check / check (push) Failing after 5s
Fetches .dockerignore, .editorconfig, the CI workflow, .gitignore, .golangci.yml, .prettierignore, .prettierrc and REPO_POLICIES.md byte for byte from sneak/prompts dd4027b, keeping this repo's anchored host-built artifacts in .dockerignore; the new .golangci.yml disables gomodguard. The Dockerfile gets a lint phase on golangci-lint v2.14.0 and a test phase on the Debian Go image; the build stage depends on both and stamps the version as the policy shows. script/test and script/lint build only their phase, and script/cibuild bootstraps and runs script/check first. bin/tools goes: script/bootstrap installs gofumpt and protoc-gen-go into bin/ with go install pinned to a commit, and bin/.gitignore ignores what lands in bin/. Model: opus-5-5
265 lines
9.3 KiB
Bash
Executable File
265 lines
9.3 KiB
Bash
Executable File
#!/bin/sh
|
|
# script/bootstrap: install all dependencies needed to build and develop
|
|
# this repo. Idempotent: every install is guarded by a check so already
|
|
# installed tools are skipped. Base tooling comes from nix, apt, brew,
|
|
# or apk (detected in that order); assumes NOTHING is present (not git,
|
|
# make, node, yarn, go, or python). Node is used directly if installed;
|
|
# otherwise a pinned version is installed via nvm (installing nvm
|
|
# itself first, from a hash-verified release archive, never curl | sh).
|
|
#
|
|
# Uncomment the language sections in main() that apply to this repo.
|
|
set -eu
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
|
|
|
# Pinned versions, 2026-07-06. Never "latest" or "lts"; exact versions.
|
|
# The node version is in .nvmrc, where script/prettier reads it too.
|
|
NODE_VERSION="$(cat "$ROOT/.nvmrc")"
|
|
NVM_VERSION="0.40.3"
|
|
# sha256 of https://github.com/nvm-sh/nvm/archive/refs/tags/v0.40.3.tar.gz
|
|
NVM_SHA256="5f4d6aaa04a177dc93c985e31dbc411ab6b8c6e1e21d8015dbc1372625fcd1d0"
|
|
YARN_VERSION="1.22.22"
|
|
# protoc v33.4, 2026-10-04, for script/generate. The sha256 of each
|
|
# platform's release archive is in ensure_protoc.
|
|
PROTOC_VERSION="33.4"
|
|
# gofumpt v0.12.0 for script/gofumpt and protoc-gen-go v1.36.11 for
|
|
# script/generate, 2026-10-04: each is installed into bin/ with
|
|
# `go install`, pinned to the commit its release tag names. Those two
|
|
# scripts refuse any other version, so a new pin is changed there too.
|
|
GOFUMPT_VERSION="v0.12.0"
|
|
GOFUMPT_COMMIT="3e07e7e70ac93761d8e79ca0083a19e3d59f753d"
|
|
PROTOC_GEN_GO_VERSION="v1.36.11"
|
|
PROTOC_GEN_GO_COMMIT="96a179180f0ad6bba9b1e7b6e38d0affb0168e9a"
|
|
|
|
PKGMGR=""
|
|
SUDO=""
|
|
|
|
detect_pkgmgr() {
|
|
[ -n "$PKGMGR" ] && return 0
|
|
if command -v nix-env >/dev/null 2>&1; then
|
|
PKGMGR="nix"
|
|
elif command -v apt-get >/dev/null 2>&1; then
|
|
PKGMGR="apt"
|
|
elif command -v brew >/dev/null 2>&1; then
|
|
PKGMGR="brew"
|
|
elif command -v apk >/dev/null 2>&1; then
|
|
PKGMGR="apk"
|
|
else
|
|
echo "bootstrap: no supported package manager (nix, apt, brew, apk)" >&2
|
|
exit 1
|
|
fi
|
|
if [ "$PKGMGR" = "apt" ]; then
|
|
export DEBIAN_FRONTEND=noninteractive
|
|
if [ "$(id -u)" != "0" ]; then
|
|
SUDO="sudo"
|
|
fi
|
|
fi
|
|
}
|
|
|
|
# pkg_install <nix-attr> <apt-pkg> <brew-formula> <apk-pkg>
|
|
pkg_install() {
|
|
detect_pkgmgr
|
|
case "$PKGMGR" in
|
|
nix) nix-env -iA "nixpkgs.$1" ;;
|
|
apt) $SUDO env DEBIAN_FRONTEND=noninteractive apt-get install -y "$2" ;;
|
|
brew) brew install "$3" ;;
|
|
apk) apk add --no-cache "$4" ;;
|
|
esac
|
|
}
|
|
|
|
missing() {
|
|
! command -v "$1" >/dev/null 2>&1
|
|
}
|
|
|
|
# verify_sha256 <file> <expected-hash>
|
|
verify_sha256() {
|
|
if command -v sha256sum >/dev/null 2>&1; then
|
|
actual="$(sha256sum "$1" | cut -d' ' -f1)"
|
|
else
|
|
actual="$(shasum -a 256 "$1" | cut -d' ' -f1)"
