From b8a24244615506d4bdd77239659dd44b6c427dd9 Mon Sep 17 00:00:00 2001 From: Jose Alekhinne Date: Mon, 5 Oct 2026 19:26:29 -0700 Subject: [PATCH 1/3] build: gate go.work.sum completeness and refresh it dependabot bumps each module's go.mod/go.sum but never go.work.sum, so after every Go dependency PR the workspace sum is short of checksums. go build and go vet don't notice; go mod download, go list -m all, go mod verify, go mod tidy, and gopls add the missing lines on the spot, so the next contributor finds an unexplained go.work.sum diff. After the grpc 1.84.0 and raft-boltdb 2.4.2 merges it was 66 lines. Commit that refresh, and add hack/check-go-work-sum.sh (make check-go-work-sum): snapshot go.work.sum, run go mod download (the largest of those additions, and stable on re-run), and fail if the file changed, leaving the refreshed file in place to commit. Wired into make audit and the CI lint job after check-go-version, so the drift fails the dependabot PR that causes it instead of landing on a contributor's machine. Spec: specs/go-work-sum-sync.md Signed-off-by: Jose Alekhinne --- .github/workflows/ci.yml | 3 ++ Makefile | 10 +++++- go.work.sum | 66 +++++++++++++++++++++++++++++++++++++++ hack/check-go-work-sum.sh | 44 ++++++++++++++++++++++++++ specs/go-work-sum-sync.md | 66 +++++++++++++++++++++++++++++++++++++++ 5 files changed, 188 insertions(+), 1 deletion(-) create mode 100755 hack/check-go-work-sum.sh create mode 100644 specs/go-work-sum-sync.md diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 7d3d29bf5..56da27908 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -70,6 +70,9 @@ jobs: - name: Check Go toolchain version sync run: make check-go-version + - name: Check go.work.sum completeness + run: make check-go-work-sum + - name: Check steering outputs freshness run: make check-steering diff --git a/Makefile b/Makefile index 881f638fc..cdedae4a8 100644 --- a/Makefile +++ b/Makefile @@ -6,7 +6,7 @@ clean all release build-all help \ test-coverage smoke site site-guard site-feed site-serve site-serve-lan site-setup audit check plugin-reload \ journal journal-serve journal-serve-lan gpg-fix gpg-test register-mcp reinstall check-tools \ -sync-version check-version-sync check-go-version sync-why check-why sync-copilot-skills check-copilot-skills sync-codex-skills check-codex-skills codex-plugin-install sync-opencode-skills check-opencode-skills sync-steering check-steering gemini-search \ +sync-version check-version-sync check-go-version check-go-work-sum sync-why check-why sync-copilot-skills check-copilot-skills sync-codex-skills check-codex-skills codex-plugin-install sync-opencode-skills check-opencode-skills sync-steering check-steering gemini-search \ gitnexus-version gitnexus-update gitnexus-index gitnexus-mcp strip-gitnexus install-ctxctl reinstall-ctxctl # Default binary name and output @@ -177,6 +177,8 @@ audit: @$(MAKE) --no-print-directory check-version-sync @echo "==> Checking Go toolchain version sync..." @$(MAKE) --no-print-directory check-go-version + @echo "==> Checking go.work.sum completeness..." + @$(MAKE) --no-print-directory check-go-work-sum @echo "==> Checking why docs freshness..." @$(MAKE) --no-print-directory check-why @echo "==> Checking Copilot skills freshness..." @@ -404,6 +406,12 @@ check-version-sync: check-go-version: @./hack/check-go-version.sh +## check-go-work-sum: Verify go.work.sum already holds every workspace checksum +# Unlike the skill checks, a failure leaves the refreshed file in place: +# the regenerated go.work.sum is exactly what needs committing. +check-go-work-sum: + @./hack/check-go-work-sum.sh + ## sync-copilot-skills: Sync Copilot CLI skills from canonical ctx skills sync-copilot-skills: @./hack/sync-copilot-skills.sh diff --git a/go.work.sum b/go.work.sum index 5c917984d..8e775ddd1 100644 --- a/go.work.sum +++ b/go.work.sum @@ -5,22 +5,35 @@ cel.dev/expr v0.25.2/go.mod h1:hrXvqGP6G6gyx8UAHSHJ5RGk//1Oj5nXQ2NI02Nrsg4= cloud.google.com/go v0.34.0 