build: unify the gate so root make check covers the backend (closes #16)
check / check (push) Successful in 11s
check / check (push) Successful in 11s
Root make check, and with it the pre-commit hook, now gates the Go backend too. The backend's Makefile targets are shims over backend/script/*; script/cibuild builds both images and is the workflow's only build step. Root make test runs both halves within one 30-second timeout. Root make lint runs golangci-lint only in Docker, by building the lint stage of Dockerfile.backend without the cache; the .golangci.yml drift check moved into backend/script/lint. script/bootstrap installs no linter: it reuses a Go at least as new as backend/go.mod asks for, otherwise installs the pinned, hash-verified release, linked into ~/.local/bin without replacing anything it did not create. With VERSION unset or empty, the backend version falls back to git describe inside a git checkout, then to dev. Model: opus-5-5
This commit was merged in pull request #38.
This commit is contained in:
Executable
+21
@@ -0,0 +1,21 @@
|
||||
#!/bin/sh
|
||||
# script/build: compile the static netwatch-server binary into the
|
||||
# backend project root, with its version and architecture stamped in.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
|
||||
# VERSION comes from the environment (Dockerfile.backend passes its
|
||||
# ARG VERSION in). Unset or empty, it is git describe, or "dev" where
|
||||
# there is no git or no repository history.
|
||||
version="${VERSION:-$(git describe --always --dirty 2>/dev/null || echo dev)}"
|
||||
|
||||
CGO_ENABLED=0 go build -trimpath \
|
||||
-ldflags "-s -w -X main.Version=$version -X main.Buildarch=$(uname -m)" \
|
||||
-o netwatch-server ./cmd/netwatch-server/
|
||||
}
|
||||
|
||||
main "$@"
|
||||
Executable
+12
@@ -0,0 +1,12 @@
|
||||
#!/bin/sh
|
||||
# script/clean: remove build artifacts.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
rm -f netwatch-server
|
||||
}
|
||||
|
||||
main "$@"
|
||||
Executable
+12
@@ -0,0 +1,12 @@
|
||||
#!/bin/sh
|
||||
# script/fmt: format the Go sources (writes).
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
go fmt ./...
|
||||
}
|
||||
|
||||
main "$@"
|
||||
Executable
+18
@@ -0,0 +1,18 @@
|
||||
#!/bin/sh
|
||||
# script/fmt-check: check Go formatting (read-only). Same scope as
|
||||
# script/fmt, but fails instead of writing.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
unformatted="$(gofmt -l .)"
|
||||
if [ -n "$unformatted" ]; then
|
||||
echo "Files not formatted:" >&2
|
||||
echo "$unformatted" >&2
|
||||
exit 1
|
||||
fi
|
||||
}
|
||||
|
||||
main "$@"
|
||||
Executable
+32
@@ -0,0 +1,32 @@
|
||||
#!/bin/sh
|
||||
# script/lint: run golangci-lint over the backend. This runs inside the
|
||||
# lint stage of Dockerfile.backend, whose digest-pinned golangci-lint
|
||||
# image provides the linter; nothing installs golangci-lint on the host.
|
||||
# From a checkout, run `make lint` at the repo root, which builds that
|
||||
# stage.
|
||||
#
|
||||
# .golangci.yml is standardized org-wide and must never be edited here
|
||||
# (REPO_POLICIES.md). Its last silent drift replaced the v2 schema with
|
||||
# v1 keys, which left every threshold in the file inert while the build
|
||||
# stayed green. So the file is first checked against the canonical
|
||||
# copy's sha256: a local comparison, no network, nothing unpinned.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
GOLANGCI_CONFIG_SHA256="021cc83f4e6fc7c31b95b34b846723dfcf20b66b7baeea1dc40406e643346bcb"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
actual="$(sha256sum .golangci.yml | cut -d' ' -f1)"
|
||||
if [ "$actual" != "$GOLANGCI_CONFIG_SHA256" ]; then
|
||||
echo ".golangci.yml has drifted from the org standard." >&2
|
||||
echo " expected $GOLANGCI_CONFIG_SHA256" >&2
|
||||
echo " actual $actual" >&2
|
||||
echo "Restore it verbatim from sneak/prompts; do not edit it." >&2
|
||||
exit 1
|
||||
fi
|
||||
golangci-lint run ./...
|
||||
}
|
||||
|
||||
main "$@"
|
||||
Executable
+13
@@ -0,0 +1,13 @@
|
||||
#!/bin/sh
|
||||
# script/run: build and run netwatch-server locally.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
"$ROOT/script/build"
|
||||
exec ./netwatch-server "$@"
|
||||
}
|
||||
|
||||
main "$@"
|
||||
Executable
+12
@@ -0,0 +1,12 @@
|
||||
#!/bin/sh
|
||||
# script/test: run the backend test suite.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
timeout 30 go test ./...
|
||||
}
|
||||
|
||||
main "$@"
|
||||
Reference in New Issue
Block a user