aboutsummaryrefslogtreecommitdiffstats
path: root/AGENTS.md
diff options
context:
space:
mode:
authorDanilo M. <danix@danix.xyz>2026-09-25 10:37:06 +0200
committerDanilo M. <danix@danix.xyz>2026-09-25 10:37:06 +0200
commit20410eb37442a510e9ca3f1b038cee647ae5bf21 (patch)
tree26819129dcdc1614e7861122a2d1ba9c38783d44 /AGENTS.md
parent9e4f0fa4c4273a81f40f26177604c43856dff8c1 (diff)
downloadslackware-pentesting-suite-20410eb37442a510e9ca3f1b038cee647ae5bf21.tar.gz
slackware-pentesting-suite-20410eb37442a510e9ca3f1b038cee647ae5bf21.zip
Move maintainer tooling out of the repo
Git hooks, the upstream sweep and the SBo delivery workflow are the maintainer's operational tools, not package knowledge. They now live in a private workspace that wraps all three SlackBuild repos, with one shared copy of each hook instead of three drifting ones. Also in this pass: - AGENTS.md: checksum loop documented as sbodl (sbofixinfo does not fix checksums), nvchecker must not run without a token config, prefer use_latest_release over use_max_tag - README: Git Hooks section replaced by a short Contributing note - sweep report renamed to LAST_SWEEP.md across all three repos Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'AGENTS.md')
-rw-r--r--AGENTS.md128
1 files changed, 22 insertions, 106 deletions
diff --git a/AGENTS.md b/AGENTS.md
index 059e520..6a009e2 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -5,23 +5,6 @@ This file governs how AI agents must behave in this repository.
---
-## Core Rules
-
-1. **Ask before acting.** If anything about the task is ambiguous — target
- version, which package, which build strategy — stop and ask. Do not infer
- intent and proceed.
-2. **Use available skills.** For git operations, commits, PRs, and any task
- covered by a skill, invoke the relevant skill. Do not improvise a workflow
- that a skill already defines.
-3. **One package per task.** Never modify multiple packages in a single
- operation unless explicitly instructed.
-4. **Never skip lint.** Every change must pass `sbolint` before committing.
- No exceptions.
-5. **Never commit without being asked.** Complete all file edits and
- verification steps, then wait for explicit instruction to commit.
-
----
-
## Repository Layout
Each package lives in its own top-level subfolder:
@@ -99,25 +82,17 @@ exact URL for the new version before editing.
### Step 3 — Fix the checksum
-Run `sbofixinfo` from inside the package directory:
-
-```bash
-cd <package-name> && sbofixinfo
-```
-
-If `sbofixinfo` reports no changes (common when the checksum is a placeholder),
-use the two-pass `sbodl` procedure instead:
+`sbofixinfo` does not fix checksums, it only normalizes `.info` formatting.
+The checksum loop is `sbodl`:
```bash
-# Pass 1 — downloads the source; fails because MD5SUM is wrong/placeholder
+# Pass 1: downloads the source and prints
+# WARN: md5sum doesn't match ... got: <new>
cd <package-name> && sbodl
-# Compute the real checksum from the downloaded file
-md5sum <downloaded-file> # adjust filename as needed
-
-# Update the MD5SUM (or MD5SUM_x86_64) in the .info file
+# Put the got: value into MD5SUM (or MD5SUM_x86_64) in the .info file
-# Pass 2 — verifies the checksum; must report "md5sum matches OK"
+# Pass 2: must report "md5sum matches OK"
cd <package-name> && sbodl
```
@@ -157,50 +132,29 @@ Then proceed:
1. Create the package directory with all required files:
`<prgnam>.SlackBuild`, `<prgnam>.info`, `README`, `slack-desc`
2. Choose the correct build strategy and follow the scripting rules below.
-3. Run `sbofixinfo`, then `sbodl` (two-pass if needed), then `sbolint`.
+3. Run `sbofixinfo`, then `sbodl` (two-pass, see above), then `sbolint`.
4. Report results and wait for commit instruction.
---
-## Version Sweep
+## Version Tracking: nvchecker.toml
-The `.extras/nvchecker.toml` file tracks upstream versions for all packages
-in the suite (both in-repo and sbo-slackbuilds). A sweep compares upstream
-against what this repo carries and identifies packages that need updating.
