diff options
| author | Danilo M. <danix@danix.xyz> | 2026-09-25 10:37:06 +0200 |
|---|---|---|
| committer | Danilo M. <danix@danix.xyz> | 2026-09-25 10:37:06 +0200 |
| commit | 20410eb37442a510e9ca3f1b038cee647ae5bf21 (patch) | |
| tree | 26819129dcdc1614e7861122a2d1ba9c38783d44 /AGENTS.md | |
| parent | 9e4f0fa4c4273a81f40f26177604c43856dff8c1 (diff) | |
| download | slackware-pentesting-suite-20410eb37442a510e9ca3f1b038cee647ae5bf21.tar.gz slackware-pentesting-suite-20410eb37442a510e9ca3f1b038cee647ae5bf21.zip | |
Move maintainer tooling out of the repo
Git hooks, the upstream sweep and the SBo delivery workflow are the
maintainer's operational tools, not package knowledge. They now live in a
private workspace that wraps all three SlackBuild repos, with one shared
copy of each hook instead of three drifting ones.
Also in this pass:
- AGENTS.md: checksum loop documented as sbodl (sbofixinfo does not fix
checksums), nvchecker must not run without a token config, prefer
use_latest_release over use_max_tag
- README: Git Hooks section replaced by a short Contributing note
- sweep report renamed to LAST_SWEEP.md across all three repos
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'AGENTS.md')
| -rw-r--r-- | AGENTS.md | 128 |
1 files changed, 22 insertions, 106 deletions
@@ -5,23 +5,6 @@ This file governs how AI agents must behave in this repository. --- -## Core Rules - -1. **Ask before acting.** If anything about the task is ambiguous — target - version, which package, which build strategy — stop and ask. Do not infer - intent and proceed. -2. **Use available skills.** For git operations, commits, PRs, and any task - covered by a skill, invoke the relevant skill. Do not improvise a workflow - that a skill already defines. -3. **One package per task.** Never modify multiple packages in a single - operation unless explicitly instructed. -4. **Never skip lint.** Every change must pass `sbolint` before committing. - No exceptions. -5. **Never commit without being asked.** Complete all file edits and - verification steps, then wait for explicit instruction to commit. - ---- - ## Repository Layout Each package lives in its own top-level subfolder: @@ -99,25 +82,17 @@ exact URL for the new version before editing. ### Step 3 — Fix the checksum -Run `sbofixinfo` from inside the package directory: - -```bash -cd <package-name> && sbofixinfo -``` - -If `sbofixinfo` reports no changes (common when the checksum is a placeholder), -use the two-pass `sbodl` procedure instead: +`sbofixinfo` does not fix checksums, it only normalizes `.info` formatting. +The checksum loop is `sbodl`: ```bash -# Pass 1 — downloads the source; fails because MD5SUM is wrong/placeholder +# Pass 1: downloads the source and prints +# WARN: md5sum doesn't match ... got: <new> cd <package-name> && sbodl -# Compute the real checksum from the downloaded file -md5sum <downloaded-file> # adjust filename as needed - -# Update the MD5SUM (or MD5SUM_x86_64) in the .info file +# Put the got: value into MD5SUM (or MD5SUM_x86_64) in the .info file -# Pass 2 — verifies the checksum; must report "md5sum matches OK" +# Pass 2: must report "md5sum matches OK" cd <package-name> && sbodl ``` @@ -157,50 +132,29 @@ Then proceed: 1. Create the package directory with all required files: `<prgnam>.SlackBuild`, `<prgnam>.info`, `README`, `slack-desc` 2. Choose the correct build strategy and follow the scripting rules below. -3. Run `sbofixinfo`, then `sbodl` (two-pass if needed), then `sbolint`. +3. Run `sbofixinfo`, then `sbodl` (two-pass, see above), then `sbolint`. 