Re-vendor the canonical files from sneak/prompts at dd4027b #504

Open
opened 2026-10-06 01:31:07 +02:00 by clawbot · 2 comments
Collaborator

sneak/prompts#78: sneak/prompts has changed the canonical files this repository vendors. Re-vendor them once, from sneak/prompts commit dd4027b (dd4027b907), fetching each file from https://git.eeqj.de/sneak/prompts/raw/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc/<path>.

Files this repository vendors now: .dockerignore .editorconfig .gitea/workflows/check.yml .gitignore .golangci.yml .prettierrc REPO_POLICIES.md. REPO_POLICIES.md comes from prompts/REPO_POLICIES.md at that commit: the root REPO_POLICIES.md there is a symlink, and its raw URL returns only the link's target path. That repository's own .gitattributes and TODO.md are not canonical.

What changed that matters here:

  • golangci-lint is v2.14.0 (golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f). The lint phase digest and .golangci.yml change in one commit, since v2.12.2 rejects the new file; the go directive may name at most Go 1.27.
  • The Go Dockerfile example: the test phase uses the Debian Go image so -race works; the stage that compiles installs git, trusts /src with git config --system --add safe.directory /src, and fails when .git is present but no version comes out.
  • Host Go tools are installed with go install pinned to a commit, never as go.mod tool dependencies.
  • The image version comes from git describe inside the build: .dockerignore sends .git without its own or any submodule's config. CHECK_EPOCH is gone; every docker build in script/ passes --no-cache.
  • .gitignore and .dockerignore keep out more secret files, hardware-backed SSH keys included.
  • Agent guidance lives in one root AGENTS.md; a committed file or directory named for one agent tool has its content moved there and is deleted.

Definition of done

  1. Every vendored canonical file is its copy at that commit, fetched rather than hand-edited, plus only the entries item 3 keeps. A canonical file the policies require and this repository lacks is added the same way.
  2. Dockerfile, Makefile and script/ follow REPO_POLICIES.md as of that commit, including the gate phases and the version step.
  3. This repository's own entries are carried forward: the deny entries of the test-support depguard rule in .golangci.yml, anchored host-built artifacts in .dockerignore, and its language's entries in .gitignore and .editorconfig, kept after the canonical content. .gitignore is a base each repository extends for its language: a Go repository keeps at least *.log, *.out, *.test and its binaries (prompts/CODE_STYLEGUIDE_GO.md), and its .editorconfig keeps tabs for *.go. (Corrected 2026-10-06: the first version of this item dropped those entries.)
  4. Findings the new files raise are fixed in the code in the same PR; no vendored file is loosened.
  5. make lint runs with no deprecation warnings, and make check passes.
  6. One reviewed PR against next. Closing this issue ticks this repository on sneak/prompts#78.

Model: opus-5-5

https://git.eeqj.de/sneak/prompts/issues/78: `sneak/prompts` has changed the canonical files this repository vendors. Re-vendor them once, from `sneak/prompts` commit `dd4027b` (https://git.eeqj.de/sneak/prompts/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc), fetching each file from `https://git.eeqj.de/sneak/prompts/raw/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc/<path>`. Files this repository vendors now: `.dockerignore .editorconfig .gitea/workflows/check.yml .gitignore .golangci.yml .prettierrc REPO_POLICIES.md`. `REPO_POLICIES.md` comes from `prompts/REPO_POLICIES.md` at that commit: the root `REPO_POLICIES.md` there is a symlink, and its raw URL returns only the link's target path. That repository's own `.gitattributes` and `TODO.md` are not canonical. What changed that matters here: - golangci-lint is v2.14.0 (`golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f`). The lint phase digest and `.golangci.yml` change in one commit, since v2.12.2 rejects the new file; the `go` directive may name at most Go 1.27. - The Go `Dockerfile` example: the test phase uses the Debian Go image so `-race` works; the stage that compiles installs `git`, trusts `/src` with `git config --system --add safe.directory /src`, and fails when `.git` is present but no version comes out. - Host Go tools are installed with `go install` pinned to a commit, never as `go.mod` tool dependencies. - The image version comes from `git describe` inside the build: `.dockerignore` sends `.git` without its own or any submodule's `config`. `CHECK_EPOCH` is gone; every `docker build` in `script/` passes `--no-cache`. - `.gitignore` and `.dockerignore` keep out more secret files, hardware-backed SSH keys included. - Agent guidance lives in one root `AGENTS.md`; a committed file or directory named for one agent tool has its content moved there and is deleted. ## Definition of done 1. Every vendored canonical file is its copy at that commit, fetched rather than hand-edited, plus only the entries item 3 keeps. A canonical file the policies require and this repository lacks is added the same way. 2. `Dockerfile`, `Makefile` and `script/` follow `REPO_POLICIES.md` as of that commit, including the gate phases and the version step. 3. This repository's own entries are carried forward: the `deny` entries of the `test-support` depguard rule in `.golangci.yml`, anchored host-built artifacts in `.dockerignore`, and its language's entries in `.gitignore` and `.editorconfig`, kept after the canonical content. `.gitignore` is a base each repository extends for its language: a Go repository keeps at least `*.log`, `*.out`, `*.test` and its binaries (`prompts/CODE_STYLEGUIDE_GO.md`), and its `.editorconfig` keeps tabs for `*.go`. (Corrected 2026-10-06: the first version of this item dropped those entries.) 4. Findings the new files raise are fixed in the code in the same PR; no vendored file is loosened. 5. `make lint` runs with no deprecation warnings, and `make check` passes. 6. One reviewed PR against `next`. Closing this issue ticks this repository on https://git.eeqj.de/sneak/prompts/issues/78. Model: opus-5-5
clawbot self-assigned this 2026-10-06 01:31:07 +02:00
Author
Collaborator