h1:eOI3/cP2VTU6uZLDYAoic+eyzzB9YyGmJ7eIjl8rOPg= cloud.google.com/go/auth v0.18.2 h1:+Nbt5Ev0xEqxlNjd6c+yYUeosQ5TtEUaNcN/3FozlaM= cloud.google.com/go/auth v0.18.2/go.mod h1:xD+oY7gcahcu7G2SG2DsBerfFxgPAJz17zz2joOFF3M= +cloud.google.com/go/auth v0.20.0 h1:kXTssoVb4azsVDoUiF8KvxAqrsQcQtB53DcSgta74CA= +cloud.google.com/go/auth v0.20.0/go.mod h1:942/yi/itH1SsmpyrbnTMDgGfdy2BUqIKyd0cyYLc5Q= cloud.google.com/go/compute/metadata v0.9.0 h1:pDUj4QMoPejqq20dK0Pg2N4yG9zIkYGdBtwLoEkH9Zs= cloud.google.com/go/compute/metadata v0.9.0/go.mod h1:E0bWwX5wTnLPedCKqk3pJmVgCBSM6qQI1yTBdEb3C10= github.com/DataDog/datadog-go v3.2.0+incompatible h1:qSG2N4FghB1He/r2mFrWKCaL7dXCilEuNEeAn20fdD4= +github.com/DataDog/datadog-go v4.8.3+incompatible h1:fNGaYSuObuQb5nzeTQqowRAd9bpDIRRV4/gUtIBjh8Q= +github.com/DataDog/datadog-go v4.8.3+incompatible/go.mod h1:LButxg5PwREeZtORoXG3tL4fMGNddJ+vMq1mwgfaqoQ= github.com/DataDog/zstd v1.5.2 h1:vUG4lAyuPCXO0TLbXvPv7EB7cNK1QV/luu55UHLrrn8= github.com/DataDog/zstd v1.5.2/go.mod h1:g4AWEaM3yOg3HYfnJ3YIawPnVdXJh9QME85blwSAmyw= github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.31.0 h1:DHa2U07rk8syqvCge0QIGMCE1WxGj9njT44GH7zNJLQ= github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.31.0/go.mod h1:P4WPRUkOhJC13W//jWpyfJNDAIpvRbAUIYLX/4jtlE0= github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.33.0 h1:l7+6kwRMJNwdCvYdDl7Eax+wzEYHSnNY7zrrfbhDdTA= github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.33.0/go.mod h1:pJTkW8hEUIIi3Pf65lPZOnn4Y81yCllX6IWk2jNXdkM= +github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.34.0 h1:yzIYdwuro811Z27D3T80Wkd3rqZzb0K43nner7Eh1yE= +github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.34.0/go.mod h1:pJTkW8hEUIIi3Pf65lPZOnn4Y81yCllX6IWk2jNXdkM= +github.com/Microsoft/go-winio v0.6.2 h1:F2VQgta7ecxGYO8k3ZZz3RS8fVIXVxONVUPlNERoyfY= +github.com/Microsoft/go-winio v0.6.2/go.mod h1:yd8OoFMLzJbo9gZq8j5qaps8bJ9aShtEA8Ipt1oGCvU= github.com/Sereal/Sereal/Go/sereal v0.0.0-20231009093132-b9187f1a92c6 h1:5kUcJJAKWWI82Xnp/CaU0eu5hLlHkmm9acjowSkwCd0= github.com/Sereal/Sereal/Go/sereal v0.0.0-20231009093132-b9187f1a92c6/go.mod h1:JwrycNnC8+sZPDyzM3MQ86LvaGzSpfxg885KOOwFRW4= github.com/alecthomas/template v0.0.0-20190718012654-fb15b899a751 h1:JYp7IbQjafoB+tBA3gMyHYHrpOtNuDiK/uB5uXxq5wM= github.com/alecthomas/units v0.0.0-20190924025748-f65c72e2690d h1:UQZhZ2O0vMHr2cI+DC1Mbh0TJxzA3RcLoMsFw+aXw7E= github.com/beorn7/perks v1.0.1 h1:VlbKKnNfV8bJzeqoa4cOKqO6bYr3WgKZxO8Z16+hsOM= +github.com/beorn7/perks v1.0.1/go.mod h1:G2ZrVWU2WbWT9wwq4/hrbKbnv/1ERSJQ0ibhJ6rlkpw= +github.com/cespare/xxhash/v2 v2.3.0 h1:UL815xU9SqsFlibzuggzjXhog7bL6oX9BbNZnL2UFvs= +github.com/cespare/xxhash/v2 v2.3.0/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs= github.com/circonus-labs/circonus-gometrics v2.3.1+incompatible h1:C29Ae4G5GtYyYMm1aztcyj/J5ckgJm2zwdDajFbx1NY= +github.com/circonus-labs/circonus-gometrics v2.3.1+incompatible/go.mod h1:nmEj6Dob7S7YxXgwXpfOuvO54S+tGdZdw9fuRZt25Ag= github.com/circonus-labs/circonusllhist v0.1.3 h1:TJH+oke8D16535+jHExHj4nQvzlZrj7ug5D7I/orNUA= +github.com/circonus-labs/circonusllhist v0.1.3/go.mod h1:kMXHVDlOchFAehlya5ePtbp5jckzBHf4XRpQvBOLI+I= github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2 h1:aBangftG7EVZoUb69Os8IaYg++6uMOdKK83QtkkvJik= github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2/go.mod h1:qwXFYgsP6T7XnJtbKlf1HP8AjxZZyzxMmc+Lq5GjlU4= github.com/cpuguy83/go-md2man/v2 v2.0.6 h1:XJtiaUW6dEEqVuZiMTn1ldk455QWwEIsMIJlo5vtkx0= @@ -37,11 +50,17 @@ github.com/envoyproxy/protoc-gen-validate v1.3.3 h1:MVQghNeW+LZcmXe7SY1V36Z+WFMD github.com/envoyproxy/protoc-gen-validate v1.3.3/go.mod h1:TsndJ/ngyIdQRhMcVVGDDHINPLWB7C82oDArY51KfB0= github.com/felixge/httpsnoop v1.0.4 h1:NFTV2Zj1bL4mc9sqWACXbQFVBBg2W3GPvqp8/ESS2Wg= github.com/felixge/httpsnoop v1.0.4/go.mod h1:m8KPJKqk1gH5J9DgRY2ASl2lWCfGKXixSwevea8zH2U= +github.com/felixge/httpsnoop v1.1.0 h1:3YtUj32ZZkqZtt3sZZsClsymw/QDuVfpNhoA31zeORc= +github.com/felixge/httpsnoop v1.1.0/go.mod