#!/bin/sh # script/lint: run golangci-lint over the backend. This runs inside the # lint stage of the root Dockerfile, whose digest-pinned golangci-lint # image provides the linter; nothing installs golangci-lint on the host. # From a checkout, run `make lint` at the repo root, which builds that # stage. # # .golangci.yml is standardized org-wide and must never be edited here # (REPO_POLICIES.md). Its last silent drift replaced the v2 schema with # v1 keys, which left every threshold in the file inert while the build # stayed green. So the file is first checked against the canonical # copy's sha256: a local comparison, no network, nothing unpinned. set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" # The sha256 of the org standard .golangci.yml. When that file changes in # sneak/prompts and is copied here again, this changes with it. GOLANGCI_CONFIG_SHA256="a79b63a254602a5318db5d0e9a06bc71b84bf0c1d896305229d8bfed1d1b1776" main() { cd "$ROOT" if [ ! -f .golangci.yml ]; then echo "backend/.golangci.yml is missing. Copy the org standard verbatim" >&2 echo "from https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml" >&2 exit 1 fi actual="$(sha256sum .golangci.yml | cut -d' ' -f1)" if [ -z "$actual" ]; then echo "sha256sum is missing or printed no hash, so" >&2 echo "backend/.golangci.yml could not be checked." >&2 exit 1 fi if [ "$actual" != "$GOLANGCI_CONFIG_SHA256" ]; then echo "backend/.golangci.yml does not match GOLANGCI_CONFIG_SHA256" >&2 echo "in backend/script/lint." >&2 echo " expected $GOLANGCI_CONFIG_SHA256" >&2 echo " actual $actual" >&2 echo "Compare it with the org standard," >&2 echo "https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml" >&2 echo "- If they differ, it was edited here: restore the org standard" >&2 echo " verbatim. Do not edit it." >&2 echo "- If they are the same, the org standard changed: set" >&2 echo " GOLANGCI_CONFIG_SHA256 in backend/script/lint to the actual hash." >&2 exit 1 fi golangci-lint run ./... } main "$@"