1 Commits

Author SHA1 Message Date
clawbot
b100814f8e build: unify the gate so root make check covers the backend (closes #16)
All checks were successful
check / check (push) Successful in 29s
Root `make check` only ever ran the frontend, so the "main is always
green" policy was satisfied vacuously: the Go backend could be entirely
broken and the root gate stayed green.

- The backend moves onto scripts-to-rule-them-all. Its test, lint, fmt,
  fmt-check, build, run and clean implementations now live in
  `backend/script/`, and `backend/Makefile` is thin shims. The backend
  is its own project (own module, README, LICENSE, linter config,
  Dockerfile stage), and `Dockerfile.backend` only copies `backend/`
  into its builder, so its scripts have to live under `backend/`.
- The root `script/test`, `script/lint`, `script/fmt` and
  `script/fmt-check` now run the frontend step and then the matching
  `backend/script/*` step, so `script/check` — and therefore the
  pre-commit hook — gates both halves. The frontend-only steps moved
  into `script/frontend-*` so nothing is duplicated.
- `script/bootstrap` now provisions the backend's toolchain as well,
  because widening the gate without widening bootstrap left the
  documented fresh-clone path (`make setup`) installing a pre-commit
  hook that rejected every commit with `golangci-lint: not found`. Go
  is reused when the installed version is new enough, otherwise it is
  installed from the official `go1.25.7` release archive; golangci-lint
  is installed at exactly `2.7.2`, the version `Dockerfile.backend`
  pins, so local findings match CI. Both come from a specific release
  archive whose sha256 is hardcoded here and verified before anything
  is unpacked — never an install script piped to a shell — and both are
  symlinked onto `PATH`, since nvm-style activation does not reach
  `make` or the git hook.
- `script/frontend-check` is the frontend half of the gate, exposed as
  the `frontend-check` target, for the frontend Dockerfile: its build
  stage is a node image with no Go toolchain. The backend half is gated
  by `Dockerfile.backend`, and `script/cibuild` builds both images, so
  the two Dockerfiles together still gate the whole repo. The
  `backend-check` target is the mirror of it. Both targets are named
  after the script they shim, like every other target.
- `script/cibuild` builds both images through one `build_image` helper,
  and the Gitea workflow's only build step is `script/cibuild`; the raw
  `docker build -f Dockerfile.backend .` is gone from the workflow.
  `script/docker` likewise builds and tags both images.
- `backend/Makefile`'s `hooks` target is removed. It wrote the same
  `.git/hooks/pre-commit` as `script/install-precommit`, so the two
  clobbered each other and the developer silently ended up gating on
  only one half of the repo. `script/install-precommit` is now the only
  installer, and the hook it writes runs the repo-wide `script/check`.
- `backend/Makefile`'s `docker` target is removed too: the backend image
  builds from the repo root with a root-level Dockerfile, so it belongs
  to the root `script/docker` and `script/cibuild` rather than to a
  backend script that would have to reach outside `backend/`.
- `backend/script/lint` verifies that `.golangci.yml` still matches its
  pinned sha256 before running the linter. Offline hash comparison, no
  network. The pin is marked provisional in the file: it is the config
  currently on `main`, and the comment names PR #31 and the canonical
  hash that must replace it when #31 lands.
- Every script locates the repo root with the mandated
  `$(cd "$(dirname "$0")/.." && pwd -P)` idiom, `cd`s there, and calls
  siblings as `"$ROOT/script/<name>"`; the `SCRIPT_DIR` variant is gone.

READMEs at the root and in `backend/` document every script, the
backend's Getting Started separates commands run from `backend/` from
those run at the repo root, and `TODO.md` records the change.
2026-08-09 06:34:04 +00:00
32 changed files with 695 additions and 125 deletions

View File

@@ -6,5 +6,6 @@ jobs:
steps: steps:
# actions/checkout v4.2.2, 2026-02-22 # actions/checkout v4.2.2, 2026-02-22
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
# script/cibuild builds both images; it is the only build
# step, so how the repo builds stays defined in script/.
- run: script/cibuild - run: script/cibuild
- run: docker build -f Dockerfile.backend .

25
.gitignore vendored
View File

@@ -1,27 +1,4 @@
# OS
.DS_Store
Thumbs.db
# Editors
*.swp
*.swo
*~
*.bak
.idea/
.vscode/
*.sublime-*
# Node
node_modules/ node_modules/
# Environment / secrets
.env
.env.*
*.pem
*.key
# Build output
dist/ dist/
.DS_Store
# Logs
*.log *.log

View File

@@ -5,10 +5,14 @@ COPY package.json yarn.lock ./
RUN yarn install --frozen-lockfile RUN yarn install --frozen-lockfile
RUN apk add --no-cache git make RUN apk add --no-cache git make
COPY . . COPY . .
# make check runs script/check (test + lint + fmt-check); its test step # make frontend-check runs script/frontend-check (test + lint +
# is the production yarn build, so this both produces dist/ and gates the # fmt-check for the frontend); its test step is the production yarn
# image on lint/fmt-check/test regressions, not merely a broken build. # build, so this both produces dist/ and gates the image on
RUN make check # lint/fmt-check/test regressions, not merely a broken build. It is the
# frontend half of `make check` rather than all of it because this stage
# is a node image with no Go toolchain; the backend half is gated by
# Dockerfile.backend, and script/cibuild builds both images.
RUN make frontend-check
# nginx:stable-alpine as of 2026-02-22 # nginx:stable-alpine as of 2026-02-22
FROM nginx@sha256:15e96e59aa3b0aada3a121296e3bce117721f42d88f5f64217ef4b18f458c6ab FROM nginx@sha256:15e96e59aa3b0aada3a121296e3bce117721f42d88f5f64217ef4b18f458c6ab

