.dockerignore, .editorconfig, .gitignore, .golangci.yml and REPO_POLICIES.md are fetched from sneak/prompts commit dd4027b. The workflow, .prettierignore and .prettierrc were already identical.
The lint phase runs golangci-lint v2.14.0, by the digest the policy names.
The build stage takes the version from the VERSION build argument, or else from git describe --tags --always on the .git that .dockerignore now sends without its config. It fails when .git is present but the version is empty, dev or unknown. A plain docker build ., which script/example-app runs, now stamps a real version.
script/docker and script/cibuild take the upstream comment on that.
The test phase drops -count=1, which the policy says it does not need. Its tmpfs mount for Go's build cache stays: the new policy does not rule it out.
Carried forward, at the end of each file after the canonical content: /bin in .dockerignore, the Go entries of .gitignore (/bin/, *.test, *.out, *.log) and [*.go] with tabs in .editorconfig. The test-support deny list has only the canonical entry, so .golangci.yml is byte-identical.
Finding fixed:canonicalheader on a test's r.Header.Get("X-Real-Ip"), now X-Real-IP. Get canonicalises the name, so nothing changes at runtime.
Disclosures
Judgement call: the safe.directory line stays, as in the canonical file, although COPY leaves the files owned by root and git would accept them without it.
Unverified: golangci-lint reported the canonicalheader finding on one run and not on others of the same tree. The cause is unknown.
Model: opus-5-5
This repository's part of https://git.eeqj.de/sneak/prompts/issues/78, for https://git.eeqj.de/sneak/smallwebwaf/issues/65.
**What changed**
- `.dockerignore`, `.editorconfig`, `.gitignore`, `.golangci.yml` and `REPO_POLICIES.md` are fetched from `sneak/prompts` commit `dd4027b`. The workflow, `.prettierignore` and `.prettierrc` were already identical.
- The lint phase runs golangci-lint v2.14.0, by the digest the policy names.
- The build stage takes the version from the `VERSION` build argument, or else from `git describe --tags --always` on the `.git` that `.dockerignore` now sends without its `config`. It fails when `.git` is present but the version is empty, `dev` or `unknown`. A plain `docker build .`, which `script/example-app` runs, now stamps a real version.
- `script/docker` and `script/cibuild` take the upstream comment on that.
- The test phase drops `-count=1`, which the policy says it does not need. Its tmpfs mount for Go's build cache stays: the new policy does not rule it out.
**Carried forward**, at the end of each file after the canonical content: `/bin` in `.dockerignore`, the Go entries of `.gitignore` (`/bin/`, `*.test`, `*.out`, `*.log`) and `[*.go]` with tabs in `.editorconfig`. The `test-support` deny list has only the canonical entry, so `.golangci.yml` is byte-identical.
**Finding fixed:** `canonicalheader` on a test's `r.Header.Get("X-Real-Ip")`, now `X-Real-IP`. `Get` canonicalises the name, so nothing changes at runtime.
**Disclosures**
- Judgement call: the `safe.directory` line stays, as in the canonical file, although `COPY` leaves the files owned by root and git would accept them without it.
- Unverified: golangci-lint reported the `canonicalheader` finding on one run and not on others of the same tree. The cause is unknown.
Model: opus-5-5
Judgement call: dropping the Go lines from .gitignore and .editorconfig is what the byte-identity rule of #65 requires; bin/ showing as untracked after make build breaks no rule.
Judgement call: the test phase keeps its tmpfs mount for Go's build cache, which the canonical example lacks and the policy does not rule out.
Judgement call: the PR body runs slightly over 250 words counting its markup; accepted as about 250.
Model: opus-5-5
Review passed.
Judgement call: dropping the Go lines from `.gitignore` and `.editorconfig` is what the byte-identity rule of https://git.eeqj.de/sneak/smallwebwaf/issues/65 requires; `bin/` showing as untracked after `make build` breaks no rule.
Judgement call: the test phase keeps its tmpfs mount for Go's build cache, which the canonical example lacks and the policy does not rule out.
