Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
fc720bfeee | ||
|
|
a7dfbf4414 |
+4
-8
@@ -13,12 +13,9 @@ RUN go mod download
|
||||
# Copy source code
|
||||
COPY . .
|
||||
|
||||
# Run formatting check and linter. The linter is invoked directly, not
|
||||
# via `make lint`: `make lint` now builds Dockerfile.lint, and there is
|
||||
# no Docker inside a Docker build. This is the same linter, image, and
|
||||
# config that Dockerfile.lint and script/lint run.
|
||||
# Run formatting check and linter
|
||||
RUN make fmt-check
|
||||
RUN golangci-lint run --config .golangci.yml ./...
|
||||
RUN make lint
|
||||
|
||||
# Build stage
|
||||
# golang:1.25.4-alpine, 2026-02-25
|
||||
@@ -70,9 +67,8 @@ RUN adduser -D -H -s /sbin/nologin pixad && \
|
||||
mkdir -p /var/lib/pixa /etc/pixa && \
|
||||
chown pixad:pixad /var/lib/pixa
|
||||
|
||||
# Copy the image config; signing_key comes from PIXA_SIGNING_KEY.
|
||||
# Mount a file over /etc/pixa/config.yml to override anything else.
|
||||
COPY config.docker.yml /etc/pixa/config.yml
|
||||
# Copy default config (edit signing_key before use)
|
||||
COPY config.example.yml /etc/pixa/config.yml
|
||||
|
||||
USER pixad
|
||||
WORKDIR /var/lib/pixa
|
||||
|
||||
@@ -1,41 +0,0 @@
|
||||
# Dockerfile.lint: the one and only path that runs golangci-lint.
|
||||
#
|
||||
# golangci-lint is never installed on the host; it runs only inside this
|
||||
# build. A clean build of this file therefore IS a clean lint over the
|
||||
# whole tree. It runs the same linter and config as Dockerfile's lint
|
||||
# stage, pinned to the same image so the two cannot drift to different
|
||||
# linter versions.
|
||||
#
|
||||
# golangci/golangci-lint:v2.12.2-alpine, 2026-08-07
|
||||
FROM golangci/golangci-lint:v2.12.2-alpine@sha256:91b27804074a0bacea298707f016911e60cf0cdbc6c7bf5ccacb5f0606d18d60
|
||||
|
||||
# pixa is CGO/libvips: the type-aware linters compile every package, so
|
||||
# this image needs the same C libraries the build does.
|
||||
RUN apk add --no-cache build-base vips-dev libheif-dev pkgconfig
|
||||
|
||||
WORKDIR /src
|
||||
|
||||
# Modules first for layer caching; go.mod/go.sum settle this layer's
|
||||
# result, so it may safely be reused between runs.
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
COPY . .
|
||||
|
||||
# Caching is deliberately waived for the lint step: an unchanged tree
|
||||
# must still run the linter, not return a cached success in well under a
|
||||
# second having linted nothing. CACHEBUST carries a value that differs
|
||||
# on every run (script/lint supplies it and refuses to build without
|
||||
# one). The lint RUN below references it, so BuildKit cannot serve that
|
||||
# step from cache. Keep the ${CACHEBUST} reference on that step: dropping
|
||||
# it lets the linter cache again and report a green that linted nothing.
|
||||
ARG CACHEBUST
|
||||
RUN test -n "${CACHEBUST}" || { \
|
||||
echo "Dockerfile.lint requires the CACHEBUST build-arg; build it via script/lint." >&2; \
|
||||
exit 1; }
|
||||
|
||||
# `golangci-lint config verify` is deliberately not run: it fetches its
|
||||
# JSON schema over an unpinned live HTTPS call, which REPO_POLICIES.md
|
||||
# forbids for external references.
|
||||
RUN echo "pixa-lint: running golangci-lint (${CACHEBUST})" && \
|
||||
golangci-lint run --config .golangci.yml ./...
