/nix/nix.conf`, so that root can use Nix without a daemon.
- nixpkgs comes from the release file on releases.nixos.org for the chosen commit, checked against its SHA-256 hash, not from a GitHub archive.
- `runsvinit` stays, since the org style guide names it for service containers. The spec says it has been archived upstream since 2015, that the image builds it at a fixed commit hash, and that, having no `go.mod`, it is built with one made for the build.
Model: opus-5-5
Finding 1 of the review of #42 is settled by REPO_POLICIES.md (every external reference pinned by content hash, no exceptions): the image build names the SHA-256 of each snapshot InRelease file apt uses and checks them after apt-get update, before apt-get install. A dated snapshot alone is not enough.
Model: opus-5-5
Finding 1 of the review of https://git.eeqj.de/sneak/smallwebwaf/pulls/42 is settled by `REPO_POLICIES.md` (every external reference pinned by content hash, no exceptions): the image build names the SHA-256 of each snapshot `InRelease` file apt uses and checks them after `apt-get update`, before `apt-get install`. A dated snapshot alone is not enough.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The review of #37 (merged for #34, the image built on the latest Ubuntu LTS with nixpkgs) and its worker noticed points to settle in
SPEC.mdor when milestone 2 (#14) builds the image. None blocked the merge.apt --snapshot), or runit from the pinned nixpkgs, where it is packaged, and Nix from a hash-checked release.nix-binandrunit. The image should installca-certificatesexplicitly, or a build without recommended packages breaks Nix downloads and GeoJS lookups, and with a country list set every visitor counts as an unknown country.runscripts follow the style guide's shebang andset -euo pipefail, but not its rule to put all code in functions, even amainfunction.gitadded); the spec does not say so.nix-binneedsbuild-users-group =in/etc/nix/nix.confbefore root can use it without a daemon.runsvinithas been archived upstream since 2015; its last tag is v2.0.0 and it has nogo.mod.Model: opus-5-5
Plan. Docs only, one PR to
nextchangingSPEC.md(andREADME.mdwhere it repeats the same text), after #33 is onnext, since both change "Deployment". Each point, decided:nix-bin,runit,ca-certificates) are installed from a dated Ubuntu snapshot (apt-get --snapshot <date>), so the same image build always gets the same files. Ubuntu's ownrunitstays, since it looks in/etc/service.ca-certificatesis installed by name, not left to come in as a recommended package.runscripts put their code in amainfunction, as the style guide asks.build-users-group =in/etc/nix/nix.conf, so that root can use Nix without a daemon.runsvinitstays, since the org style guide names it for service containers. The spec says it has been archived upstream since 2015, that the image builds it at a fixed commit hash, and that, having nogo.mod, it is built with one made for the build.Model: opus-5-5
Settled in
SPEC.mdby #42.Model: opus-5-5
Finding 1 of the review of #42 is settled by
REPO_POLICIES.md(every external reference pinned by content hash, no exceptions): the image build names the SHA-256 of each snapshotInReleasefile apt uses and checks them afterapt-get update, beforeapt-get install. A dated snapshot alone is not enough.Model: opus-5-5
clawbot referenced this issue2026-10-04 02:43:31 +02:00