View File

@@ -1,8 +1,10 @@
.PHONY: bootstrap setup dev test lint fmt fmt-check check docker hooks .PHONY: bootstrap setup dev test lint fmt fmt-check check frontend-check \
backend-check docker hooks
# Standard targets are thin shims; the implementations live in script/ # Standard targets are thin shims; the implementations live in script/
# per the scripts-to-rule-them-all pattern (see the Entrypoints section # per the scripts-to-rule-them-all pattern (see the Entrypoints section
# of README.md). # of README.md). test, lint, fmt, fmt-check and check all cover the
# whole repo: the frontend at the root and the Go backend in backend/.
bootstrap: bootstrap:
@script/bootstrap @script/bootstrap
@@ -28,6 +30,15 @@ fmt-check:
check: check:
@script/check @script/check
# Half-repo gates. Used by the two Dockerfiles, whose build stages only
# have the toolchain for their own half; prefer `make check` otherwise.
# Each is named after the script it shims, like every other target here.
frontend-check:
@script/frontend-check
backend-check:
@backend/script/check
docker: docker:
@script/docker @script/docker

View File

@@ -28,23 +28,62 @@ docker run -p 8080:8080 netwatch
This repository adheres to the This repository adheres to the
[Scripts to Rule Them All](https://github.com/github/scripts-to-rule-them-all) [Scripts to Rule Them All](https://github.com/github/scripts-to-rule-them-all)
standard: normalized scripts in `script/` are the entrypoints for the standard: normalized scripts in `script/` are the entrypoints for the
development workflow, and the Makefile targets are thin shims that call them. We development workflow, and the Makefile targets are thin shims that call them.
provide:
- `script/bootstrap` — install all dependencies (pinned node via nvm if needed, The repo holds two projects: the frontend at the repo root and the Go backend in
yarn via corepack, `yarn install --frozen-lockfile`) `backend/`, which has its own `script/` directory and its own shim Makefile. The
root scripts cover both, so `make check` at the root fails if either half is
broken. We provide:
- `script/bootstrap` — install all dependencies, assuming nothing is present:
pinned node via nvm if needed, yarn via corepack,
`yarn install --frozen-lockfile`, and the backend's toolchain — Go (reused if
already new enough) and golangci-lint at the version `Dockerfile.backend`
pins. Everything not installed by the system package manager comes from a
hash-verified release archive and is symlinked onto `PATH`, so `make check`
works in a plain shell afterwards
- `script/setup` — make a fresh clone ready for development: bootstrap plus the - `script/setup` — make a fresh clone ready for development: bootstrap plus the
git pre-commit hook git pre-commit hook
- `script/projectname` — print the project name (used for the Docker image tag) - `script/projectname` — print the project name (used for the Docker image tags)
- `script/test` — run the production build as the test (no unit tests yet) - `script/test` — run the whole repo's tests: `script/frontend-test`, then
- `script/lint` — run prettier in check mode `backend/script/test`
- `script/fmt`format all files (writes) - `script/lint`lint the whole repo: `script/frontend-lint`, then
- `script/fmt-check` — check formatting (read-only) `backend/script/lint`
- `script/check` — run test, lint, and fmt-check - `script/fmt` — format the whole repo (writes): `script/frontend-fmt`, then
- `script/docker` — build the Docker image tagged via `script/projectname` `backend/script/fmt`
- `script/cibuild` — CI entrypoint: plain `docker build .` - `script/fmt-check` — check formatting across the whole repo (read-only)
- `script/precommit` — run by the git pre-commit hook; runs `script/check` - `script/check` — run test, lint, and fmt-check; this is the repo-wide gate
- `script/install-precommit` — install the git pre-commit hook - `script/frontend-test` — the frontend's test: the production build (no unit
tests yet)
- `script/frontend-lint` — run prettier in check mode
- `script/frontend-fmt` — format everything prettier understands (writes)
- `script/frontend-fmt-check` — check prettier formatting (read-only)
- `script/frontend-check` — the frontend half of `script/check`, shimmed by
`make frontend-check` and used by `Dockerfile`, whose build stage is a node
image with no Go toolchain. Its mirror `make backend-check` shims to
`backend/script/check`
- `script/docker` — build both images, tagged via `script/projectname`:
`netwatch` from `Dockerfile` and `netwatch-server` from `Dockerfile.backend`
- `script/cibuild` — CI entrypoint: builds both images; the only build step in
the Gitea workflow
- `script/precommit` — run by the git pre-commit hook; runs `script/check`, so a
commit is gated on both halves of the repo
- `script/install-precommit` — install the git pre-commit hook; this is the
repo's only pre-commit hook installer
The backend's scripts are shimmed by `backend/Makefile` and are also called by
the root scripts above:
- `backend/script/build` — compile `netwatch-server` with version and
architecture stamped in
- `backend/script/test` — run the Go tests under a 30-second timeout
- `backend/script/lint` — assert `.golangci.yml` still matches its pinned
sha256, then run golangci-lint
- `backend/script/fmt` — format the Go sources (writes)
- `backend/script/fmt-check` — check Go formatting (read-only)
- `backend/script/check` — run the backend's test, lint, and fmt-check
- `backend/script/run` — build and run the server locally
- `backend/script/clean` — remove build artifacts
## Rationale ## Rationale

