Compare commits

Author SHA1 Message Date
sneak c45310dc9e Build a static binary so the scratch image runs (closes #126)
check / check (push) Successful in 1m7s
The final stage is scratch, which has no C library, but the builder
compiled mfer with cgo on (the golang image's default). google/uuid
imports net, so the binary came out dynamically linked and the image
could not start. The image's go build now sets CGO_ENABLED=0; nothing
in mfer needs cgo. A new builder step runs ldd on the binary and fails
the build unless it reports a static executable.

Model: opus-5-5
2026-10-04 04:38:13 +00:00
9 changed files with 85 additions and 72 deletions
-1
View File
@@ -16,7 +16,6 @@ linters:
- depguard # Dependency allow/block lists - depguard # Dependency allow/block lists
- godot # Requires comments to end with periods - godot # Requires comments to end with periods
- wsl # Deprecated, replaced by wsl_v5 - wsl # Deprecated, replaced by wsl_v5
- gomodguard # Deprecated, replaced by gomodguard_v2
- wrapcheck # Too verbose for internal packages - wrapcheck # Too verbose for internal packages
- varnamelen # Short names like db, id are idiomatic Go - varnamelen # Short names like db, id are idiomatic Go
settings: settings:
+1 -3
View File
@@ -14,9 +14,7 @@ RUN touch mfer/mf.pb.go
# Go half of fmt-check only: this image has no node, so no prettier. The # Go half of fmt-check only: this image has no node, so no prettier. The
# markdown half runs in the mdfmt stage below. # markdown half runs in the mdfmt stage below.
RUN make fmt-check-go RUN make fmt-check-go
# The linter directly, not `make lint`: script/lint builds this stage, and RUN make lint
# there is no docker inside this build.
RUN golangci-lint run --config .golangci.yml ./...
# Markdown/JSON format stage — prettier needs node, which the Go images # Markdown/JSON format stage — prettier needs node, which the Go images
# do not have. node:22.17.0-bookworm-slim (2026-08-09); ships node # do not have. node:22.17.0-bookworm-slim (2026-08-09); ships node
+3
View File
@@ -58,6 +58,9 @@ fmt-check-md:
hooks: hooks:
@script/install-precommit @script/install-precommit
devprereqs:
which golangci-lint || go install -v github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.12.2
mfer/mf.pb.go: mfer/mf.proto mfer/mf.pb.go: mfer/mf.proto
cd mfer && go generate . cd mfer && go generate .
+11 -12
View File
@@ -65,9 +65,9 @@ standard: normalized scripts in `script/` are the entrypoints for the
development workflow, and the Makefile targets are thin shims that call them. We development workflow, and the Makefile targets are thin shims that call them. We
provide: provide:
- `script/bootstrap` — install all dependencies (Go, Go module download, and - `script/bootstrap` — install all dependencies (Go, golangci-lint, Go module
node/yarn plus the prettier version pinned in `package.json`/`yarn.lock`), download, and node/yarn plus the prettier version pinned in
idempotently; golangci-lint is not installed, it runs only in Docker `package.json`/`yarn.lock`), idempotently
- `script/setup` — make a fresh clone ready for development: runs - `script/setup` — make a fresh clone ready for development: runs
`script/bootstrap`, then `script/install-precommit` `script/bootstrap`, then `script/install-precommit`
- `script/projectname` — output the project name (`mfer`); used by other scripts - `script/projectname` — output the project name (`mfer`); used by other scripts
@@ -77,11 +77,9 @@ provide:
- `script/fuzz` — fuzz the manifest parser for one minute; run by hand - `script/fuzz` — fuzz the manifest parser for one minute; run by hand
(`make fuzz`), never by CI, while `script/test` runs its committed seed corpus (`make fuzz`), never by CI, while `script/test` runs its committed seed corpus
as ordinary tests as ordinary tests
- `script/lint` — run `golangci-lint` in Docker: builds only the `lint` stage of - `script/lint` — run `golangci-lint` and verify `gofmt` cleanliness
the `Dockerfile` (the Go format check, then the linter), uncached so it runs - `script/fmt` — format all code and docs (writes): `gofumpt`,
every time, then removes the image `golangci-lint run --fix`, and `script/prettier --write`
- `script/fmt` — format all code and docs (writes): `gofumpt` and
`script/prettier --write`
- `script/prettier` — run prettier over the repository's canonical file set - `script/prettier` — run prettier over the repository's canonical file set
(Markdown and JSON, minus `.prettierignore`) in the given mode, `--write` or (Markdown and JSON, minus `.prettierignore`) in the given mode, `--write` or
`--check`; the single definition of that file set, so `script/fmt` and `--check`; the single definition of that file set, so `script/fmt` and
@@ -107,10 +105,11 @@ yet. Primary development happens on a privately-run Gitea instance at
[tracked there](https://git.eeqj.de/sneak/mfer/issues). [tracked there](https://git.eeqj.de/sneak/mfer/issues).
