build: re-vendor canonical files from prompts dd4027b (closes #257)
check / check (push) Canceled after 0s

The canonical files are fetched whole from sneak/prompts at dd4027b.
Kept after the canonical content: the livednstest deny entry in
.golangci.yml, /bin in .dockerignore, and this repo's own .gitignore
lines. The workflow keeps its concurrency block and
persist-credentials: false. Lint and test are phases of the Dockerfile
(golangci-lint v2.14.0; tests on the Debian Go 1.25.7 image with the
same flags); the build stage depends on both and stamps the version the
canonical way. Dockerfile.lint is gone; the prettier stages of
Dockerfile.fmt moved into the Dockerfile, so Markdown formatting still
runs in Docker. Every scripted docker build passes --no-cache;
script/cibuild bootstraps, runs script/check, then builds the image.
script/fmt-check absorbs fmt-check-go and fmt-check-markdown.

Model: opus-5-5
This commit is contained in:
2026-10-06 01:03:55 +00:00
parent d1060315b7
commit 9fb70396e9
22 changed files with 689 additions and 434 deletions
+7 -14
View File
@@ -1,6 +1,6 @@
#!/bin/sh
# script/fmt: format all files (writes). Go with gofmt and goimports on
# the host, markdown with the prettier pinned by Dockerfile.fmt.
# the host, markdown with prettier in the Dockerfile's fmt stage.
#
# goimports runs with `go run` at a pinned commit, never from PATH, so
# every machine formats with the same version and nothing installs it.
@@ -8,21 +8,15 @@
# The markdown pass is a `docker build --output type=local` rather than a
# `docker run -v`, so it needs no bind mount and behaves the same against
# a remote daemon; the formatted documents come back out of the build and
# are copied over the tree here.
#
# Unlike script/fmt-check-markdown this does not bust the cache: it is
# not a gate, and any edit to a document changes the COPY layer above the
# prettier step, so a cached result is a result over this exact tree.
# are copied over the tree here. --output writes files and makes no
# image, so there is nothing to tag.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
# goimports v0.42.0, 2026-08-07. Must match script/fmt-check-go.
# goimports v0.42.0, 2026-08-07. Must match script/fmt-check.
GOIMPORTS_REF="golang.org/x/tools/cmd/goimports@009367f5c17a8d4c45a961a3a509277190a9a6f0"
# Must match the export stage name in Dockerfile.fmt.
stage=fmt-out
die() {
echo "script/fmt: $*" >&2
exit 1
@@ -36,10 +30,9 @@ main() {
tmp="$(mktemp -d "${TMPDIR:-/tmp}/dnswatcher-fmt.XXXXXX")"
trap 'rm -rf "$tmp"' EXIT INT TERM
docker build \
--target "$stage" \
--output "type=local,dest=$tmp/out" \
-f Dockerfile.fmt .
docker build --no-cache \
--target fmt-out \
--output "type=local,dest=$tmp/out" .
# An empty export means prettier was handed nothing, which must not
# read as "already formatted".