14
TODO.md
View File

@@ -22,13 +22,13 @@ files, so merging it also closes most compliance gaps.
# Completed Steps # Completed Steps
- 2026-08-09: dotfile compliance — lifted `backend/.editorconfig` to the repo - 2026-08-09: unified the gate: the root `make check` now covers the Go backend
root so `root = true` covers the frontend too, and replaced `.gitignore` with as well as the frontend, the backend moved onto scripts-to-rule-them-all
the org model (OS, editor, node, and environment/secrets sections) plus this (`backend/script/*` with `backend/Makefile` as thin shims), the duplicate
repo's `dist/` and `*.log`. `.env`, `.env.*`, `*.pem`, and `*.key` are now pre-commit hook installer in `backend/Makefile` was removed, `script/cibuild`
ignored repo-wide, not just under `backend/`. Excluding `.git` from now builds both images as the workflow's only build step, and
`.dockerignore` stays deferred: both images read git metadata at build time `script/bootstrap` provisions the backend toolchain (pinned, hash-verified Go
(`COPY .git` in `Dockerfile.backend`, `git rev-parse` in `vite.config.js`) and golangci-lint) so a fresh clone can pass the widened gate
- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints, Makefile - 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints, Makefile
shims, README Entrypoints section shims, README Entrypoints section
- 2026-02-27: backend with buffered zstd-compressed report storage; CI workflow - 2026-02-27: backend with buffered zstd-compressed report storage; CI workflow

View File

@@ -1,53 +1,38 @@
UNAME_S := $(shell uname -s) # Standard targets are thin shims; the implementations live in
VERSION := $(shell git describe --always --dirty) # backend/script/ per the scripts-to-rule-them-all pattern (see the
BUILDARCH := $(shell uname -m) # Entrypoints section of README.md).
BINARY := netwatch-server #
# There is no `hooks` target here: the repo has exactly one pre-commit
# hook installer, the root `script/install-precommit`, and the hook it
# installs gates both halves of the repo. There is no `docker` target
# either: the backend image is built from Dockerfile.backend with the
# repo root as its context, so it belongs to the root `make docker` and
# `script/cibuild`.
GOLDFLAGS += -X main.Version=$(VERSION) .PHONY: all build test lint fmt fmt-check check run clean
GOLDFLAGS += -X main.Buildarch=$(BUILDARCH)
ifeq ($(UNAME_S),Darwin)
GOFLAGS := -ldflags "$(GOLDFLAGS)"
else
GOFLAGS = -ldflags "-linkmode external -extldflags -static $(GOLDFLAGS)"
endif
.PHONY: all build test lint fmt fmt-check check docker hooks run clean
all: build all: build
build: ./$(BINARY) build:
@script/build
./$(BINARY): $(shell find . -name '*.go' -type f) go.mod go.sum
go build -o $@ $(GOFLAGS) ./cmd/netwatch-server/
test: test:
timeout 30 go test ./... @script/test
lint: lint:
golangci-lint run ./... @script/lint
fmt: fmt:
go fmt ./... @script/fmt
fmt-check: fmt-check:
@test -z "$$(gofmt -l .)" || \ @script/fmt-check
(echo "Files not formatted:"; gofmt -l .; exit 1)
check: test lint fmt-check check:
@script/check
docker: run:
timeout 300 docker build -t netwatch-server -f ../Dockerfile.backend .. @script/run
hooks:
@printf '#!/bin/sh\ncd backend && make check\n' > \
$$(git rev-parse --show-toplevel)/.git/hooks/pre-commit
@chmod +x \
$$(git rev-parse --show-toplevel)/.git/hooks/pre-commit
@echo "Pre-commit hook installed"
run: build
./$(BINARY)
clean: clean:
rm -f ./$(BINARY) @script/clean

View File

@@ -4,18 +4,54 @@ SPA and persists them as zstd-compressed JSONL files on disk.
## Getting Started ## Getting Started
From this directory (`backend/`):
```bash ```bash
# Build and run locally # Build and run locally
make run make run
# Run tests, lint, and format check # Run the backend's tests, lint, and format check
make check make check
```
# Docker From the repo root, one directory up — `Dockerfile.backend` lives there and its
docker build -t netwatch-server . build context is the repo root, so there is no `docker` target here:
```bash
# Build both images, including netwatch-server
make docker
# Run the backend image
docker run -p 8080:8080 netwatch-server docker run -p 8080:8080 netwatch-server
``` ```
## Entrypoints
This project follows the same
[Scripts to Rule Them All](https://github.com/github/scripts-to-rule-them-all)
pattern as the repo root: the implementations live in `backend/script/` and the
targets in `backend/Makefile` are thin shims that call them. The repo root's
`script/test`, `script/lint`, `script/fmt` and `script/fmt-check` call these
too, so the root `make check` covers the backend.
- `script/build` — compile `netwatch-server` with the version and architecture
stamped in via ldflags (statically linked on Linux)
- `script/test` — run the Go tests under a 30-second timeout
- `script/lint` — assert `.golangci.yml` still matches its pinned sha256, then
run golangci-lint
- `script/fmt` — format the Go sources (writes)
- `script/fmt-check` — check Go formatting (read-only)
- `script/check` — run test, lint, and fmt-check
- `script/run` — build and run the server locally
- `script/clean` — remove build artifacts
There is deliberately no `hooks` target here: the repo has exactly one
pre-commit hook installer, the root `script/install-precommit`, and the hook it
installs runs the root `script/check`, which gates both halves of the repo.
There is no `docker` target either: `Dockerfile.backend` lives at the repo root
and builds with the repo root as its context, so the backend image is built by
the root `make docker` and by `script/cibuild`.
## Rationale ## Rationale
The NetWatch frontend collects latency measurements from the browser but has no The NetWatch frontend collects latency measurements from the browser but has no

