1 Commits

Author SHA1 Message Date
clawbot
4d70317d6d lint: adopt org-standard .golangci.yml and golangci-lint v2.12.2 (closes #14)
All checks were successful
check / check (push) Successful in 1m13s
backend/.golangci.yml declared version: "2" on line 1 but used the
golangci-lint v1 schema below it: a top-level linters-settings key and
an issues.exclude-use-default key that does not exist in v2. Under v2
that config does not validate, so every threshold in it was inert --
lll fell back to its 120-column default rather than the intended 88,
and funlen, cyclop and dupl were not applied at all. The `0 issues.`
result the repo has been relying on was therefore meaningless.

Replace it with the org-standard file verbatim (sha256
021cc83f4e6fc7c31b95b34b846723dfcf20b66b7baeea1dc40406e643346bcb) and
repoint the golangci-lint pin in Dockerfile.backend from v2.7.2 to the
org-standard v2.12.2.

Guard against the config drifting from the standard again by asserting
its sha256 as the first step of the backend lint target. The check is a
local hash comparison against a constant in the Makefile: it needs no
network, fetches nothing, and adds no unpinned external reference to
the build path. It also catches a strictly larger class of breakage
than schema validation would, since a schema-valid but non-canonical
config is exactly how this file got into its broken state.

With the config actually loading, lll reports server.go:65 at 93
columns. Fix it, plus the two other over-long lines called out on the
issue (server.go:97 at 81 and reportbuf.go:166 at 88) which are inside
the 88-column lint limit but over the 77-column hard wrap in the Go
styleguide. All three were long //nolint justifications on the code
line; move the justification into a preceding comment block and leave
a short directive behind. No suppression is added or widened, and
.golangci.yml is not touched after the copy.

Drop the //nolint:wsl in server.go entirely rather than relocating it.
The standard config disables wsl, so the directive suppressed nothing;
removing it still yields `0 issues.`

Verified: `cd backend && make check` reports `0 issues.` and passes
with the network unavailable, root `make check` passes, and
`docker build -f Dockerfile.backend .` builds green against the pinned
v2.12.2.
2026-08-09 02:04:06 +00:00
34 changed files with 158 additions and 722 deletions

View File

@@ -6,6 +6,5 @@ jobs:
steps:
# actions/checkout v4.2.2, 2026-02-22
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
# script/cibuild builds both images; it is the only build
# step, so how the repo builds stays defined in script/.
- run: script/cibuild
- run: docker build -f Dockerfile.backend .

View File

@@ -5,14 +5,10 @@ COPY package.json yarn.lock ./
RUN yarn install --frozen-lockfile
RUN apk add --no-cache git make
COPY . .
# make frontend-check runs script/frontend-check (test + lint +
# fmt-check for the frontend); its test step is the production yarn
# build, so this both produces dist/ and gates the image on
# lint/fmt-check/test regressions, not merely a broken build. It is the
# frontend half of `make check` rather than all of it because this stage
# is a node image with no Go toolchain; the backend half is gated by
# Dockerfile.backend, and script/cibuild builds both images.
RUN make frontend-check
# make check runs script/check (test + lint + fmt-check); its test step
# is the production yarn build, so this both produces dist/ and gates the
# image on lint/fmt-check/test regressions, not merely a broken build.
RUN make check
# nginx:stable-alpine as of 2026-02-22
FROM nginx@sha256:15e96e59aa3b0aada3a121296e3bce117721f42d88f5f64217ef4b18f458c6ab

View File

@@ -3,8 +3,8 @@ FROM golang:1.25-alpine@sha256:f6751d823c26342f9506c03797d2527668d095b0a15f1862c
RUN apk add --no-cache git make gcc musl-dev
# golangci-lint v2.7.2 (2026-02-27)
RUN CGO_ENABLED=0 go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@9f61b0f53f80672872fced07b6874397c3ed197b
# golangci-lint v2.12.2 (2026-08-09)
RUN CGO_ENABLED=0 go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@c0d3ddc9cf3faa61a4e378e879ece580256d76e5
WORKDIR /repo/backend
COPY backend/go.mod backend/go.sum ./

View File

@@ -1,10 +1,8 @@
.PHONY: bootstrap setup dev test lint fmt fmt-check check frontend-check \
backend-check docker hooks
.PHONY: bootstrap setup dev test lint fmt fmt-check check docker hooks
# Standard targets are thin shims; the implementations live in script/
# per the scripts-to-rule-them-all pattern (see the Entrypoints section
# of README.md). test, lint, fmt, fmt-check and check all cover the
# whole repo: the frontend at the root and the Go backend in backend/.
# of README.md).
bootstrap:
@script/bootstrap
@@ -30,15 +28,6 @@ fmt-check:
check:
@script/check
# Half-repo gates. Used by the two Dockerfiles, whose build stages only
# have the toolchain for their own half; prefer `make check` otherwise.
# Each is named after the script it shims, like every other target here.
frontend-check:
@script/frontend-check
backend-check:
@backend/script/check
docker:
@script/docker

