f5761b6227308afd11c51367b1739a62122768ff
8 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
f5761b6227 |
Run every lint-class check inside Docker (closes #38)
All checks were successful
check / check (push) Successful in 1m9s
Add a root Dockerfile.lint that carries the checks as build steps -- a `lint` stage running `hugo --minify --printPathWarnings` and a `fmt-check` stage running the prettier check -- and reduce script/lint and script/fmt-check to building their stage. A successful build is a clean check. There is no host path and deliberately no "am I already inside a container?" branch, which would be a host lint path in disguise. The two stages share a `base` whose first four instructions are byte-identical to the main Dockerfile's, so the expensive `RUN script/bootstrap` layer that compiles the pinned Hugo from source is a cache hit against the main image instead of a second build of the same thing. Resolve the resulting recursion by splitting the checks by where they run, not with an escape hatch. `make check` runs script/lint, so the main Dockerfile can no longer `RUN make check`: that would be docker-in-docker inside a bare Alpine with no docker client and no daemon socket, and script/cibuild is what CI runs on every push. The main Dockerfile therefore runs `make test`, the production build, and script/cibuild builds it and then calls script/lint and script/fmt-check. CI still covers the production build, lint and the format check, and it runs exactly what a developer runs. script/fmt stays on the host because it rewrites the working tree, which a container build cannot do. That makes it the authoritative copy of the prettier version, scope and flags that the fmt-check stage duplicates; both sides carry a keep-in-sync note. The duplication is forced: any `RUN script/fmt-check` inside the image is the recursion again. Caching is waived for the checks in the shape this repo already settled: `ARG CHECK_EPOCH` with no default, declared and guarded separately in each stage because ARG does not cross a FROM, with the value expanded into the checked command as well as the guard so invalidation does not rest on BuildKit's treatment of an unreferenced ARG. All four image-building entrypoints now generate and pass it -- script/cibuild, script/docker, script/lint, script/fmt-check. Verified: two consecutive script/lint runs on an unchanged tree both executed hugo for real, with script/bootstrap CACHED; a constant-epoch counterfactual restored the false green (exit 0, lint layer CACHED, no hugo output); an empty epoch failed closed on the guard; a broken template failed the lint stage and an unformatted README failed the fmt-check stage, both reverted and re-run clean; script/cibuild and `make check` are green with all three checks demonstrably executing. |
||
|
|
407b0a0d79 |
Add the MIT LICENSE and state it in the README (closes #10)
All checks were successful
check / check (push) Successful in 11s
The repo had no LICENSE, which REPO_POLICIES.md lists as a mandatory
minimum file, and the README's License section said "Content is provided
as-is for community use." That granted nothing explicitly and matched no
committed file.
The repo is public, verified on the Gitea API rather than assumed, so
the standing policy applies: MIT on any public repo lacking a license.
LICENSE is byte-identical to the canonical sneak/homoicon copy (same git
blob,
|
||
| 9bfc37bb76 |
Restructure README.md into the canonical section set (closes #11)
All checks were successful
check / check (push) Successful in 9s
REPO_POLICIES.md mandates a fixed set of README sections; this README predated the standard being applied here and had About / Contributing / Technical Details / Entrypoints / License instead. It is now a Description first line followed by Getting Started, Entrypoints, Rationale, Design, TODO, License, Author, with Author last. Nothing the old headings held was dropped: the list of what the site publishes moved under the Description, and the contribute contact and the local-preview instructions moved into Getting Started. Getting Started was written against the current Makefile rather than carried over from the old prose, which had drifted. There is no `make build` target, so the old "Build: `hugo`" instruction is now `make test`; "Local Development: `hugo server`" is now `make setup` then `make serve`, and `make setup` is what makes a fresh clone buildable at all since it installs the pinned Hugo. Two stale claims are fixed. The site is deployed by Gitea Actions to Cloudflare Pages, not "automatically via GitHub Actions". And the Entrypoints bullet for `script/fmt` still described the top-level-markdown-only scope that #12 replaced with `'**/*.md'` and `'**/*.css'`; the rest of that section was verified accurate against the scripts, including the `script/check` order and the `CHECK_EPOCH` guard that makes a bare `docker build .` fail closed. The License section body is deliberately untouched and no LICENSE file is added: that is #10's, which is blocked on the owner's choice of license. For the same reason the Description sentence omits the license clause the policy asks for; #10 completes both. The Design section's claims were checked against the tree rather than assumed: the vendored theme, the `readFile` inline of style.css in baseof.html, the `hugo --minify` output to `public/`, and the deploy workflow. |
|||
| 223c520110 |
Cache-bust the make check layer via CHECK_EPOCH (closes #23)
All checks were successful
check / check (push) Successful in 56s
script/cibuild was a bare `docker build .`, and the Dockerfile did
`COPY . .` then `RUN make check`. COPY is keyed on content, so on an
unchanged tree Docker served the check layer from cache: the checks
never executed, no Hugo or prettier output appeared, and the build still
exited 0. A gate that reports success without running is worse than no
gate, because it is trusted -- three separate reviewers in this repo
have been fooled by it.