27
backend/script/build Executable file
View File

@@ -0,0 +1,27 @@
#!/bin/sh
# script/build: compile the netwatch-server binary into the backend
# project root. Version and architecture are stamped into the binary via
# ldflags; on Linux the binary is statically linked.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
BINARY="netwatch-server"
main() {
cd "$ROOT"
# git describe fails outside a working repo (e.g. a source tarball),
# which must not abort the build.
version="$(git describe --always --dirty 2>/dev/null || echo unknown)"
buildarch="$(uname -m)"
ldflags="-X main.Version=$version -X main.Buildarch=$buildarch"
if [ "$(uname -s)" != "Darwin" ]; then
ldflags="-linkmode external -extldflags -static $ldflags"
fi
go build -o "$BINARY" -ldflags "$ldflags" ./cmd/netwatch-server/
}
main "$@"

16
backend/script/check Executable file
View File

@@ -0,0 +1,16 @@
#!/bin/sh
# script/check: run all backend checks (test, lint, fmt-check). Must not
# modify any files. The root script/check calls this, so the repo-wide
# gate covers the backend.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
"$ROOT/script/test"
"$ROOT/script/lint"
"$ROOT/script/fmt-check"
}
main "$@"

12
backend/script/clean Executable file
View File

@@ -0,0 +1,12 @@
#!/bin/sh
# script/clean: remove build artifacts.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
rm -f netwatch-server
}
main "$@"

12
backend/script/fmt Executable file
View File

@@ -0,0 +1,12 @@
#!/bin/sh
# script/fmt: format all Go sources in the backend (writes).
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
go fmt ./...
}
main "$@"

18
backend/script/fmt-check Executable file
View File

@@ -0,0 +1,18 @@
#!/bin/sh
# script/fmt-check: check Go formatting (read-only). Same scope as
# script/fmt, but fails instead of writing.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
unformatted="$(gofmt -l .)"
if [ -n "$unformatted" ]; then
echo "Files not formatted:"
echo "$unformatted"
exit 1
fi
}
main "$@"

56
backend/script/lint Executable file
View File

@@ -0,0 +1,56 @@
#!/bin/sh
# script/lint: run the Go linter over the backend.
#
# .golangci.yml is standardized org-wide and must never be edited here
# (REPO_POLICIES.md). Its last silent drift replaced the v2 schema with
# v1 keys, which left every threshold in the file inert while the build
# stayed green. This script therefore asserts the file still matches the
# pinned copy byte for byte before the linter runs. The check is a local
# hash comparison: no network, no remote schema, nothing unpinned in the
# build path.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
# sha256 of the pinned backend/.golangci.yml.
#
# PROVISIONAL. The hash below is the file currently on main, which is
# the schema-invalid v1-keyed config described above: it is pinned only
# so this branch and main stay green, NOT because it is canonical.
#
# The canonical org-wide .golangci.yml is
# 021cc83f4e6fc7c31b95b34b846723dfcf20b66b7baeea1dc40406e643346bcb,
# and PR #31 replaces backend/.golangci.yml with it. When #31 lands,
# GOLANGCI_CONFIG_SHA256 must be updated to that hash in the same
# commit. Until then, do not treat the pinned file as the standard.
GOLANGCI_CONFIG_SHA256="33ba2bf7fe4a44779d09b0fb31d6daf03685f8dc9d2bc417f963d7aabb0d17dc"
# sha256 <file>: print the file's sha256, coreutils or Darwin/busybox.
sha256() {
if command -v sha256sum >/dev/null 2>&1; then
sha256sum "$1" | cut -d' ' -f1
else
shasum -a 256 "$1" | cut -d' ' -f1
fi
}
check_config_hash() {
actual="$(sha256 .golangci.yml)"
if [ "$actual" != "$GOLANGCI_CONFIG_SHA256" ]; then
echo ".golangci.yml has drifted from the pinned config."
echo " expected $GOLANGCI_CONFIG_SHA256"
echo " actual $actual"
echo "Restore it verbatim from sneak/prompts; do not edit it."
echo "Only update GOLANGCI_CONFIG_SHA256 in this script when the"
echo "pinned config is deliberately replaced with a new standard."
exit 1
fi
}
main() {
cd "$ROOT"
check_config_hash
golangci-lint run ./...
}
main "$@"

13
backend/script/run Executable file
View File

@@ -0,0 +1,13 @@
#!/bin/sh
# script/run: build and run netwatch-server locally.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
"$ROOT/script/build"
exec ./netwatch-server "$@"
}
main "$@"