h1:Zqxgdd+1Rkcz8euOqdr7lqgCRJztwr5hp9vDSi5UZCE= github.com/go-jose/go-jose/v4 v4.1.4 h1:moDMcTHmvE6Groj34emNPLs/qtYXRVcd6S7NHbHz3kA= github.com/go-jose/go-jose/v4 v4.1.4/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9Kf04k1rs08= github.com/go-kit/kit v0.9.0 h1:wDJmvq38kDhkVxi50ni9ykkdUr1PKgqKOoi01fa0Mdk= github.com/go-kit/log v0.1.0 h1:DGJh0Sm43HbOeYDNnVZFl8BvcYVvjD5bqYJvp0REbwQ= github.com/go-logfmt/logfmt v0.5.0 h1:TrB8swr/68K7m9CcGut2g3UOihhbcbiMAYiuTXdEih4= +github.com/go-logr/logr v1.4.3 h1:CjnDlHq8ikf6E492q6eKboGOC0T8CDaOvkHCIg8idEI= +github.com/go-logr/logr v1.4.3/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY= +github.com/go-logr/stdr v1.2.2 h1:hSWxHoqTgW2S2qGc0LTAI563KZ5YKYRhT3MFKZMbjag= +github.com/go-logr/stdr v1.2.2/go.mod h1:mMo/vtBO5dYbehREoey6XUKy/eSumjCCveDpRre4VKE= github.com/go-stack/stack v1.8.0 h1:5SgMzNM5HxrEjV0ww2lTmX6E2Izsfxas4+YHWRs3Lsk= github.com/gogo/protobuf v1.1.1 h1:72R+M5VuhED/KujmZVcIquuo8mBgX4oVda//DQb3PXo= github.com/golang/glog v1.2.5 h1:DrW6hGnjIhtvhOIiAKT6Psh/Kd/ldepEa81DKeiRJ5I= @@ -51,12 +70,22 @@ github.com/golang/snappy v0.0.4/go.mod h1:/XxbfmMg8lxefKM7IXC3fBNl/7bRcc72aCRzEW github.com/google/gofuzz v1.0.0 h1:A8PeW59pxE9IoFRqBp37U+mSNaQoZ46F1f0f863XSXw= github.com/google/s2a-go v0.1.9 h1:LGD7gtMgezd8a/Xak7mEWL0PjoTQFvpRudN895yqKW0= github.com/google/s2a-go v0.1.9/go.mod h1:YA0Ei2ZQL3acow2O62kdp9UlnvMmU7kA6Eutn0dXayM= +github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0= +github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo= github.com/googleapis/enterprise-certificate-proxy v0.3.11 h1:vAe81Msw+8tKUxi2Dqh/NZMz7475yUvmRIkXr4oN2ao= github.com/googleapis/enterprise-certificate-proxy v0.3.11/go.mod h1:RFV7MUdlb7AgEq2v7FmMCfeSMCllAzWxFgRdusoGks8= +github.com/googleapis/enterprise-certificate-proxy v0.3.15 h1:xolVQTEXusUcAA5UgtyRLjelpFFHWlPQ4XfWGc7MBas= +github.com/googleapis/enterprise-certificate-proxy v0.3.15/go.mod h1:vqVt9yG9480NtzREnTlmGSBmFrA+bzb0yl0TxoBQXOg= github.com/googleapis/gax-go/v2 v2.17.0 h1:RksgfBpxqff0EZkDWYuz9q/uWsTVz+kf43LsZ1J6SMc= github.com/googleapis/gax-go/v2 v2.17.0/go.mod h1:mzaqghpQp4JDh3HvADwrat+6M3MOIDp5YKHhb9PAgDY= +github.com/googleapis/gax-go/v2 v2.22.0 h1:PjIWBpgGIVKGoCXuiCoP64altEJCj3/Ei+kSU5vlZD4= +github.com/googleapis/gax-go/v2 v2.22.0/go.mod h1:irWBbALSr0Sk3qlqb9SyJ1h68WjgeFuiOzI4Rqw5+aY= github.com/hashicorp/go-cleanhttp v0.5.0 h1:wvCrVc9TjDls6+YGAF2hAifE1E5U1+b4tH6KdvN3Gig= +github.com/hashicorp/go-cleanhttp v0.5.2 h1:035FKYIWjmULyFRBKPs8TBQoi0x6d9G4xc9neXJWAZQ= +github.com/hashicorp/go-cleanhttp v0.5.2/go.mod h1:kO/YDlP8L1346E6Sodw+PrpBSV4/SoxCXGY6BqNFT48= github.com/hashicorp/go-retryablehttp v0.5.3 h1:QlWt0KvWT0lq8MFppF9tsJGF+ynG7ztc2KIPhzRGk7s= +github.com/hashicorp/go-retryablehttp v0.7.7 h1:C8hUCYzor8PIfXHa4UrZkU4VvK8o9ISHxT2Q8+VepXU= +github.com/hashicorp/go-retryablehttp v0.7.7/go.mod h1:pkQpWZeYWskR+D1tR2O5OcBFOxfA7DoAO6xtkuQnHTk= github.com/josharian/intern v1.0.0 h1:vlS4z54oSdjm0bgjRigI+G1HpF+tI+9rE5LLzOg8HmY= github.com/josharian/intern v1.0.0/go.mod h1:5DoeVV0s6jJacbCEi61lwdGj/aVlrQvzHFFd8Hwg//Y= github.com/jpillora/backoff v1.0.0 h1:uvFg412JmmHBHw7iwprIxkPMI+sGQ4kzOWsMeHnm2EA= @@ -70,21 +99,33 @@ github.com/mailru/easyjson v0.7.7 h1:UGYAvKxe3sBsEDzO8ZeWOSlIQfWFlxbzLZe7hwFURr0 github.com/mailru/easyjson v0.7.7/go.mod h1:xzfreul335JAWq5oZzymOObrkdz5UnU4kGfJJLY9Nlc= github.com/matttproud/golang_protobuf_extensions v1.0.1 h1:4hp9jkHxhMHkqkrB3Ix0jegS5sx/RkqARlsWZ6pIwiU= github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd h1:TRLaZ9cD/w8PVh93nsPXa1VrQ6jlwL5oN8l14QlcNfg= +github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd/go.mod h1:6dJC0mAP4ikYIbvyc7fijjWJddQyLn8Ig3JB5CqoB9Q= github.com/modern-go/reflect2 v1.0.2 h1:xBagoLtFs94CBntxluKeaWgTMpvLxC4ur3nMaC9Gz0M= github.com/modern-go/reflect2 v1.0.2/go.mod h1:yWuevngMOJpCy52FWWMvUC8ws7m/LJsjYzDa0/r8luk= +github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 h1:C3w9PqII01/Oq1c1nUAm88MOHcQC9l5mIlSMApZMrHA= +github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822/go.mod