|
||||
@@ -10,7 +10,7 @@ ifdef HAS_PKGCONFIG
|
||||
NIX_RUN_PREFIX =
|
||||
NIX_RUN_SUFFIX =
|
||||
else
|
||||
NIX_RUN_PREFIX = nix-shell -p pkg-config vips libheif git --run '
|
||||
NIX_RUN_PREFIX = nix-shell -p pkg-config vips libheif golangci-lint git --run '
|
||||
NIX_RUN_SUFFIX = '
|
||||
endif
|
||||
|
||||
|
||||
@@ -15,25 +15,14 @@ git clone https://git.eeqj.de/sneak/pixa.git
|
||||
cd pixa
|
||||
make build
|
||||
|
||||
# run with a config file: copy the example and set a real signing key
|
||||
# (the example placeholder is refused at startup), e.g. with
|
||||
# openssl rand -base64 32
|
||||
cp config.example.yml config.yml
|
||||
$EDITOR config.yml # replace the signing_key placeholder
|
||||
./bin/pixad --config config.yml
|
||||
# run with a config file
|
||||
./bin/pixad --config config.example.yml
|
||||
|
||||
# or build and run via Docker
|
||||
make docker
|
||||
docker run -p 8080:8080 -e PIXA_SIGNING_KEY="$(openssl rand -base64 32)" pixa:latest
|
||||
docker run -p 8080:8080 pixad:latest
|
||||
```
|
||||
|
||||
A container is configured two ways. The signing key comes from the
|
||||
`PIXA_SIGNING_KEY` environment variable, which the baked-in config
|
||||
reads; if it is unset the container exits at startup naming the
|
||||
variable. Everything else uses built-in defaults, so to change any
|
||||
other setting mount your own file over `/etc/pixa/config.yml` (see
|
||||
`config.example.yml` for the full set of keys).
|
||||
|
||||
## Rationale
|
||||
|
||||
Image-heavy web applications need a fast, caching reverse proxy that
|
||||
|
||||
@@ -39,17 +39,6 @@ exhaustion
|
||||
(IPv4-mapped forms covered); enforcement stays in the dial-time
|
||||
re-resolution so the DNS-rebinding window remains closed; documented in
|
||||
`README.md` and `config.example.yml`.
|
||||
- 2026-09-21 run all linting in Docker via `Dockerfile.lint` +
|
||||
`script/lint` (closes #104): `script/lint` builds a hash-pinned root
|
||||
`Dockerfile.lint`, and no host or nix-shell `golangci-lint` path
|
||||
remains (`script/bootstrap` installs no linter, and the Makefile and
|
||||
`script/test` nix-shell package lists carry only build/test deps); a
|
||||
per-run `CACHEBUST` build-arg forces the lint step to execute every
|
||||
run, so an unchanged tree cannot return a cached green that linted
|
||||
nothing; `Dockerfile`'s lint stage runs `golangci-lint` directly,
|
||||
since `make lint` now builds a container and there is no Docker inside
|
||||
a build; `golangci-lint config verify` stays out, as it fetches its
|
||||
schema over an unpinned live HTTPS call
|
||||
- 2026-09-21 http.Server hardening (closes #92): added
|
||||
`HTTPReadHeaderTimeout` (10s, bounds the slowloris header dribble) and
|
||||
`HTTPIdleTimeout` (120s, bounds keep-alive reuse) alongside the
|
||||
|
||||
@@ -1,11 +0,0 @@
|
||||
# Pixa configuration baked into the Docker image.
|
||||
#
|
||||
# The signing key is read from the PIXA_SIGNING_KEY environment
|
||||
# variable; startup aborts naming it when it is unset. Every other key
|
||||
# is omitted so its default applies. Operators who need more (an
|
||||
# allowlist, metrics, and so on) mount their own file over
|
||||
# /etc/pixa/config.yml.
|
||||
|
||||
signing_key: "${ENV:PIXA_SIGNING_KEY}"
|
||||
state_dir: /var/lib/pixa
|
||||
port: 8080
|
||||
@@ -46,12 +46,6 @@ const (
|
||||
keyBlockedNetworks = "blocked_networks"
|
||||
)
|
||||
|
||||
// placeholderSigningKey is the dummy signing_key shipped in
|
||||
// config.example.yml. It is 45 characters, so it passes the length
|
||||
// check, but it is public in this repository and must be rejected at
|
||||
// startup so no deployment ever signs URLs with it.