View File

@@ -28,62 +28,23 @@ docker run -p 8080:8080 netwatch
This repository adheres to the
[Scripts to Rule Them All](https://github.com/github/scripts-to-rule-them-all)
standard: normalized scripts in `script/` are the entrypoints for the
development workflow, and the Makefile targets are thin shims that call them.
development workflow, and the Makefile targets are thin shims that call them. We
provide:
The repo holds two projects: the frontend at the repo root and the Go backend in
`backend/`, which has its own `script/` directory and its own shim Makefile. The
root scripts cover both, so `make check` at the root fails if either half is
broken. We provide:
- `script/bootstrap` — install all dependencies, assuming nothing is present:
pinned node via nvm if needed, yarn via corepack,
`yarn install --frozen-lockfile`, and the backend's toolchain — Go (reused if
already new enough) and golangci-lint at the version `Dockerfile.backend`
pins. Everything not installed by the system package manager comes from a
hash-verified release archive and is symlinked onto `PATH`, so `make check`
works in a plain shell afterwards
- `script/bootstrap` — install all dependencies (pinned node via nvm if needed,
yarn via corepack, `yarn install --frozen-lockfile`)
- `script/setup` — make a fresh clone ready for development: bootstrap plus the
git pre-commit hook
- `script/projectname` — print the project name (used for the Docker image tags)
- `script/test` — run the whole repo's tests: `script/frontend-test`, then
`backend/script/test`
- `script/lint`lint the whole repo: `script/frontend-lint`, then
`backend/script/lint`
- `script/fmt` — format the whole repo (writes): `script/frontend-fmt`, then
`backend/script/fmt`
- `script/fmt-check` — check formatting across the whole repo (read-only)
- `script/check` — run test, lint, and fmt-check; this is the repo-wide gate
- `script/frontend-test` — the frontend's test: the production build (no unit
tests yet)
- `script/frontend-lint` — run prettier in check mode
- `script/frontend-fmt` — format everything prettier understands (writes)
- `script/frontend-fmt-check` — check prettier formatting (read-only)
- `script/frontend-check` — the frontend half of `script/check`, shimmed by
`make frontend-check` and used by `Dockerfile`, whose build stage is a node
image with no Go toolchain. Its mirror `make backend-check` shims to
`backend/script/check`
- `script/docker` — build both images, tagged via `script/projectname`:
`netwatch` from `Dockerfile` and `netwatch-server` from `Dockerfile.backend`
- `script/cibuild` — CI entrypoint: builds both images; the only build step in
the Gitea workflow
- `script/precommit` — run by the git pre-commit hook; runs `script/check`, so a
commit is gated on both halves of the repo
- `script/install-precommit` — install the git pre-commit hook; this is the
repo's only pre-commit hook installer
The backend's scripts are shimmed by `backend/Makefile` and are also called by
the root scripts above:
- `backend/script/build` — compile `netwatch-server` with version and
architecture stamped in
- `backend/script/test` — run the Go tests under a 30-second timeout
- `backend/script/lint` — assert `.golangci.yml` still matches its pinned
sha256, then run golangci-lint
- `backend/script/fmt` — format the Go sources (writes)
- `backend/script/fmt-check` — check Go formatting (read-only)
- `backend/script/check` — run the backend's test, lint, and fmt-check
- `backend/script/run` — build and run the server locally
- `backend/script/clean` — remove build artifacts
- `script/projectname` — print the project name (used for the Docker image tag)
- `script/test` — run the production build as the test (no unit tests yet)
- `script/lint` — run prettier in check mode
- `script/fmt`format all files (writes)
- `script/fmt-check` — check formatting (read-only)
- `script/check` — run test, lint, and fmt-check
- `script/docker` — build the Docker image tagged via `script/projectname`
- `script/cibuild` — CI entrypoint: plain `docker build .`
- `script/precommit` — run by the git pre-commit hook; runs `script/check`
- `script/install-precommit` — install the git pre-commit hook
## Rationale

40
TODO.md
View File

@@ -10,30 +10,31 @@
# Status
pre-1.0. No git tags. Backend work in flight on feat/reportbuf-storage (dirty:
src/main.js). Frontend is functional; backend is new and unmerged.
pre-1.0. No git tags. `feat/reportbuf-storage` is merged; the backend, the CI
workflow, and the backend repo standard files are all on `main`. Frontend and
backend are both functional. Working toward the 1.0.0 milestone by closing the
remaining repo-compliance issues on the tracker.
# Next Step
Land feat/reportbuf-storage: finish the in-progress src/main.js change, get make
check green, and merge the branch to main. The branch adds the backend (buffered
zstd-compressed report storage), the CI workflow, and backend repo standard
files, so merging it also closes most compliance gaps.
Compliance top-up as one small commit: add an `.editorconfig` at the repo root.
`backend/.editorconfig` exists but the root has none. (The `hooks` target this
step used to also name is already present in both the root `Makefile` and
`backend/Makefile`.)
# Completed Steps
- 2026-08-09: unified the gate: the root `make check` now covers the Go backend
as well as the frontend, the backend moved onto scripts-to-rule-them-all
(`backend/script/*` with `backend/Makefile` as thin shims), the duplicate
pre-commit hook installer in `backend/Makefile` was removed, `script/cibuild`
now builds both images as the workflow's only build step, and
`script/bootstrap` provisions the backend toolchain (pinned, hash-verified Go
and golangci-lint) so a fresh clone can pass the widened gate
- 2026-08-09: adopted the org-standard `backend/.golangci.yml` verbatim and
bumped the pinned golangci-lint to v2.12.2; the previous config declared
`version: "2"` but used v1 schema keys, so every threshold in it was inert and
its green result was meaningless. `backend/Makefile`'s `lint` target now
asserts the config's sha256 against the canonical file first, so drift from
the org standard fails the build instead of silently degrading to defaults
- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints, Makefile
shims, README Entrypoints section
- 2026-02-27: backend with buffered zstd-compressed report storage; CI workflow
and backend repo standard files; backend Dockerfile fixed (Go 1.25,
golangci-lint) and moved to repo root (feat/reportbuf-storage, unmerged)
golangci-lint) and moved to repo root (feat/reportbuf-storage)
- 2026-02-26: host row layout redesigned with CSS grid; overflow and spacing
fixes; nginx config extracted; port hardcoded to 8080
- 2026-02-26: debug log panel, median stats, recovery probe, Docker build fix,
@@ -46,9 +47,12 @@ files, so merging it also closes most compliance gaps.
# Future Steps
- Compliance top-up as one small commit: add .editorconfig and add the hooks
target to the Makefile
- After merge, confirm .gitea/workflows/check.yml is on main and CI is green
(main always green policy)
- Confirm `.gitea/workflows/check.yml` is on `main` and CI is green (main always
green policy)
- Decide what to do with untracked resume.sh: commit it, gitignore it, or delete
it
- Upstream fix needed in `sneak/prompts`: the org-standard `.golangci.yml`
enables `gomodguard`, which golangci-lint v2.12.2 reports as deprecated since
v2.12.0 and replaced by `gomodguard_v2`, so every backend lint run prints a
deprecation warning. The file is standardized and must never be edited in this
repo, so nothing can be done here beyond tracking it