4. Report results and wait for commit instruction. --- -## Version Sweep +## Version Tracking: nvchecker.toml -The `.extras/nvchecker.toml` file tracks upstream versions for all packages -in the suite (both in-repo and sbo-slackbuilds). A sweep compares upstream -against what this repo carries and identifies packages that need updating. +`.extras/nvchecker.toml` is the **suite catalog**: it tracks upstream versions +for every tool in the suite, not only the packages in this repo. That +includes packages maintained in `sbo-slackbuilds` and tools packaged on SBo by +others (e.g. `hashcat`, `john`). Stanzas without a package directory here are +intentional; do not remove them. New packages get a stanza too. -### Procedure +The file has no `[__config__]`. Do not run it as-is against GitHub: the +anonymous API budget (60 req/h) runs out and later stanzas 403. Run it from a +throwaway copy with a `[__config__]` that adds a GitHub token keyfile, and +probe single stanzas with `nvchecker -c <cfg> -e <name>`. Prefer +`use_latest_release` over `use_max_tag` for github stanzas; `use_max_tag` is +tightly rate-limited and only needed for repos that tag without cutting +Releases. -1. Generate a throwaway nvchecker config in the scratchpad (`/tmp/opencode/`) - that prepends a `[__config__]` section pointing at the personal keyfile - (`~/.config/nvchecker/keys.toml`, provides a GitHub token for 5000 req/h) - plus scratchpad `oldver`/`newver` paths, then appends the stanzas from - `.extras/nvchecker.toml`. - -2. Run `nvchecker -c <throwaway-config>` on the throwaway config. With a - fresh `oldver`, every stanza reports "updated to X" — that is the - *upstream* version, not a diff. - -3. For each **in-repo** package (cadaver, netexec, windows-binaries, - webshells), compare the reported upstream version against the `VERSION=` - in that package's `.info` file. Packages maintained in `sbo-slackbuilds` - are out of scope for this repo's sweep. - -4. Update `LAST_SWEEP` (gitignored) with the date and a table showing - carried version, upstream version, and status (current / needs bump) - for each in-repo package. - -5. For any package that needs a bump, follow the Mandatory Workflow: - Updating a Package Version above. - -### Important notes - -- Never run `nvchecker -c .extras/nvchecker.toml` directly — the tracked - config has no `[__config__]`, so GitHub stanzas hit the anonymous rate - limit (60 req/h) and 403. -- Probe a single package with `nvchecker -c <config> -e <name>` when - testing a specific stanza. -- Never audit GitHub repos with raw `curl` loops — a burst burns the - anonymous quota and later calls 403. +Maintainer tooling (git hooks, the upstream sweep, test builds, SBo archive +builder) is kept outside this repo, in the maintainer's private workspace. --- @@ -348,41 +302,3 @@ Commit conventions: - Add: `<package-name>: add version X.Y.Z` - Update: `<package-name>: update to X.Y.Z` - Fix: `<package-name>: fix <short description>` - ---- - -## Git Hooks - -Versioned source lives in `.extras/hooks/`. After a fresh clone, install them: - -```bash -cp .extras/hooks/* .git/hooks/ && chmod 0755 .git/hooks/{pre,post}-commit -``` - -- `pre-commit` — runs `sbolint` on each changed package; aborts the commit on - any error. Also auto-removes staged source-archive symlinks and blocks - staged regular source archives (`*.tar.*`, `*.zip`, `*.deb`, etc.). Skip - with `SBOLINT=no git commit ...`. -- `post-commit` — for each added/updated `*.SlackBuild`, offers to build the - SBo submission tarball into `SBo/<package>.tar.gz`. - -### `SBO_ARCHIVE` (non-interactive archive answer) - -`post-commit` normally prompts on a TTY. To answer without one (agents, -scripts), set `SBO_ARCHIVE`: - -- `SBO_ARCHIVE=yes git commit ...` — build the tarball, no prompt -- `SBO_ARCHIVE=no git commit ...` — skip, no prompt -- unset + TTY → interactive prompt; unset + no TTY → skip - ---- - -## What Requires User Confirmation - -Stop and ask before doing any of the following: - -- Committing or pushing changes -- Modifying files in more than one package directory -- Deleting any file -- Bypassing the pre-commit hook (`SBOLINT=no`) -- Any action not covered by the workflows above |
