script/bootstrap installs the Dockerfile's Go from go.dev (closes #46) #47

Merged
clawbot merged 1 commits from issue-46-bootstrap-go into next 2026-10-04 05:06:32 +02:00
Collaborator

Fixes #46.

  • script/bootstrap pins GO_VERSION to 1.26.8, the Go in the Dockerfile's golang image. Whenever the go first on PATH reports anything else, or there is none, it downloads the release archive from https://go.dev/dl/, checks it against the sha256 written in the script, and unpacks it into ~/.local/go. Hashes are pinned for linux-amd64, linux-arm64, darwin-amd64 and darwin-arm64; darwin is included because bootstrap already supports brew hosts.
  • script/fmt, script/fmt-check, script/precommit and the Makefile put ~/.local/go/bin first on their own PATH, so they find that Go although bootstrap cannot change their caller's PATH.
  • The apt path runs apt-get update once, inside detect_pkgmgr, which runs only before the first install.

Worth knowing:

  • Bumping the golang digest in the Dockerfile means bumping GO_VERSION and the four hashes in script/bootstrap; comments in both files say so.
  • ~/.local/go is one directory per user; a pin change replaces it.
  • #45 also edits script/bootstrap, script/fmt and script/fmt-check and had not landed; its rebase needs to keep the PATH lines.

Disclosures:

  • Judgement call: the Makefile is beyond the scripts the issue names; without the line, make build cannot find a Go that only bootstrap installed.
  • Unverified: the darwin archives' hashes were checked, but bootstrap was not run on a Mac.
  • Unverified: the Gitea CI run of this branch did not start within an hour of the push; it is still queued.
  • Unchanged: on a non-root apt host, a missing git, make or curl still goes through the existing sudo; Go itself needs none.

Model: opus-5-5

Fixes https://git.eeqj.de/sneak/keyfunc/issues/46. - `script/bootstrap` pins `GO_VERSION` to `1.26.8`, the Go in the `Dockerfile`'s golang image. Whenever the `go` first on `PATH` reports anything else, or there is none, it downloads the release archive from `https://go.dev/dl/`, checks it against the sha256 written in the script, and unpacks it into `~/.local/go`. Hashes are pinned for linux-amd64, linux-arm64, darwin-amd64 and darwin-arm64; darwin is included because bootstrap already supports brew hosts. - `script/fmt`, `script/fmt-check`, `script/precommit` and the `Makefile` put `~/.local/go/bin` first on their own `PATH`, so they find that Go although bootstrap cannot change their caller's `PATH`. - The apt path runs `apt-get update` once, inside `detect_pkgmgr`, which runs only before the first install. Worth knowing: - Bumping the golang digest in the `Dockerfile` means bumping `GO_VERSION` and the four hashes in `script/bootstrap`; comments in both files say so. - `~/.local/go` is one directory per user; a pin change replaces it. - https://git.eeqj.de/sneak/keyfunc/pulls/45 also edits `script/bootstrap`, `script/fmt` and `script/fmt-check` and had not landed; its rebase needs to keep the `PATH` lines. Disclosures: - Judgement call: the `Makefile` is beyond the scripts the issue names; without the line, `make build` cannot find a Go that only bootstrap installed. - Unverified: the darwin archives' hashes were checked, but bootstrap was not run on a Mac. - Unverified: the Gitea CI run of this branch did not start within an hour of the push; it is still queued. - Unchanged: on a non-root apt host, a missing git, make or curl still goes through the existing `sudo`; Go itself needs none. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 03:57:10 +02:00
clawbot self-assigned this 2026-10-04 03:57:10 +02:00
clawbot added 1 commit 2026-10-04 03:57:10 +02:00
The Gitea runner has Docker and git but no Go, and the apt path never
ran apt-get update, so on a fresh host every install failed.

Bootstrap now installs Go 1.26.8, the version in the Dockerfile's
golang image, from the release archive at go.dev, checked against a
sha256 in the script, into ~/.local/go whenever the go first on PATH
reports any other version. script/fmt, script/fmt-check,
script/precommit and the Makefile put ~/.local/go/bin first on their
PATH so they use it. The apt path runs apt-get update once, before its
first install.

Model: opus-5-5
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot merged commit 7280ee35f4 into next 2026-10-04 05:06:32 +02:00
clawbot deleted branch issue-46-bootstrap-go 2026-10-04 05:06:32 +02:00
Sign in to join this conversation.