|
|
fi
|
|
if [ "$actual" != "$2" ]; then
|
|
echo "bootstrap: sha256 mismatch for $1" >&2
|
|
echo " expected: $2" >&2
|
|
echo " actual: $actual" >&2
|
|
exit 1
|
|
fi
|
|
}
|
|
|
|
# nvm is a bash script; run a command in a bash with nvm loaded.
|
|
# --no-use: otherwise loading nvm here switches to the version .nvmrc
|
|
# names, and fails silently while that version is not installed yet.
|
|
nvm_sh() {
|
|
bash -c ". \"\$HOME/.nvm/nvm.sh\" --no-use && $*"
|
|
}
|
|
|
|
ensure_nvm() {
|
|
[ -s "$HOME/.nvm/nvm.sh" ] && return 0
|
|
# nvm prerequisites; nvm itself requires bash, so install it too
|
|
if missing bash; then pkg_install bash bash bash bash; fi
|
|
if missing curl; then pkg_install curl curl curl curl; fi
|
|
if missing git; then pkg_install git git git git; fi
|
|
tmp="$(mktemp -d)"
|
|
curl -fsSL -o "$tmp/nvm.tar.gz" \
|
|
"https://github.com/nvm-sh/nvm/archive/refs/tags/v${NVM_VERSION}.tar.gz"
|
|
verify_sha256 "$tmp/nvm.tar.gz" "$NVM_SHA256"
|
|
mkdir -p "$HOME/.nvm"
|
|
tar -xzf "$tmp/nvm.tar.gz" -C "$HOME/.nvm" --strip-components=1
|
|
rm -rf "$tmp"
|
|
}
|
|
|
|
ensure_node() {
|
|
if ! missing node; then return 0; fi
|
|
ensure_nvm
|
|
nvm_sh "nvm install $NODE_VERSION"
|
|
}
|
|
|
|
ensure_yarn() {
|
|
if ! missing yarn; then return 0; fi
|
|
if ! missing corepack; then
|
|
corepack enable
|
|
corepack prepare "yarn@$YARN_VERSION" --activate
|
|
elif [ -s "$HOME/.nvm/nvm.sh" ]; then
|
|
nvm_sh "nvm use $NODE_VERSION >/dev/null && corepack enable && \
|
|
corepack prepare yarn@$YARN_VERSION --activate"
|
|
else
|
|
npm install -g "yarn@$YARN_VERSION"
|
|
fi
|
|
}
|
|
|
|
install_js_deps() {
|
|
if missing yarn && [ -s "$HOME/.nvm/nvm.sh" ]; then
|
|
nvm_sh "nvm use $NODE_VERSION >/dev/null && cd \"$ROOT\" && \
|
|
yarn install --frozen-lockfile"
|
|
else
|
|
yarn install --frozen-lockfile
|
|
fi
|
|
}
|
|
|
|
# Unpack protoc's release archive for this platform into bin/protoc, after
|
|
# checking the archive's sha256, unless bin/protoc already holds the pinned
|
|
# version. script/generate runs bin/protoc/bin/protoc, so that is the
|
|
# binary checked again after unpacking.
|
|
ensure_protoc() {
|
|
dir="$ROOT/bin/protoc"
|
|
if [ "$("$dir/bin/protoc" --version 2>/dev/null)" = \
|
|
"libprotoc $PROTOC_VERSION" ]; then
|
|
echo "protoc $PROTOC_VERSION"
|
|
return 0
|
|
fi
|
|
case "$(uname -s) $(uname -m)" in
|
|
"Linux x86_64")
|
|
platform="linux-x86_64"
|
|
sha256="c0040ea9aef08fdeb2c74ca609b18d5fdbfc44ea0042fcfbfb38860d35f7dd66"
|
|
;;
|
|
"Linux aarch64" | "Linux arm64")
|
|
platform="linux-aarch_64"
|
|
sha256="15aa988f4a6090636525ec236a8e4b3aab41eef402751bd5bb2df6afd9b7b5a5"
|
|
;;
|
|
"Darwin x86_64")
|
|
platform="osx-x86_64"
|
|
sha256="a49bec10d039e902d3b43e49938c42526f90011467609864fa6386ac4014da58"
|
|
;;
|
|
"Darwin arm64")
|
|
platform="osx-aarch_64"
|
|
sha256="726297dcfed58592fd35620a5a6246ae020c39e88f3fd4cb1827df7bcf3dfcf1"
|
|
;;
|
|
*)
|
|
echo "bootstrap: no protoc archive pinned for $(uname -s) $(uname -m)" >&2
|
|
exit 1
|
|
;;
|
|
esac
|
|
if missing curl; then pkg_install curl curl curl curl; fi
|
|
if missing unzip; then pkg_install unzip unzip unzip unzip; fi
|
|
tmp="$(mktemp -d)"
|
|
curl -fsSL -o "$tmp/protoc.zip" \
|
|
"https://github.com/protocolbuffers/protobuf/releases/download/v${PROTOC_VERSION}/protoc-${PROTOC_VERSION}-${platform}.zip"
|
|
verify_sha256 "$tmp/protoc.zip" "$sha256"
|
|
rm -rf "$dir"
|
|
unzip -q "$tmp/protoc.zip" -d "$dir"
|
|
rm -rf "$tmp"
|
|
actual="$("$dir/bin/protoc" --version 2>/dev/null || true)"
|
|
if [ "$actual" != "libprotoc $PROTOC_VERSION" ]; then
|
|
echo "bootstrap: $dir/bin/protoc reports '$actual'," \
|
|
"not libprotoc $PROTOC_VERSION" >&2
|
|
exit 1
|
|
fi
|
|
echo "protoc $PROTOC_VERSION"