|
||||
const placeholderSigningKey = "CHANGE_ME_generate_with_openssl_rand_base64_32"
|
||||
|
||||
// Static validation errors. Each use site attaches the offending key
|
||||
// and value by wrapping these with fmt.Errorf and %w.
|
||||
var (
|
||||
@@ -70,9 +64,6 @@ var (
|
||||
errPortOutOfRange = errors.New("outside the valid port range")
|
||||
errTooFewConnections = errors.New("must be at least 1")
|
||||
errValueTooShort = errors.New("value too short")
|
||||
errPlaceholderKey = errors.New(
|
||||
"is the placeholder from config.example.yml; " +
|
||||
"generate a real key with: openssl rand -base64 32")
|
||||
errMustBeSetTogether = errors.New("must be set together")
|
||||
errMustNotBeNegative = errors.New("must not be negative")
|
||||
errOverflowsInt64 = errors.New("overflows a 64-bit integer")
|
||||
@@ -364,10 +355,10 @@ func (c *Config) ensureStateDirWritable() error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// validateSigningKey checks that the signing key is present, long
|
||||
// enough, and not the public placeholder from config.example.yml. The
|
||||
// key value itself is never echoed in error messages.
|
||||
func (c *Config) validateSigningKey() error {
|
||||
// validate checks that all required configuration values are set and
|
||||
// that every value is within its valid range.
|
||||
func (c *Config) validate() error {
|
||||
// The signing key value is never echoed in error messages.
|
||||
if c.SigningKey == "" {
|
||||
return fmt.Errorf("config key %q: %w", keySigningKey, errValueRequired)
|
||||
}
|
||||
@@ -379,21 +370,6 @@ func (c *Config) validateSigningKey() error {
|
||||
keySigningKey, errValueTooShort, minKeyLength, len(c.SigningKey))
|
||||
}
|
||||
|
||||
if c.SigningKey == placeholderSigningKey {
|
||||
return fmt.Errorf("config key %q: %w", keySigningKey, errPlaceholderKey)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// validate checks that all required configuration values are set and
|
||||
// that every value is within its valid range.
|
||||
func (c *Config) validate() error {
|
||||
err := c.validateSigningKey()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