The Dockerfile now declares `ARG CHECK_EPOCH` immediately below
`COPY . .`, guards it, and expands it into the check command:
ARG CHECK_EPOCH
RUN [ -n "$CHECK_EPOCH" ] || exit 1
RUN echo "check epoch: ${CHECK_EPOCH}" && make check
script/cibuild and script/docker both generate the value identically and
pass it. Every element is load-bearing:
- No default value. A default is a constant, and a constant is a stable
cache key -- the defect unchanged.
- Placed below `COPY . .`. Everything above keeps caching, so the
script/bootstrap layer, which compiles Hugo from source, is not
rebuilt. Whole-build `--no-cache` would have discarded it and blown
the five-minute budget for no benefit.
- The guard. An unset ARG is the empty string, which is also a stable
cache key, so without it a bare `docker build .` still collects the
false green. Failed steps are never cached, so it fails on every such
invocation rather than only the first. This is why script/docker had
to be updated too: the guard makes passing the argument mandatory for
every entrypoint that builds the image.
- The value expanded into the RUN. Hardening rather than the fix: the
bare unreferenced-ARG form does work, but expansion makes the cache
miss contractual rather than dependent on BuildKit's handling of an
unreferenced ARG, and puts the epoch in the build log. The guard also
references the value, so there are two independent invalidation
points, not one.
- `epoch="$(date +%s%N)$$"` on its own line rather than inlined into the
argument list. A command substitution that fails inside an argument
does not trip `set -e`, so the inline form would quietly pass an empty
string and restore the cached false green. `%N` keeps concurrent
invocations distinct; `$$` covers busybox date, which drops `%N`
silently and still exits 0.
ARG is stage-scoped and must be redeclared in every stage that runs
checks. This image is single-stage, so one declaration is complete.
This is the shape settled upstream in the prompts repo, where it has not
merged to main yet, so it may need re-syncing later.
Verified: two consecutive script/cibuild runs on an unchanged tree both
executed the checks (two Hugo builds and the prettier line in each,
15s then 6s) with `RUN script/bootstrap` and `COPY . .` both CACHED in
the second -- the validity control that rules out a cache eviction
between them. A constant-epoch counterfactual restored the cached false
green, confirming the varying value is what does the work. A bare
`docker build .` now fails on the guard, and fails again on immediate
repeat. A planted prettier failure failed the build with exit 1. `make
docker` and `make check` both pass.
