Re-vendor the canonical files from sneak/prompts dd4027b (closes #159, closes #116)
check / check (push) Failing after 7s

Fetches .dockerignore, .editorconfig, the CI workflow, .gitignore,
.golangci.yml, .prettierignore, .prettierrc and REPO_POLICIES.md byte
for byte from sneak/prompts dd4027b; this repo's own entries follow the
canonical text in .dockerignore, .gitignore and .editorconfig. The new
.golangci.yml disables gomodguard. The Dockerfile gets a lint phase on
golangci-lint v2.14.0 and a test phase on the Debian Go image; the
build stage depends on both and stamps the version as the policy shows.
script/test and script/lint build only their phase, and script/cibuild
bootstraps and runs script/check first. bin/tools goes: script/bootstrap
installs gofumpt and protoc-gen-go into bin/ with go install pinned to a
commit.

Model: opus-5-5
This commit was merged in pull request #162.
This commit is contained in:
2026-10-06 04:43:18 +02:00
parent 343431dd30
commit ce66f7c1c1
21 changed files with 688 additions and 292 deletions
+60 -4
View File
@@ -22,6 +22,14 @@ YARN_VERSION="1.22.22"
# protoc v33.4, 2026-10-04, for script/generate. The sha256 of each
# platform's release archive is in ensure_protoc.
PROTOC_VERSION="33.4"
# gofumpt v0.12.0 for script/gofumpt and protoc-gen-go v1.36.11 for
# script/generate, 2026-10-04: each is installed into bin/ with
# `go install`, pinned to the commit its release tag names. Those two
# scripts refuse any other version, so a new pin is changed there too.
GOFUMPT_VERSION="v0.12.0"
GOFUMPT_COMMIT="3e07e7e70ac93761d8e79ca0083a19e3d59f753d"
PROTOC_GEN_GO_VERSION="v1.36.11"
PROTOC_GEN_GO_COMMIT="96a179180f0ad6bba9b1e7b6e38d0affb0168e9a"
PKGMGR=""
SUDO=""
@@ -130,11 +138,13 @@ install_js_deps() {
# Unpack protoc's release archive for this platform into bin/protoc, after
# checking the archive's sha256, unless bin/protoc already holds the pinned
# version.
# version. script/generate runs bin/protoc/bin/protoc, so that is the
# binary checked again after unpacking.
ensure_protoc() {
dir="$ROOT/bin/protoc"
if [ "$("$dir/bin/protoc" --version 2>/dev/null)" = \
"libprotoc $PROTOC_VERSION" ]; then
echo "protoc $PROTOC_VERSION"
return 0
fi
case "$(uname -s) $(uname -m)" in
@@ -168,6 +178,53 @@ ensure_protoc() {
rm -rf "$dir"
unzip -q "$tmp/protoc.zip" -d "$dir"
rm -rf "$tmp"
actual="$("$dir/bin/protoc" --version 2>/dev/null || true)"
if [ "$actual" != "libprotoc $PROTOC_VERSION" ]; then
echo "bootstrap: $dir/bin/protoc reports '$actual'," \
"not libprotoc $PROTOC_VERSION" >&2
exit 1
fi
echo "protoc $PROTOC_VERSION"
}
# Install gofumpt into bin/ unless bin/gofumpt already reports the pinned
# version. script/gofumpt runs bin/gofumpt, so that is the binary checked
# again after installing. Its --version prints the version, then the Go
# version it was built with. The old file is removed first because
# `go install` refuses to replace a file that is not a Go binary.
ensure_gofumpt() {
tool="$ROOT/bin/gofumpt"
if [ "$("$tool" --version 2>/dev/null | cut -d' ' -f1)" != \
"$GOFUMPT_VERSION" ]; then
rm -f "$tool"
GOBIN="$ROOT/bin" go install "mvdan.cc/gofumpt@$GOFUMPT_COMMIT"
fi
actual="$("$tool" --version 2>/dev/null | cut -d' ' -f1)"
if [ "$actual" != "$GOFUMPT_VERSION" ]; then
echo "bootstrap: $tool reports '$actual', not $GOFUMPT_VERSION" >&2
exit 1
fi
echo "gofumpt $GOFUMPT_VERSION"
}
# Install protoc-gen-go into bin/ unless bin/protoc-gen-go already reports
# the pinned version, as ensure_gofumpt does. script/generate runs
# bin/protoc-gen-go, so that is the binary checked again after installing.
ensure_protoc_gen_go() {
tool="$ROOT/bin/protoc-gen-go"
if [ "$("$tool" --version 2>/dev/null)" != \
"protoc-gen-go $PROTOC_GEN_GO_VERSION" ]; then
rm -f "$tool"
GOBIN="$ROOT/bin" go install \
"google.golang.org/protobuf/cmd/protoc-gen-go@$PROTOC_GEN_GO_COMMIT"
fi
actual="$("$tool" --version 2>/dev/null || true)"
if [ "$actual" != "protoc-gen-go $PROTOC_GEN_GO_VERSION" ]; then
echo "bootstrap: $tool reports '$actual'," \
"not protoc-gen-go $PROTOC_GEN_GO_VERSION" >&2
exit 1
fi
echo "protoc-gen-go $PROTOC_GEN_GO_VERSION"