h1:+n7T8mK8HuQTcFwEeznm/DIxMOiR9yIdICNftLE1DvQ= github.com/mwitkow/go-conntrack v0.0.0-20190716064945-2f068394615f h1:KUppIJq7/+SVif2QVs3tOP0zanoHgBEVAwHxUSIzRqU= github.com/philhofer/fwd v1.1.2 h1:bnDivRJ1EWPjUIRXV5KfORO897HTbpFAQddBdE8t7Gw= github.com/philhofer/fwd v1.1.2/go.mod h1:qkPdfjR2SIEbspLqpe1tO4n5yICnr2DY7mqEx2tUTP0= github.com/pkg/diff v0.0.0-20210226163009-20ebb0f2a09e h1:aoZm08cpOy4WuID//EZDgcC4zIxODThtZNPirFr42+A= github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4= +github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0= github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 h1:GFCKgmp0tecUJ0sJuv4pzYCqS9+RGSn52M3FUwPs+uo= github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10/go.mod h1:t/avpk3KcrXxUnYOhZhMXJlSEyie6gQbtLq5NM3loB8= github.com/pquerna/ffjson v0.0.0-20190930134022-aa0246cd15f7 h1:xoIK0ctDddBMnc74udxJYBqlo9Ylnsp1waqjLsnef20= github.com/pquerna/ffjson v0.0.0-20190930134022-aa0246cd15f7/go.mod h1:YARuvh7BUWHNhzDq2OM5tzR2RiCcN2D7sapiKyCel/M= github.com/prometheus/client_golang v1.11.1 h1:+4eQaD7vAZ6DsfsxB15hbE0odUjGI5ARs9yskGu1v4s= +github.com/prometheus/client_golang v1.24.1 h1:JnJkREXzWxUdCuPFpIWZiPispT9xVV59uiuyR2bPlnU= +github.com/prometheus/client_golang v1.24.1/go.mod h1:F+oSRECHg4sse5ucfYpYDeIv/hu68Zo0uoHKetWnzcE= github.com/prometheus/client_model v0.2.0 h1:uq5h0d+GuxiXLJLNABMgp2qUWDPiLvgCzz2dUR+/W/M= +github.com/prometheus/client_model v0.6.3 h1:O0jaTVAYNxTHYInEPFJt5I3+sN8zqBtVMPTB1qyxiEo= +github.com/prometheus/client_model v0.6.3/go.mod h1:gpN5P9S7Rr6Yr92PiQ+Ixvhf6JZEkF1dnxsYL2aPBEM= github.com/prometheus/common v0.26.0 h1:iMAkS2TDoNWnKM+Kopnx/8tnEStIfpYA0ur0xQzzhMQ= +github.com/prometheus/common v0.71.0 h1:9KDAKb7Mj3HEVKyFCK6Dc/HIwlBzZIN2l7/lrHl3KK8= +github.com/prometheus/common v0.71.0/go.mod h1:CLJ5H8TEsGX8bl31BdMkfhIZ+QmZ9tBPPotUxUbfcmk= github.com/prometheus/procfs v0.6.0 h1:mxy4L2jP6qMonqmq+aTtOx1ifVWUgG/TAmntgbh3xv4= +github.com/prometheus/procfs v0.21.1 h1:GljZCt+zSTS+NZq88cyQ1LjZ+RCHp3uVuabBWA5+OJI= +github.com/prometheus/procfs v0.21.1/go.mod h1:aB55Cww9pdSJVHk0hUf0inxWyyjPogFIjmHKYgMKmtY= github.com/russross/blackfriday/v2 v2.1.0 h1:JIOH55/0cWyOuilr9/qlrm0BSXldqnqwMsf35Ld67mk= github.com/sirupsen/logrus v1.6.0 h1:UBcNElsrwanuuMsnGSlYmtmgbb23qDR5dG+6X6Oo89I= github.com/spf13/cobra v1.10.1/go.mod h1:7SmJGaTHFVBY0jW4NXGluQoLvhqFQM+6XSKD+P4XaB0= @@ -92,20 +133,41 @@ github.com/spiffe/go-spiffe/v2 v2.6.0 h1:l+DolpxNWYgruGQVV0xsfeya3CsC7m8iBzDnMps github.com/spiffe/go-spiffe/v2 v2.6.0/go.mod h1:gm2SeUoMZEtpnzPNs2Csc0D/gX33k1xIx7lEzqblHEs= github.com/spiffe/go-spiffe/v2 v2.7.0 h1:uXe1MflJoHw58wAUvxVlcM7WpKtijWG7I1UidcGh6g4= github.com/spiffe/go-spiffe/v2 v2.7.0/go.mod h1:47Q0Q9/AqGha8QLHp+kxpH4Wca7X7EnOtlIJy3mxZ3U= +github.com/spiffe/go-spiffe/v2 v2.8.1 h1:eXZMLsu+3MLEPJyGJkolqtVrteZfQdUpOWj6LTiDl/E= +github.com/spiffe/go-spiffe/v2 v2.8.1/go.mod h1:47Q0Q9/AqGha8QLHp+kxpH4Wca7X7EnOtlIJy3mxZ3U= github.com/stretchr/objx v0.1.1 h1:2vfRuCMp5sSVIDSqO8oNnWJq7mPa6KVP3iPIwFBuy8A= github.com/stretchr/objx v0.5.2 h1:xuMeJ0Sdp5ZMRXx/aWO6RZxdr3beISkG5/G/aIRr3pY= github.com/stretchr/objx v0.5.2/go.mod h1:FRsXN1f5AsAjCGJKqEizvkpNtU+EGNCLh3NxZ/8L+MA= +github.com/stretchr/objx v0.5.3 h1:jmXUvGomnU1o3W/V5h2VEradbpJDwGrzugQQvL0POH4= +github.com/stretchr/objx v0.5.3/go.mod h1:rDQraq+vQZU7Fde9LOZLr8Tax6zZvy4kuNKF+QYS+U0= github.com/tinylib/msgp v1.1.8 h1:FCXC1xanKO4I8plpHGH2P7koL/RzZs12l/+r7vakfm0= github.com/tinylib/msgp v1.1.8/go.mod h1:qkpG+2ldGg4xRFmx+jfTvZPxfGFhi64BcnL9vkCm/Tw= github.com/tv42/httpunix v0.0.0-20150427012821-b75d8614f926 h1:G3dpKMzFDjgEh2q1Z7zUUtKa8ViPtH+ocF0bE0g00O8= +github.com/tv42/httpunix v0.0.0-20150427012821-b75d8614f926/go.mod h1:9ESjWnEqriFuLhtthL60Sar/7RFoluCcXsuvEwTV5KM= github.com/yuin/goldmark v1.4.13 h1:fVcFKWvrslecOb/tg+Cc05dkeYx540o0FuFt3nUVDoE= github.com/yuin/goldmark v1.4.13/go.mod h1:6yULJ656Px+3vBD8DxQVa3kxgyrAnzto9xy5taEt/CY= +go.etcd.io/gofail v0.2.0 h1:p19drv16FKK345a09a1iubchlw/vmRuksmRzgBIGjcA= +go.etcd.io/gofail v0.2.0/go.mod