Skip to content

build(deps): refresh SQLite runtime and Go lint tooling - #264

Merged
steipete merged 1 commit into
mainfrom
oss-s6-discrawl
Sep 30, 2026
Merged

steipete merged 1 commit into
mainfrom
oss-s6-discrawl

Conversation

@steipete

Copy link
Copy Markdown
Contributor

Refresh the database runtime to modernc SQLite v1.60.1 with its upstream-required libc v1.77.1, update go-strftime to v1.1.0, and align local/CI golangci-lint at v2.14.0. The Go 1.27.0 minimum, preferred Go 1.27.1 toolchain, and Crawlkit version stay unchanged. Release documentation records the new SQLite/libc pairing; Unreleased records the maintenance change.

Validation: make check passed on a clean Linux amd64 AWS Crabbox with Go 1.27.1: module verification/tidiness, formatting, lint/vet/staticcheck/gosec/deadcode, govulncheck, full race tests with 86.0% coverage, CLI smoke, and all six snapshot platform builds. Cloud publisher/docs tests (15 tests), docs generation, and the source-reconciliation tests also passed.

Codex autoreview completed at P0–P2 with no accepted actionable finding. Its sole finding claimed go-strftime v1.1.0 was unpublished, based on a cached tag page; the live GitHub tag, Go proxy metadata, checksum database, and clean download all independently confirm the published version.

@steipete
steipete requested a review from a team as a code owner September 30, 2026 02:06
@clawsweeper

clawsweeper Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 30, 2026
@clawsweeper

clawsweeper Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Codex review: needs maintainer review before merge. Reviewed September 29, 2026, 10:09 PM ET / September 30, 2026, 02:09 UTC.

ClawSweeper review

What this changes

Updates Discrawl’s SQLite driver, paired libc and date-format dependency, aligns local and CI lint versions, and records the versions in release documentation.

Merge readiness

✅ Ready for maintainer review

Keep open: current main still has the older versions, so this maintenance PR remains useful. The inspected patch has no definite correctness or security defect.

Priority: P3
Reviewed head: 500f140c1b93f1db852f728c7820501a5e0ed04c

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A focused maintenance patch with matched upstream versions and broad reported validation, with no definite introduced defect found.
Proof confidence 🌊 off-meta tidepool Not applicable: Repository State classifies the author as MEMBER, so the external-contributor proof gate does not apply. The changed module graph feeds the archive store and SQLite repair helper; the PR reports Linux checks and CLI smoke, but no production archive run. No stored-data format or schema contract changes.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: Repository State classifies the author as MEMBER, so the external-contributor proof gate does not apply. The changed module graph feeds the archive store and SQLite repair helper; the PR reports Linux checks and CLI smoke, but no production archive run. No stored-data format or schema contract changes.
Evidence reviewed 9 items Introduced module versions: The pinned PR diff updates SQLite to v1.60.1, libc to v1.77.1, and go-strftime to v1.1.0.
Upstream dependency pairing: The official SQLite repository’s v1.60.1 go.mod requires modernc.org/libc v1.77.1, matching the PR.
Date-format version exists: GitHub’s tag endpoint identifies refs/tags/v1.1.0, supporting the PR body’s response to the earlier cached-tag concern.
Findings None None.
Security None None.

How this fits together

Discrawl stores Discord history in a local SQLite archive that its search and diagnostic commands read. Go dependency pins affect that archive and its repair helper; the Makefile and CI workflow check the resulting source.

flowchart LR
  A[Discord archive inputs] --> B[Go storage layer]
  B --> C[SQLite driver and libc]
  C --> D[Local SQLite archive]
  D --> E[Search and diagnostics]
  F[Go dependency pins] --> C
  F --> G[Local and CI lint checks]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

None.

Technical review

Best possible solution:

Maintain a reproducible dependency set that continues to open existing archives across supported platforms without changing the stored schema or Go minimum.

Do we have a high-confidence way to reproduce the issue?

Not applicable: this is a version refresh, not a reported failure; current main’s older pins are directly visible in source.

Is this the best way to solve the issue?

Yes: the driver and libc versions match upstream’s module requirement, and local and CI lint pins follow the repository’s existing pattern.

AGENTS.md: found, but no applicable review policy affected this item.

Codex review notes: model internal, reasoning high; reviewed against d481b3b56e51.

Labels

Label changes:

  • add P3: This is a focused dependency and lint-tool maintenance update without an established urgent user regression.
  • add rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • add status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: Repository State classifies the author as MEMBER, so the external-contributor proof gate does not apply. The changed module graph feeds the archive store and SQLite repair helper; the PR reports Linux checks and CLI smoke, but no production archive run. No stored-data format or schema contract changes.

Label justifications:

  • P3: This is a focused dependency and lint-tool maintenance update without an established urgent user regression.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: Repository State classifies the author as MEMBER, so the external-contributor proof gate does not apply. The changed module graph feeds the archive store and SQLite repair helper; the PR reports Linux checks and CLI smoke, but no production archive run. No stored-data format or schema contract changes.

Evidence

What I checked:

  • Introduced module versions: The pinned PR diff updates SQLite to v1.60.1, libc to v1.77.1, and go-strftime to v1.1.0. (go.mod:48, 500f140c1b93)
  • Upstream dependency pairing: The official SQLite repository’s v1.60.1 go.mod requires modernc.org/libc v1.77.1, matching the PR. (go.mod:9, b122d0417c01)
  • Date-format version exists: GitHub’s tag endpoint identifies refs/tags/v1.1.0, supporting the PR body’s response to the earlier cached-tag concern. (fa91ab7a1dcb)
  • Lint versions aligned: The PR pins golangci-lint v2.14.0 in both the CI action and the local Makefile target; the action revision and workflow permissions are unchanged. (.github/workflows/ci.yml:50, 500f140c1b93)
  • SQLite production boundary: The archive store opens through Crawlkit, while the separately maintained cache-repair helper directly imports modernc.org/sqlite; both use the changed Go module graph. (scripts/repair_discord_cache.go:28, 500f140c1b93)
  • Existing archive coverage: Store tests open older schemas and check migration results. The cache-repair workflow also runs its explicit helper tests when go.mod or go.sum changes. (internal/store/store_test.go:1404, 500f140c1b93)

Likely related people:

  • steipete: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • vincentkoc: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@steipete
steipete merged commit d554857 into main Sep 30, 2026
24 checks passed
@steipete
steipete deleted the oss-s6-discrawl branch September 30, 2026 02:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant