Per explicit direction: this repository is not going on GitHub. Moved
.github/workflows/ci.yml to .gitea/workflows/ci.yml (Gitea Actions'
convention) and updated every doc that referenced the old path or assumed
GitHub-specific features:
- .gitea/workflows/ci.yml: added a header comment on the two things that
are genuinely Gitea-specific and instance-dependent, not just a renamed
file -- `runs-on: ubuntu-latest` must match a label the actual
registered Gitea runner advertises (there is no GitHub-hosted-runner
equivalent, this is self-hosted), and `actions/checkout@v4` resolves
against whatever action source that runner is configured with.
- CONTRIBUTING.md: corrected a claim that no longer holds -- it previously
said CI "runs on a normal, unrestricted GitHub Actions VM where TSan is
expected to work"; since this is actually a self-hosted Gitea runner
whose environment isn't controlled by this repo, that assumption isn't
something this repo can vouch for, so the text now says so rather than
carrying the old (GitHub-shaped) assumption forward silently.
- SECURITY.md: removed a claim this project can't back up (that "private
security advisories" are available once hosted -- that's a GitHub
feature this repo never had access to); reporting is by direct email to
the maintainer only.
- README.md: fixed a real gap while in here -- the "Security" section
never actually linked to SECURITY.md despite it existing since the
previous commit.
- CLAUDE.md, CHANGELOG.md: updated path references; CLAUDE.md's
self-evaluation section (a historical record of an audit finding) keeps
the old .github path where it describes what was literally true at that
time, with a note explaining the rename, rather than rewriting history.
Verified: clean make all + make test, all 6 binaries pass.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UqJpkdJ6Njnt1pw3CbghzB
Project-hygiene pass toward being a properly citable, embeddable,
professionally-packaged C library rather than just working code:
- PACKFS_VERSION_MAJOR/MINOR/PATCH/STRING in include/packfs.h, the single
source of truth for the project's version, plus a runtime pfs_version()
(src/vfs.c, next to vfs_new/vfs_free) so a dynamically-linked consumer
can check ABI/API compatibility without recompiling. Covered by a new
assertion in tests/test_mem.c that the macro and the runtime function
never disagree.
- packfs.pc.in + a `make install` rule that generates packfs.pc with its
Version: field derived from PACKFS_VERSION_STRING via a Makefile-level
grep/sed, never hand-maintained separately -- verified end-to-end with a
scratch `make install PREFIX=...` + `pkg-config --cflags --libs packfs`
+ `make uninstall`, not just by reading the rule.
- SPDX-License-Identifier: MIT added to every src/*.c and src/internal.h
(include/packfs.h already had one); the whole distributed source tree
now carries consistent machine-readable license metadata.
- SECURITY.md, stating precisely what this project's containment and pack-
integrity code actually claims as a security boundary (concept.md
Section 6/7) versus what it explicitly does not (unenforced `mode`, no
cross-process concurrency) -- not generic boilerplate -- with a real
reporting contact rather than a placeholder.
- CHANGELOG.md (Keep a Changelog format), summarizing the real history in
git log to date; explicitly notes no version is tagged yet.
Verified: clean `make all` + `make test` (all 6 binaries, including the
new version-check assertion), and a full ASan/UBSan sweep of all 6
binaries with zero real findings (one run hit the already-documented
DEADLYSIGNAL sandbox flake on test_pack_write_perf across all 3 retries;
re-verified directly afterward with 5/5 additional clean passes and timing
well under any plausible timeout, confirming it was the flake, not a
regression, before treating this as done).
Deliberately not done here, by the user's explicit choice: no
CODE_OF_CONDUCT.md, and no git remote/publishing -- this repository still
has neither, and both are decisions left to the maintainer.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UqJpkdJ6Njnt1pw3CbghzB