#!/bin/sh
# script/lint: run golangci-lint over the whole tree. This is the only
# way the linter is run, everywhere; it is never installed on the host.
#
# Inside a container it runs the linter. Anywhere else it builds
# Dockerfile.lint, whose last step runs this script again inside that
# container.
#
# Dockerfile.lint and the Dockerfile lint stage set container=docker
# (the systemd convention for marking a container) to say where we are.
# /.dockerenv cannot: it is missing inside build steps, and present on
# hosts that are themselves containers.
set -eu

ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"

main() {
    cd "$ROOT"
    if [ "${container:-}" = docker ]; then
        # `golangci-lint config verify` is not run: it fetches its JSON
        # schema over an unpinned live HTTPS call, which REPO_POLICIES.md
        # forbids.
        echo "Running linter..."
        golangci-lint run --config .golangci.yml ./...
    else
        # A new CACHEBUST on every run means the lint step is never
        # served from cache (see Dockerfile.lint). The cacheonly output
        # leaves no image behind.
        docker build \
            --progress=plain \
            --build-arg CACHEBUST="$(date +%s)-$$" \
            --output=type=cacheonly \
            -f Dockerfile.lint .
    fi
}

main "$@"