h1:nL3ILMGfkXTekKI3clMBNazKnjUZjYLKmBHzsVAnC1o= +go.opentelemetry.io/auto/sdk v1.2.1 h1:jXsnJ4Lmnqd11kwkBV2LgLoFMZKizbCi5fNZ/ipaZ64= +go.opentelemetry.io/auto/sdk v1.2.1/go.mod h1:KRTj+aOaElaLi+wW1kO/DZRXwkF4C5xPbEe3ZiIhN7Y= go.opentelemetry.io/contrib/detectors/gcp v1.42.0 h1:kpt2PEJuOuqYkPcktfJqWWDjTEd/FNgrxcniL7kQrXQ= go.opentelemetry.io/contrib/detectors/gcp v1.42.0/go.mod h1:W9zQ439utxymRrXsUOzZbFX4JhLxXU4+ZnCt8GG7yA8= go.opentelemetry.io/contrib/detectors/gcp v1.44.0 h1:NmLfL734pJhM0JKaYd2Y28+nY9dPRWYAAbxhRCrKXPw= go.opentelemetry.io/contrib/detectors/gcp v1.44.0/go.mod h1:tNAsgd8avTGke1+MndXlU5Cru4PQ9Ai/cCNWQv/ZJ/s= go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.61.0 h1:F7Jx+6hwnZ41NSFTO5q4LYDtJRXBf2PD0rNBkeB/lus= go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.61.0/go.mod h1:UHB22Z8QsdRDrnAtX4PntOl36ajSxcdUMt1sF7Y6E7Q= +go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0 h1:8tvICD4vSTOOsNrsI4Ljf6C+6UKvpTEH5XY3JMoyPoo= +go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0/go.mod h1:z9+yiacE0IHRqM4qFfkbt/JYlmYXgss8GY/jXoNuPJI= +go.opentelemetry.io/otel v1.44.0 h1:JjwHmHpA4iZ3wBxluu2fbbE7j4kqlE8jXyAyPXH7HqU= +go.opentelemetry.io/otel v1.44.0/go.mod h1:BMgjTHL9WPRlRjL2oZCBTL4whCGtXch2H4BhOPIAyYc= +go.opentelemetry.io/otel/metric v1.44.0 h1:1w0gILTcHdr3YI+ixLyjemwrVnsMURbTZFrSYCdDdmc= +go.opentelemetry.io/otel/metric v1.44.0/go.mod h1:8O7hanEPBNgEMmybD3s2VBKcgWOCsA6tzHBPODAiquo= +go.opentelemetry.io/otel/sdk v1.44.0 h1:nHYwb9lK+fJPU/dnT6s7W7Z8itMWyqrnVfbheVYrZ58= +go.opentelemetry.io/otel/sdk v1.44.0/go.mod h1:Osuydd3Se74nqjAKxid74N5eC+jfEqfTegHRnq58oK0= +go.opentelemetry.io/otel/sdk/metric v1.44.0 h1:3LlKgI+VjbVsjNRFZJZAJ30WjXC5VkNRks6si09iEfI= +go.opentelemetry.io/otel/sdk/metric v1.44.0/go.mod h1:5B5pMARnXxKhltooO4xUuCBorl65a4EpnTalObqOigA= +go.opentelemetry.io/otel/trace v1.44.0 h1:jxF5CsGYCe74MCRx2X4g7WsY/VBKRqqpNvXlX/6gtIk= +go.opentelemetry.io/otel/trace v1.44.0/go.mod h1:oLl1jrMQAVo6v3GAggN+1VH9VIz9iUSvW53sW1Q8PIE= go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc= golang.org/x/crypto v0.51.0 h1:IBPXwPfKxY7cWQZ38ZCIRPI50YLeevDLlLnyC5wRGTI= golang.org/x/crypto v0.51.0/go.mod h1:8AdwkbraGNABw2kOX6YFPs3WM22XqI4EXEd8g+x7Oc8= @@ -142,12 +204,16 @@ golang.org/x/term v0.45.0/go.mod h1:9aqxs0blBcrm/n0L9QW0aRVD+ktan8ssZromtqJC43w= golang.org/x/term v0.46.0 h1:3+OXuTbaKDgwk8jTi3aSLHRlmWqHEUDUtxnbFigO4YE= golang.org/x/term v0.46.0/go.mod h1:+K02xbkittuwc0Am4abfA3Fc+XRGXkvBXNO88NCXPoc= golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543 h1:E7g+9GITq07hpfrRu66IVDexMakfv52eLZ2CXBWiKr4= +google.golang.org/api v0.278.0 h1:W7jiRvRi53VYFfZ/HoZjQBtJk7gOFbHD8ot1RzVZU6E= +google.golang.org/api v0.278.0/go.mod h1:B9TqLBwJqVjp1mtt7WeoQwWRwvu/400y5lETOql+giQ= google.golang.org/appengine v1.6.7 h1:FZR1q0exgwxzPzp/aF+VccGrSfxfPpkBqjIIEq3ru6c= google.golang.org/appengine v1.6.7/go.mod h1:8WjMMxjGQR8xUklV/ARdw2HLXBOI7O7uCIDZVag1xfc= google.golang.org/genproto/googleapis/api v0.0.0-20260226221140-a57be14db171 h1:tu/dtnW1o3wfaxCOjSLn5IRX4YDcJrtlpzYkhHhGaC4= google.golang.org/genproto/googleapis/api v0.0.0-20260226221140-a57be14db171/go.mod h1:M5krXqk4GhBKvB596udGL3UyjL4I1+cTbK0orROM9ng= google.golang.org/genproto/googleapis/api v0.0.0-20260526163538-3dc84a4a5aaa h1:Kjn0N0tCrDgiAFW+lGO4JZ3ck44CehvJQMAwj9QF0G8= google.golang.org/genproto/googleapis/api v0.0.0-20260526163538-3dc84a4a5aaa/go.mod h1:q4lMZS6kskjT5HvCPrnnypcDPVJqT/f4nfxmkE7gryY= +google.golang.org/genproto/googleapis/api v0.0.0-20260706201446-f0a921348800 h1:admdQBe8jR3VWhBsUrAOaF2Qw6K/+p5pSm1GN8+6Fw4= +google.golang.org/genproto/googleapis/api v0.0.0-20260706201446-f0a921348800/go.mod h1:FPk7EXUKMtImne7AmknoYjT4QXqKIzzRbeQIXzLk6fQ= google.golang.org/grpc v1.83.1 h1:HIO0+BEtBP6soyqvqC8sNUjZ7bTs+0hFQuFF+RAy++Y= google.golang.org/grpc v1.83.1/go.mod h1:kDyl6SKsiHKt0uylY5gtn5cEjkrIOhQOGDgIc4JGwzQ= gopkg.in/alecthomas/kingpin.v2 v2.2.6 h1:jMFz6MfLP0/4fUyZle81rXUoxOBFi19VUFKVDOQfozc= diff --git a/hack/check-go-work-sum.sh b/hack/check-go-work-sum.sh new file mode 100755 index 000000000..4953c0f65 --- /dev/null +++ b/hack/check-go-work-sum.sh @@ -0,0 +1,44 @@ +#!