+`.extras/nvchecker.toml` is the **suite catalog**: it tracks upstream versions
+for every tool in the suite, not only the packages in this repo. That
+includes packages maintained in `sbo-slackbuilds` and tools packaged on SBo by
+others (e.g. `hashcat`, `john`). Stanzas without a package directory here are
+intentional; do not remove them. New packages get a stanza too.
-### Procedure
+The file has no `[__config__]`. Do not run it as-is against GitHub: the
+anonymous API budget (60 req/h) runs out and later stanzas 403. Run it from a
+throwaway copy with a `[__config__]` that adds a GitHub token keyfile, and
+probe single stanzas with `nvchecker -c <cfg> -e <name>`. Prefer
+`use_latest_release` over `use_max_tag` for github stanzas; `use_max_tag` is
+tightly rate-limited and only needed for repos that tag without cutting
+Releases.
-1. Generate a throwaway nvchecker config in the scratchpad (`/tmp/opencode/`)
- that prepends a `[__config__]` section pointing at the personal keyfile
- (`~/.config/nvchecker/keys.toml`, provides a GitHub token for 5000 req/h)
- plus scratchpad `oldver`/`newver` paths, then appends the stanzas from
- `.extras/nvchecker.toml`.
-
-2. Run `nvchecker -c <throwaway-config>` on the throwaway config. With a
- fresh `oldver`, every stanza reports "updated to X" — that is the
- *upstream* version, not a diff.
-
-3. For each **in-repo** package (cadaver, netexec, windows-binaries,
- webshells), compare the reported upstream version against the `VERSION=`
- in that package's `.info` file. Packages maintained in `sbo-slackbuilds`
- are out of scope for this repo's sweep.
-
-4. Update `LAST_SWEEP` (gitignored) with the date and a table showing
- carried version, upstream version, and status (current / needs bump)
- for each in-repo package.
-
-5. For any package that needs a bump, follow the Mandatory Workflow:
- Updating a Package Version above.
-
-### Important notes
-
-- Never run `nvchecker -c .extras/nvchecker.toml` directly — the tracked
- config has no `[__config__]`, so GitHub stanzas hit the anonymous rate
- limit (60 req/h) and 403.
-- Probe a single package with `nvchecker -c <config> -e <name>` when
- testing a specific stanza.
-- Never audit GitHub repos with raw `curl` loops — a burst burns the
- anonymous quota and later calls 403.
+Maintainer tooling (git hooks, the upstream sweep, test builds, SBo archive
+builder) is kept outside this repo, in the maintainer's private workspace.
---
@@ -348,41 +302,3 @@ Commit conventions:
- Add: `<package-name>: add version X.Y.Z`
- Update: `<package-name>: update to X.Y.Z`
- Fix: `<package-name>: fix <short description>`
-
----
-
-## Git Hooks
-
-Versioned source lives in `.extras/hooks/`. After a fresh clone, install them:
-
-```bash
-cp .extras/hooks/* .git/hooks/ && chmod 0755 .git/hooks/{pre,post}-commit
-```
-
-- `pre-commit` — runs `sbolint` on each changed package; aborts the commit on
- any error. Also auto-removes staged source-archive symlinks and blocks
- staged regular source archives (`*.tar.*`, `*.zip`, `*.deb`, etc.). Skip
- with `SBOLINT=no git commit ...`.
-- `post-commit` — for each added/updated `*.SlackBuild`, offers to build the
- SBo submission tarball into `SBo/<package>.tar.gz`.
-
-### `SBO_ARCHIVE` (non-interactive archive answer)
-
-`post-commit` normally prompts on a TTY. To answer without one (agents,
-scripts), set `SBO_ARCHIVE`:
-
-- `SBO_ARCHIVE=yes git commit ...` — build the tarball, no prompt
-- `SBO_ARCHIVE=no git commit ...` — skip, no prompt
-- unset + TTY → interactive prompt; unset + no TTY → skip
-
----
-
-## What Requires User Confirmation
-
-Stop and ask before doing any of the following:
-
-- Committing or pushing changes
-- Modifying files in more than one package directory
-- Deleting any file
-- Bypassing the pre-commit hook (`SBOLINT=no`)
-- Any action not covered by the workflows above