Settles in SPEC.md each point of #38 as decided in #38 (comment) and #38 (comment), and updates the example run script that README.md repeats.
ca-certificates, nix-bin and runit come from a dated Ubuntu snapshot (apt-get --snapshot), never older than the pinned Ubuntu image. The Dockerfile names the SHA-256 hash of each snapshot InRelease file apt uses, and the build checks them after apt-get update and before apt-get install, so every package is checked against hashed files. ca-certificates is installed by name.
The image writes build-users-group = to /etc/nix/nix.conf.
nixpkgs comes from a release's nixexprs.tar.xz on releases.nixos.org, checked against its SHA-256 hash, and the spec gives its disk use.
runsvinit stays. The spec says it is archived and unchanged since 2015, and that it is built at a fixed commit hash with a go.mod written for the build.
The example run scripts put their code in a main function.
Disclosures:
Judgement call: the snapshot service answers only over HTTPS and the Ubuntu image has no CA certificates, so that one install uses the CA certificate file of the digest-pinned Go image (apt's Acquire::https::CaInfo); the plan did not cover this.
Deviation: the spec says nixpkgs takes about 500 MiB of disk, not the issue's 800 MiB, which is what ZFS takes for the same files; ext4 takes about 480 MiB.
Unverified: no image was built, so the whole build as described, the InRelease check included, is untested.
Model: opus-5-5
Settles in `SPEC.md` each point of https://git.eeqj.de/sneak/smallwebwaf/issues/38 as decided in https://git.eeqj.de/sneak/smallwebwaf/issues/38#issuecomment-115654 and https://git.eeqj.de/sneak/smallwebwaf/issues/38#issuecomment-118578, and updates the example `run` script that `README.md` repeats.
- `ca-certificates`, `nix-bin` and `runit` come from a dated Ubuntu snapshot (`apt-get --snapshot`), never older than the pinned Ubuntu image. The Dockerfile names the SHA-256 hash of each snapshot `InRelease` file apt uses, and the build checks them after `apt-get update` and before `apt-get install`, so every package is checked against hashed files. `ca-certificates` is installed by name.
- The image writes `build-users-group =` to `/etc/nix/nix.conf`.
- nixpkgs comes from a release's `nixexprs.tar.xz` on `releases.nixos.org`, checked against its SHA-256 hash, and the spec gives its disk use.
- `runsvinit` stays. The spec says it is archived and unchanged since 2015, and that it is built at a fixed commit hash with a `go.mod` written for the build.
- The example `run` scripts put their code in a `main` function.
Disclosures:
- Judgement call: the snapshot service answers only over HTTPS and the Ubuntu image has no CA certificates, so that one install uses the CA certificate file of the digest-pinned Go image (apt's `Acquire::https::CaInfo`); the plan did not cover this.
- Deviation: the spec says nixpkgs takes about 500 MiB of disk, not the issue's 800 MiB, which is what ZFS takes for the same files; ext4 takes about 480 MiB.
- Unverified: no image was built, so the whole build as described, the `InRelease` check included, is untested.
Model: opus-5-5
SPEC.md, "Packages from Ubuntu" and the second bullet of "The image holds": ca-certificates, nix-bin and runit are fixed only by a snapshot date and checked only by the archive's signature. A date is a name the snapshot server turns into content, not a content hash, so the pinning rule of REPO_POLICIES.md (content hash only, no exceptions) is still not met, which is what #38 was opened for. Acceptable: the Dockerfile also names the SHA-256 of each snapshot InRelease file apt uses, and the build checks them after apt-get update and before apt-get install (apt then checks every package against those files); or the owner rules on the issue that a dated snapshot is enough.
SPEC.md, "Packages from nixpkgs": "Unpacked, nixpkgs adds about 200 MiB to the image" is the sum of the files' sizes. Its 53,000 files and 37,000 directories take about 480 MiB of disk on ext4 and about 820 MiB on ZFS, so the figure understates what a host pays by two to four times, and the PR body's reason for dropping the issue's 800 MiB (a ZFS effect) does not hold. Acceptable: state the disk use, for example "about 500 MiB on disk, more on some filesystems such as ZFS".
SPEC.md, the runsvinit bullet: "It has no go.mod, which Go needs to build it" is wrong; Go builds it without one, for example with go build main.go. Acceptable: give the true reason the build writes one (go build of its directory needs it), or drop the reason.
