All checks were successful
check / check (push) Successful in 38s
script/fmt ran prettier with default settings over root-level *.md and *.json, swallowing every failure with `|| true`, while script/fmt-check checked gofmt only. The formatter and the gate therefore disagreed silently: `make fmt` rewrote markdown that `make check` never looked at, including REPO_POLICIES.md, which is a verbatim copy of an authoritative upstream document that local tooling must not touch. Configuration: - .prettierrc pins the two policy deviations from prettier defaults, four-space indents and proseWrap: always. Nothing else. - .prettierignore excludes REPO_POLICIES.md so no local run can drift it from upstream again, plus .golangci.yml (user-owned, and listed even though the current file set does not reach it) and node_modules, vendor, bin. One canonical file set: - New script/prettier takes --write or --check and applies the same patterns in both modes, so script/fmt and script/fmt-check cannot drift apart by construction. The patterns are repo-wide (**/*.md, **/*.json) rather than root-only, so markdown in subdirectories such as a future docs/ is covered. - No `|| true` anywhere, and no --no-error-on-unmatched-pattern: both patterns always match tracked files, so an empty match means the glob broke and prettier should say so instead of passing vacuously. A missing prettier is a hard error naming script/bootstrap, not a silent skip. Pinned prettier: - package.json/yarn.lock pin prettier 3.9.6; the lockfile carries the integrity hash, and --frozen-lockfile enforces it. script/prettier prefers node_modules/.bin/prettier and warns on stderr when it has to fall back to a PATH prettier of unknown version. - script/bootstrap now installs node, yarn, and the locked JS deps. Its NODE_VERSION and YARN_VERSION pins already existed. Docker gate: - The golangci-lint image has no node, so the lint stage runs the new script/fmt-check-go (the Go half of fmt-check, extracted) instead of the whole thing. - The markdown half gets its own stage on a digest-pinned node image shipping exactly the node and yarn versions bootstrap pins. The builder stage takes a COPY --from dependency on it, so BuildKit cannot skip it and a markdown violation fails `docker build .` rather than being skipped somewhere nobody looks. Markdown files other than REPO_POLICIES.md are reformatted here for the first time under the policy settings.
30 lines
795 B
Bash
Executable File
30 lines
795 B
Bash
Executable File
#!/bin/sh
|
|
# script/fmt-check-go: check Go formatting (read-only). Split out from
|
|
# script/fmt-check so the Docker lint stage, whose image has no node and
|
|
# therefore no prettier, can run the Go half on its own.
|
|
set -eu
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
|
|
|
# Regenerate mfer/mf.pb.go from mfer/mf.proto if it is missing or stale
|
|
# (mirrors the old Makefile prerequisite; the generated file is
|
|
# committed, so this is normally a no-op).
|
|
ensure_pb() {
|
|
if [ ! -f mfer/mf.pb.go ] ||
|
|
[ -n "$(find mfer/mf.proto -newer mfer/mf.pb.go 2>/dev/null)" ]; then
|
|
(cd mfer && go generate .)
|
|
fi
|
|
}
|
|
|
|
main() {
|
|
cd "$ROOT"
|
|
ensure_pb
|
|
if [ -n "$(gofmt -l .)" ]; then
|
|
echo "gofmt: files need formatting:" >&2
|
|
gofmt -l . >&2
|
|
exit 1
|
|
fi
|
|
}
|
|
|
|
main "$@"
|