}
main() {
@@ -192,10 +249,9 @@ main() {
if missing go; then pkg_install go golang go go; fi
# No golangci-lint: script/lint runs it in Docker only.
go mod download
# gofumpt and protoc-gen-go: bin/tools/go.mod pins them, and
# script/gofumpt and script/generate build them from there.
(cd "$ROOT/bin/tools" && go mod download)
ensure_gofumpt
ensure_protoc
ensure_protoc_gen_go
# ---- Python repos ----
# if missing python3; then pkg_install python3 python3 python3 python3; fi
+3 -2
View File
@@ -1,7 +1,8 @@
#!/bin/sh
# script/check: run all checks (test, lint, fmt-check). Our own
# extension to scripts-to-rule-them-all. Must not modify any files.
# Generic: usually needs no adaptation.
# extension to scripts-to-rule-them-all. test and lint are Docker
# phases; fmt-check is native, because a formatter writes the working
# tree. Must not modify any files.
set -eu
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
+8 -4
View File
@@ -1,8 +1,10 @@
#!/bin/sh
# script/cibuild: run the CI build; the Gitea workflow runs this on push.
# It builds the image with the same command as script/docker. --no-cache
# because the checks the final stage depends on are RUN steps, and a
# cached one is a check that did not run.
# script/cibuild: run the CI build. It bootstraps first: a CI runner
# checks out and runs this and nothing else, and script/fmt-check runs
# the formatter on the host, which a pristine checkout cannot do.
# --no-cache for the same reason as script/docker: the gate phases the
# final stage depends on are RUN steps, and a cached one is a check that
# did not run.
set -eu
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
@@ -10,6 +12,8 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
main() {
cd "$ROOT"
"$SCRIPT_DIR/bootstrap"
"$SCRIPT_DIR/check"
# Own line: a failing command substitution inside an argument does
# not trip `set -e`, so the inline form degrades silently to an
# empty constant. The VERSION build argument takes precedence over
+15 -10
View File
@@ -5,16 +5,18 @@
# protoc. A test fails while mf.proto no longer matches the recorded hash.
#
# Runs the protoc that script/bootstrap unpacks into bin/protoc, and the
# protoc-gen-go that bin/tools/go.mod pins. Another version of either
# writes a different mf.pb.go.
# protoc-gen-go it installs into bin/. Another version of either writes a
# different mf.pb.go.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
# The protoc version script/bootstrap installs. protoc 33.4 names itself
# v6.33.4 in the mf.pb.go header.
# The versions script/bootstrap installs. protoc 33.4 names itself v6.33.4
# in the mf.pb.go header.
PROTOC_VERSION="33.4"
PROTOC="$ROOT/bin/protoc/bin/protoc"
PROTOC_GEN_GO_VERSION="v1.36.11"
PROTOC_GEN_GO="$ROOT/bin/protoc-gen-go"
# sha256 <file>: print "<hash> <file>", with sha256sum, or with shasum
# where there is no sha256sum.
@@ -30,23 +32,26 @@ sha256() {
}
main() {
# A bin/protoc left from before the pin moved fails here, until
# script/bootstrap replaces it.
# A bin/protoc or bin/protoc-gen-go left from before its pin moved
# fails here, until script/bootstrap replaces it.
actual="$("$PROTOC" --version 2>/dev/null || true)"
if [ "$actual" != "libprotoc $PROTOC_VERSION" ]; then
echo "generate: needs protoc $PROTOC_VERSION in bin/protoc," \
"found: ${actual:-none}; run script/bootstrap" >&2
exit 1
fi
# `go tool -n` builds protoc-gen-go from bin/tools and prints where the
# binary is, without running it.
plugin="$(cd "$ROOT/bin/tools" && go tool -n protoc-gen-go)"
actual="$("$PROTOC_GEN_GO" --version 2>/dev/null || true)"
if [ "$actual" != "protoc-gen-go $PROTOC_GEN_GO_VERSION" ]; then
echo "generate: needs protoc-gen-go $PROTOC_GEN_GO_VERSION in" \
"bin/protoc-gen-go, found: ${actual:-none}; run script/bootstrap" >&2
exit 1
fi
cd "$ROOT/mfer"
# Hashed before regenerating, so a missing hash tool stops the script
# before it changes anything. Regenerating leaves mf.proto as it is.
proto_hash="$(sha256 mf.proto)"