/usr/bin/env bash +# / ctx: https://ctx.ist +# ,'`./ do you remember? +# `.,'\ +# \ Copyright 2026-present Context contributors. +# SPDX-License-Identifier: Apache-2.0 + + +# check-go-work-sum.sh — go.work.sum must already hold every checksum +# the workspace needs. +# +# dependabot bumps each module's go.mod/go.sum but never go.work.sum, +# so the workspace sum goes stale after every Go dependency PR, and the +# next contributor whose tooling runs `go mod download` (or +# `go list -m all`, `go mod verify`, gopls) finds it dirty. This gate +# runs that download and fails if the file had to change. +# +# Snapshot-then-regenerate, like check-steering: the comparison is +# against the working copy, not HEAD, so an uncommitted refresh passes. +# On failure the refreshed go.work.sum is left in place, ready to commit. +# +# Portable: bash 3.2 + BSD diff/sed (see specs/hack-script-portability.md). +# +# Exit code: 0 = complete, 1 = stale (go.work.sum now refreshed). + +set -euo pipefail + +ROOT="$(cd "$(dirname "$0")/.." && pwd)" +cd "$ROOT" + +snapshot="$(mktemp)" +trap 'rm -f "$snapshot"' EXIT + +cp go.work.sum "$snapshot" +go mod download + +if ! cmp -s "$snapshot" go.work.sum; then + added="$(diff "$snapshot" go.work.sum | grep -c '^>' || true)" + echo "FAIL: go.work.sum was missing $added workspace checksum line(s);" + echo " it has been refreshed in place. Commit it." + diff "$snapshot" go.work.sum | sed -n 's/^> / + /p' | head -n 10 || true + exit 1 +fi +echo "go.work.sum is complete." diff --git a/specs/go-work-sum-sync.md b/specs/go-work-sum-sync.md new file mode 100644 index 000000000..f28d1700b --- /dev/null +++ b/specs/go-work-sum-sync.md @@ -0,0 +1,66 @@ +# go.work.sum Completeness Gate + +The repo tracks `go.work` and `go.work.sum`. Nothing kept +`go.work.sum` complete, so it went stale after Go dependency bumps +and dirtied contributors' trees. + +## Problem + +dependabot updates each module's `go.mod` and `go.sum` but never +`go.work.sum`. Every Go dependency PR it opens (#173, #174, #175 in +2026-09/10) leaves the workspace sum short of checksums that +workspace-mode commands need. + +`go build` and `go vet` don't notice. `go mod download`, +`go list -m all`, `go mod verify`, and `go mod tidy` do: they add the +missing lines to `go.work.sum` on the spot. gopls and IDE module +loaders run the same commands. So after a dependabot merge, the next +contributor finds an unexplained `go.work.sum` diff in their tree (66 +lines after the grpc 1.84.0 and raft-boltdb 2.4.2 merges) and has to +work out whether it's +theirs to commit. + +History shows the cost: repeated standalone "chore: refresh +go.work.sum" commits, each made after someone tripped over the drift. + +## Gate + +`hack/check-go-work-sum.sh`, exposed as `make check-go-work-sum`: + +1. Snapshot `go.work.sum`. +2. Run `go mod download`. Of the commands above, it produces the + largest set of additions (a superset of `go list -m all` and + `go mod verify`), and running it again adds nothing. +3. If the file changed, print the missing line count and the first + few lines, leave the refreshed file in place, and exit 1. + +The comparison is against the working copy (snapshot-then-regenerate, +like `check-steering`), so an uncommitted refresh passes. Unlike the +skill-sync checks, a failure doesn't restore the snapshot, because +the regenerated file is exactly what needs committing. + +## Wiring + +- `make audit` runs it right after `check-go-version`. +- The CI `lint` job runs it right after `make check-go-version`. + +Consequence: a dependabot Go bump now fails CI until `go.work.sum` +is refreshed on that PR. That is the intent: the drift shows up on +the PR that causes it, not later in a contributor's checkout. To fix +one, run `make check-go-work-sum` on the PR branch and commit the +result (or supersede the PR with a branch that includes it). + +## Non-Goals + +- Automating the refresh on dependabot PRs. A workflow that pushes + to dependabot branches needs write credentials and produces + commits that need their own DCO sign-off. Revisit if refreshing + by hand gets tedious. +- `tools/ctxctl/go.sum`. Module-level sums are maintained by + dependabot and by `go mod tidy` in that module; this gate covers + only the workspace file. + +## See Also + +- `specs/go-version-sync.md`: the sibling gate for the toolchain + version pins, wired at the same points. From e79fb43126493542ae26e043aac1babc52cfd662 Mon Sep 17 00:00:00 2001 From: Jose Alekhinne Date: Mon, 5 Oct 2026 19:26:30 -0700 Subject: [PATCH 2/3] chore(gitignore): label the keys block and dedupe .gitnexus The encryption keys, the encrypted scratchpad, .DS_Store, and .gitnexus sat in one unlabeled block after dreams. Split it: a header for the keys and scratchpad, one for .DS_Store, and fold .gitnexus into the existing GitNexus section, replacing its .gitnexus/ entry (the bare pattern already covered the directory). No change in what is ignored: git ls-files -o -i --exclude-standard lists the same 547 paths before and after. Spec: specs/meta/chores.md Signed-off-by: Jose Alekhinne --- .gitignore | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 633690254..77d821859 100644 --- a/.gitignore +++ b/.gitignore @@ -97,15 +97,19 @@ outbox # ideas/'s privacy class; the don't-leak guard double-checks at write # time. Must stay gitignored (see specs/ctx-dream.md). dreams + +# Encryption keys and the encrypted scratchpad. Never commit these +# (TestGitignoreProtectsSensitiveFiles guards the scratchpad key). .context/.ctx.key .context/.scratchpad.key .context/scratchpad.enc + +# macOS Finder metadata .DS_Store -.gitnexus # Generated skills .claude/skills/generated .claude/skills/gitnexus # GitNexus code-graph index (local, do not commit) -.gitnexus/ +.gitnexus From a3eea29aad0cbcb08ff1b1a6ae0154577b735ee7 Mon Sep 17 00:00:00 2001 From: Jose Alekhinne Date: Mon, 5 Oct 2026 19:26:30 -0700 Subject: [PATCH 3/3] docs(tasks): track private mode, with a stub spec Record the private-mode backlog item from session 28b10323 (2026-09-23): ctx can't be used in a project without committing to it. ctx init edits tracked files, a committed CLAUDE.md without .context/ makes other contributors' agents STOP on a bootstrap error, and ignoring .context/ drops the git undo layer. specs/private-mode.md is a stub: it holds the problem and the candidate scope from the task, plus the open questions. It makes no design decisions. The task links to it. Spec: specs/private-mode.md Signed-off-by: Jose Alekhinne --- .context/TASKS.md | 26 ++++++++++++++++++ specs/private-mode.md | 64 +++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 90 insertions(+) create mode 100644 specs/private-mode.md diff --git a/.context/TASKS.md b/.context/TASKS.md index bb09ddc19..6d5b9d87a 100644 --- a/.context/TASKS.md +++ b/.context/TASKS.md @@ -313,6 +313,32 @@ These have priority because other knowledge ingestion projects depend on them. Important things that agent (or human) yeeted to the future. +- [ ] Private mode: let `ctx` run in a project without committing anything + to it. Open-source projects cannot make `ctx` a contributor dependency, + and today using `ctx` there leaks into tracked files or breaks for + others. Observed in spike-sdk-go (session 28b10323, 2026-09-23): + - `ctx init` edits tracked files: appends to `.gitignore` and adds + `-include Makefile.ctx` to `Makefile`; writes `CLAUDE.md`. + - If `CLAUDE.md` is committed but `.context/` is not, a contributor + who has `ctx` installed hits `Error: no .context here` from + `ctx system bootstrap`, and CLAUDE.md's "installed but returns an + error -> relay and STOP" rule blocks their agent. (Reproduced in a + fresh clone with only CLAUDE.md.) + - Ignoring `.context/` drops the undo layer the constitution relies on + ("persistent memory is dishonest without git reflog"); the + LEARNINGS clobber recovery (`git