const maxPort = 65535
|
||||
if c.Port < 1 || c.Port > maxPort {
|
||||
return fmt.Errorf("config key %q: value %d is %w 1-%d",
|
||||
|
||||
@@ -303,11 +303,6 @@ func invalidHostAndCredentialCases() []abortCase {
|
||||
yaml: "signing_key: short\n",
|
||||
wantErrSubstrings: []string{keySigningKey},
|
||||
},
|
||||
{
|
||||
name: "signing_key is the documented placeholder",
|
||||
yaml: "signing_key: " + placeholderSigningKey + "\n",
|
||||
wantErrSubstrings: []string{keySigningKey},
|
||||
},
|
||||
{
|
||||
name: "signing_key missing",
|
||||
yaml: "port: 8080\n",
|
||||
|
||||
+58
-4
@@ -3,13 +3,20 @@
|
||||
# this repo. Idempotent: every install is guarded by a check so already
|
||||
# installed tools are skipped. Base tooling comes from nix, apt, brew,
|
||||
# or apk (detected in that order); assumes NOTHING is present (not git,
|
||||
# make, or go). The linter is never installed on the host: golangci-lint
|
||||
# runs only inside Dockerfile.lint (see script/lint). CGO image libraries
|
||||
# (pkg-config, vips, libheif) are installed for the govips bindings.
|
||||
# make, or go). golangci-lint is packaged in nix, brew, and apk; on apt
|
||||
# it is installed from a hash-verified GitHub release archive (never
|
||||
# curl | sh). CGO image libraries (pkg-config, vips, libheif) are
|
||||
# installed for the govips bindings.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
# Pinned versions, 2026-08-07. Never "latest"; exact versions only.
|
||||
GOLANGCI_LINT_VERSION="2.12.2"
|
||||
# sha256 of golangci-lint-2.12.2-linux-<arch>.tar.gz release archives
|
||||
GOLANGCI_LINT_SHA256_AMD64="8df580d2670fed8fa984aac0507099af8df275e665215f5c7a2ae3943893a553"
|
||||
GOLANGCI_LINT_SHA256_ARM64="44cd40a8c76c86755375adfeea52cfd3533cb43d7bd647771e0ae065e166df3a"
|
||||
|
||||
PKGMGR=""
|
||||
SUDO=""
|
||||
|
||||
@@ -50,6 +57,52 @@ missing() {
|
||||
! command -v "$1" >/dev/null 2>&1
|
||||
}
|
||||
|
||||
# verify_sha256 <file> <expected-hash>
|
||||
verify_sha256() {
|
||||
if command -v sha256sum >/dev/null 2>&1; then
|
||||
actual="$(sha256sum "$1" | cut -d' ' -f1)"
|
||||
else
|
||||
actual="$(shasum -a 256 "$1" | cut -d' ' -f1)"
|
||||
fi
|
||||
if [ "$actual" != "$2" ]; then
|
||||
echo "bootstrap: sha256 mismatch for $1" >&2
|
||||
echo " expected: $2" >&2
|
||||
echo " actual: $actual" >&2
|
||||
exit 1
|
||||
fi
|
||||
}
|
||||
|
||||
# apt has no golangci-lint package: install a pinned release archive
|
||||
# from GitHub, verified by hardcoded sha256 (never curl | sh).
|
||||
install_golangci_lint_release() {
|
||||
case "$(uname -m)" in
|
||||
x86_64) goarch="amd64"; sha="$GOLANGCI_LINT_SHA256_AMD64" ;;
|
||||
aarch64|arm64) goarch="arm64"; sha="$GOLANGCI_LINT_SHA256_ARM64" ;;
|
||||
*)
|
||||
echo "bootstrap: unsupported architecture $(uname -m)" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
if missing curl; then pkg_install curl curl curl curl; fi
|
||||
name="golangci-lint-${GOLANGCI_LINT_VERSION}-linux-${goarch}"
|
||||
tmp="$(mktemp -d)"
|
||||
curl -fsSL -o "$tmp/$name.tar.gz" \
|
||||
"https://github.com/golangci/golangci-lint/releases/download/v${GOLANGCI_LINT_VERSION}/${name}.tar.gz"
|
||||
verify_sha256 "$tmp/$name.tar.gz" "$sha"
|
||||
tar -xzf "$tmp/$name.tar.gz" -C "$tmp"
|
||||
$SUDO install -m 0755 "$tmp/$name/golangci-lint" /usr/local/bin/golangci-lint
|
||||
rm -rf "$tmp"
|
||||
}
|
||||
|
||||
ensure_golangci_lint() {
|
||||
if ! missing golangci-lint; then return 0; fi
|
||||
detect_pkgmgr
|
||||
case "$PKGMGR" in
|
||||
apt) install_golangci_lint_release ;;
|
||||
*) pkg_install golangci-lint golangci-lint golangci-lint golangci-lint ;;