"$PROTOC" --plugin=protoc-gen-go="$plugin" \
"$PROTOC" --plugin=protoc-gen-go="$PROTOC_GEN_GO" \
--go_out=paths=source_relative:. ./mf.proto
echo "$proto_hash" >mf.proto.sha256
}
+16 -10
View File
@@ -3,17 +3,16 @@
#
# Takes exactly one mode argument, --write or --check, and runs the same
# gofumpt version over the same files in both modes. script/fmt and
# script/fmt-check both go through here, and so does the Docker lint
# stage, so what gets formatted and what gets verified cannot drift
# apart.
# script/fmt-check both go through here, so what gets formatted and what
# gets verified cannot drift apart.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
# The gofumpt version is the one bin/tools/go.mod pins. `go tool` run in
# bin/tools builds it from source checked against the hashes in
# bin/tools/go.sum, so neither a developer machine nor the lint image needs
# it installed.
# The gofumpt script/bootstrap installs into bin/. Must match the pin
# there.
GOFUMPT_VERSION="v0.12.0"
GOFUMPT="$ROOT/bin/gofumpt"
usage() {
echo "usage: script/gofumpt --write|--check" >&2
@@ -22,15 +21,22 @@ usage() {
main() {
[ "$#" -eq 1 ] || usage
cd "$ROOT/bin/tools"
# A bin/gofumpt left from before the pin moved formats differently, so
# it fails here until script/bootstrap replaces it.
actual="$("$GOFUMPT" --version 2>/dev/null | cut -d' ' -f1)"
if [ "$actual" != "$GOFUMPT_VERSION" ]; then
echo "gofumpt: needs $GOFUMPT_VERSION in bin/gofumpt," \
"found: ${actual:-none}; run script/bootstrap" >&2
exit 1
fi
# Every Go file in the repo, from $ROOT down. gofumpt holds generated
# files, such as mfer/mf.pb.go, to gofmt's rules only.
case "$1" in
--write) go tool gofumpt -l -w "$ROOT" ;;
--write) "$GOFUMPT" -l -w "$ROOT" ;;
--check)
# Own line: a failing command inside `[ -n "$(...)" ]` does
# not trip `set -e`, so a gofumpt that never ran would pass.
unformatted="$(go tool gofumpt -l "$ROOT")"
unformatted="$("$GOFUMPT" -l "$ROOT")"
if [ -n "$unformatted" ]; then
echo "gofumpt: files need formatting (run make fmt):" >&2
echo "$unformatted" >&2
-1
View File
@@ -1,7 +1,6 @@
#!/bin/sh
# script/install-precommit: install the git pre-commit hook that runs
# script/precommit. Our own extension to scripts-to-rule-them-all.
# Generic: needs no adaptation.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
+12 -9
View File
@@ -1,8 +1,13 @@
#!/bin/sh
# script/lint: run golangci-lint, in Docker only. Builds the lint stage of
# the Dockerfile, whose build runs the linter, so a successful build is a
# clean lint. --no-cache because a cached build runs no linter. The image
# is removed afterwards, whatever the outcome.
# script/lint: run the linter. Linting is a phase of the Dockerfile and
# this builds that phase alone; the linter is never installed or run on
# a developer host, where a shared result cache and a host-global lock
# make its answer untrustworthy.
#
# The phase is not the last stage in the file, so it is built only when
# --target names it. --no-cache because a cached lint layer is a lint
# that did not run. The tag makes each build replace the previous image
# instead of leaving a dangling one behind.
set -eu
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
@@ -10,11 +15,9 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
main() {
cd "$ROOT"
# Tagged per run, so concurrent runs never remove each other's image.
image="$("$SCRIPT_DIR/projectname")-lint:$$"
# A failed build leaves no image, so there is nothing to remove then.
trap 'docker image rm "$image" >/dev/null 2>&1 || true' EXIT INT TERM
docker build --no-cache --target lint -t "$image" .
docker build --no-cache \
--target lint \
-t "$("$SCRIPT_DIR/projectname")-lint" .
}
main "$@"
+1 -2
View File
@@ -56,8 +56,7 @@ main() {
# Markdown and JSON, repo-wide rather than root-only, so files in
# subdirectories (docs/, once it exists) are covered too. Exclusions
# live in .prettierignore; REPO_POLICIES.md is excluded there because
# it is a verbatim copy of an upstream document.
# live in .prettierignore.
#
# --no-error-on-unmatched-pattern is deliberately NOT used: both
# patterns always match at least one tracked file (README.md,
+1 -2
View File
@@ -1,7 +1,6 @@
#!/bin/sh
# script/setup: set up the repo for development after a fresh clone:
# installs dependencies (script/bootstrap) and the git pre-commit hook.
# Add any repo-specific initialization (db init, .env template) here.
# installs dependencies and the git pre-commit hook.
set -eu
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
+10 -8
View File
@@ -1,17 +1,19 @@
#!/bin/sh
# script/test: run the test suite.
# script/test: run the test suite. Testing is a phase of the Dockerfile
# and this builds that phase alone, on the same terms as script/lint:
# --target because a phase that is not the last stage is built only when
# named, --no-cache because a cached test layer is a test that did not
# run, and a tag so each build replaces the previous image.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
main() {
cd "$ROOT"
go test -timeout 30s -race -cover ./... ||
{
echo "--- Rerunning with -v for details ---"
go test -timeout 30s -race -v ./...
exit 1
}
docker build --no-cache \
--target test \
-t "$("$SCRIPT_DIR/projectname")-test" .
}
main "$@"