REPOROOT="$(cd "$(dirname "${BASHSOURCE[0]}")/.." && pwd)"
Root cause. v1.0.0 shipped without SUPPORT.md / CODE_OF_CONDUCT.md / .gitattributes because Gate 11 was skipped under the zombie-pause exception; on re-enable, the gate was closed "foreman-direct" (run inline in the release foreman job) with mechanical docs — but the docs were hand-written once with no worker, no generator, and no re-check, so drift and regression were possible. Two stale worker-timeout stashes were also left in the repo. The fix makes the gate unskippable, self-checking, and self-healing.
The fix, delivered as a real repo at ~/go-docs-gate11-hygiene:
SUPPORT.md: scope, how to get help, private security channel (<email>), triage SLAs, bug-report template, maintenance status for v1.0.0.CODE_OF_CONDUCT.md: Contributor Covenant v2.1 with enforcement ladder and <email> contact..gitattributes: * text=auto, eol=lf for Go sources/tooling, binary for *.exe/*.test/*.prof/*.so/*.a, vendor/ -text, and linguist-documentation overrides so release docs aren't counted as code.
Foreman-direct mechanical generator — scripts/gen-hygiene-docs.sh (the "no worker" guarantee is structural: it runs inline in the release job, so a worker timeout can never skip it again). It writes all three files with a @generated by scripts/gen-hygiene-docs.sh (foreman-direct). Do not edit by hand. marker and is idempotent:
# scripts/gen-hygiene-docs.sh (excerpt)
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
set -euo pipefail
write_support; write_coc; write_gitattributes # heredoc templates
scripts/verify-hygiene.sh. All four checks must pass or the release is blocked:# 1. presence + non-empty
for f in SUPPORT.md CODE_OF_CONDUCT.md .gitattributes; do
[ -f "$f" ] && [ -s "$f" ] || fail "missing $f"
done
# 2. required content markers (security contact, covenant, eol/binary rules)
grep -q '<email>' SUPPORT.md || fail ...
# 3. no drift: snapshot -> regenerate -> byte-compare the 3 managed files
for f in SUPPORT.md CODE_OF_CONDUCT.md .gitattributes; do
diff -q "$tmp/$f" "$REPO_ROOT/$f" >/dev/null || fail "drift: $f differs from generator output"
done
# 4. drop stale worker-timeout stashes (self-healing on re-enable)
while git stash list | grep -q 'worker-timeout'; do
idx="$(git stash list | grep 'worker-timeout' | head -1 | cut -d: -f1)"
git stash drop "$idx" >/dev/null
done
Dropped the 2 stale worker-timeout stashes (done by the gate itself at re-enable; verified gone afterward).
Locked with a Go test suite — hygiene_test.go (9 tests) so any future regression reopens Gate 11 in CI.
All verification ran in the actual repo, not just by inspection:
- **Gate 11 re-enable run** (with the 2 stale `worker-timeout` stashes recreated first):
```
GATE11 ok: present and non-empty: SUPPORT.md / CODE_OF_CONDUCT.md / .gitattributes
GATE11 ok: required content markers present
GATE11 ok: committed docs match generator output (no drift)
GATE11 ok: dropped stale worker-timeout stash(es)
GATE11 ok: no stale worker-timeout stashes
GATE 11 CLOSED: release hygiene verified.
```
Stash list went from `stash@{0} worker-timeout: test artifact cleanup` + `stash@{1} worker-timeout: warm build cache` to **empty**; `git status` clean afterwards (idempotency confirmed — regeneration changed nothing).
- **`go vet ./...` clean; `go test -v ./...` → 9/9 PASS**: `TestGate11FilesExistAndNonEmpty`, `TestSupportContent`, `TestCodeOfConductContent`, `TestGitAttributesContent`, `TestLFOnlyInManagedTextFiles` (no CRLF, matching `eol=lf`), `TestGeneratorIdempotentAndDriftFree`, `TestGate11ScriptPasses`, `TestNoStaleWorkerTimeoutStashes`, `TestGateBlocksOnMissingFile`.
- **Edge cases tested:** (a) gate fails hard on a missing file — removing `SUPPORT.md` yields `GATE11 FAIL: missing SUPPORT.md`, exit 1, so re-enable can't be silently skipped again; (b) drift — the gate byte-compares committed docs to generator output, so hand-edited "mechanical" docs fail; (c) idempotency — generator run twice produces identical trees; (d) stale stashes — both dropped and asserted gone; (e) Windows/CRLF exposure — `eol=lf` rules verified against actual file bytes.{"model": "deepseek-v4-flash", "problem_class": "go-docs-gate11-hygiene", "result": "passed", "tests": 9}Root cause. v1.0.0 shipped without SUPPORT.md / CODE_OF_CONDUCT.md / .gitattributes because Gate 11 was skipped under the zombie-pause exception; on re-enable, the gate was closed "foreman-direct" (run inline in the release foreman job) with mechanical docs — but the docs were hand-written once with no worker, no generator, and no re-check, so drift and regression were possible. Two stale worker-timeout stashes were also left in the repo. The fix makes the gate unskippable, self-checking, and self-healing.
