build: gate go.work.sum, tidy .gitignore, track private mode - #188
Merged
Merged
Conversation
dependabot bumps each module's go.mod/go.sum but never go.work.sum, so after every Go dependency PR the workspace sum is short of checksums. go build and go vet don't notice; go mod download, go list -m all, go mod verify, go mod tidy, and gopls add the missing lines on the spot, so the next contributor finds an unexplained go.work.sum diff. After the grpc 1.84.0 and raft-boltdb 2.4.2 merges it was 66 lines. Commit that refresh, and add hack/check-go-work-sum.sh (make check-go-work-sum): snapshot go.work.sum, run go mod download (the largest of those additions, and stable on re-run), and fail if the file changed, leaving the refreshed file in place to commit. Wired into make audit and the CI lint job after check-go-version, so the drift fails the dependabot PR that causes it instead of landing on a contributor's machine. Spec: specs/go-work-sum-sync.md Signed-off-by: Jose Alekhinne <jose@ctx.ist>
The encryption keys, the encrypted scratchpad, .DS_Store, and .gitnexus sat in one unlabeled block after dreams. Split it: a header for the keys and scratchpad, one for .DS_Store, and fold .gitnexus into the existing GitNexus section, replacing its .gitnexus/ entry (the bare pattern already covered the directory). No change in what is ignored: git ls-files -o -i --exclude-standard lists the same 547 paths before and after. Spec: specs/meta/chores.md Signed-off-by: Jose Alekhinne <jose@ctx.ist>
Record the private-mode backlog item from session 28b10323 (2026-09-23): ctx can't be used in a project without committing to it. ctx init edits tracked files, a committed CLAUDE.md without .context/ makes other contributors' agents STOP on a bootstrap error, and ignoring .context/ drops the git undo layer. specs/private-mode.md is a stub: it holds the problem and the candidate scope from the task, plus the open questions. It makes no design decisions. The task links to it. Spec: specs/private-mode.md Signed-off-by: Jose Alekhinne <jose@ctx.ist>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Three independent commits:
build: gate go.work.sum completeness and refresh it
dependabot bumps each module's go.mod/go.sum but never go.work.sum,
so after every Go dependency PR the workspace sum is short of
checksums. go build and go vet don't notice; go mod download,
go list -m all, go mod verify, go mod tidy, and gopls add the
missing lines on the spot, so the next contributor finds an
unexplained go.work.sum diff. After the grpc 1.84.0 and raft-boltdb
2.4.2 merges it was 66 lines.
Commit that refresh, and add hack/check-go-work-sum.sh
(make check-go-work-sum): snapshot go.work.sum, run go mod download
(the largest of those additions, and stable on re-run), and fail if
the file changed, leaving the refreshed file in place to commit.
Wired into make audit and the CI lint job after check-go-version, so
the drift fails the dependabot PR that causes it instead of landing
on a contributor's machine.
Spec: specs/go-work-sum-sync.md
chore(gitignore): label the keys block and dedupe .gitnexus
The encryption keys, the encrypted scratchpad, .DS_Store, and
.gitnexus sat in one unlabeled block after dreams. Split it: a
header for the keys and scratchpad, one for .DS_Store, and fold
.gitnexus into the existing GitNexus section, replacing its
.gitnexus/ entry (the bare pattern already covered the directory).
No change in what is ignored: git ls-files -o -i --exclude-standard
lists the same 547 paths before and after.
Spec: specs/meta/chores.md
docs(tasks): track private mode, with a stub spec
Record the private-mode backlog item from session 28b10323
(2026-09-23): ctx can't be used in a project without committing to
it. ctx init edits tracked files, a committed CLAUDE.md without
.context/ makes other contributors' agents STOP on a bootstrap
error, and ignoring .context/ drops the git undo layer.
specs/private-mode.md is a stub: it holds the problem and the
candidate scope from the task, plus the open questions. It makes no
design decisions. The task links to it.
Spec: specs/private-mode.md