|
|||
| 4720c40cfa |
Install Hugo at a deliberate, hash-verified version (closes #26)
script/bootstrap did `pkg_install hugo hugo hugo hugo`, so the tool that produces the published artifact was whatever the base image's package repo happened to serve: alpine 3.21 gives hugo 0.139.0, about two years behind upstream, chosen by nobody, and liable to change silently on any base image digest bump. Hugo's version is a property of the site's output, not of the build environment, so it now gets pinned like every other external reference in this repo. It is installed with `go install github.com/gohugoio/hugo@v0.164.0`, which verifies the module against the sum.golang.org checksum database. That is genuine hash verification rather than bare version pinning, it is the mechanism REPO_POLICIES.md already names for Go, and it needs no hand-maintained sha256. It also keeps a single pinned base image: a digest-pinned Hugo container would have reintroduced the second base image that #7 deliberately removed. Two constants carry the decision, each with the canonical `# name version, YYYY-MM-DD` comment: - HUGO_VERSION=v0.164.0, the current stable release. - HUGO_GOTOOLCHAIN=go1.26.5. hugo v0.164.0's go.mod requires go >= 1.26.0 and alpine 3.21's go package is 1.23.9 built with GOTOOLCHAIN=local, so a bare `go install` refuses to run at all. Naming the toolchain makes Go fetch it through the module proxy and verify it against sum.golang.org like any other module, so the chain stays hash-verified end to end and the compiler is deliberate too. CGO_ENABLED=0 is deliberate: standard Hugo, not extended. Verified that this site uses nothing extended provides - no .scss/.sass, no resources.ToCSS, no PostCSS, and no image processing; the CSS is plain and inlined by readFile in baseof.html. The `+extended` on the apk build this replaces was incidental, and the script says so, so a later change does not assume extended is required. The binary is placed in /usr/local/bin rather than left in a GOPATH bin directory, because it has to be on the default PATH of a *fresh* shell: the Dockerfile's `RUN make check` and deploy.yml's `script/test` step each start their own shell. The location is overridable via HUGO_BIN_DIR for unprivileged installs, and `go install` itself runs as the invoking user so a workstation's module cache is not populated as root. The idempotency guard is version-aware instead of `missing hugo`: an older hugo already on PATH must be replaced, not accepted, or the pin means nothing. A same-version build that happens to be `+extended` is accepted, since it renders this site identically. After installing, the script re-checks what `hugo` on PATH actually resolves to and fails loudly if something else shadows it. Rendered output was compared three ways in a container carrying both binaries - apk 0.139.0 against 0.164.0 on identical sources. Across the whole public/ tree the only byte that differs is the generator meta tag's version string, which is the change describing itself. The RSS <language> element and the html lang attribute are unchanged. Cold `script/cibuild` is 2m36s, within the five-minute budget: 52.6s of it is the bootstrap layer (apk go, toolchain fetch, compile) and 100s is image export. The check image grows to 683 MB because the Go toolchain and module cache stay in the bootstrap layer; that image is only ever built to run checks, never published or deployed. |
|||
|
|
bcb90e74b4 |
Run script/lint from script/check (closes #9)
All checks were successful
check / check (push) Successful in 14s
script/check ran only fmt-check then test, so script/lint was never invoked anywhere in the gate: make check shims to script/check, the Dockerfile runs make check, script/cibuild builds the Dockerfile, and the pre-commit hook calls script/check. The script was dead code that the README advertised as part of the gate. It now runs test, lint, fmt-check in the canonical order. script/lint is hugo --minify --printPathWarnings, which reports render-target collisions that the plain hugo --minify in script/test does not; that signal was being discarded. The gate still modifies no tracked files. script/test and script/lint both write to public/, which is gitignored and was already written by script/test before this change. Corrects the two documents that enumerated the old two-step gate: the README Entrypoints line for script/check, and the Dockerfile header comment above the RUN make check that executes it. |
||
| 7cad989724 |
Add scripts-to-rule-them-all scaffold (closes #4)
Adopt the Scripts to Rule Them All standard for this Hugo site: - script/ POSIX-sh entrypoints (bootstrap, setup, projectname, test, lint, fmt, fmt-check, check, docker, cibuild, precommit, install-precommit). The correctness check (test/lint) is a clean `hugo --minify` production build; fmt/fmt-check run prettier over the repo's own top-level markdown only, leaving content/ untouched. - Makefile targets reduced to thin shims that call script/NAME, plus a convenience serve target for `hugo server`. - Dockerfile on a sha256-pinned alpine base that installs deps via script/bootstrap and runs `make check`, so the image build fails on any formatting or Hugo build error; .dockerignore added. - .gitea/workflows/check.yml runs script/cibuild on push. - README Entrypoints section documenting the scripts. |
|||
| 52f9ccf42e | add README and contribute link in footer |