All checks were successful
check / check (push) Successful in 1m9s
Add a root Dockerfile.lint that carries the checks as build steps -- a `lint` stage running `hugo --minify --printPathWarnings` and a `fmt-check` stage running the prettier check -- and reduce script/lint and script/fmt-check to building their stage. A successful build is a clean check. There is no host path and deliberately no "am I already inside a container?" branch, which would be a host lint path in disguise. The two stages share a `base` whose first four instructions are byte-identical to the main Dockerfile's, so the expensive `RUN script/bootstrap` layer that compiles the pinned Hugo from source is a cache hit against the main image instead of a second build of the same thing. Resolve the resulting recursion by splitting the checks by where they run, not with an escape hatch. `make check` runs script/lint, so the main Dockerfile can no longer `RUN make check`: that would be docker-in-docker inside a bare Alpine with no docker client and no daemon socket, and script/cibuild is what CI runs on every push. The main Dockerfile therefore runs `make test`, the production build, and script/cibuild builds it and then calls script/lint and script/fmt-check. CI still covers the production build, lint and the format check, and it runs exactly what a developer runs. script/fmt stays on the host because it rewrites the working tree, which a container build cannot do. That makes it the authoritative copy of the prettier version, scope and flags that the fmt-check stage duplicates; both sides carry a keep-in-sync note. The duplication is forced: any `RUN script/fmt-check` inside the image is the recursion again. Caching is waived for the checks in the shape this repo already settled: `ARG CHECK_EPOCH` with no default, declared and guarded separately in each stage because ARG does not cross a FROM, with the value expanded into the checked command as well as the guard so invalidation does not rest on BuildKit's treatment of an unreferenced ARG. All four image-building entrypoints now generate and pass it -- script/cibuild, script/docker, script/lint, script/fmt-check. Verified: two consecutive script/lint runs on an unchanged tree both executed hugo for real, with script/bootstrap CACHED; a constant-epoch counterfactual restored the false green (exit 0, lint layer CACHED, no hugo output); an empty epoch failed closed on the guard; a broken template failed the lint stage and an unformatted README failed the fmt-check stage, both reverted and re-run clean; script/cibuild and `make check` are green with all three checks demonstrably executing.
28 lines
1008 B
Bash
Executable File
28 lines
1008 B
Bash
Executable File
#!/bin/sh
|
|
# script/fmt: format this repo's markdown and CSS with prettier, using
|
|
# our standard settings. Scope is every markdown and CSS file in the
|
|
# tree, per REPO_POLICIES.md ("prettier for JS/CSS/Markdown/HTML").
|
|
# What is deliberately NOT covered is recorded in .prettierignore, with
|
|
# the reason next to each entry: the Hugo layout templates, which are
|
|
# Go templates and not HTML, and content/, whose reformatting was
|
|
# measured to change the rendered page.
|
|
#
|
|
# This runs on the host, unlike the read-only check: it rewrites the
|
|
# working tree, which a container build cannot do. It is therefore the
|
|
# authoritative copy of the prettier version, scope and flags -- the
|
|
# fmt-check stage of Dockerfile.lint duplicates them and must be kept in
|
|
# sync with this file.
|
|
set -eu
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
|
|
|
PRETTIER_VERSION="3.4.2"
|
|
|
|
main() {
|
|
cd "$ROOT"
|
|
npx --yes "prettier@${PRETTIER_VERSION}" --write \
|
|
'**/*.md' '**/*.css' --tab-width 4 --prose-wrap always
|
|
}
|
|
|
|
main "$@"
|