Archilyzer · Source

archilyzer

Archilyzer
git clone https://archilyzer.pages.dev/source/archilyzer.git
Log | Files | Refs | README | LICENSE

commit 04dab989c7bb88216795073918d8bcb3fea0377f
parent 085c6978883ed2756dc2cfe865362b0d5edc96b6
Author: I Mean I'm Just Saying <imeanimjustsaying@kiwifarms.st>
Date:   Tue,  6 Oct 2026 09:06:05 -0400

plans: release 18 — S5 review fixes; only the runtime target was built (vulkan, cuda left for the rollout); the second half's added items

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

Diffstat:
Mplans/release-18.md | 30+++++++++++++++++++++++++++++-
1 file changed, 29 insertions(+), 1 deletion(-)

diff --git a/plans/release-18.md b/plans/release-18.md @@ -444,6 +444,9 @@ merged, so the doctor's `wrangler`, `publish-lock` and `index-stamp` checks, the - **Image:** `docker buildx build --target runtime` in a builder capped at 8 GB (`--driver-opt memory=8g memory-swap=8g`), `WHISPER_BUILD_JOBS=4`: exit 0 in 280 s from an empty builder cache, 241 s for the rebuild after the doctor commit. `archilyzer:r18smoke` is **1.76 GB** (`docker image inspect .Size`). + **Only `--target runtime` was built.** `runtime-vulkan` (trixie apt, the same pipx install) and + `runtime-cuda` (ubuntu 24.04: `pipx`, `python3-pycryptodome`, `python3-brotli` from universe) carry the + same package list unverified by a build — each to be built once, capped, before the rollout. - **Compose smoke** (`-p r18smoke`, the `channel-with-counts` e2e fixture + `sites/testsite` copied into `$T/s5-corpus` and bind-mounted over the corpus volume, `ARCHILYZER_FETCH_MODEL=none`, `ARCHILYZER_IDLE_BOOT=1`, the editor alone): the boot log shows `yt-dlp: /usr/local/bin/yt-dlp @@ -482,9 +485,22 @@ merged, so the doctor's `wrangler`, `publish-lock` and `index-stamp` checks, the - `WRANGLER_BIN` / `E2E_LIVE_CHECK` in `envVars.ts` (whichever of S2/S5 lands second). - The publish-stage smoke in the container (rollout's shape: `publish index && publish build <fixture> && publish deploy <fixture> --preview smoke`, no token → refused before wrangler, a bogus token → refused by - Cloudflare). + Cloudflare), plus `exec editor pnpm archilyzer source publish --check` over a throwaway repo with + throwaway rules copied into `/data/config/archilyzer` (the container's mirror over the read-only, + foreign-owned mount, which the doctor's `rev-parse` alone does not prove). +- The envVars dedupe at the merges: S2 also declares `CLOUDFLARE_API_TOKEN` and `ARCHILYZER_HOMEPAGE_OUT` + (one row per name, `readBy` unioned); S1's `stamps.ts` imports `imageBuildFacts` from `lib/envVars` + instead of its own. `cloudflare-auth` grades through S2's `cloudflareCredentialProblem` (which accepts + `CLOUDFLARE_API_KEY` + `CLOUDFLARE_EMAIL`). +- Building `runtime-vulkan` and `runtime-cuda` once (above). **Found and left.** +- The image has no gitleaks and no stagit: a source publish from the container skips the secret scan + (with its WARNING; the literal audit still runs) and has no history pages. RUNNING_IN_DOCKER.md says so; + a pinned gitleaks in the image is a follow-up. +- `.env` (now carrying the Cloudflare token and the R2 keys) reaches `site`, `homepage` and `umtool` + through the shared `env_file`, as it always did; nothing serves or prints it. An editor-only credentials + file is an option, not done. - The shared tool probe (`toolProbe.mjs`) counts any output from a failing `--version` as presence, so the `tools/yt-dlp` row reads `ok` with the wrapper's sentence as its "version" when no checkout is mounted; the new `downloader/yt-dlp` row asks by exit status and is the honest one. Not changed: the probe is @@ -492,6 +508,18 @@ merged, so the doctor's `wrangler`, `publish-lock` and `index-stamp` checks, the - `docker images` reported the previous `archilyzer:local` (6 weeks old) at 7.3 GB; this build is 1.76 GB. Not investigated. +**Review fixes** (review `SHIP AFTER FIXES`, no highs; the four asked for now) + +| Commit | Fix | +|---|---| +| `ba83cbff` | `docker-compose.source.yml`: long bind syntax, `create_host_path: false` — a missing host `.git` now fails `up` ("bind source path does not exist: …", verified) instead of becoming an empty root-owned dir | +| `fb1a1f24` | `YTDLP_AUTO_UPDATE`: the doctor reads it with the entrypoint's exact-match rule (`1`, `true`, `yes`, `on` as written; `TRUE` is off in both), +1 test loop; RUNNING_IN_DOCKER.md states the rule | +| `07bc2395` | RUNNING_IN_DOCKER.md: no gitleaks or stagit in the image — the container's source publish skips the secret scan (with its warning) and the history pages; pinned gitleaks a follow-up | +| this one | the record: only `--target runtime` was built (vulkan and cuda unverified, left for the rollout); the second half's added items; found and left | + +Re-run after the fixes at `07bc2395`: tsc (all workspaces) clean; `doctor`, `buildImage`, `source` and +`envVars` tests **61/61** (`$T/s5-fix-tests.log`). + ## Rollout (Steps 1–7 above; "### As it went" is written as the rollout runs.)