View File

@@ -1,5 +1,9 @@
version: "2"
# Config schema uses the golangci-lint v2 layout (settings live under
# linters.settings, not top-level linters-settings) so that the
# thresholds below are actually applied by golangci-lint >= v2.
run:
timeout: 5m
modules-download-mode: readonly
@@ -14,8 +18,7 @@ linters:
- wsl # Deprecated, replaced by wsl_v5
- wrapcheck # Too verbose for internal packages
- varnamelen # Short names like db, id are idiomatic Go
linters-settings:
settings:
lll:
line-length: 88
funlen:
@@ -27,6 +30,5 @@ linters-settings:
threshold: 100
issues:
exclude-use-default: false
max-issues-per-linter: 0
max-same-issues: 0

View File

@@ -1,38 +1,71 @@
# Standard targets are thin shims; the implementations live in
# backend/script/ per the scripts-to-rule-them-all pattern (see the
# Entrypoints section of README.md).
#
# There is no `hooks` target here: the repo has exactly one pre-commit
# hook installer, the root `script/install-precommit`, and the hook it
# installs gates both halves of the repo. There is no `docker` target
# either: the backend image is built from Dockerfile.backend with the
# repo root as its context, so it belongs to the root `make docker` and
# `script/cibuild`.
UNAME_S := $(shell uname -s)
VERSION := $(shell git describe --always --dirty)
BUILDARCH := $(shell uname -m)
BINARY := netwatch-server
.PHONY: all build test lint fmt fmt-check check run clean
GOLDFLAGS += -X main.Version=$(VERSION)
GOLDFLAGS += -X main.Buildarch=$(BUILDARCH)
ifeq ($(UNAME_S),Darwin)
GOFLAGS := -ldflags "$(GOLDFLAGS)"
SHA256SUM := shasum -a 256
else
GOFLAGS = -ldflags "-linkmode external -extldflags -static $(GOLDFLAGS)"
SHA256SUM := sha256sum
endif
# .golangci.yml is standardized org-wide and must never be edited here
# (REPO_POLICIES.md). Its last silent drift replaced the v2 schema with
# v1 keys, which left every threshold in the file inert while the build
# stayed green. The lint target therefore asserts the file still matches
# the canonical copy byte for byte. The check is a local hash comparison:
# no network, no remote schema, nothing unpinned in the build path.
GOLANGCI_CONFIG_SHA256 := 021cc83f4e6fc7c31b95b34b846723dfcf20b66b7baeea1dc40406e643346bcb
.PHONY: all build test lint fmt fmt-check check docker hooks run clean
all: build
build:
@script/build
build: ./$(BINARY)
./$(BINARY): $(shell find . -name '*.go' -type f) go.mod go.sum
go build -o $@ $(GOFLAGS) ./cmd/netwatch-server/
test:
@script/test
timeout 30 go test ./...
lint:
@script/lint
@actual=$$($(SHA256SUM) .golangci.yml | cut -d' ' -f1); \
if [ "$$actual" != "$(GOLANGCI_CONFIG_SHA256)" ]; then \
echo ".golangci.yml has drifted from the org standard."; \
echo " expected $(GOLANGCI_CONFIG_SHA256)"; \
echo " actual $$actual"; \
echo "Restore it verbatim from sneak/prompts; do not edit it."; \
exit 1; \
fi
golangci-lint run ./...
fmt:
@script/fmt
go fmt ./...
fmt-check:
@script/fmt-check
@test -z "$$(gofmt -l .)" || \
(echo "Files not formatted:"; gofmt -l .; exit 1)
check:
@script/check
check: test lint fmt-check
run:
@script/run
docker:
timeout 300 docker build -t netwatch-server -f ../Dockerfile.backend ..
hooks:
@printf '#!/bin/sh\ncd backend && make check\n' > \
$$(git rev-parse --show-toplevel)/.git/hooks/pre-commit
@chmod +x \
$$(git rev-parse --show-toplevel)/.git/hooks/pre-commit
@echo "Pre-commit hook installed"
run: build
./$(BINARY)
clean:
@script/clean
rm -f ./$(BINARY)