Changes must always be formatted with a standard `go fmt`, syntactically valid, Changes must always be formatted with a standard `go fmt`, syntactically valid,
and must pass the linting defined in the repository's `.golangci.yml`, which and must pass the linting defined in the repository (presently only the
`make lint` runs in Docker. The `main` branch is protected and all changes must `golangci-lint` defaults), which can be run with a `make lint`. The `main`
be made via [pull requests](https://git.eeqj.de/sneak/mfer/pulls) and pass CI to branch is protected and all changes must be made via
be merged. Any changes submitted to this project must also be [pull requests](https://git.eeqj.de/sneak/mfer/pulls) and pass CI to be merged.
Any changes submitted to this project must also be
[WTFPL-licensed](https://wtfpl.net) to be considered. [WTFPL-licensed](https://wtfpl.net) to be considered.
See [`REPO_POLICIES.md`](REPO_POLICIES.md) for detailed coding standards, See [`REPO_POLICIES.md`](REPO_POLICIES.md) for detailed coding standards,
+18 -34
View File
@@ -10,7 +10,6 @@ import (
"path/filepath" "path/filepath"
"strconv" "strconv"
"strings" "strings"
"syscall"
"testing" "testing"
"time" "time"
@@ -426,31 +425,18 @@ func TestGPGTimeoutKillsGPG(t *testing.T) {
assert.Contains(t, err.Error(), "gpg sign failed: gpg timed out") assert.Contains(t, err.Error(), "gpg sign failed: gpg timed out")
} }
// TestGPGCancelWhenChildHoldsOutput uses a fake gpg that runs sleep as a // TestGPGTimeoutWhenChildHoldsOutput uses a fake gpg that runs sleep as a
// child instead of exec-ing it, the way a wrapper script around the real // child instead of exec-ing it, the way a wrapper script around the real
// gpg might. Killing the fake gpg leaves sleep holding its stdout and // gpg might. Killing the fake gpg leaves sleep holding its stdout and
// stderr open; the call must still return once ctx ends instead of waiting // stderr open; the call must still return shortly after the deadline
// for sleep to exit. The fake gpg writes the process ID of sleep to a named // instead of waiting for sleep to exit. The fake gpg writes the process ID
// pipe; the test ends ctx only after reading it, so sleep is running by // of sleep to a file so that the test can kill it before returning.
// then, and kills sleep before returning. func TestGPGTimeoutWhenChildHoldsOutput(t *testing.T) {
func TestGPGCancelWhenChildHoldsOutput(t *testing.T) { pidFile := filepath.Join(t.TempDir(), "sleep.pid")
pidPipe := filepath.Join(t.TempDir(), "sleep.pid")
require.NoError(t, syscall.Mkfifo(pidPipe, 0o600))
// sleep outlasts the 10 s wait below, so a call that waits for it fails.
t.Setenv("PATH", fakeGPGPath(t, t.Setenv("PATH", fakeGPGPath(t,
"#!/bin/sh\nsleep 60 &\necho $! >'"+pidPipe+"'\nwait\n")) "#!/bin/sh\nsleep 3 &\necho $! >'"+pidFile+"'\nwait\n"))
t.Cleanup(func() {
ctx, cancel := context.WithCancel(context.Background()) pid, err := os.ReadFile(pidFile) //nolint:gosec // G304: path inside t.TempDir()
defer cancel()
signErr := make(chan error, 1)
go func() {
_, err := gpgSign(ctx, []byte("data"), GPGKeyID("any"))
signErr <- err
}()
pid, err := os.ReadFile(pidPipe) //nolint:gosec // G304: path inside t.TempDir()
require.NoError(t, err) require.NoError(t, err)
n, err := strconv.Atoi(strings.TrimSpace(string(pid))) n, err := strconv.Atoi(strings.TrimSpace(string(pid)))
@@ -458,19 +444,17 @@ func TestGPGCancelWhenChildHoldsOutput(t *testing.T) {
sleep, err := os.FindProcess(n) sleep, err := os.FindProcess(n)
require.NoError(t, err) require.NoError(t, err)
t.Cleanup(func() { require.NoError(t, sleep.Kill()) }) require.NoError(t, sleep.Kill())
})
cancel() ctx, cancel := context.WithTimeout(context.Background(), 100*time.Millisecond)
defer cancel()
// The call should return about gpgWaitDelay (one second) after the start := time.Now()
// cancel. 10 s is far above that and well under the 30 s test timeout, _, err := gpgSign(ctx, []byte("data"), GPGKeyID("any"))
