4baf2a1c781a2452937984360e2121bb7f271ff9
3
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
4baf2a1c78 |
build: unify the gate so root make check covers the backend (closes #16)
check / check (push) Successful in 23s
Root `make check` only ever ran the frontend, so the "main is always green" policy was satisfied vacuously: the Go backend could be entirely broken and the root gate stayed green. - The backend moves onto scripts-to-rule-them-all. Its test, lint, fmt, fmt-check, build, run and clean implementations now live in `backend/script/`, and `backend/Makefile` is thin shims. The backend is its own project (own module, README, LICENSE, linter config, Dockerfile stage), and `Dockerfile.backend` only copies `backend/` into its builder, so its scripts have to live under `backend/`. - The root `script/test`, `script/lint`, `script/fmt` and `script/fmt-check` now run the frontend step and then the matching `backend/script/*` step, so `script/check` — and therefore the pre-commit hook — gates both halves. The frontend-only steps moved into `script/frontend-*` so nothing is duplicated. - `script/bootstrap` now provisions the backend's toolchain as well, because widening the gate without widening bootstrap left the documented fresh-clone path (`make setup`) installing a pre-commit hook that rejected every commit with `golangci-lint: not found`. golangci-lint is installed at exactly `2.7.2`, the version `Dockerfile.backend` pins, so local findings match CI. Go is reused only when the installed version falls inside a window — at least `backend/go.mod`'s floor, and no newer in major.minor than the Go the pinned linter was built with — otherwise `go1.25.7` is installed. The upper bound is load-bearing: golangci-lint links `go/types` from its own build toolchain, so the pinned `2.7.2` (built with `go1.25.4`) panics with "file requires newer Go version go1.26" against a host Go 1.26, which would leave `make setup` exiting 0 and every commit rejected. Both tools come from a specific release archive whose sha256 is hardcoded here and verified before anything is unpacked — never an install script piped to a shell — and both are symlinked onto `PATH`, since nvm-style activation does not reach `make` or the git hook. - `script/bootstrap` links only into `~/.local/bin` and never into a system-wide prefix. `/usr/local/bin` is shared with other users and with a package manager — on an Intel Mac it is the Homebrew prefix — and pointing an entry there at one user's `$HOME` breaks it for everyone else. It also refuses, non-zero, to replace anything it did not create: only a symlink already pointing into its own toolchain directory is overwritten, so a pre-existing binary is reported rather than deleted. `corepack enable` is given `--install-directory` so its four shims (`yarn`, `yarnpkg`, `pnpm`, `pnpx`) land inside that same toolchain directory instead of beside the corepack binary, and only `yarn` is linked onto `PATH`. - `script/bootstrap` exits non-zero when it cannot guarantee the pinned toolchain is the one the gate will run. Reporting success while knowing a different linter or a newer Go precedes `~/.local/bin` is the same defect this commit exists to remove, so the final step re-resolves `go`, `gofmt`, `golangci-lint`, `node` and `yarn` against the caller's own `PATH` and fails with what it found and how to fix it. - `script/frontend-check` is the frontend half of the gate, exposed as the `frontend-check` target, for the frontend Dockerfile: its build stage is a node image with no Go toolchain. The backend half is gated by `Dockerfile.backend`, and `script/cibuild` builds both images, so the two Dockerfiles together still gate the whole repo. The `backend-check` target is the mirror of it. Both targets are named after the script they shim, like every other target. - `script/cibuild` builds both images through one `build_image` helper, and the Gitea workflow's only build step is `script/cibuild`; the raw `docker build -f Dockerfile.backend .` is gone from the workflow. `script/docker` likewise builds and tags both images. - `backend/Makefile`'s `hooks` target is removed. It wrote the same `.git/hooks/pre-commit` as `script/install-precommit`, so the two clobbered each other and the developer silently ended up gating on only one half of the repo. `script/install-precommit` is now the only installer, and the hook it writes runs the repo-wide `script/check`. - `backend/Makefile`'s `docker` target is removed too: the backend image builds from the repo root with a root-level Dockerfile, so it belongs to the root `script/docker` and `script/cibuild` rather than to a backend script that would have to reach outside `backend/`. - `backend/script/lint` verifies that `.golangci.yml` still matches its pinned sha256 before running the linter. Offline hash comparison, no network. The pin is marked provisional in the file: it is the config currently on `main`, and the comment names PR #31 and the canonical hash that must replace it when #31 lands. - Every script locates the repo root with the mandated `$(cd "$(dirname "$0")/.." && pwd -P)` idiom, `cd`s there, and calls siblings as `"$ROOT/script/<name>"`; the `SCRIPT_DIR` variant is gone. READMEs at the root and in `backend/` document every script, the backend's Getting Started separates commands run from `backend/` from those run at the repo root, and `TODO.md` records the change. |
||
|
|
8ca57746df |
Move backend Dockerfile to repo root for git access
check / check (push) Successful in 24s
Place the backend Dockerfile at repo root as Dockerfile.backend so the build context includes .git, giving git describe access for version stamping. Fix .gitignore pattern to anchor /netwatch-server so it does not exclude cmd/netwatch-server/. Remove .git from .dockerignore. Update CI workflow and backend Makefile docker target. |
||
|
|
b57afeddbd |
Add backend with buffered zstd-compressed report storage
Introduce the Go backend (netwatch-server) with an HTTP API that accepts telemetry reports and persists them as zstd-compressed JSONL files. Reports are buffered in memory and flushed to disk when the buffer reaches 10 MiB or every 60 seconds. |