View File

@@ -4,54 +4,18 @@ SPA and persists them as zstd-compressed JSONL files on disk.
## Getting Started
From this directory (`backend/`):
```bash
# Build and run locally
make run
# Run the backend's tests, lint, and format check
# Run tests, lint, and format check
make check
```
From the repo root, one directory up — `Dockerfile.backend` lives there and its
build context is the repo root, so there is no `docker` target here:
```bash
# Build both images, including netwatch-server
make docker
# Run the backend image
# Docker
docker build -t netwatch-server .
docker run -p 8080:8080 netwatch-server
```
## Entrypoints
This project follows the same
[Scripts to Rule Them All](https://github.com/github/scripts-to-rule-them-all)
pattern as the repo root: the implementations live in `backend/script/` and the
targets in `backend/Makefile` are thin shims that call them. The repo root's
`script/test`, `script/lint`, `script/fmt` and `script/fmt-check` call these
too, so the root `make check` covers the backend.
- `script/build` — compile `netwatch-server` with the version and architecture
stamped in via ldflags (statically linked on Linux)
- `script/test` — run the Go tests under a 30-second timeout
- `script/lint` — assert `.golangci.yml` still matches its pinned sha256, then
run golangci-lint
- `script/fmt` — format the Go sources (writes)
- `script/fmt-check` — check Go formatting (read-only)
- `script/check` — run test, lint, and fmt-check
- `script/run` — build and run the server locally
- `script/clean` — remove build artifacts
There is deliberately no `hooks` target here: the repo has exactly one
pre-commit hook installer, the root `script/install-precommit`, and the hook it
installs runs the root `script/check`, which gates both halves of the repo.
There is no `docker` target either: `Dockerfile.backend` lives at the repo root
and builds with the repo root as its context, so the backend image is built by
the root `make docker` and by `script/cibuild`.
## Rationale
The NetWatch frontend collects latency measurements from the browser but has no

View File

@@ -163,7 +163,9 @@ func (b *Buffer) writeFile(data []byte) {
name := fmt.Sprintf("reports-%s.jsonl.zst", ts)
path := filepath.Join(b.dataDir, name)
f, err := os.OpenFile( //nolint:gosec // path built from controlled dataDir + timestamp
// path is built from the operator-supplied dataDir plus a
// generated timestamp, so it carries no external input.
f, err := os.OpenFile( //nolint:gosec // see comment above
path,
os.O_WRONLY|os.O_CREATE|os.O_EXCL,
filePerms,

View File

@@ -62,7 +62,10 @@ func New(
OnStart: func(_ context.Context) error {
s.startupTime = time.Now().UTC()
go func() { //nolint:contextcheck // fx OnStart ctx is startup-only; run() creates its own
// The fx OnStart context is scoped to startup and is
// cancelled once the hook returns; run() derives its
// own context instead of inheriting this one.
go func() { //nolint:contextcheck // see comment above
s.run()
}()
@@ -94,7 +97,7 @@ func (s *Server) run() {
}
func (s *Server) serve() int {
var ctx context.Context //nolint:wsl // ctx must be declared before multi-assign
var ctx context.Context
ctx, s.cancelFunc = context.WithCancel(
context.Background(),

View File

@@ -1,27 +0,0 @@
#!/bin/sh
# script/build: compile the netwatch-server binary into the backend
# project root. Version and architecture are stamped into the binary via
# ldflags; on Linux the binary is statically linked.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
BINARY="netwatch-server"
main() {
cd "$ROOT"
# git describe fails outside a working repo (e.g. a source tarball),
# which must not abort the build.
version="$(git describe --always --dirty 2>/dev/null || echo unknown)"
buildarch="$(uname -m)"
ldflags="-X main.Version=$version -X main.Buildarch=$buildarch"
if [ "$(uname -s)" != "Darwin" ]; then
ldflags="-linkmode external -extldflags -static $ldflags"
fi
go build -o "$BINARY" -ldflags "$ldflags" ./cmd/netwatch-server/
}
main "$@"

View File

@@ -1,16 +0,0 @@
#!/bin/sh
# script/check: run all backend checks (test, lint, fmt-check). Must not
# modify any files. The root script/check calls this, so the repo-wide
# gate covers the backend.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
"$ROOT/script/test"
"$ROOT/script/lint"
"$ROOT/script/fmt-check"
}
main "$@"

View File

@@ -1,12 +0,0 @@
#!/bin/sh
# script/clean: remove build artifacts.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
rm -f netwatch-server
}
main "$@"

View File

@@ -1,12 +0,0 @@
#!/bin/sh
# script/fmt: format all Go sources in the backend (writes).
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
go fmt ./...
}
main "$@"

View File

@@ -1,18 +0,0 @@
#!/bin/sh
# script/fmt-check: check Go formatting (read-only). Same scope as
# script/fmt, but fails instead of writing.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
unformatted="$(gofmt -l .)"
if [ -n "$unformatted" ]; then
echo "Files not formatted:"
echo "$unformatted"
exit 1
fi
}
main "$@"

