1 Commits

Author SHA1 Message Date
584b5f5b39 build: update golangci-lint to v2.12.2 with commit-pinned installs
All checks were successful
check / check (push) Successful in 1m0s
Pin golangci-lint to commit c0d3ddc9cf3faa61a4e378e879ece580256d76e5
(v2.12.2) in Dockerfile and script/bootstrap. Fix the goconst findings
the new version reports under the unchanged canonical .golangci.yml by
extracting shared test fixture constants and a statusError constant in
the watcher.
2026-08-07 20:21:36 +00:00
9 changed files with 157 additions and 154 deletions

View File

@@ -1,9 +1,5 @@
version: "2"
# Config schema uses the golangci-lint v2 layout (settings live under
# linters.settings, not top-level linters-settings) so that the
# thresholds below are actually applied by golangci-lint >= v2.
run:
timeout: 5m
modules-download-mode: readonly
@@ -18,17 +14,19 @@ linters:
- wsl # Deprecated, replaced by wsl_v5
- wrapcheck # Too verbose for internal packages
- varnamelen # Short names like db, id are idiomatic Go
settings:
lll:
line-length: 88
funlen:
lines: 80
statements: 50
cyclop:
max-complexity: 15
dupl:
threshold: 100
linters-settings:
lll:
line-length: 88
funlen:
lines: 80
statements: 50
cyclop:
max-complexity: 15
dupl:
threshold: 100
issues:
exclude-use-default: false
max-issues-per-linter: 0
max-same-issues: 0

View File

@@ -5,7 +5,7 @@ FROM golang@sha256:f6751d823c26342f9506c03797d2527668d095b0a15f1862cddb4d927a7a4
RUN apk add --no-cache git make gcc musl-dev binutils-gold
# golangci-lint v2.12.2, 2026-08-07
RUN go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.12.2
RUN go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@c0d3ddc9cf3faa61a4e378e879ece580256d76e5
# goimports v0.42.0
RUN go install golang.org/x/tools/cmd/goimports@009367f5c17a8d4c45a961a3a509277190a9a6f0

View File

@@ -25,10 +25,9 @@ confirm make check still passes.
# Completed Steps
- 2026-08-07: golangci-lint bumped to v2.12.2 (pins in `Dockerfile` and
`script/bootstrap`), `.golangci.yml` replaced with the canonical v2
config (settings moved under `linters.settings` so thresholds now
apply); fixed all resulting `goconst`, `dupl`, and `lll` findings
- 2026-08-07: golangci-lint bumped to v2.12.2 (commit-pinned installs
in `Dockerfile` and `script/bootstrap`); fixed the resulting
`goconst` findings. `.golangci.yml` unchanged (canonical)
- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints,
Makefile shims, README Entrypoints section
- 2026-02-20: iterative DNS resolver implemented; tests made hermetic

View File

@@ -17,33 +17,13 @@ func TestClassifyDNSName(t *testing.T) {
}{
{name: "apex domain simple", input: "example.com", want: config.DNSNameTypeDomain},
{name: "hostname simple", input: "www.example.com", want: config.DNSNameTypeHostname},
{
name: "apex domain multi-part TLD",
input: "example.co.uk",
want: config.DNSNameTypeDomain,
},
{
name: "hostname multi-part TLD",
input: "api.example.co.uk",
want: config.DNSNameTypeHostname,
},
{name: "apex domain multi-part TLD", input: "example.co.uk", want: config.DNSNameTypeDomain},
{name: "hostname multi-part TLD", input: "api.example.co.uk", want: config.DNSNameTypeHostname},
{name: "public suffix itself", input: "co.uk", wantErr: true},
{name: "empty string", input: "", wantErr: true},
{
name: "deeply nested hostname",
input: "a.b.c.example.com",
want: config.DNSNameTypeHostname,
},
{
name: "trailing dot stripped",
input: "example.com.",
want: config.DNSNameTypeDomain,
},
{
name: "uppercase normalized",
input: "WWW.Example.COM",
want: config.DNSNameTypeHostname,
},
{name: "deeply nested hostname", input: "a.b.c.example.com", want: config.DNSNameTypeHostname},
{name: "trailing dot stripped", input: "example.com.", want: config.DNSNameTypeDomain},
{name: "uppercase normalized", input: "WWW.Example.COM", want: config.DNSNameTypeHostname},
}
for _, tt := range tests {

