Re-vendor the canonical files from sneak/prompts at dd4027b (closes #112)
check / check (push) Failing after 4s
check / check (push) Failing after 4s
The shared files are fetched from sneak/prompts dd4027b, with this repository's own entries after the shared content in .gitignore, .editorconfig and .dockerignore. Lint and tests are Dockerfile phases (golangci-lint v2.14.0, Debian Go 1.24.13) that the build stage depends on, and the Makefile targets call the script/ entrypoints. make fmt also formats Markdown with prettier. Fixes for the new lint findings: the auth cookie is always Secure, an IRC connection's relay goroutine stops when the connection closes, and repeated strings are constants. neoirc-cli treats a plain-HTTP server on localhost or a loopback address as secure, so local use keeps its session. Whether the 60-second test cap covers building the test phase is open on sneak/prompts issue 113. Model: opus-5-5
This commit was merged in pull request #115.
This commit is contained in:
+35
-19
@@ -8,41 +8,56 @@ COPY web/src/ src/
|
||||
COPY web/build.sh build.sh
|
||||
RUN sh build.sh
|
||||
|
||||
# Lint stage — fast feedback on formatting and lint issues
|
||||
# golangci/golangci-lint:v2.1.6, 2026-03-02
|
||||
FROM golangci/golangci-lint@sha256:568ee1c1c53493575fa9494e280e579ac9ca865787bafe4df3023ae59ecf299b AS lint
|
||||
# Lint phase, built alone by script/lint. The linter is invoked directly
|
||||
# rather than through `make lint`, which is itself a docker build and
|
||||
# would recurse into a daemon that does not exist in a build step.
|
||||
# golangci/golangci-lint:v2.14.0, 2026-10-06
|
||||
FROM golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f AS lint
|
||||
WORKDIR /src
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
COPY . .
|
||||
# Create placeholder files so //go:embed dist/* in web/embed.go resolves
|
||||
# without depending on the web-builder stage (lint should fail fast)
|
||||
# Placeholder files so //go:embed dist/* in web/embed.go resolves
|
||||
# without waiting for the web-builder stage. The test phase does the same.
|
||||
RUN mkdir -p web/dist && touch web/dist/index.html web/dist/style.css web/dist/app.js
|
||||
RUN make fmt-check
|
||||
RUN make lint
|
||||
RUN golangci-lint run --config .golangci.yml ./...
|
||||
|
||||
# Build stage
|
||||
# Test phase, built alone by script/test. -race needs cgo and so a C
|
||||
# compiler, which the Debian Go image ships and the alpine one does not.
|
||||
# golang:1.24.13-bookworm, 2026-10-06
|
||||
FROM golang@sha256:1a6d4452c65dea36aac2e2d606b01b4a029ec90cc1ae53890540ce6173ea77ac AS test
|
||||
WORKDIR /src
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
COPY . .
|
||||
RUN mkdir -p web/dist && touch web/dist/index.html web/dist/style.css web/dist/app.js
|
||||
# -p 4 because test runs on a shared build host cap their parallelism.
|
||||
RUN go test -p 4 -timeout 90s -race -cover ./... || \
|
||||
{ echo "--- Rerunning with -v for details ---"; \
|
||||
go test -p 4 -timeout 90s -race -v ./...; exit 1; }
|
||||
|
||||
# Build stage. Nothing is wanted from either phase above; the copies
|
||||
# are what make BuildKit build them first, so this stage cannot run
|
||||
# unless lint and test passed.
|
||||
# golang:1.24-alpine, 2026-02-26
|
||||
FROM golang@sha256:8bee1901f1e530bfb4a7850aa7a479d17ae3a18beb6e09064ed54cfd245b7191 AS builder
|
||||
WORKDIR /src
|
||||
RUN apk add --no-cache git build-base make
|
||||
|
||||
# Force BuildKit to run the lint stage before proceeding
|
||||
COPY --from=lint /src/go.sum /dev/null
|
||||
|
||||
COPY --from=test /src/go.sum /dev/null
|
||||
RUN apk add --no-cache git
|
||||
# A tar-stream context keeps the sender's file owners, which git refuses.
|
||||
RUN git config --system --add safe.directory /src
|
||||
WORKDIR /src
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
COPY . .
|
||||
COPY --from=web-builder /web/dist/ web/dist/
|
||||
|
||||
RUN make test
|
||||
|
||||
# Build static binaries (no cgo needed at runtime — modernc.org/sqlite is pure Go)
|
||||
#
|
||||
# neoircd is stamped with the VERSION build arg when one is given, otherwise
|
||||
# with the tag or short commit from the .git in the build context. With .git
|
||||
# present, a version that is still empty, dev or unknown fails the build.
|
||||
# with `git describe --tags --always` on the .git in the build context. With
|
||||
# .git present, a version that is still empty, dev or unknown fails the build:
|
||||
# git is missing or could not read the checkout.
|
||||
ARG VERSION
|
||||
RUN VERSION="${VERSION:-$(git describe --tags --always)}"; \
|
||||
if [ -e .git ]; then \
|
||||
@@ -54,7 +69,8 @@ RUN VERSION="${VERSION:-$(git describe --tags --always)}"; \
|
||||
CGO_ENABLED=0 go build -trimpath -ldflags="-s -w -X main.Version=${VERSION}" -o /neoircd ./cmd/neoircd/
|
||||
RUN CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o /neoirc-cli ./cmd/neoirc-cli/
|
||||
|
||||
# Runtime stage
|
||||
# Runtime stage, and the last one: a plain `docker build .` builds this
|
||||
# stage's chain and nothing else.
|
||||
# alpine:3.21, 2026-02-26
|
||||
FROM alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709
|
||||
RUN apk add --no-cache ca-certificates \
|
||||
|
||||
Reference in New Issue
Block a user