View File

@@ -1,56 +0,0 @@
#!/bin/sh
# script/lint: run the Go linter over the backend.
#
# .golangci.yml is standardized org-wide and must never be edited here
# (REPO_POLICIES.md). Its last silent drift replaced the v2 schema with
# v1 keys, which left every threshold in the file inert while the build
# stayed green. This script therefore asserts the file still matches the
# pinned copy byte for byte before the linter runs. The check is a local
# hash comparison: no network, no remote schema, nothing unpinned in the
# build path.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
# sha256 of the pinned backend/.golangci.yml.
#
# PROVISIONAL. The hash below is the file currently on main, which is
# the schema-invalid v1-keyed config described above: it is pinned only
# so this branch and main stay green, NOT because it is canonical.
#
# The canonical org-wide .golangci.yml is
# 021cc83f4e6fc7c31b95b34b846723dfcf20b66b7baeea1dc40406e643346bcb,
# and PR #31 replaces backend/.golangci.yml with it. When #31 lands,
# GOLANGCI_CONFIG_SHA256 must be updated to that hash in the same
# commit. Until then, do not treat the pinned file as the standard.
GOLANGCI_CONFIG_SHA256="33ba2bf7fe4a44779d09b0fb31d6daf03685f8dc9d2bc417f963d7aabb0d17dc"
# sha256 <file>: print the file's sha256, coreutils or Darwin/busybox.
sha256() {
if command -v sha256sum >/dev/null 2>&1; then
sha256sum "$1" | cut -d' ' -f1
else
shasum -a 256 "$1" | cut -d' ' -f1
fi
}
check_config_hash() {
actual="$(sha256 .golangci.yml)"
if [ "$actual" != "$GOLANGCI_CONFIG_SHA256" ]; then
echo ".golangci.yml has drifted from the pinned config."
echo " expected $GOLANGCI_CONFIG_SHA256"
echo " actual $actual"
echo "Restore it verbatim from sneak/prompts; do not edit it."
echo "Only update GOLANGCI_CONFIG_SHA256 in this script when the"
echo "pinned config is deliberately replaced with a new standard."
exit 1
fi
}
main() {
cd "$ROOT"
check_config_hash
golangci-lint run ./...
}
main "$@"

View File

@@ -1,13 +0,0 @@
#!/bin/sh
# script/run: build and run netwatch-server locally.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
"$ROOT/script/build"
exec ./netwatch-server "$@"
}
main "$@"

View File

@@ -1,12 +0,0 @@
#!/bin/sh
# script/test: run the backend test suite.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
timeout 30 go test ./...
}
main "$@"