|
|
}
|
|
|
|
# Install gofumpt into bin/ unless bin/gofumpt already reports the pinned
|
|
# version. script/gofumpt runs bin/gofumpt, so that is the binary checked
|
|
# again after installing. Its --version prints the version, then the Go
|
|
# version it was built with. The old file is removed first because
|
|
# `go install` refuses to replace a file that is not a Go binary.
|
|
ensure_gofumpt() {
|
|
tool="$ROOT/bin/gofumpt"
|
|
if [ "$("$tool" --version 2>/dev/null | cut -d' ' -f1)" != \
|
|
"$GOFUMPT_VERSION" ]; then
|
|
rm -f "$tool"
|
|
GOBIN="$ROOT/bin" go install "mvdan.cc/gofumpt@$GOFUMPT_COMMIT"
|
|
fi
|
|
actual="$("$tool" --version 2>/dev/null | cut -d' ' -f1)"
|
|
if [ "$actual" != "$GOFUMPT_VERSION" ]; then
|
|
echo "bootstrap: $tool reports '$actual', not $GOFUMPT_VERSION" >&2
|
|
exit 1
|
|
fi
|
|
echo "gofumpt $GOFUMPT_VERSION"
|
|
}
|
|
|
|
# Install protoc-gen-go into bin/ unless bin/protoc-gen-go already reports
|
|
# the pinned version, as ensure_gofumpt does. script/generate runs
|
|
# bin/protoc-gen-go, so that is the binary checked again after installing.
|
|
ensure_protoc_gen_go() {
|
|
tool="$ROOT/bin/protoc-gen-go"
|
|
if [ "$("$tool" --version 2>/dev/null)" != \
|
|
"protoc-gen-go $PROTOC_GEN_GO_VERSION" ]; then
|
|
rm -f "$tool"
|
|
GOBIN="$ROOT/bin" go install \
|
|
"google.golang.org/protobuf/cmd/protoc-gen-go@$PROTOC_GEN_GO_COMMIT"
|
|
fi
|
|
actual="$("$tool" --version 2>/dev/null || true)"
|
|
if [ "$actual" != "protoc-gen-go $PROTOC_GEN_GO_VERSION" ]; then
|
|
echo "bootstrap: $tool reports '$actual'," \
|
|
"not protoc-gen-go $PROTOC_GEN_GO_VERSION" >&2
|
|
exit 1
|
|
fi
|
|
echo "protoc-gen-go $PROTOC_GEN_GO_VERSION"
|
|
}
|
|
|
|
main() {
|
|
cd "$ROOT"
|
|
|
|
# Base tooling (every repo)
|
|
if missing git; then pkg_install git git git git; fi
|
|
if missing make; then pkg_install gnumake make make make; fi
|
|
|
|
# ---- JS / docs repos ----
|
|
# This is a Go repo, but node and yarn are required anyway: prettier
|
|
# formats the Markdown and JSON, and script/fmt-check verifies it.
|
|
# The version is pinned by package.json/yarn.lock: yarn checks every
|
|
# package it fetches against its yarn.lock integrity hash, and
|
|
# --frozen-lockfile fails instead of rewriting a yarn.lock that no
|
|
# longer matches package.json.
|
|
ensure_node
|
|
ensure_yarn
|
|
install_js_deps
|
|
|
|
# ---- Go repos ----
|
|
if missing go; then pkg_install go golang go go; fi
|
|
# No golangci-lint: script/lint runs it in Docker only.
|
|
go mod download
|
|
ensure_gofumpt
|
|
ensure_protoc
|
|
ensure_protoc_gen_go
|
|
|
|
# ---- Python repos ----
|
|
# if missing python3; then pkg_install python3 python3 python3 python3; fi
|
|
# python3 -m venv .venv
|
|
# ./.venv/bin/pip install -e '.[dev]'
|
|
|
|
echo "bootstrap complete"
|
|
}
|
|
|
|
main "$@"
|