// which would abort the whole package before the cleanup kills sleep. require.ErrorIs(t, err, context.DeadlineExceeded)
select { assert.Less(t, time.Since(start), 3*time.Second,
case err := <-signErr: "the call waited for the child holding gpg's output to exit")
require.ErrorIs(t, err, context.Canceled)
case <-time.After(10 * time.Second):
t.Fatal("the call waited for the child holding gpg's output to exit")
}
} }
// TestBuildPassesContextToSigning checks that a caller can cancel the gpg // TestBuildPassesContextToSigning checks that a caller can cancel the gpg
+29 -2
View File
@@ -304,19 +304,46 @@ func TestScannerEnumerateFS(t *testing.T) {
func TestSendEnumerateStatusNonBlocking(t *testing.T) { func TestSendEnumerateStatusNonBlocking(t *testing.T) {
t.Parallel() t.Parallel()
// Nobody receives, so a blocking send would hang the test into its timeout. // Channel with no buffer - send should not block
ch := make(chan EnumerateStatus) ch := make(chan EnumerateStatus)
// This should not block
done := make(chan bool)
go func() {
sendEnumerateStatus(ch, EnumerateStatus{FilesFound: 1}) sendEnumerateStatus(ch, EnumerateStatus{FilesFound: 1})
done <- true
}()
select {
case <-done:
// Success - did not block
case <-time.After(100 * time.Millisecond):
t.Fatal("sendEnumerateStatus blocked on full channel")
}
} }
func TestSendScanStatusNonBlocking(t *testing.T) { func TestSendScanStatusNonBlocking(t *testing.T) {
t.Parallel() t.Parallel()
// Nobody receives, so a blocking send would hang the test into its timeout. // Channel with no buffer - send should not block
ch := make(chan ScanStatus) ch := make(chan ScanStatus)
done := make(chan bool)
go func() {
sendScanStatus(ch, ScanStatus{ScannedFiles: 1}) sendScanStatus(ch, ScanStatus{ScannedFiles: 1})
done <- true
}()
select {
case <-done:
// Success - did not block
case <-time.After(100 * time.Millisecond):
t.Fatal("sendScanStatus blocked on full channel")
}
} }
func TestSendStatusNilChannel(t *testing.T) { func TestSendStatusNilChannel(t *testing.T) {
+6 -1
View File
@@ -140,7 +140,12 @@ main() {
# ---- Go repos ---- # ---- Go repos ----
if missing go; then pkg_install go golang go go; fi if missing go; then pkg_install go golang go go; fi
# No golangci-lint: script/lint runs it in Docker only. # golangci-lint: packaged in nix, brew, and apk. On apt there is no
# package: download a specific release archive from GitHub and
# verify its hash (verify_sha256), never curl | sh.
if missing golangci-lint; then
pkg_install golangci-lint golangci-lint golangci-lint golangci-lint
fi
go mod download go mod download
# ---- Python repos ---- # ---- Python repos ----
+1
View File
@@ -19,6 +19,7 @@ main() {
cd "$ROOT" cd "$ROOT"
ensure_pb ensure_pb
gofumpt -l -w mfer internal cmd gofumpt -l -w mfer internal cmd
golangci-lint run --fix
# Markdown and JSON, over the same file set script/fmt-check verifies. # Markdown and JSON, over the same file set script/fmt-check verifies.
"$SCRIPT_DIR/prettier" --write "$SCRIPT_DIR/prettier" --write
} }
+8 -11
View File
@@ -1,20 +1,17 @@
#!/bin/sh #!/bin/sh
# script/lint: run golangci-lint, in Docker only. Builds the lint stage of # script/lint: run the linter.
# the Dockerfile, whose build runs the linter, so a successful build is a
# clean lint. --no-cache because a cached build runs no linter. The image
# is removed afterwards, whatever the outcome.
set -eu set -eu
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
main() { main() {
cd "$ROOT" cd "$ROOT"
# Tagged per run, so concurrent runs never remove each other's image. golangci-lint run
image="$("$SCRIPT_DIR/projectname")-lint:$$" if [ -n "$(gofmt -l .)" ]; then
# A failed build leaves no image, so there is nothing to remove then. echo "gofmt: files need formatting:" >&2
trap 'docker image rm "$image" >/dev/null 2>&1 || true' EXIT INT TERM gofmt -l . >&2
docker build --no-cache --target lint -t "$image" . exit 1
fi
} }
main "$@" main "$@"