View File

@@ -5,20 +5,7 @@
# or apk (detected in that order); assumes nothing is present. Node is
# used directly if installed; otherwise it is installed at a pinned
# version via nvm (installing nvm itself first, from a hash-verified
# release archive, never curl | sh). Go is used directly if it is
# already new enough, and golangci-lint is installed at the exact pinned
# version; both come from hash-verified official release archives, never
# an install script.
#
# The backend's toolchain is bootstrapped here because script/check runs
# backend/script/test and backend/script/lint, so a machine that cannot
# run go and golangci-lint cannot pass the repo-wide gate or the
# pre-commit hook that script/setup installs.
#
# Anything installed outside the system package manager is symlinked
# into a directory that is on PATH, so a later `make check` in a plain
# shell finds it. nvm only puts node on PATH for shells that source
# nvm.sh, which neither make nor the git hook does.
# release archive, never curl | sh).
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
@@ -30,37 +17,9 @@ NVM_VERSION="0.40.3"
NVM_SHA256="5f4d6aaa04a177dc93c985e31dbc411ab6b8c6e1e21d8015dbc1372625fcd1d0"
YARN_VERSION="1.22.22"
# Go 1.25.7 (2026-08-09). This is the toolchain inside the pinned
# golang:1.25-alpine builder of Dockerfile.backend, so a local build
# uses the same compiler CI does. GO_MIN_VERSION is the floor from
# backend/go.mod; an already-installed go at or above it is used as is.
GO_VERSION="1.25.7"
GO_MIN_VERSION="1.25.5"
# golangci-lint 2.7.2 (2026-08-09). MUST stay equal to the golangci-lint
# pinned in Dockerfile.backend (currently commit
# 9f61b0f53f80672872fced07b6874397c3ed197b, which is tag v2.7.2), so a
# local `make lint` and CI's in-image `make check` report the same
# findings.
#
# Reconciliation note: PR #31 moves Dockerfile.backend to golangci-lint
# v2.12.2, commit c0d3ddc9cf3faa61a4e378e879ece580256d76e5. When that
# lands, GOLANGCI_LINT_VERSION and every hash in golangci_lint_sha256()
# below must be updated to the v2.12.2 release archives in the same
# commit, or local and CI will disagree.
GOLANGCI_LINT_VERSION="2.7.2"
# Where hash-verified archives are unpacked. Version-scoped, so bumping
# a pin installs alongside the old copy instead of half-overwriting it.
# Filled in by main() from script/projectname.
GO_DIR=""
GOLANGCI_LINT_DIR=""
PKGMGR=""
SUDO=""
APT_UPDATED=""
BIN_DIR=""
NODE_BIN=""
detect_pkgmgr() {
[ -n "$PKGMGR" ] && return 0
@@ -120,85 +79,6 @@ verify_sha256() {
fi
}
# fetch_verified <url> <expected-hash> <dest>: download a release
# archive and check it against a hash hardcoded in this script before
# anything is unpacked or run. Never pipe a remote script to a shell.
fetch_verified() {
if missing curl; then pkg_install curl curl curl curl; fi
curl -fsSL -o "$3" "$1"
verify_sha256 "$3" "$2"
}
# platform: <os>-<arch> as used in the Go and golangci-lint release
# archive filenames.
platform() {
plat_os="$(uname -s)"
plat_arch="$(uname -m)"
case "$plat_os" in
Linux) plat_os="linux" ;;
Darwin) plat_os="darwin" ;;
*)
echo "bootstrap: unsupported OS $plat_os" >&2
exit 1
;;
esac
case "$plat_arch" in
x86_64 | amd64) plat_arch="amd64" ;;
aarch64 | arm64) plat_arch="arm64" ;;
*)
echo "bootstrap: unsupported architecture $plat_arch" >&2
exit 1
;;
esac
echo "$plat_os-$plat_arch"
}
# ver_ge <have> <want>: succeed if dotted version <have> is at least
# <want>, comparing up to three numeric components.
ver_ge() {
awk -v have="$1" -v want="$2" '
BEGIN {
n = split(have, h, ".")
m = split(want, w, ".")
for (i = 1; i <= 3; i++) {
hv = (i <= n) ? h[i] + 0 : 0
wv = (i <= m) ? w[i] + 0 : 0
if (hv > wv) exit 0
if (hv < wv) exit 1
}
exit 0
}'
}
# ensure_bin_dir: pick the directory provisioned tools are linked into.
# /usr/local/bin when writable (root, or a Homebrew prefix), otherwise
# ~/.local/bin, which is prepended to PATH for the rest of this run and
# reported so the user can add it permanently.
ensure_bin_dir() {
[ -n "$BIN_DIR" ] && return 0
if [ -d /usr/local/bin ] && [ -w /usr/local/bin ]; then
BIN_DIR="/usr/local/bin"
else
BIN_DIR="$HOME/.local/bin"
mkdir -p "$BIN_DIR"
fi
case ":$PATH:" in
*":$BIN_DIR:"*) ;;
*)
PATH="$BIN_DIR:$PATH"
export PATH
echo "bootstrap: add $BIN_DIR to your PATH" >&2
;;
esac
}
# link_bin <target> <name>: idempotently expose one provisioned binary
# on PATH.
link_bin() {
ensure_bin_dir
ln -sfn "$1" "$BIN_DIR/$2"
}
# nvm is a bash script; run a command in a bash with nvm loaded
nvm_sh() {
bash -c ". \"\$HOME/.nvm/nvm.sh\" && $*"
@@ -211,9 +91,9 @@ ensure_nvm() {
if missing curl; then pkg_install curl curl curl curl; fi
if missing git; then pkg_install git git git git; fi
tmp="$(mktemp -d)"
fetch_verified \
"https://github.com/nvm-sh/nvm/archive/refs/tags/v${NVM_VERSION}.tar.gz" \