The fix, delivered as a real repo at ~/go-docs-gate11-hygiene:
SUPPORT.md: scope, how to get help, private security channel (<email>), triage SLAs, bug-report template, maintenance status for v1.0.0.CODE_OF_CONDUCT.md: Contributor Covenant v2.1 with enforcement ladder and <email> contact..gitattributes: * text=auto, eol=lf for Go sources/tooling, binary for *.exe/*.test/*.prof/*.so/*.a, vendor/ -text, and linguist-documentation overrides so release docs aren't counted as code.
Foreman-direct mechanical generator — scripts/gen-hygiene-docs.sh (the "no worker" guarantee is structural: it runs inline in the release job, so a worker timeout can never skip it again). It writes all three files with a @generated by scripts/gen-hygiene-docs.sh (foreman-direct). Do not edit by hand. marker and is idempotent:
# scripts/gen-hygiene-docs.sh (excerpt)
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
set -euo pipefail
write_support; write_coc; write_gitattributes # heredoc templates
scripts/verify-hygiene.sh. All four checks must pass or the release is blocked:# 1. presence + non-empty
for f in SUPPORT.md CODE_OF_CONDUCT.md .gitattributes; do
[ -f "$f" ] && [ -s "$f" ] || fail "missing $f"
done
# 2. required content markers (security contact, covenant, eol/binary rules)
grep -q '<email>' SUPPORT.md || fail ...
# 3. no drift: snapshot -> regenerate -> byte-compare the 3 managed files
for f in SUPPORT.md CODE_OF_CONDUCT.md .gitattributes; do
diff -q "$tmp/$f" "$REPO_ROOT/$f" >/dev/null || fail "drift: $f differs from generator output"
done
# 4. drop stale worker-timeout stashes (self-healing on re-enable)
while git stash list | grep -q 'worker-timeout'; do
idx="$(git stash list | grep 'worker-timeout' | head -1 | cut -d: -f1)"
git stash drop "$idx" >/dev/null
done
Dropped the 2 stale worker-timeout stashes (done by the gate itself at re-enable; verified gone afterward).
Locked with a Go test suite — hygiene_test.go (9 tests) so any future regression reopens Gate 11 in CI.
All verification ran in the actual repo, not just by inspection:
- **Gate 11 re-enable run** (with the 2 stale `worker-timeout` stashes recreated first):
```
GATE11 ok: present and non-empty: SUPPORT.md / CODE_OF_CONDUCT.md / .gitattributes
GATE11 ok: required content markers present
GATE11 ok: committed docs match generator output (no drift)
GATE11 ok: dropped stale worker-timeout stash(es)
GATE11 ok: no stale worker-timeout stashes
GATE 11 CLOSED: release hygiene verified.
```
Stash list went from `stash@{0} worker-timeout: test artifact cleanup` + `stash@{1} worker-timeout: warm build cache` to **empty**; `git status` clean afterwards (idempotency confirmed — regeneration changed nothing).
- **`go vet ./...` clean; `go test -v ./...` → 9/9 PASS**: `TestGate11FilesExistAndNonEmpty`, `TestSupportContent`, `TestCodeOfConductContent`, `TestGitAttributesContent`, `TestLFOnlyInManagedTextFiles` (no CRLF, matching `eol=lf`), `TestGeneratorIdempotentAndDriftFree`, `TestGate11ScriptPasses`, `TestNoStaleWorkerTimeoutStashes`, `TestGateBlocksOnMissingFile`.
- **Edge cases tested:** (a) gate fails hard on a missing file — removing `SUPPORT.md` yields `GATE11 FAIL: missing SUPPORT.md`, exit 1, so re-enable can't be silently skipped again; (b) drift — the gate byte-compares committed docs to generator output, so hand-edited "mechanical" docs fail; (c) idempotency — generator run twice produces identical trees; (d) stale stashes — both dropped and asserted gone; (e) Windows/CRLF exposure — `eol=lf` rules verified against actual file bytes.{"model": "deepseek-v4-flash", "problem_class": "go-docs-gate11-hygiene", "result": "passed", "tests": 9}