show :.context/LEARNINGS.md`) + would be impossible. + Scope: (1) `ctx init --private` (or equivalent) writes ignore rules + to `.git/info/exclude` instead of `.gitignore`, and never touches + tracked files (no Makefile include; e.g. an untracked `GNUmakefile` + or no make targets); (2) the agent instructions live in an untracked + file (e.g. `CLAUDE.local.md`) or the CLAUDE.md template treats a + missing `.context/` as "not a ctx project", not an error to STOP on; + (3) a versioning story for an untracked `.context/` (e.g. its own + nested git repo or snapshot) so undo still exists; (4) `ctx drift` / + `ctx doctor` flag private-mode leaks into tracked files. + Spec (stub): specs/private-mode.md. #priority:high #session:28b10323 #branch:build/go-version-sync #commit:7094924a #added:2026-09-23-111723 + - [x] Nav gap: doc pages absent from zensical.toml's nav are silently unreachable from the site sidebar. Discovered + fully fixed 2026-07-06 (session 7f6de29d, UNCOMMITTED). Swept EVERY docs/ tree, not just diff --git a/specs/private-mode.md b/specs/private-mode.md new file mode 100644 index 000000000..f2804316e --- /dev/null +++ b/specs/private-mode.md @@ -0,0 +1,64 @@ +# Private Mode + +> **Status: stub.** This captures the problem and the candidate +> scope recorded in TASKS.md on 2026-09-23 (session 28b10323). No +> design decisions have been made; the Approach section lists +> options, not choices. Flesh out with `/ctx-plan` or `/ctx-spec` +> before implementing. + +## Problem + +`ctx` can't be used in a project without committing to that +project. Open-source projects can't make `ctx` a contributor +dependency, and today using `ctx` there either leaks into tracked +files or breaks things for other contributors. Observed in +spike-sdk-go: + +- **`ctx init` edits tracked files.** It appends to `.gitignore`, + adds `-include Makefile.ctx` to `Makefile`, and writes + `CLAUDE.md`. +- **A committed `CLAUDE.md` without `.context/` blocks other + agents.** A contributor who has `ctx` installed gets + `Error: no .context here` from `ctx system bootstrap`, and the + CLAUDE.md rule "installed but returns an error -> relay and STOP" + halts their agent. Reproduced in a fresh clone containing only + `CLAUDE.md`. +- **Ignoring `.context/` removes the undo layer.** The constitution + requires git as the safety net for agent-driven edits ("persistent + memory is dishonest without git reflog"). With `.context/` + untracked, recoveries like + `git show :.context/LEARNINGS.md` after a clobber become + impossible. + +## Approach + +Candidate scope, from the task. Each item is an option to evaluate, +not a decision: + +1. **Init without touching tracked files.** `ctx init --private` + (or equivalent) writes ignore rules to `.git/info/exclude` + instead of `.gitignore`, and adds no Makefile include (for + example an untracked `GNUmakefile`, or no make targets at all). +2. **Untracked agent instructions.** The instructions live in an + untracked file (for example `CLAUDE.local.md`), or the CLAUDE.md + template treats a missing `.context/` as "not a ctx project" + rather than as an error to STOP on. +3. **Undo for an untracked `.context/`.** A versioning story so + recovery still works, for example a nested git repo inside + `.context/` or snapshots. +4. **Leak detection.** `ctx drift` / `ctx doctor` flag private-mode + state that has leaked into tracked files. + +## Open Questions + +- Is private mode a flag on `init`, a persisted mode in `.ctxrc`, + or detected from the environment (`.context/` excluded via + `.git/info/exclude`)? +- Item 2 has two different fixes: an untracked instructions file, + or a CLAUDE.md template change that benefits non-private projects + too. Pick one or both. +- How does a nested repo in item 3 interact with the "Git is + required" invariant (`specs/require-git.md`) and with tools that + walk the outer repo? +- Which existing `ctx` commands assume `.gitignore` or `Makefile` + ownership and need a private-mode branch?