"$NVM_SHA256" "$tmp/nvm.tar.gz"
curl -fsSL -o "$tmp/nvm.tar.gz" \
"https://github.com/nvm-sh/nvm/archive/refs/tags/v${NVM_VERSION}.tar.gz"
verify_sha256 "$tmp/nvm.tar.gz" "$NVM_SHA256"
mkdir -p "$HOME/.nvm"
tar -xzf "$tmp/nvm.tar.gz" -C "$HOME/.nvm" --strip-components=1
rm -rf "$tmp"
@@ -223,10 +103,6 @@ ensure_node() {
if ! missing node; then return 0; fi
ensure_nvm
nvm_sh "nvm install $NODE_VERSION"
NODE_BIN="$HOME/.nvm/versions/node/v$NODE_VERSION/bin"
for nb in node npm npx corepack; do
if [ -e "$NODE_BIN/$nb" ]; then link_bin "$NODE_BIN/$nb" "$nb"; fi
done
}
ensure_yarn() {
@@ -240,9 +116,6 @@ ensure_yarn() {
else
npm install -g "yarn@$YARN_VERSION"
fi
if [ -n "$NODE_BIN" ] && [ -e "$NODE_BIN/yarn" ]; then
link_bin "$NODE_BIN/yarn" yarn
fi
}
install_js_deps() {
@@ -254,136 +127,9 @@ install_js_deps() {
fi
}
# go_sha256 <platform>: sha256 of
# https://go.dev/dl/go1.25.7.<platform>.tar.gz, from the signed release
# index at https://go.dev/dl/?mode=json (2026-08-09).
go_sha256() {
case "$1" in
linux-amd64)
echo "12e6d6a191091ae27dc31f6efc630e3a3b8ba409baf3573d955b196fdf086005"
;;
linux-arm64)
echo "ba611a53534135a81067240eff9508cd7e256c560edd5d8c2fef54f083c07129"
;;
darwin-amd64)
echo "bf5050a2152f4053837b886e8d9640c829dbacbc3370f913351eb0904cb706f5"
;;
darwin-arm64)
echo "ff18369ffad05c57d5bed888b660b31385f3c913670a83ef557cdfd98ea9ae1b"
;;
*)
echo "bootstrap: no pinned Go archive hash for $1" >&2
exit 1
;;
esac
}
# go_ok: an already-installed go is acceptable if it is at least
# GO_MIN_VERSION, mirroring how node is used when already present.
go_ok() {
if missing go; then return 1; fi
have="$(go version 2>/dev/null | awk '{print $3}')"
have="${have#go}"
[ -n "$have" ] || return 1
ver_ge "$have" "$GO_MIN_VERSION"
}
ensure_go() {
if go_ok; then return 0; fi
if [ ! -x "$GO_DIR/bin/go" ]; then
plat="$(platform)"
tmp="$(mktemp -d)"
fetch_verified \
"https://go.dev/dl/go${GO_VERSION}.${plat}.tar.gz" \
"$(go_sha256 "$plat")" "$tmp/go.tar.gz"
rm -rf "$GO_DIR.partial"
mkdir -p "$GO_DIR.partial"
tar -xzf "$tmp/go.tar.gz" -C "$GO_DIR.partial" --strip-components=1
rm -rf "$GO_DIR"
mv "$GO_DIR.partial" "$GO_DIR"
rm -rf "$tmp"
fi
link_bin "$GO_DIR/bin/go" go
link_bin "$GO_DIR/bin/gofmt" gofmt
}
# golangci_lint_sha256 <platform>: sha256 of the golangci-lint 2.7.2
# release archive for that platform, from
# https://github.com/golangci/golangci-lint/releases/download/v2.7.2/golangci-lint-2.7.2-checksums.txt
# (2026-08-09).
golangci_lint_sha256() {
case "$1" in
linux-amd64)
echo "ce46a1f1d890e7b667259f70bb236297f5cf8791a9b6b98b41b283d93b5b6e88"
;;
linux-arm64)
echo "7028e810837722683dab679fb121336cfa303fecff39dfe248e3e36bc18d941b"
;;
darwin-amd64)
echo "6966554840a02229a14c52641bc38c2c7a14d396f4c59ba0c7c8bb0675ca25c9"
;;
darwin-arm64)
echo "6ce86a00e22b3709f7b994838659c322fdc9eae09e263db50439ad4f6ec5785c"
;;
*)
echo "bootstrap: no pinned golangci-lint archive hash for $1" >&2
exit 1
;;
esac
}
# golangci_lint_ok: unlike go, this must be the exact pinned version.
# A different version reports a different set of findings, so local
# results would stop matching what Dockerfile.backend gates on.
golangci_lint_ok() {
if missing golangci-lint; then return 1; fi
have="$(golangci-lint version 2>&1 | awk '
{
for (i = 1; i < NF; i++) {
if ($i == "version") {
v = $(i + 1)
sub(/^v/, "", v)
print v
exit
}
}
}')"
[ "$have" = "$GOLANGCI_LINT_VERSION" ]
}
ensure_golangci_lint() {
if golangci_lint_ok; then return 0; fi
if [ ! -x "$GOLANGCI_LINT_DIR/golangci-lint" ]; then
plat="$(platform)"
base="golangci-lint-${GOLANGCI_LINT_VERSION}-${plat}"
tmp="$(mktemp -d)"
fetch_verified \
"https://github.com/golangci/golangci-lint/releases/download/v${GOLANGCI_LINT_VERSION}/${base}.tar.gz" \
"$(golangci_lint_sha256 "$plat")" "$tmp/golangci-lint.tar.gz"
mkdir -p "$tmp/x"
tar -xzf "$tmp/golangci-lint.tar.gz" -C "$tmp/x" --strip-components=1
rm -rf "$GOLANGCI_LINT_DIR.partial"
mkdir -p "$GOLANGCI_LINT_DIR.partial"
cp "$tmp/x/golangci-lint" "$GOLANGCI_LINT_DIR.partial/golangci-lint"
chmod +x "$GOLANGCI_LINT_DIR.partial/golangci-lint"
rm -rf "$GOLANGCI_LINT_DIR"
mv "$GOLANGCI_LINT_DIR.partial" "$GOLANGCI_LINT_DIR"
rm -rf "$tmp"
fi
link_bin "$GOLANGCI_LINT_DIR/golangci-lint" golangci-lint
if ! golangci_lint_ok; then
echo "bootstrap: a different golangci-lint precedes $BIN_DIR on your" >&2
echo " PATH; local lint findings may not match what CI gates on" >&2
fi
}
main() {
cd "$ROOT"
toolchain="$HOME/.local/share/$("$ROOT/script/projectname")/toolchain"
GO_DIR="$toolchain/go-$GO_VERSION"
GOLANGCI_LINT_DIR="$toolchain/golangci-lint-$GOLANGCI_LINT_VERSION"
if missing make; then pkg_install gnumake make make make; fi
if missing git; then pkg_install git git git git; fi
@@ -391,9 +137,6 @@ main() {
ensure_yarn
install_js_deps
ensure_go
ensure_golangci_lint
echo "bootstrap complete"
}

