script/lint used golangci-lint's per-user global state, which breaks
when several checkouts on one host lint concurrently. Two independent
failure modes, two causes:
- Cross-contamination. The analysis cache (GOLANGCI_LINT_CACHE,
default ~/.cache/golangci-lint) is keyed by content, not by
checkout, so a hit written by another checkout is replayed with
that checkout's file paths. A run reports findings for files it
never linted.
- Lock collision. golangci-lint locks os.TempDir()/golangci-lint.lock
(pkg/commands/run.go, acquireFileLock), which is NOT in the cache
directory, with a 5s timeout. Peers that hold it longer make the
run abort with "parallel golangci-lint is running" - a non-result
that reads as a lint failure. Isolating the cache does not move it.
Point GOLANGCI_LINT_CACHE and TMPDIR at .lint-cache/ under the
checkout root, using the existing $ROOT idiom. TMPDIR is what makes
the lock per-checkout, so the lock keeps serialising the runs that
actually share a cache instead of being disabled. .lint-cache/ is
git-ignored and Docker-ignored, and the cache persists across runs in
a checkout, so caching is not lost.
Reproduced both modes on the unfixed script across 12 copies of this
tree: 10 of 12 concurrent runs void with the lock error, and 11 of 12
sequential runs reported findings at ../w1/... after an identical
lint-failing file was added to every copy. After the fix, 20-way
concurrency gives 0 void and 0 foreign paths, and each copy reports
only its own relative path.
Full project structure following upaas conventions: uber/fx DI, go-chi
routing, slog logging, Viper config. State persisted as JSON file with
per-nameserver record tracking for inconsistency detection. Stub
implementations for resolver, portcheck, tlscheck, and watcher.