View File

@@ -25,20 +25,18 @@ const (
colorDefault = "#6c757d"
)
// Priority strings used across multiple tests.
// Priority and fixture values shared across tests.
const (
prioError = "error"
prioWarning = "warning"
prioSuccess = "success"
prioInfo = "info"
prioSuccess = "success"
prioUnknown = "unknown"
prioDefault = "default"
prioUrgent = "urgent"
ntfyUrgent = "urgent"
ntfyDefault = "default"
testHost = "example.com"
)
// testHost is the hostname used in request construction tests.
const testHost = "example.com"
// errSimulated is a static error for transport failures.
var errSimulated = errors.New("simulated transport failure")
@@ -115,13 +113,13 @@ func TestNtfyPriority(t *testing.T) {
input string
want string
}{
{prioError, prioUrgent},
{prioError, ntfyUrgent},
{prioWarning, "high"},
{prioSuccess, prioDefault},
{prioSuccess, ntfyDefault},
{prioInfo, "low"},
{"", prioDefault},
{prioUnknown, prioDefault},
{"critical", prioDefault},
{"", ntfyDefault},
{prioUnknown, ntfyDefault},
{"critical", ntfyDefault},
}
for _, tc := range cases {
@@ -303,10 +301,10 @@ func TestSendNtfyHeaders(t *testing.T) {
)
}
if captured.priority != prioUrgent {
if captured.priority != ntfyUrgent {
t.Errorf(
"Priority header = %q, want %q",
captured.priority, prioUrgent,
captured.priority, ntfyUrgent,
)
}
@@ -325,9 +323,9 @@ func TestSendNtfyAllPriorities(t *testing.T) {
input string
want string
}{
{prioError, prioUrgent},
{prioError, ntfyUrgent},
{prioWarning, "high"},
{prioSuccess, prioDefault},
{prioSuccess, ntfyDefault},
{prioInfo, "low"},
}
@@ -370,69 +368,56 @@ func TestSendNtfyAllPriorities(t *testing.T) {
}
}
// assertSendStatusError verifies that send returns an error
// wrapping wantErr when the server responds with status.
func assertSendStatusError(
t *testing.T,
status int,
wantErr error,
send func(*notify.Service, *url.URL) error,
) {
t.Helper()
func TestSendNtfyClientError(t *testing.T) {
t.Parallel()
srv := httptest.NewServer(
http.HandlerFunc(
func(w http.ResponseWriter, _ *http.Request) {
w.WriteHeader(status)
w.WriteHeader(http.StatusForbidden)
}),
)
defer srv.Close()
svc := notify.NewTestService(srv.Client().Transport)
target, _ := url.Parse(srv.URL)
topicURL, _ := url.Parse(srv.URL)
err := send(svc, target)
err := svc.SendNtfy(
context.Background(), topicURL, "t", "m", "info",
)
if err == nil {
t.Fatalf("expected error for %d response", status)
t.Fatal("expected error for 403 response")
}
if !errors.Is(err, wantErr) {
t.Errorf("error = %v, want %v", err, wantErr)
if !errors.Is(err, notify.ErrNtfyFailed) {
t.Errorf("error = %v, want ErrNtfyFailed", err)
}
}
func sendNtfyInfo(
svc *notify.Service, target *url.URL,
) error {
return svc.SendNtfy(
context.Background(), target, "t", "m", prioInfo,
)
}
func sendSlackInfo(
svc *notify.Service, target *url.URL,
) error {
return svc.SendSlack(
context.Background(), target, "t", "m", prioInfo,
)
}
func TestSendNtfyClientError(t *testing.T) {
t.Parallel()
assertSendStatusError(
t, http.StatusForbidden,
notify.ErrNtfyFailed, sendNtfyInfo,
)
}
func TestSendNtfyServerError(t *testing.T) {
t.Parallel()
assertSendStatusError(
t, http.StatusInternalServerError,
notify.ErrNtfyFailed, sendNtfyInfo,
srv := httptest.NewServer(
http.HandlerFunc(
func(w http.ResponseWriter, _ *http.Request) {
w.WriteHeader(http.StatusInternalServerError)
}),
)
defer srv.Close()
svc := notify.NewTestService(srv.Client().Transport)
topicURL, _ := url.Parse(srv.URL)
err := svc.SendNtfy(
context.Background(), topicURL, "t", "m", "info",
)
if err == nil {
t.Fatal("expected error for 500 response")
}
if !errors.Is(err, notify.ErrNtfyFailed) {
t.Errorf("error = %v, want ErrNtfyFailed", err)
}
}
func TestSendNtfySuccess(t *testing.T) {
@@ -633,19 +618,53 @@ func TestSendSlackAllColors(t *testing.T) {
func TestSendSlackClientError(t *testing.T) {
t.Parallel()
assertSendStatusError(
t, http.StatusBadRequest,
notify.ErrSlackFailed, sendSlackInfo,
srv := httptest.NewServer(
http.HandlerFunc(
func(w http.ResponseWriter, _ *http.Request) {
w.WriteHeader(http.StatusBadRequest)
}),
)
defer srv.Close()
svc := notify.NewTestService(srv.Client().Transport)
webhookURL, _ := url.Parse(srv.URL)
err := svc.SendSlack(
context.Background(), webhookURL, "t", "m", "info",
)
if err == nil {
t.Fatal("expected error for 400 response")
}
if !errors.Is(err, notify.ErrSlackFailed) {
t.Errorf("error = %v, want ErrSlackFailed", err)
}
}
func TestSendSlackServerError(t *testing.T) {
t.Parallel()
assertSendStatusError(
t, http.StatusBadGateway,
notify.ErrSlackFailed, sendSlackInfo,
srv := httptest.NewServer(
http.HandlerFunc(
func(w http.ResponseWriter, _ *http.Request) {
w.WriteHeader(http.StatusBadGateway)
}),
)
defer srv.Close()
svc := notify.NewTestService(srv.Client().Transport)
webhookURL, _ := url.Parse(srv.URL)
err := svc.SendSlack(
context.Background(), webhookURL, "t", "m", "error",
)
if err == nil {
t.Fatal("expected error for 502 response")
}
if !errors.Is(err, notify.ErrSlackFailed) {
t.Errorf("error = %v, want ErrSlackFailed", err)
}
}
func TestSendSlackNetworkError(t *testing.T) {
@@ -970,62 +989,74 @@ func TestSendNotificationMattermostOnly(t *testing.T) {
}
}
// assertSendNotificationTolerates verifies SendNotification
// neither panics nor blocks when the endpoint configured by
// setURL responds with status.
func assertSendNotificationTolerates(
t *testing.T,
status int,
priority string,
setURL func(*notify.Service, *url.URL),
) {
t.Helper()
func TestSendNotificationNtfyError(t *testing.T) {
t.Parallel()
srv := httptest.NewServer(
http.HandlerFunc(
func(w http.ResponseWriter, _ *http.Request) {
w.WriteHeader(status)
w.WriteHeader(http.StatusInternalServerError)
}),
)
defer srv.Close()
target, _ := url.Parse(srv.URL)
ntfyURL, _ := url.Parse(srv.URL)
svc := notify.NewTestService(http.DefaultTransport)
setURL(svc, target)
svc.SetNtfyURL(ntfyURL)
// Should not panic or block.
svc.SendNotification(
context.Background(), "t", "m", priority,
context.Background(), "t", "m", "error",
)
time.Sleep(100 * time.Millisecond)
}
func TestSendNotificationNtfyError(t *testing.T) {
t.Parallel()
assertSendNotificationTolerates(
t, http.StatusInternalServerError, prioError,
(*notify.Service).SetNtfyURL,
)
}
func TestSendNotificationSlackError(t *testing.T) {
t.Parallel()
assertSendNotificationTolerates(
t, http.StatusForbidden, prioError,
(*notify.Service).SetSlackWebhookURL,
srv := httptest.NewServer(
http.HandlerFunc(
func(w http.ResponseWriter, _ *http.Request) {
w.WriteHeader(http.StatusForbidden)
}),
)
defer srv.Close()
slackURL, _ := url.Parse(srv.URL)
svc := notify.NewTestService(http.DefaultTransport)
svc.SetSlackWebhookURL(slackURL)
svc.SendNotification(
context.Background(), "t", "m", "error",
)
time.Sleep(100 * time.Millisecond)
}
func TestSendNotificationMattermostError(t *testing.T) {
t.Parallel()
assertSendNotificationTolerates(
t, http.StatusBadGateway, prioWarning,
(*notify.Service).SetMattermostWebhookURL,
srv := httptest.NewServer(
http.HandlerFunc(
func(w http.ResponseWriter, _ *http.Request) {
w.WriteHeader(http.StatusBadGateway)
}),
)
defer srv.Close()
mmURL, _ := url.Parse(srv.URL)
svc := notify.NewTestService(http.DefaultTransport)
svc.SetMattermostWebhookURL(mmURL)
svc.SendNotification(
context.Background(), "t", "m", "warning",
)
time.Sleep(100 * time.Millisecond)
}
// ── SlackPayload JSON marshaling ──────────────────────────

View File

@@ -69,7 +69,7 @@ func (rc RetryConfig) backoff(attempt int) time.Duration {
lo := raw * (1 - jitterFraction)
hi := raw * (1 + jitterFraction)
jittered := lo + rand.Float64()*(hi-lo) //nolint:gosec // jitter needs no crypto/rand
jittered := lo + rand.Float64()*(hi-lo) //nolint:gosec // jitter does not need crypto/rand
return time.Duration(jittered)
}

View File

@@ -223,8 +223,7 @@ func TestSaveLoadRoundTrip_Ports(t *testing.T) {
}
}
// TestSaveLoadRoundTrip_Certificates verifies certificate data
// survives a save/load cycle.
// TestSaveLoadRoundTrip_Certificates verifies certificate data survives a save/load cycle.
func TestSaveLoadRoundTrip_Certificates(t *testing.T) {
t.Parallel()
@@ -1073,8 +1072,7 @@ func TestConcurrentGetSet(t *testing.T) {
wg.Wait()
}
// runConcurrentOps performs a series of get/set/delete
// operations for concurrency testing.
// runConcurrentOps performs a series of get/set/delete operations for concurrency testing.
func runConcurrentOps(s *state.State, key string, now time.Time) {
const iterations = 50

View File

@@ -26,11 +26,8 @@ const tlsPort = 443
// hoursPerDay converts days to hours for duration calculations.
const hoursPerDay = 24
// Status values recorded for nameserver and certificate checks.
const (
statusOK = "ok"
statusError = "error"
)
// statusError is the status value recorded for failed checks.
const statusError = "error"
// Params contains dependencies for Watcher.
type Params struct {
@@ -350,7 +347,7 @@ func buildHostnameState(
for ns, recs := range records {
hs.RecordsByNameserver[ns] = &state.NameserverRecordState{
Records: recs,
Status: statusOK,
Status: "ok",
LastChecked: now,
}
}
@@ -408,7 +405,7 @@ func (w *Watcher) detectNSDisappearances(
current map[string]map[string][]string,
) {
for ns, prevNS := range prev.RecordsByNameserver {
if _, ok := current[ns]; ok || prevNS.Status != statusOK {
if _, ok := current[ns]; ok || prevNS.Status != "ok" {
continue
}
@@ -711,7 +708,7 @@ func (w *Watcher) handleTLSError(
now time.Time,
err error,
) {
if hasPrev && !w.firstRun && prev.Status == statusOK {
if hasPrev && !w.firstRun && prev.Status == "ok" {
msg := fmt.Sprintf(
"Host: %s\nIP: %s\nError: %s",
hostname, ip, err,
@@ -754,7 +751,7 @@ func (w *Watcher) handleTLSSuccess(
Issuer: cert.Issuer,
NotAfter: cert.NotAfter,
SubjectAlternativeNames: cert.SubjectAlternativeNames,
Status: statusOK,
Status: "ok",
LastChecked: now,
},
)

View File

@@ -4,14 +4,14 @@
# installed tools are skipped. Base tooling comes from nix, apt, brew,
# or apk (detected in that order); assumes nothing is present.
# golangci-lint and goimports are installed via `go install` at the same
# pinned refs the Dockerfile uses (never "latest").
# pinned commits the Dockerfile uses (never "latest").
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
# Pinned versions, 2026-08-07 (same pins as the Dockerfile)
# golangci-lint v2.12.2
GOLANGCI_LINT_REF="github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.12.2"
GOLANGCI_LINT_REF="github.com/golangci/golangci-lint/v2/cmd/golangci-lint@c0d3ddc9cf3faa61a4e378e879ece580256d76e5"
# goimports v0.42.0
GOIMPORTS_REF="golang.org/x/tools/cmd/goimports@009367f5c17a8d4c45a961a3a509277190a9a6f0"