build: always install pinned lint tools in script/bootstrap (closes #117) #131

Open
clawbot wants to merge 1 commits from fix/117-bootstrap-pin into next
2 changed files with 51 additions and 9 deletions

View File

@@ -25,6 +25,13 @@ confirm make check still passes.
# Completed Steps # Completed Steps
- 2026-08-09: `script/bootstrap` now installs the pinned `golangci-lint`
and `goimports` unconditionally instead of only when the binary is
absent from `PATH`, so the commit pins actually take effect on
already-provisioned machines; it also warns when `PATH` resolves
either tool to a copy outside the directory `go install` writes to.
The `missing` presence check is retained for `git`, `make`, and `go`
(#117)
- 2026-08-07: golangci-lint bumped to v2.12.2 (commit-pinned installs - 2026-08-07: golangci-lint bumped to v2.12.2 (commit-pinned installs
in `Dockerfile` and `script/bootstrap`); `.golangci.yml` set to the in `Dockerfile` and `script/bootstrap`); `.golangci.yml` set to the
org-standard v2-schema config used across the org's repos org-standard v2-schema config used across the org's repos

View File

@@ -1,10 +1,13 @@
#!/bin/sh #!/bin/sh
# script/bootstrap: install all dependencies needed to build and develop # script/bootstrap: install all dependencies needed to build and develop
# this repo. Idempotent: every install is guarded by a check so already # this repo. Base tooling (git, make, go) comes from nix, apt, brew, or
# installed tools are skipped. Base tooling comes from nix, apt, brew, # apk (detected in that order) and is installed only when absent;
# or apk (detected in that order); assumes nothing is present. # assumes nothing is present. golangci-lint and goimports are always
# golangci-lint and goimports are installed via `go install` at the same # (re)installed via `go install` at the same pinned commits the
# pinned commits the Dockerfile uses (never "latest"). # Dockerfile uses (never "latest") -- a presence check cannot tell the
# pinned build from an arbitrary one already on PATH, so guarding them
# would make the pins inert. Idempotent either way: running this twice
# succeeds both times and leaves the same result.
set -eu set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
@@ -62,6 +65,31 @@ missing() {
! command -v "$1" >/dev/null 2>&1 ! command -v "$1" >/dev/null 2>&1
} }
# go_bin_dir: directory `go install` writes binaries to.
go_bin_dir() {
gobin="$(go env GOBIN)"
if [ -n "$gobin" ]; then
echo "$gobin"
else
echo "$(go env GOPATH)/bin"
fi
}
# warn_if_shadowed <tool> <dir>: the pinned build was just installed
# into <dir>. If PATH resolves <tool> anywhere else, that other copy is
# what `make lint` and `make fmt` will actually run, and it is not the
# pinned version. Warn loudly rather than failing, since the fix is the
# user's PATH and not anything this script can do.
warn_if_shadowed() {
resolved="$(command -v "$1" 2>/dev/null || true)"
if [ "$resolved" != "$2/$1" ]; then
echo "bootstrap: WARNING: installed pinned $1 to $2/$1, but PATH" >&2
echo "bootstrap: WARNING: resolves $1 to ${resolved:-(not on PATH)};" >&2
echo "bootstrap: WARNING: put $2 first on PATH or lint results will" >&2
echo "bootstrap: WARNING: not match CI." >&2
fi
}
main() { main() {
cd "$ROOT" cd "$ROOT"
@@ -69,10 +97,17 @@ main() {
if missing make; then pkg_install gnumake make make make; fi if missing make; then pkg_install gnumake make make make; fi
if missing go; then pkg_install go golang go go; fi if missing go; then pkg_install go golang go go; fi
# Lint/format tools, pinned via go install (installs into # Lint/format tools, pinned via go install. These are installed
# "$(go env GOPATH)/bin"; ensure that is on your PATH). # unconditionally: `command -v` only proves *some* build is on PATH,
if missing golangci-lint; then go install "$GOLANGCI_LINT_REF"; fi # and a wrong golangci-lint either cannot parse our v2-schema
if missing goimports; then go install "$GOIMPORTS_REF"; fi # .golangci.yml at all or silently disagrees with CI. Installing at
# a fixed commit ref is idempotent and cheap with a warm module
# cache, so there is nothing to save by skipping it.
GOBIN_DIR="$(go_bin_dir)"
go install "$GOLANGCI_LINT_REF"
go install "$GOIMPORTS_REF"
warn_if_shadowed golangci-lint "$GOBIN_DIR"
warn_if_shadowed goimports "$GOBIN_DIR"
go mod download go mod download