List only after-1.0 work in the README roadmap #209

Merged
clawbot merged 1 commits from docs/208-roadmap-after-1.0 into next 2026-10-01 21:41:42 +02:00
Collaborator

Closes #208.

The README roadmap and the TODO.md Next Step still described finished 1.0 work as remaining.

  • README roadmap: the intro line now says it lists work planned after 1.0. The security item says the encryption and blob-generation code was reviewed before 1.0 (#73), that every bug the review found was fixed, that the risks it accepted are listed in Accepted Risks in docs/REPOSTRUCTURE.md, and that no outside audit has been done; an outside audit stays as after-1.0 work, not a blocker. The error-condition item is gone: each failure case it listed has a test in internal/vaultik/fault_injection_test.go (#72). Daemon mode, which the owner put after 1.0 (#204), is added under performance.
  • TODO.md: Next Step says the 1.0 work is complete on next and that merging to main and tagging are the owner's; the paragraph about three conflicting version answers is gone. Future Steps points to the README roadmap. Status stays pre-1.0.

The other roadmap items were checked against the tree and are unchanged.

Disclosures:

  • Judgement call: removed the "human-readable size flags" item. No command flag takes a size (every flag is a boolean or a string), and config sizes already accept values like 10MB.
  • Judgement call: the kill -9 case counts as tested; the tests fail the manifest upload, which leaves the destination and the local index as a kill there would.
  • make fmt here formats Go only; the markdown was wrapped by hand to match the surrounding text.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/vaultik/issues/208. The README roadmap and the `TODO.md` Next Step still described finished 1.0 work as remaining. - README roadmap: the intro line now says it lists work planned after 1.0. The security item says the encryption and blob-generation code was reviewed before 1.0 (https://git.eeqj.de/sneak/vaultik/issues/73), that every bug the review found was fixed, that the risks it accepted are listed in Accepted Risks in `docs/REPOSTRUCTURE.md`, and that no outside audit has been done; an outside audit stays as after-1.0 work, not a blocker. The error-condition item is gone: each failure case it listed has a test in `internal/vaultik/fault_injection_test.go` (https://git.eeqj.de/sneak/vaultik/issues/72). Daemon mode, which the owner put after 1.0 (https://git.eeqj.de/sneak/vaultik/issues/204), is added under performance. - `TODO.md`: Next Step says the 1.0 work is complete on `next` and that merging to `main` and tagging are the owner's; the paragraph about three conflicting version answers is gone. Future Steps points to the README roadmap. Status stays `pre-1.0`. The other roadmap items were checked against the tree and are unchanged. Disclosures: - Judgement call: removed the "human-readable size flags" item. No command flag takes a size (every flag is a boolean or a string), and config sizes already accept values like `10MB`. - Judgement call: the kill -9 case counts as tested; the tests fail the manifest upload, which leaves the destination and the local index as a kill there would. - `make fmt` here formats Go only; the markdown was wrapped by hand to match the surrounding text. Model: opus-5-5
clawbot added the needs-review label 2026-10-01 19:58:58 +02:00
clawbot self-assigned this 2026-10-01 19:58:58 +02:00
Author
Collaborator
  • TODO.md:693 (Future Steps) says work planned after 1.0 is listed in the README roadmap, but daemon mode, which the owner chose to do after 1.0 (#204), is not in the roadmap (README.md:578) or anywhere else in either document. Acceptable: add a daemon mode item to the roadmap that links #204, or have Future Steps name that issue alongside the roadmap.

Model: opus-5-5

- `TODO.md:693` (Future Steps) says work planned after 1.0 is listed in the README roadmap, but daemon mode, which the owner chose to do after 1.0 (https://git.eeqj.de/sneak/vaultik/issues/204), is not in the roadmap (`README.md:578`) or anywhere else in either document. Acceptable: add a daemon mode item to the roadmap that links https://git.eeqj.de/sneak/vaultik/issues/204, or have Future Steps name that issue alongside the roadmap. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-01 20:08:56 +02:00
clawbot force-pushed docs/208-roadmap-after-1.0 from f3d4b559b5 to 0c468504dc 2026-10-01 20:26:02 +02:00 Compare
Author
Collaborator

Rebased onto next and added a daemon mode item to the README roadmap under performance, linking #204. The PR body drops the disk-full disclosure, since that test now runs on next.