Plan: one PR against next, as the definition of done says. Notes specific to this repository:

  • Replaces #98 and #265, both closed into this issue, and #503, closed unmerged because it copied the older shared .golangci.yml.
  • From 265: -trimpath and -s -w follow the Go Dockerfile example at dd4027b; if the binary build here cannot take one of them, the PR body says why.
  • Carried forward: this repository has no test-support packages of its own, so its depguard deny list adds nothing (checked again in the PR). The .dockerignore entries specific to this repository (bin/, static/js/alpine.min.js, node_modules/) stay, anchored as the canonical file asks.
  • The .ci-fingerprint cache barrier goes once every docker build in script/ passes --no-cache; the README and Dockerfile comments that describe it go with it.
  • go 1.26.1 in go.mod is within the Go 1.27 limit; the lint stage moves to golangci-lint v2.14.0 in the same commit as .golangci.yml.
  • The README's Entrypoints section and its version notes describe the scripts and the version step as they end up.

Model: opus-5-5

Plan: one PR against `next`, as the definition of done says. Notes specific to this repository: - Replaces https://git.eeqj.de/sneak/webhooker/issues/98 and https://git.eeqj.de/sneak/webhooker/issues/265, both closed into this issue, and https://git.eeqj.de/sneak/webhooker/pulls/503, closed unmerged because it copied the older shared `.golangci.yml`. - From 265: `-trimpath` and `-s -w` follow the Go `Dockerfile` example at `dd4027b`; if the binary build here cannot take one of them, the PR body says why. - Carried forward: this repository has no test-support packages of its own, so its `depguard` deny list adds nothing (checked again in the PR). The `.dockerignore` entries specific to this repository (`bin/`, `static/js/alpine.min.js`, `node_modules/`) stay, anchored as the canonical file asks. - The `.ci-fingerprint` cache barrier goes once every `docker build` in `script/` passes `--no-cache`; the README and `Dockerfile` comments that describe it go with it. - `go 1.26.1` in `go.mod` is within the Go 1.27 limit; the lint stage moves to golangci-lint v2.14.0 in the same commit as `.golangci.yml`. - The README's Entrypoints section and its version notes describe the scripts and the version step as they end up. Model: opus-5-5
Author
Collaborator

Built in #505.

The shared files are the copies at sneak/prompts commit dd4027b, fetched and written unchanged. sha256 of each as fetched:

  • .dockerignore 5ac21268c72605e56463c078a81ba118765c84fda6bfd64d155774ab34275081; the committed file is this plus this repository's anchored entries at its end: /bin, /static/js/alpine.min.js, /data
  • .editorconfig 14903ff7b0eb82bc2b3581af6e4f42c3f457a23fa4b9283efe99b6acd0971ce3
  • .gitea/workflows/check.yml ea57b499d7257d7c1b16cf02132c98b98fd7d9ff6a414fb23da6974d366e1cab
  • .gitignore 97cff2f8942cbce265bad478ea9024e8e2d80c1571cf4348aa978bb6a04469e9
  • .golangci.yml 3ed73ffd561691e565c5c89a994dd8cfeb3faf06a1f87638ca9ab4dde4fecfa2; its depguard deny list adds nothing, as this repository has no test-support packages
  • .prettierrc 1a709149f32ac4adf4004017cf30d8f5482ccf263f414081ae8c499037691133
  • .prettierignore (new: the policies ask for it in a repository with package.json) dbe0186431d09e741fe0ccddf3ac97451575ab88f94fe89353dc2e3ecb83d64b
  • REPO_POLICIES.md, from prompts/REPO_POLICIES.md 6d31d1a5d6d7d0022323a26305b0de33c4b455237fa8eb7d8640aa96a6967840

Linting and testing are now the lint and test phases of the Dockerfile, and the image build depends on both. The lint phase is the golangci-lint v2.14.0 image at the policy's digest and also runs the js-lint stage; Dockerfile.lint is gone. The test phase is the golang bookworm image and keeps the -p 4 -parallel 8 cap. script/lint, script/test, script/docker and script/cibuild are the model scripts; every docker build in script/ passes --no-cache, and the .ci-fingerprint barrier is gone. The version check also refuses an empty version and dev, and make build passes -trimpath and -s -w. The README describes the new layout.

  • Judgement call: the shared workflow no longer calls script/ci-mark-superseded, so it and its tests are removed.
  • Judgement call: /data, where the README's dev run writes its databases, is left out of the build context.
  • Judgement call: the test phase reruns only the failed tests with -v, as script/test did, not the whole suite, which passes the build's 2 MiB log limit.
  • Consequence: with .gitignore the shared copy, git no longer ignores bin/, data/ or the extracted static/js/alpine.min.js.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/webhooker/pulls/505. The shared files are the copies at `sneak/prompts` commit `dd4027b`, fetched and written unchanged. sha256 of each as fetched: - `.dockerignore` `5ac21268c72605e56463c078a81ba118765c84fda6bfd64d155774ab34275081`; the committed file is this plus this repository's anchored entries at its end: `/bin`, `/static/js/alpine.min.js`, `/data` - `.editorconfig` `14903ff7b0eb82bc2b3581af6e4f42c3f457a23fa4b9283efe99b6acd0971ce3` - `.gitea/workflows/check.yml` `ea57b499d7257d7c1b16cf02132c98b98fd7d9ff6a414fb23da6974d366e1cab` - `.gitignore` `97cff2f8942cbce265bad478ea9024e8e2d80c1571cf4348aa978bb6a04469e9` - `.golangci.yml` `3ed73ffd561691e565c5c89a994dd8cfeb3faf06a1f87638ca9ab4dde4fecfa2`; its `depguard` deny list adds nothing, as this repository has no test-support packages - `.prettierrc` `1a709149f32ac4adf4004017cf30d8f5482ccf263f414081ae8c499037691133` - `.prettierignore` (new: the policies ask for it in a repository with `package.json`) `dbe0186431d09e741fe0ccddf3ac97451575ab88f94fe89353dc2e3ecb83d64b` - `REPO_POLICIES.md`, from `prompts/REPO_POLICIES.md` `6d31d1a5d6d7d0022323a26305b0de33c4b455237fa8eb7d8640aa96a6967840` Linting and testing are now the `lint` and `test` phases of the `Dockerfile`, and the image build depends on both. The `lint` phase is the `golangci-lint` v2.14.0 image at the policy's digest and also runs the `js-lint` stage; `Dockerfile.lint` is gone. The `test` phase is the `golang` bookworm image and keeps the `-p 4 -parallel 8` cap. `script/lint`, `script/test`, `script/docker` and `script/cibuild` are the model scripts; every `docker build` in `script/` passes `--no-cache`, and the `.ci-fingerprint` barrier is gone. The version check also refuses an empty version and `dev`, and `make build` passes `-trimpath` and `-s -w`. The README describes the new layout. - Judgement call: the shared workflow no longer calls `script/ci-mark-superseded`, so it and its tests are removed. - Judgement call: `/data`, where the README's dev run writes its databases, is left out of the build context. - Judgement call: the `test` phase reruns only the failed tests with `-v`, as `script/test` did, not the whole suite, which passes the build's 2 MiB log limit. - Consequence: with `.gitignore` the shared copy, git no longer ignores `bin/`, `data/` or the extracted `static/js/alpine.min.js`. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/webhooker#504