View File

@@ -1,16 +1,14 @@
#!/bin/sh
# script/check: run all checks (test, lint, fmt-check) across the whole
# repo, frontend and backend. Our own extension to
# scripts-to-rule-them-all. Must not modify any files.
# script/check: run all checks (test, lint, fmt-check). Our own
# extension to scripts-to-rule-them-all. Must not modify any files.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
main() {
cd "$ROOT"
"$ROOT/script/test"
"$ROOT/script/lint"
"$ROOT/script/fmt-check"
"$SCRIPT_DIR/test"
"$SCRIPT_DIR/lint"
"$SCRIPT_DIR/fmt-check"
}
main "$@"

View File

@@ -1,24 +1,13 @@
#!/bin/sh
# script/cibuild: run the CI build. It builds every image in the repo:
# the frontend image from Dockerfile and the backend image from
# Dockerfile.backend. Each Dockerfile runs its half of make check as a
# build step, so a successful cibuild implies the whole repo is green.
# This is the only build step the Gitea workflow runs.
# script/cibuild: run the CI build. The Dockerfile runs make check, so
# a successful build implies all checks pass.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
# build_image <dockerfile>: build one image from the repo root context.
# Every docker build CI performs goes through here, so build-wide flags
# only ever have to be added in one place.
build_image() {
timeout 300 docker build -f "$1" .
}
main() {
cd "$ROOT"
build_image Dockerfile
build_image Dockerfile.backend
docker build .
}
main "$@"

View File

@@ -1,16 +1,14 @@
#!/bin/sh
# script/docker: build the repo's Docker images, tagged from
# script/projectname: the frontend image as <name> and the backend image
# as <name>-server. Both build from the repo root as their context.
# script/docker: build the Docker image tagged with the project name.
# The tag comes from script/projectname.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
main() {
cd "$ROOT"
name="$("$ROOT/script/projectname")"
timeout 300 docker build -t "$name" -f Dockerfile .
timeout 300 docker build -t "$name-server" -f Dockerfile.backend .
timeout 300 docker build -t "$("$SCRIPT_DIR/projectname")" .
}
main "$@"

View File

@@ -1,14 +1,12 @@
#!/bin/sh
# script/fmt: format the whole repo (writes): prettier over everything
# it understands, then gofmt over the Go backend.
# script/fmt: format all files (writes).
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
"$ROOT/script/frontend-fmt"
"$ROOT/backend/script/fmt"
yarn prettier --write .
}
main "$@"

View File

@@ -1,14 +1,13 @@
#!/bin/sh
# script/fmt-check: check formatting across the whole repo (read-only).
# Same scope as script/fmt, but fails instead of writing.
# script/fmt-check: check formatting (read-only). Same scope as
# script/fmt, but fails instead of writing.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
"$ROOT/script/frontend-fmt-check"
"$ROOT/backend/script/fmt-check"
yarn prettier --check .
}
main "$@"

View File

@@ -1,18 +0,0 @@
#!/bin/sh
# script/frontend-check: run the frontend half of the checks only (test,
# lint, fmt-check). This exists for the frontend Dockerfile, whose build
# stage is a node image with no Go toolchain; the backend half is gated
# by Dockerfile.backend. Everywhere else, use script/check, which covers
# the whole repo. Must not modify any files.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
"$ROOT/script/frontend-test"
"$ROOT/script/frontend-lint"
"$ROOT/script/frontend-fmt-check"
}
main "$@"

View File

@@ -1,14 +0,0 @@
#!/bin/sh
# script/frontend-fmt: format the frontend and every other file prettier
# understands, repo-wide (writes). backend/ is in .prettierignore; Go
# sources are formatted by backend/script/fmt.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
yarn prettier --write .
}
main "$@"

View File

@@ -1,13 +0,0 @@
#!/bin/sh
# script/frontend-fmt-check: check prettier formatting (read-only). Same
# scope as script/frontend-fmt, but fails instead of writing.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
yarn prettier --check .
}
main "$@"

View File

@@ -1,12 +0,0 @@
#!/bin/sh
# script/frontend-lint: run the frontend linter (prettier in check mode).
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
yarn prettier --check .
}
main "$@"

View File

@@ -1,14 +0,0 @@
#!/bin/sh
# script/frontend-test: run the frontend test suite. The frontend has no
# unit tests; the production build serves as the test (fails on broken
# code).
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
timeout 30 yarn build
}
main "$@"

View File

@@ -1,14 +1,12 @@
#!/bin/sh
# script/lint: lint the whole repo: prettier over everything it
# understands, then golangci-lint over the Go backend.
# script/lint: run the linter (prettier in check mode).
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
"$ROOT/script/frontend-lint"
"$ROOT/backend/script/lint"
yarn prettier --check .
}
main "$@"

View File

@@ -3,11 +3,10 @@
# checks fail. Our own extension to scripts-to-rule-them-all.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
main() {
cd "$ROOT"
"$ROOT/script/check"
"$SCRIPT_DIR/check"
}
main "$@"

View File

@@ -3,12 +3,11 @@
# installs dependencies and the git pre-commit hook.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
main() {
cd "$ROOT"
"$ROOT/script/bootstrap"
"$ROOT/script/install-precommit"
"$SCRIPT_DIR/bootstrap"
"$SCRIPT_DIR/install-precommit"
}
main "$@"

View File

@@ -1,14 +1,13 @@
#!/bin/sh
# script/test: run the test suite for the whole repo: the frontend at
# the repo root, then the Go backend in backend/.
# script/test: run the test suite. This repo has no unit tests; the
# production build serves as the test (fails on broken code).
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
"$ROOT/script/frontend-test"
"$ROOT/backend/script/test"
timeout 30 yarn build
}
main "$@"