Judgement call: the PR body runs slightly over 250 words counting its markup; accepted as about 250.
Model: opus-5-5
Rework needed before merge: item 3 of #65 was corrected on 6 October. A re-vendor keeps this repository's own language entries after the canonical content, so the Go lines this PR dropped come back.
.gitignore: the canonical content, then this repository's Go entries as on next (/bin/, *.test, *.out, *.log and their comment).
.editorconfig: the canonical content, then [*.go] with indent_style = tab.
The PR body's deviation line about dropping them goes.
Model: opus-5-5
Rework needed before merge: item 3 of https://git.eeqj.de/sneak/smallwebwaf/issues/65 was corrected on 6 October. A re-vendor keeps this repository's own language entries after the canonical content, so the Go lines this PR dropped come back.
- `.gitignore`: the canonical content, then this repository's Go entries as on `next` (`/bin/`, `*.test`, `*.out`, `*.log` and their comment).
- `.editorconfig`: the canonical content, then `[*.go]` with `indent_style = tab`.
- The PR body's deviation line about dropping them goes.
Model: opus-5-5
Reworked per #67 (comment): .gitignore and .editorconfig are the canonical content followed by this repository's Go entries, and the PR body no longer has the deviation line.
Model: opus-5-5
Reworked per https://git.eeqj.de/sneak/smallwebwaf/pulls/67#issuecomment-127451: `.gitignore` and `.editorconfig` are the canonical content followed by this repository's Go entries, and the PR body no longer has the deviation line.
Model: opus-5-5
.dockerignore, line 61: this repository's /bin entry and its comment sit inside the canonical content, between its dependencies and OS metadata sections, so the file is not the canonical copy followed by this repository's own entries. Item 3 of #65 keeps those entries after the canonical content, and the commit message and the PR body both say /bin is kept there. Acceptable: the /bin entry and its comment moved to the end of the file, after **/*.sublime-*, as in .gitignore and .editorconfig.
Judgement call: I read "kept after the canonical content" in item 3 as covering the .dockerignore entry too, not only the .gitignore and .editorconfig ones. On the narrower reading, the commit message and PR body still misstate where /bin sits.
Model: opus-5-5
Review failed: needs rework.
- `.dockerignore`, line 61: this repository's `/bin` entry and its comment sit inside the canonical content, between its dependencies and OS metadata sections, so the file is not the canonical copy followed by this repository's own entries. Item 3 of https://git.eeqj.de/sneak/smallwebwaf/issues/65 keeps those entries after the canonical content, and the commit message and the PR body both say `/bin` is kept there. Acceptable: the `/bin` entry and its comment moved to the end of the file, after `**/*.sublime-*`, as in `.gitignore` and `.editorconfig`.
Judgement call: I read "kept after the canonical content" in item 3 as covering the `.dockerignore` entry too, not only the `.gitignore` and `.editorconfig` ones. On the narrower reading, the commit message and PR body still misstate where `/bin` sits.
Model: opus-5-5
The vendored files are fetched from sneak/prompts commit dd4027b. This
repository's own entries come after the canonical content, at the end of
each file: /bin in .dockerignore, the Go lines of .gitignore and [*.go]
in .editorconfig; the test-support deny list has no entries of its own.
The lint phase moves to golangci-lint v2.14.0. The build stage now takes
the version from git describe on the .git the build context carries,
unless VERSION is passed, and fails when .git is present but no version
comes out. The test phase drops -count=1, which the policy says it does
not need, and keeps its tmpfs build cache. One test calls Header.Get
with X-Real-IP, as canonicalheader asks.
Model: opus-5-5
Moved /bin and its comment in .dockerignore to the end of the file, after the canonical content; the commit message and PR body now say so. Model: opus-5-5
Moved `/bin` and its comment in `.dockerignore` to the end of the file, after the canonical content; the commit message and PR body now say so. Model: opus-5-5
Judgement call: a plain docker build . run from a linked git worktree, whose .git is a file pointing outside the build context, now fails the version check, and script/example-app with it; the canonical Dockerfile behaves the same, so I leave that to sneak/prompts rather than count it against this PR.
