diff --git a/Dockerfile b/Dockerfile index e629c25..2f33928 100644 --- a/Dockerfile +++ b/Dockerfile @@ -17,7 +17,8 @@ COPY . . RUN golangci-lint run --config .golangci.yml ./... # Test phase -# golang:1.26-alpine, 2026-09-07 +# golang:1.26-alpine, 2026-09-07. It carries Go 1.26.8, the version +# script/bootstrap installs on the host; change both together. FROM golang@sha256:ce864e7223ac17b1775e6fd0b4c0db580c2eb50e7953a427916379e4b92a1628 AS test # -race needs cgo, and cgo needs a C toolchain. diff --git a/Makefile b/Makefile index eb1d4bd..a4129c9 100644 --- a/Makefile +++ b/Makefile @@ -5,6 +5,9 @@ VERSION := $(shell git describe --tags --always --dirty 2>/dev/null || echo dev) LDFLAGS := -s -w -X 'sneak.berlin/go/keyfunc/internal/cli.Version=$(VERSION)' +# Where script/bootstrap installs Go; it cannot put it on our PATH. +export PATH := $(HOME)/.local/go/bin:$(PATH) + .PHONY: default bootstrap setup build test lint fmt fmt-check check \ docker cibuild hooks clean diff --git a/README.md b/README.md index 8ee721b..043ef54 100644 --- a/README.md +++ b/README.md @@ -283,9 +283,13 @@ The repo adheres to the standard: most Makefile targets are thin shims over an executable in `script/` (`build` and `clean` are the exceptions). -- `script/bootstrap` installs everything needed to build and develop (git, make, - Go), idempotently, from nix, apt, brew or apk; it does not install the linter, - which only runs inside Docker. +- `script/bootstrap` installs everything needed to build and develop, + idempotently: git and make from nix, apt, brew or apk, and Go, at the version + the `Dockerfile`'s Go image carries, from the official release archive + (checked against a sha256 in the script) into `~/.local/go`. `script/fmt`, + `script/fmt-check`, `script/precommit` and the `Makefile` put + `~/.local/go/bin` first on their `PATH`, so they use that Go. It does not + install the linter, which only runs inside Docker. - `script/setup` prepares a fresh clone: it runs `bootstrap`, then installs the git pre-commit hook. - `script/projectname` prints the project name; other scripts call it so they diff --git a/script/bootstrap b/script/bootstrap index 4705d2b..33d46f2 100755 --- a/script/bootstrap +++ b/script/bootstrap @@ -3,13 +3,25 @@ # repo. Idempotent: every install is guarded by a check, so tools that # are already there are left alone. Base tooling comes from nix, apt, # brew, or apk, detected in that order, and nothing is assumed to be -# present. The linter is not installed here: linting and testing run -# only as phases of the Dockerfile, so Docker is what is needed for -# them, and that is checked for rather than installed. +# present. Go is installed at the version the Dockerfile's Go image +# carries, from the official release archive, into ~/.local/go. The +# linter is not installed here: linting and testing run only as phases +# of the Dockerfile, so Docker is what is needed for them, and that is +# checked for rather than installed. set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" +# Must match the Go in the Dockerfile's golang image; the sha256 of each +# archive is in install_go. +GO_VERSION="1.26.8" + +# This script cannot change its caller's PATH, so script/fmt, +# script/fmt-check, script/precommit and the Makefile put this directory +# first on their own PATH, as is done here. +GO_DIR="$HOME/.local/go" +PATH="$GO_DIR/bin:$PATH" + PKGMGR="" SUDO="" @@ -32,6 +44,9 @@ detect_pkgmgr() { if [ "$(id -u)" != "0" ]; then SUDO="sudo" fi + # This runs once, before the first install: a fresh host or + # runner image has no package lists yet. + $SUDO apt-get update fi } @@ -50,12 +65,82 @@ missing() { ! command -v "$1" >/dev/null 2>&1 } +# verify_sha256 +verify_sha256() { + if command -v sha256sum >/dev/null 2>&1; then + actual="$(sha256sum "$1" | cut -d' ' -f1)" + else + actual="$(shasum -a 256 "$1" | cut -d' ' -f1)" + fi + if [ "$actual" != "$2" ]; then + echo "bootstrap: sha256 mismatch for $1" >&2 + echo " expected: $2" >&2 + echo " actual: $actual" >&2 + exit 1 + fi +} + +# True when the go first on PATH reports exactly GO_VERSION. No go, a go +# that fails, or any other output is a mismatch. +go_version_matches() { + out="$(go version 2>/dev/null)" || return 1 + case "$out" in + "go version go$GO_VERSION "*) return 0 ;; + *) return 1 ;; + esac +} + +install_go() { + # sha256 of the go1.26.8 archives at https://go.dev/dl/, 2026-10-04 + case "$(uname -s)-$(uname -m)" in + Linux-x86_64) + platform="linux-amd64" + sha256="d0f743b33e8d8945e6b1f432edd15785c70507121d6e2a723b21285eddf8b57b" + ;; + Linux-aarch64) + platform="linux-arm64" + sha256="211ffced9dcb9633a55eac6364816ec0ddd951389a740e88fa8b3337971bdda0" + ;; + Darwin-x86_64) + platform="darwin-amd64" + sha256="186be014105aa6542b767d2c6ed5cca10a0214bdff809ef1724022a8c7894150" + ;; + Darwin-arm64) + platform="darwin-arm64" + sha256="a012b25b571bd0138a03dcd25375ceba866fe5ca822f426d2c66a4de56fd3f4b" + ;; + *) + echo "bootstrap: no Go archive pinned for $(uname -s) $(uname -m)" >&2 + exit 1 + ;; + esac + if missing curl; then pkg_install curl curl curl curl; fi + tmp="$(mktemp -d)" + curl -fsSL -o "$tmp/go.tar.gz" \ + "https://go.dev/dl/go${GO_VERSION}.${platform}.tar.gz" + verify_sha256 "$tmp/go.tar.gz" "$sha256" + # An archive unpacked over an older Go leaves a broken tree. + rm -rf "$GO_DIR" + mkdir -p "$GO_DIR" + tar -xzf "$tmp/go.tar.gz" -C "$GO_DIR" --strip-components=1 + rm -rf "$tmp" +} + main() { cd "$ROOT" if missing git; then pkg_install git git git git; fi if missing make; then pkg_install gnumake make make make; fi - if missing go; then pkg_install go golang go go; fi + + if ! go_version_matches; then + install_go + hash -r + if ! go_version_matches; then + echo "bootstrap: $(command -v go) is not go$GO_VERSION after installing it" >&2 + exit 1 + fi + fi + go version go mod download diff --git a/script/fmt b/script/fmt index e95d111..10a62ff 100755 --- a/script/fmt +++ b/script/fmt @@ -4,6 +4,9 @@ set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" +# Where script/bootstrap installs Go; it cannot put it on our PATH. +PATH="$HOME/.local/go/bin:$PATH" + main() { cd "$ROOT" go fmt ./... diff --git a/script/fmt-check b/script/fmt-check index 2e91588..8170456 100755 --- a/script/fmt-check +++ b/script/fmt-check @@ -5,6 +5,9 @@ set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" +# Where script/bootstrap installs Go; it cannot put it on our PATH. +PATH="$HOME/.local/go/bin:$PATH" + main() { cd "$ROOT" if [ -n "$(gofmt -l .)" ]; then diff --git a/script/precommit b/script/precommit index fe9775b..4794d57 100755 --- a/script/precommit +++ b/script/precommit @@ -7,6 +7,9 @@ set -eu SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)" +# Where script/bootstrap installs Go; it cannot put it on our PATH. +PATH="$HOME/.local/go/bin:$PATH" + main() { cd "$ROOT" go mod tidy