12
backend/script/test Executable file
View File

@@ -0,0 +1,12 @@
#!/bin/sh
# script/test: run the backend test suite.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
timeout 30 go test ./...
}
main "$@"

View File

@@ -5,7 +5,20 @@
# or apk (detected in that order); assumes nothing is present. Node is # or apk (detected in that order); assumes nothing is present. Node is
# used directly if installed; otherwise it is installed at a pinned # used directly if installed; otherwise it is installed at a pinned
# version via nvm (installing nvm itself first, from a hash-verified # version via nvm (installing nvm itself first, from a hash-verified
# release archive, never curl | sh). # release archive, never curl | sh). Go is used directly if it is
# already new enough, and golangci-lint is installed at the exact pinned
# version; both come from hash-verified official release archives, never
# an install script.
#
# The backend's toolchain is bootstrapped here because script/check runs
# backend/script/test and backend/script/lint, so a machine that cannot
# run go and golangci-lint cannot pass the repo-wide gate or the
# pre-commit hook that script/setup installs.
#
# Anything installed outside the system package manager is symlinked
# into a directory that is on PATH, so a later `make check` in a plain
# shell finds it. nvm only puts node on PATH for shells that source
# nvm.sh, which neither make nor the git hook does.
set -eu set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
@@ -17,9 +30,37 @@ NVM_VERSION="0.40.3"
NVM_SHA256="5f4d6aaa04a177dc93c985e31dbc411ab6b8c6e1e21d8015dbc1372625fcd1d0" NVM_SHA256="5f4d6aaa04a177dc93c985e31dbc411ab6b8c6e1e21d8015dbc1372625fcd1d0"
YARN_VERSION="1.22.22" YARN_VERSION="1.22.22"
# Go 1.25.7 (2026-08-09). This is the toolchain inside the pinned
# golang:1.25-alpine builder of Dockerfile.backend, so a local build
# uses the same compiler CI does. GO_MIN_VERSION is the floor from
# backend/go.mod; an already-installed go at or above it is used as is.
GO_VERSION="1.25.7"
GO_MIN_VERSION="1.25.5"
# golangci-lint 2.7.2 (2026-08-09). MUST stay equal to the golangci-lint
# pinned in Dockerfile.backend (currently commit
# 9f61b0f53f80672872fced07b6874397c3ed197b, which is tag v2.7.2), so a
# local `make lint` and CI's in-image `make check` report the same
# findings.
#
# Reconciliation note: PR #31 moves Dockerfile.backend to golangci-lint
# v2.12.2, commit c0d3ddc9cf3faa61a4e378e879ece580256d76e5. When that
# lands, GOLANGCI_LINT_VERSION and every hash in golangci_lint_sha256()
# below must be updated to the v2.12.2 release archives in the same
# commit, or local and CI will disagree.
GOLANGCI_LINT_VERSION="2.7.2"
# Where hash-verified archives are unpacked. Version-scoped, so bumping
# a pin installs alongside the old copy instead of half-overwriting it.
# Filled in by main() from script/projectname.
GO_DIR=""
GOLANGCI_LINT_DIR=""
PKGMGR="" PKGMGR=""
SUDO="" SUDO=""
APT_UPDATED="" APT_UPDATED=""
BIN_DIR=""
NODE_BIN=""
detect_pkgmgr() { detect_pkgmgr() {
[ -n "$PKGMGR" ] && return 0 [ -n "$PKGMGR" ] && return 0
@@ -79,6 +120,85 @@ verify_sha256() {
fi fi
} }
# fetch_verified <url> <expected-hash> <dest>: download a release
# archive and check it against a hash hardcoded in this script before
# anything is unpacked or run. Never pipe a remote script to a shell.
fetch_verified() {
if missing curl; then pkg_install curl curl curl curl; fi
curl -fsSL -o "$3" "$1"
verify_sha256 "$3" "$2"
}
# platform: <os>-<arch> as used in the Go and golangci-lint release
# archive filenames.
platform() {
plat_os="$(uname -s)"
plat_arch="$(uname -m)"
case "$plat_os" in
Linux) plat_os="linux" ;;
Darwin) plat_os="darwin" ;;
*)
echo "bootstrap: unsupported OS $plat_os" >&2
exit 1
;;
esac
case "$plat_arch" in
x86_64 | amd64) plat_arch="amd64" ;;
aarch64 | arm64) plat_arch="arm64" ;;
*)
echo "bootstrap: unsupported architecture $plat_arch" >&2
exit 1
;;
esac
echo "$plat_os-$plat_arch"
}
# ver_ge <have> <want>: succeed if dotted version <have> is at least
# <want>, comparing up to three numeric components.
ver_ge() {
awk -v have="$1" -v want="$2" '
BEGIN {
n = split(have, h, ".")
m = split(want, w, ".")
for (i = 1; i <= 3; i++) {
hv = (i <= n) ? h[i] + 0 : 0
wv = (i <= m) ? w[i] + 0 : 0
if (hv > wv) exit 0
if (hv < wv) exit 1
}
exit 0
}'
}
# ensure_bin_dir: pick the directory provisioned tools are linked into.
# /usr/local/bin when writable (root, or a Homebrew prefix), otherwise
# ~/.local/bin, which is prepended to PATH for the rest of this run and
# reported so the user can add it permanently.
ensure_bin_dir() {
[ -n "$BIN_DIR" ] && return 0
if [ -d /usr/local/bin ] && [ -w /usr/local/bin ]; then
BIN_DIR="/usr/local/bin"
else
BIN_DIR="$HOME/.local/bin"
mkdir -p "$BIN_DIR"
fi
case ":$PATH:" in
*":$BIN_DIR:"*) ;;
*)
PATH="$BIN_DIR:$PATH"
export PATH
echo "bootstrap: add $BIN_DIR to your PATH" >&2
;;
esac
}
# link_bin <target> <name>: idempotently expose one provisioned binary
# on PATH.
link_bin() {
ensure_bin_dir
ln -sfn "$1" "$BIN_DIR/$2"
}
# nvm is a bash script; run a command in a bash with nvm loaded # nvm is a bash script; run a command in a bash with nvm loaded
nvm_sh() { nvm_sh() {
bash -c ". \"\$HOME/.nvm/nvm.sh\" && $*" bash -c ". \"\$HOME/.nvm/nvm.sh\" && $*"
@@ -91,9 +211,9 @@ ensure_nvm() {
if missing curl; then pkg_install curl curl curl curl; fi if missing curl; then pkg_install curl curl curl curl; fi
