#!/bin/sh
# script/lint: run golangci-lint over the backend. This runs inside the
# lint stage of the root Dockerfile, whose digest-pinned golangci-lint
# image provides the linter; nothing installs golangci-lint on the host.
# From a checkout, run `make lint` at the repo root, which builds that
# stage.
#
# .golangci.yml is standardized org-wide and must never be edited here
# (REPO_POLICIES.md). Its last silent drift replaced the v2 schema with
# v1 keys, which left every threshold in the file inert while the build
# stayed green. So the file is first checked against the canonical
# copy's sha256: a local comparison, no network, nothing unpinned.
set -eu

ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"

GOLANGCI_CONFIG_SHA256="a79b63a254602a5318db5d0e9a06bc71b84bf0c1d896305229d8bfed1d1b1776"

main() {
    cd "$ROOT"
    actual="$(sha256sum .golangci.yml | cut -d' ' -f1)"
    if [ "$actual" != "$GOLANGCI_CONFIG_SHA256" ]; then
        echo ".golangci.yml has drifted from the org standard." >&2
        echo "  expected $GOLANGCI_CONFIG_SHA256" >&2
        echo "  actual   $actual" >&2
        echo "Restore it verbatim from sneak/prompts; do not edit it." >&2
        exit 1
    fi
    golangci-lint run ./...
}

main "$@"