|
||||
esac
|
||||
}
|
||||
|
||||
# CGO dependencies for govips (image processing)
|
||||
ensure_cgo_deps() {
|
||||
if missing pkg-config; then
|
||||
@@ -70,8 +123,9 @@ main() {
|
||||
if missing git; then pkg_install git git git git; fi
|
||||
if missing make; then pkg_install gnumake make make make; fi
|
||||
|
||||
# Go toolchain
|
||||
# Go toolchain and linter
|
||||
if missing go; then pkg_install go golang go go; fi
|
||||
ensure_golangci_lint
|
||||
|
||||
# CGO image libraries
|
||||
ensure_cgo_deps
|
||||
|
||||
+14
-46
@@ -1,55 +1,23 @@
|
||||
#!/bin/sh
|
||||
# script/lint: run golangci-lint over the whole tree.
|
||||
#
|
||||
# The linter is never installed on the host: it runs only inside the
|
||||
# Dockerfile.lint build, one way, everywhere. A clean build is a clean
|
||||
# lint. See Dockerfile.lint for why the lint step cannot be cached.
|
||||
# script/lint: run the linter. CGO dependencies (pkg-config, vips,
|
||||
# libheif) come from nix-shell when not already available (e.g. inside
|
||||
# a Docker build or an existing nix-shell).
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
|
||||
# A value no other run repeats. Dockerfile.lint folds it into the
|
||||
# lint step's cache key, so the linter re-executes every run instead
|
||||
# of an unchanged tree returning a cached success having linted
|
||||
# nothing.
|
||||
cachebust="$(date +%s)-$$"
|
||||
|
||||
tmp="$(mktemp -d "${TMPDIR:-/tmp}/pixa-lint.XXXXXX")"
|
||||
trap 'rm -rf "$tmp"' EXIT INT TERM
|
||||
|
||||
# --progress=plain so the lint step's own output reaches the log we
|
||||
# check below; --output=type=cacheonly because we want the linter's
|
||||
# verdict, not an image left in the local store. The build status
|
||||
# travels through a file: a pipeline's exit status is tee's, not the
|
||||
# build's.
|
||||
(
|
||||
set +e
|
||||
docker build \
|
||||
--progress=plain \
|
||||
--build-arg CACHEBUST="$cachebust" \
|
||||
--output=type=cacheonly \
|
||||
-f Dockerfile.lint . 2>&1
|
||||
echo "$?" >"$tmp/status"
|
||||
) | tee "$tmp/build.log"
|
||||
|
||||
status="$(cat "$tmp/status" 2>/dev/null || echo 1)"
|
||||
[ "${status:-1}" -eq 0 ] || exit "${status:-1}"
|
||||
|
||||
# The linter's start line must appear as build output, not only in
|
||||
# the build's echo of the RUN instruction. A step served from cache
|
||||
# prints the instruction and none of its output; a step that runs
|
||||
# prints a "#<n> <elapsed> ..." output line. Requiring that output
|
||||
# line means a future edit dropping the CACHEBUST reference from
|
||||
# Dockerfile.lint fails here rather than passing having linted
|
||||
# nothing.
|
||||
if ! grep -Eq '^#[0-9]+ +[0-9]+\.[0-9]+ +pixa-lint: running golangci-lint' \
|
||||
"$tmp/build.log"; then
|
||||
echo "script/lint: golangci-lint did not execute (cached step?)." >&2
|
||||
exit 1
|
||||
run_with_cgo_deps() {
|
||||
if command -v pkg-config >/dev/null 2>&1; then
|
||||
sh -c "$1"
|
||||
else
|
||||
nix-shell -p pkg-config vips libheif golangci-lint git --run "$1"
|
||||
fi
|
||||
}
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
echo "Running linter..."
|
||||
run_with_cgo_deps "golangci-lint run"
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
+1
-1
@@ -10,7 +10,7 @@ run_with_cgo_deps() {
|
||||
if command -v pkg-config >/dev/null 2>&1; then
|
||||
sh -c "$1"
|
||||
else
|
||||
nix-shell -p pkg-config vips libheif git --run "$1"
|
||||
nix-shell -p pkg-config vips libheif golangci-lint git --run "$1"
|
||||
fi
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user