if missing git; then pkg_install git git git git; fi if missing git; then pkg_install git git git git; fi
tmp="$(mktemp -d)" tmp="$(mktemp -d)"
curl -fsSL -o "$tmp/nvm.tar.gz" \ fetch_verified \
"https://github.com/nvm-sh/nvm/archive/refs/tags/v${NVM_VERSION}.tar.gz" "https://github.com/nvm-sh/nvm/archive/refs/tags/v${NVM_VERSION}.tar.gz" \
verify_sha256 "$tmp/nvm.tar.gz" "$NVM_SHA256" "$NVM_SHA256" "$tmp/nvm.tar.gz"
mkdir -p "$HOME/.nvm" mkdir -p "$HOME/.nvm"
tar -xzf "$tmp/nvm.tar.gz" -C "$HOME/.nvm" --strip-components=1 tar -xzf "$tmp/nvm.tar.gz" -C "$HOME/.nvm" --strip-components=1
rm -rf "$tmp" rm -rf "$tmp"
@@ -103,6 +223,10 @@ ensure_node() {
if ! missing node; then return 0; fi if ! missing node; then return 0; fi
ensure_nvm ensure_nvm
nvm_sh "nvm install $NODE_VERSION" nvm_sh "nvm install $NODE_VERSION"
NODE_BIN="$HOME/.nvm/versions/node/v$NODE_VERSION/bin"
for nb in node npm npx corepack; do
if [ -e "$NODE_BIN/$nb" ]; then link_bin "$NODE_BIN/$nb" "$nb"; fi
done
} }
ensure_yarn() { ensure_yarn() {
@@ -116,6 +240,9 @@ ensure_yarn() {
else else
npm install -g "yarn@$YARN_VERSION" npm install -g "yarn@$YARN_VERSION"
fi fi
if [ -n "$NODE_BIN" ] && [ -e "$NODE_BIN/yarn" ]; then
link_bin "$NODE_BIN/yarn" yarn
fi
} }
install_js_deps() { install_js_deps() {
@@ -127,9 +254,136 @@ install_js_deps() {
fi fi
} }
# go_sha256 <platform>: sha256 of
# https://go.dev/dl/go1.25.7.<platform>.tar.gz, from the signed release
# index at https://go.dev/dl/?mode=json (2026-08-09).
go_sha256() {
case "$1" in
linux-amd64)
echo "12e6d6a191091ae27dc31f6efc630e3a3b8ba409baf3573d955b196fdf086005"
;;
linux-arm64)
echo "ba611a53534135a81067240eff9508cd7e256c560edd5d8c2fef54f083c07129"
;;
darwin-amd64)
echo "bf5050a2152f4053837b886e8d9640c829dbacbc3370f913351eb0904cb706f5"
;;
darwin-arm64)
echo "ff18369ffad05c57d5bed888b660b31385f3c913670a83ef557cdfd98ea9ae1b"
;;
*)
echo "bootstrap: no pinned Go archive hash for $1" >&2
exit 1
;;
esac
}
# go_ok: an already-installed go is acceptable if it is at least
# GO_MIN_VERSION, mirroring how node is used when already present.
go_ok() {
if missing go; then return 1; fi
have="$(go version 2>/dev/null | awk '{print $3}')"
have="${have#go}"
[ -n "$have" ] || return 1
ver_ge "$have" "$GO_MIN_VERSION"
}
ensure_go() {
if go_ok; then return 0; fi
if [ ! -x "$GO_DIR/bin/go" ]; then
plat="$(platform)"
tmp="$(mktemp -d)"
fetch_verified \
"https://go.dev/dl/go${GO_VERSION}.${plat}.tar.gz" \
"$(go_sha256 "$plat")" "$tmp/go.tar.gz"
rm -rf "$GO_DIR.partial"
mkdir -p "$GO_DIR.partial"
tar -xzf "$tmp/go.tar.gz" -C "$GO_DIR.partial" --strip-components=1
rm -rf "$GO_DIR"
mv "$GO_DIR.partial" "$GO_DIR"
rm -rf "$tmp"
fi
link_bin "$GO_DIR/bin/go" go
link_bin "$GO_DIR/bin/gofmt" gofmt
}
# golangci_lint_sha256 <platform>: sha256 of the golangci-lint 2.7.2
# release archive for that platform, from
# https://github.com/golangci/golangci-lint/releases/download/v2.7.2/golangci-lint-2.7.2-checksums.txt
# (2026-08-09).
golangci_lint_sha256() {
case "$1" in
linux-amd64)
echo "ce46a1f1d890e7b667259f70bb236297f5cf8791a9b6b98b41b283d93b5b6e88"
;;
linux-arm64)
echo "7028e810837722683dab679fb121336cfa303fecff39dfe248e3e36bc18d941b"
;;
darwin-amd64)
echo "6966554840a02229a14c52641bc38c2c7a14d396f4c59ba0c7c8bb0675ca25c9"
;;
darwin-arm64)
echo "6ce86a00e22b3709f7b994838659c322fdc9eae09e263db50439ad4f6ec5785c"
;;
*)
echo "bootstrap: no pinned golangci-lint archive hash for $1" >&2
exit 1
;;
esac
}
# golangci_lint_ok: unlike go, this must be the exact pinned version.
# A different version reports a different set of findings, so local
# results would stop matching what Dockerfile.backend gates on.
golangci_lint_ok() {
if missing golangci-lint; then return 1; fi
have="$(golangci-lint version 2>&1 | awk '
{
for (i = 1; i < NF; i++) {
if ($i == "version") {
v = $(i + 1)
sub(/^v/, "", v)
print v
exit
}
}
}')"
[ "$have" = "$GOLANGCI_LINT_VERSION" ]
}
ensure_golangci_lint() {
if golangci_lint_ok; then return 0; fi
if [ ! -x "$GOLANGCI_LINT_DIR/golangci-lint" ]; then
plat="$(platform)"
base="golangci-lint-${GOLANGCI_LINT_VERSION}-${plat}"
tmp="$(mktemp -d)"
fetch_verified \
"https://github.com/golangci/golangci-lint/releases/download/v${GOLANGCI_LINT_VERSION}/${base}.tar.gz" \
"$(golangci_lint_sha256 "$plat")" "$tmp/golangci-lint.tar.gz"
mkdir -p "$tmp/x"
tar -xzf "$tmp/golangci-lint.tar.gz" -C "$tmp/x" --strip-components=1
rm -rf "$GOLANGCI_LINT_DIR.partial"
mkdir -p "$GOLANGCI_LINT_DIR.partial"
cp "$tmp/x/golangci-lint" "$GOLANGCI_LINT_DIR.partial/golangci-lint"
chmod +x "$GOLANGCI_LINT_DIR.partial/golangci-lint"
rm -rf "$GOLANGCI_LINT_DIR"
mv "$GOLANGCI_LINT_DIR.partial" "$GOLANGCI_LINT_DIR"
rm -rf "$tmp"
fi
link_bin "$GOLANGCI_LINT_DIR/golangci-lint" golangci-lint
if ! golangci_lint_ok; then
echo "bootstrap: a different golangci-lint precedes $BIN_DIR on your" >&2
echo " PATH; local lint findings may not match what CI gates on" >&2
fi
}
main() { main() {
cd "$ROOT" cd "$ROOT"
toolchain="$HOME/.local/share/$("$ROOT/script/projectname")/toolchain"
GO_DIR="$toolchain/go-$GO_VERSION"
GOLANGCI_LINT_DIR="$toolchain/golangci-lint-$GOLANGCI_LINT_VERSION"
if missing make; then pkg_install gnumake make make make; fi if missing make; then pkg_install gnumake make make make; fi
if missing git; then pkg_install git git git git; fi if missing git; then pkg_install git git git git; fi
@@ -137,6 +391,9 @@ main() {
ensure_yarn ensure_yarn
install_js_deps install_js_deps
ensure_go
ensure_golangci_lint
echo "bootstrap complete" echo "bootstrap complete"
} }

View File

@@ -1,14 +1,16 @@
#!/bin/sh #!/bin/sh
# script/check: run all checks (test, lint, fmt-check). Our own # script/check: run all checks (test, lint, fmt-check) across the whole
# extension to scripts-to-rule-them-all. Must not modify any files. # repo, frontend and backend. Our own extension to
# scripts-to-rule-them-all. Must not modify any files.
set -eu set -eu
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() { main() {
"$SCRIPT_DIR/test" cd "$ROOT"
"$SCRIPT_DIR/lint" "$ROOT/script/test"
"$SCRIPT_DIR/fmt-check" "$ROOT/script/lint"
"$ROOT/script/fmt-check"
} }
main "$@" main "$@"

View File

@@ -1,13 +1,24 @@
#!/bin/sh #!/bin/sh
# script/cibuild: run the CI build. The Dockerfile runs make check, so # script/cibuild: run the CI build. It builds every image in the repo:
# a successful build implies all checks pass. # the frontend image from Dockerfile and the backend image from
# Dockerfile.backend. Each Dockerfile runs its half of make check as a
# build step, so a successful cibuild implies the whole repo is green.
# This is the only build step the Gitea workflow runs.
set -eu set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
# build_image <dockerfile>: build one image from the repo root context.
# Every docker build CI performs goes through here, so build-wide flags
# only ever have to be added in one place.
build_image() {
timeout 300 docker build -f "$1" .
}
main() { main() {
cd "$ROOT" cd "$ROOT"
docker build . build_image Dockerfile
build_image Dockerfile.backend
} }
main "$@" main "$@"