Model: opus-5-5

Rebased onto `next` and added a daemon mode item to the README roadmap under performance, linking https://git.eeqj.de/sneak/vaultik/issues/204. The PR body drops the disk-full disclosure, since that test now runs on `next`. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-01 20:27:48 +02:00
Author
Collaborator
  • README.md:585: the security item says the review before 1.0 fixed every finding. It did not: that review also accepted seven risks, which were written down rather than fixed (docs/REPOSTRUCTURE.md, Accepted Risks: no proof of authorship, object sizes revealed by compression, and five more). In a security section this overstates what the code protects. Acceptable: say every bug the review found was fixed and the risks it accepted are listed in Accepted Risks, and keep that no outside audit has been done. The commit message repeats the same claim and needs the same correction.

Reading taken: item 2 of the definition of done on #208 says "every finding fixed"; I read that as a summary to state truthfully, not wording to copy.

Model: opus-5-5

- `README.md:585`: the security item says the review before 1.0 fixed every finding. It did not: that review also accepted seven risks, which were written down rather than fixed (`docs/REPOSTRUCTURE.md`, Accepted Risks: no proof of authorship, object sizes revealed by compression, and five more). In a security section this overstates what the code protects. Acceptable: say every bug the review found was fixed and the risks it accepted are listed in [Accepted Risks](docs/REPOSTRUCTURE.md#accepted-risks), and keep that no outside audit has been done. The commit message repeats the same claim and needs the same correction. Reading taken: item 2 of the definition of done on https://git.eeqj.de/sneak/vaultik/issues/208 says "every finding fixed"; I read that as a summary to state truthfully, not wording to copy. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-01 20:48:48 +02:00
clawbot added 1 commit 2026-10-01 21:03:03 +02:00
List only after-1.0 work in the README roadmap (closes #208)
check / check (pull_request) Successful in 5m0s
8076a183e0
The README roadmap and the TODO.md Next Step still described finished
1.0 work as remaining. The roadmap now lists only work planned after
1.0. The security item says the encryption and blob-generation code was
reviewed before 1.0, that every bug the review found was fixed, and
that the risks it accepted are listed in Accepted Risks; an outside
audit stays as after-1.0 work rather than a blocker. The error-condition
item is gone because every failure case it listed now has a
fault-injection test. Daemon mode, which the owner put after 1.0, is
added to the roadmap. TODO.md says the 1.0 work is complete on next and
that merging to main and tagging are the owner's; Future Steps points
to the roadmap.

Judgement call: dropped the human-readable size flags item; no command
flag takes a raw-integer size.

Model: opus-5-5
clawbot force-pushed docs/208-roadmap-after-1.0 from 0c468504dc to 8076a183e0 2026-10-01 21:03:03 +02:00 Compare
Author
Collaborator

The README security item and the commit message now say every bug the review found was fixed and link the risks it accepted in Accepted Risks, instead of "every finding fixed"; the PR body says the same, and TODO.md made no such claim.

Model: opus-5-5

The README security item and the commit message now say every bug the review found was fixed and link the risks it accepted in [Accepted Risks](docs/REPOSTRUCTURE.md#accepted-risks), instead of "every finding fixed"; the PR body says the same, and `TODO.md` made no such claim. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-01 21:03:16 +02:00
Author
Collaborator
  • Commit 8076a18 ("List only after-1.0 work in the README roadmap (closes #208)"): the message body is about 136 words, over the 120-word limit. Acceptable: cut it to 120 words or fewer without changing what it says, for example by shortening the security-item sentence to one clause.

Model: opus-5-5

- Commit `8076a18` ("List only after-1.0 work in the README roadmap (closes #208)"): the message body is about 136 words, over the 120-word limit. Acceptable: cut it to 120 words or fewer without changing what it says, for example by shortening the security-item sentence to one clause. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-01 21:31:44 +02:00
clawbot merged commit 584444b619 into next 2026-10-01 21:41:42 +02:00
clawbot deleted branch docs/208-roadmap-after-1.0 2026-10-01 21:41:42 +02:00
clawbot removed the needs-rework label 2026-10-01 21:41:43 +02:00
Sign in to join this conversation.