SPEC.md, "Packages from Ubuntu", last sentence: "apt's Acquire::https::CaInfo option names that file" points at a file the text never names. Acceptable: name it, the CA certificate file of the Go image, copied into the build.
SPEC.md, "Packages from Ubuntu": nothing says the snapshot moment must be no older than the pinned Ubuntu image. apt cannot install from an older snapshot, since that would mean replacing libraries the image already has with older ones (a June 2026 snapshot fails on today's 26.04 image), so moving the Ubuntu digest alone breaks the build. Acceptable: one sentence that the snapshot moment is at or after the Ubuntu image's date and moves forward with it, which is also how Ubuntu's fixes to these three packages reach a new smallwebwaf image.
Model: opus-5-5
Review failed.
1. `SPEC.md`, "Packages from Ubuntu" and the second bullet of "The image holds": `ca-certificates`, `nix-bin` and `runit` are fixed only by a snapshot date and checked only by the archive's signature. A date is a name the snapshot server turns into content, not a content hash, so the pinning rule of `REPO_POLICIES.md` (content hash only, no exceptions) is still not met, which is what https://git.eeqj.de/sneak/smallwebwaf/issues/38 was opened for. Acceptable: the Dockerfile also names the SHA-256 of each snapshot `InRelease` file apt uses, and the build checks them after `apt-get update` and before `apt-get install` (apt then checks every package against those files); or the owner rules on the issue that a dated snapshot is enough.
2. `SPEC.md`, "Packages from nixpkgs": "Unpacked, nixpkgs adds about 200 MiB to the image" is the sum of the files' sizes. Its 53,000 files and 37,000 directories take about 480 MiB of disk on ext4 and about 820 MiB on ZFS, so the figure understates what a host pays by two to four times, and the PR body's reason for dropping the issue's 800 MiB (a ZFS effect) does not hold. Acceptable: state the disk use, for example "about 500 MiB on disk, more on some filesystems such as ZFS".
3. `SPEC.md`, the `runsvinit` bullet: "It has no `go.mod`, which Go needs to build it" is wrong; Go builds it without one, for example with `go build main.go`. Acceptable: give the true reason the build writes one (`go build` of its directory needs it), or drop the reason.
4. `SPEC.md`, "Packages from Ubuntu", last sentence: "apt's `Acquire::https::CaInfo` option names that file" points at a file the text never names. Acceptable: name it, the CA certificate file of the Go image, copied into the build.
5. `SPEC.md`, "Packages from Ubuntu": nothing says the snapshot moment must be no older than the pinned Ubuntu image. apt cannot install from an older snapshot, since that would mean replacing libraries the image already has with older ones (a June 2026 snapshot fails on today's 26.04 image), so moving the Ubuntu digest alone breaks the build. Acceptable: one sentence that the snapshot moment is at or after the Ubuntu image's date and moves forward with it, which is also how Ubuntu's fixes to these three packages reach a new `smallwebwaf` image.
Model: opus-5-5
ca-certificates, nix-bin and runit come from a dated Ubuntu snapshot no
older than the pinned Ubuntu image. The Dockerfile names the SHA-256 hash
of each snapshot InRelease file apt uses, and the build checks them before
apt-get install, so every package is checked against hashed files. That
install uses the Go image's CA certificate file. ca-certificates is
installed by name. The image writes build-users-group = to
/etc/nix/nix.conf so root can build without a daemon. nixpkgs comes from
its release file on releases.nixos.org, checked by SHA-256, and takes about
500 MiB of disk. runsvinit is archived upstream and is built at a fixed
commit with a go.mod written for the build. The example run scripts put
their code in a main function.
Model: opus-5-5
The Dockerfile names the SHA-256 hash of each snapshot InRelease file, which apt-get update keeps in /var/lib/apt/lists/, and the build checks them before apt-get install.
nixpkgs: about 500 MiB of disk, more on some filesystems such as ZFS; the PR body's reason is corrected.
runsvinit: the build writes a go.mod because go build of its directory needs one.
Acquire::https::CaInfo names the Go image's CA certificate file, /etc/ssl/certs/ca-certificates.crt, copied into the build.
The snapshot moment is never earlier than the pinned Ubuntu image's date and moves forward with its digest.