View File

@@ -1,14 +1,16 @@
#!/bin/sh #!/bin/sh
# script/docker: build the Docker image tagged with the project name. # script/docker: build the repo's Docker images, tagged from
# The tag comes from script/projectname. # script/projectname: the frontend image as <name> and the backend image
# as <name>-server. Both build from the repo root as their context.
set -eu set -eu
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
main() { main() {
cd "$ROOT" cd "$ROOT"
timeout 300 docker build -t "$("$SCRIPT_DIR/projectname")" . name="$("$ROOT/script/projectname")"
timeout 300 docker build -t "$name" -f Dockerfile .
timeout 300 docker build -t "$name-server" -f Dockerfile.backend .
} }
main "$@" main "$@"

View File

@@ -1,12 +1,14 @@
#!/bin/sh #!/bin/sh
# script/fmt: format all files (writes). # script/fmt: format the whole repo (writes): prettier over everything
# it understands, then gofmt over the Go backend.
set -eu set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() { main() {
cd "$ROOT" cd "$ROOT"
yarn prettier --write . "$ROOT/script/frontend-fmt"
"$ROOT/backend/script/fmt"
} }
main "$@" main "$@"

View File

@@ -1,13 +1,14 @@
#!/bin/sh #!/bin/sh
# script/fmt-check: check formatting (read-only). Same scope as # script/fmt-check: check formatting across the whole repo (read-only).
# script/fmt, but fails instead of writing. # Same scope as script/fmt, but fails instead of writing.
set -eu set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() { main() {
cd "$ROOT" cd "$ROOT"
yarn prettier --check . "$ROOT/script/frontend-fmt-check"
"$ROOT/backend/script/fmt-check"
} }
main "$@" main "$@"

18
script/frontend-check Executable file
View File

@@ -0,0 +1,18 @@
#!/bin/sh
# script/frontend-check: run the frontend half of the checks only (test,
# lint, fmt-check). This exists for the frontend Dockerfile, whose build
# stage is a node image with no Go toolchain; the backend half is gated
# by Dockerfile.backend. Everywhere else, use script/check, which covers
# the whole repo. Must not modify any files.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
"$ROOT/script/frontend-test"
"$ROOT/script/frontend-lint"
"$ROOT/script/frontend-fmt-check"
}
main "$@"

14
script/frontend-fmt Executable file
View File

@@ -0,0 +1,14 @@
#!/bin/sh
# script/frontend-fmt: format the frontend and every other file prettier
# understands, repo-wide (writes). backend/ is in .prettierignore; Go
# sources are formatted by backend/script/fmt.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
yarn prettier --write .
}
main "$@"

13
script/frontend-fmt-check Executable file
View File

@@ -0,0 +1,13 @@
#!/bin/sh
# script/frontend-fmt-check: check prettier formatting (read-only). Same
# scope as script/frontend-fmt, but fails instead of writing.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
yarn prettier --check .
}
main "$@"

12
script/frontend-lint Executable file
View File

@@ -0,0 +1,12 @@
#!/bin/sh
# script/frontend-lint: run the frontend linter (prettier in check mode).
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
yarn prettier --check .
}
main "$@"

14
script/frontend-test Executable file
View File

@@ -0,0 +1,14 @@
#!/bin/sh
# script/frontend-test: run the frontend test suite. The frontend has no
# unit tests; the production build serves as the test (fails on broken
# code).
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
timeout 30 yarn build
}
main "$@"

View File

@@ -1,12 +1,14 @@
#!/bin/sh #!/bin/sh
# script/lint: run the linter (prettier in check mode). # script/lint: lint the whole repo: prettier over everything it
# understands, then golangci-lint over the Go backend.
set -eu set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() { main() {
cd "$ROOT" cd "$ROOT"
yarn prettier --check . "$ROOT/script/frontend-lint"
"$ROOT/backend/script/lint"
} }
main "$@" main "$@"

View File

@@ -3,10 +3,11 @@
# checks fail. Our own extension to scripts-to-rule-them-all. # checks fail. Our own extension to scripts-to-rule-them-all.
set -eu set -eu
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() { main() {
"$SCRIPT_DIR/check" cd "$ROOT"
"$ROOT/script/check"
} }
main "$@" main "$@"

View File

@@ -3,11 +3,12 @@
# installs dependencies and the git pre-commit hook. # installs dependencies and the git pre-commit hook.
set -eu set -eu
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() { main() {
"$SCRIPT_DIR/bootstrap" cd "$ROOT"
"$SCRIPT_DIR/install-precommit" "$ROOT/script/bootstrap"
"$ROOT/script/install-precommit"
} }
main "$@" main "$@"

View File

@@ -1,13 +1,14 @@
#!/bin/sh #!/bin/sh
# script/test: run the test suite. This repo has no unit tests; the # script/test: run the test suite for the whole repo: the frontend at
# production build serves as the test (fails on broken code). # the repo root, then the Go backend in backend/.
set -eu set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() { main() {
cd "$ROOT" cd "$ROOT"
timeout 30 yarn build "$ROOT/script/frontend-test"
"$ROOT/backend/script/test"
} }
main "$@" main "$@"