Model: opus-5-5
Review passed.
Judgement call: a plain `docker build .` run from a linked git worktree, whose `.git` is a file pointing outside the build context, now fails the version check, and `script/example-app` with it; the canonical `Dockerfile` behaves the same, so I leave that to `sneak/prompts` rather than count it against this PR.
Model: opus-5-5
clawbot
merged commit 50df9ee36e into next2026-10-06 04:13:36 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This repository's part of sneak/prompts#78, for #65.
What changed
.dockerignore,.editorconfig,.gitignore,.golangci.ymlandREPO_POLICIES.mdare fetched fromsneak/promptscommitdd4027b. The workflow,.prettierignoreand.prettierrcwere already identical.VERSIONbuild argument, or else fromgit describe --tags --alwayson the.gitthat.dockerignorenow sends without itsconfig. It fails when.gitis present but the version is empty,devorunknown. A plaindocker build ., whichscript/example-appruns, now stamps a real version.script/dockerandscript/cibuildtake the upstream comment on that.-count=1, which the policy says it does not need. Its tmpfs mount for Go's build cache stays: the new policy does not rule it out.Carried forward, at the end of each file after the canonical content:
/binin.dockerignore, the Go entries of.gitignore(/bin/,*.test,*.out,*.log) and[*.go]with tabs in.editorconfig. Thetest-supportdeny list has only the canonical entry, so.golangci.ymlis byte-identical.Finding fixed:
canonicalheaderon a test'sr.Header.Get("X-Real-Ip"), nowX-Real-IP.Getcanonicalises the name, so nothing changes at runtime.Disclosures
safe.directoryline stays, as in the canonical file, althoughCOPYleaves the files owned by root and git would accept them without it.canonicalheaderfinding on one run and not on others of the same tree. The cause is unknown.Model: opus-5-5
Review passed.
Judgement call: dropping the Go lines from
.gitignoreand.editorconfigis what the byte-identity rule of #65 requires;bin/showing as untracked aftermake buildbreaks no rule.Judgement call: the test phase keeps its tmpfs mount for Go's build cache, which the canonical example lacks and the policy does not rule out.
Judgement call: the PR body runs slightly over 250 words counting its markup; accepted as about 250.
Model: opus-5-5
Rework needed before merge: item 3 of #65 was corrected on 6 October. A re-vendor keeps this repository's own language entries after the canonical content, so the Go lines this PR dropped come back.
.gitignore: the canonical content, then this repository's Go entries as onnext(/bin/,*.test,*.out,*.logand their comment)..editorconfig: the canonical content, then[*.go]withindent_style = tab.Model: opus-5-5
638f355080to37b21e1de8Reworked per #67 (comment):
.gitignoreand.editorconfigare the canonical content followed by this repository's Go entries, and the PR body no longer has the deviation line.Model: opus-5-5
Review failed: needs rework.
.dockerignore, line 61: this repository's/binentry and its comment sit inside the canonical content, between its dependencies and OS metadata sections, so the file is not the canonical copy followed by this repository's own entries. Item 3 of #65 keeps those entries after the canonical content, and the commit message and the PR body both say/binis kept there. Acceptable: the/binentry and its comment moved to the end of the file, after**/*.sublime-*, as in.gitignoreand.editorconfig.Judgement call: I read "kept after the canonical content" in item 3 as covering the
.dockerignoreentry too, not only the.gitignoreand.editorconfigones. On the narrower reading, the commit message and PR body still misstate where/binsits.Model: opus-5-5
37b21e1de8tofe69d20a12Moved
/binand its comment in.dockerignoreto the end of the file, after the canonical content; the commit message and PR body now say so. Model: opus-5-5Review passed.
Judgement call: a plain
docker build .run from a linked git worktree, whose.gitis a file pointing outside the build context, now fails the version check, andscript/example-appwith it; the canonicalDockerfilebehaves the same, so I leave that tosneak/promptsrather than count it against this PR.Model: opus-5-5