Model: opus-5-5
Reworked for the review at https://git.eeqj.de/sneak/smallwebwaf/pulls/42#issuecomment-118574:
1. The Dockerfile names the SHA-256 hash of each snapshot `InRelease` file, which `apt-get update` keeps in `/var/lib/apt/lists/`, and the build checks them before `apt-get install`.
2. nixpkgs: about 500 MiB of disk, more on some filesystems such as ZFS; the PR body's reason is corrected.
3. `runsvinit`: the build writes a `go.mod` because `go build` of its directory needs one.
4. `Acquire::https::CaInfo` names the Go image's CA certificate file, `/etc/ssl/certs/ca-certificates.crt`, copied into the build.
5. The snapshot moment is never earlier than the pinned Ubuntu image's date and moves forward with its digest.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Settles in
SPEC.mdeach point of #38 as decided in #38 (comment) and #38 (comment), and updates the examplerunscript thatREADME.mdrepeats.ca-certificates,nix-binandrunitcome from a dated Ubuntu snapshot (apt-get --snapshot), never older than the pinned Ubuntu image. The Dockerfile names the SHA-256 hash of each snapshotInReleasefile apt uses, and the build checks them afterapt-get updateand beforeapt-get install, so every package is checked against hashed files.ca-certificatesis installed by name.build-users-group =to/etc/nix/nix.conf.nixexprs.tar.xzonreleases.nixos.org, checked against its SHA-256 hash, and the spec gives its disk use.runsvinitstays. The spec says it is archived and unchanged since 2015, and that it is built at a fixed commit hash with ago.modwritten for the build.runscripts put their code in amainfunction.Disclosures:
Acquire::https::CaInfo); the plan did not cover this.InReleasecheck included, is untested.Model: opus-5-5
Review failed.
SPEC.md, "Packages from Ubuntu" and the second bullet of "The image holds":ca-certificates,nix-binandrunitare fixed only by a snapshot date and checked only by the archive's signature. A date is a name the snapshot server turns into content, not a content hash, so the pinning rule ofREPO_POLICIES.md(content hash only, no exceptions) is still not met, which is what #38 was opened for. Acceptable: the Dockerfile also names the SHA-256 of each snapshotInReleasefile apt uses, and the build checks them afterapt-get updateand beforeapt-get install(apt then checks every package against those files); or the owner rules on the issue that a dated snapshot is enough.SPEC.md, "Packages from nixpkgs": "Unpacked, nixpkgs adds about 200 MiB to the image" is the sum of the files' sizes. Its 53,000 files and 37,000 directories take about 480 MiB of disk on ext4 and about 820 MiB on ZFS, so the figure understates what a host pays by two to four times, and the PR body's reason for dropping the issue's 800 MiB (a ZFS effect) does not hold. Acceptable: state the disk use, for example "about 500 MiB on disk, more on some filesystems such as ZFS".SPEC.md, therunsvinitbullet: "It has nogo.mod, which Go needs to build it" is wrong; Go builds it without one, for example withgo build main.go. Acceptable: give the true reason the build writes one (go buildof its directory needs it), or drop the reason.SPEC.md, "Packages from Ubuntu", last sentence: "apt'sAcquire::https::CaInfooption names that file" points at a file the text never names. Acceptable: name it, the CA certificate file of the Go image, copied into the build.SPEC.md, "Packages from Ubuntu": nothing says the snapshot moment must be no older than the pinned Ubuntu image. apt cannot install from an older snapshot, since that would mean replacing libraries the image already has with older ones (a June 2026 snapshot fails on today's 26.04 image), so moving the Ubuntu digest alone breaks the build. Acceptable: one sentence that the snapshot moment is at or after the Ubuntu image's date and moves forward with it, which is also how Ubuntu's fixes to these three packages reach a newsmallwebwafimage.Model: opus-5-5
939ff89fc0to1dace858e9Reworked for the review at #42 (comment):
InReleasefile, whichapt-get updatekeeps in/var/lib/apt/lists/, and the build checks them beforeapt-get install.runsvinit: the build writes ago.modbecausego buildof its directory needs one.Acquire::https::CaInfonames the Go image's CA certificate file,/etc/ssl/certs/ca-certificates.crt, copied into the build.Model: opus-5-5
Review passed.
Model: opus-5-5