#!/bin/sh # script/lint: run golangci-lint over the whole tree. This is the only # way the linter is run, everywhere; it is never installed on the host. # # Inside a container it runs the linter. Anywhere else it builds # Dockerfile.lint, whose last step runs this script again inside that # container. # # Dockerfile.lint and the Dockerfile lint stage set container=docker # (the systemd convention for marking a container) to say where we are. # /.dockerenv cannot: it is missing inside build steps, and present on # hosts that are themselves containers. set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" main() { cd "$ROOT" if [ "${container:-}" = docker ]; then # `golangci-lint config verify` is not run: it fetches its JSON # schema over an unpinned live HTTPS call, which REPO_POLICIES.md # forbids. echo "Running linter..." golangci-lint run --config .golangci.yml ./... else # A new CACHEBUST on every run means the lint step is never # served from cache (see Dockerfile.lint). The cacheonly output # leaves no image behind. docker build \ --progress=plain \ --build-arg CACHEBUST="$(date +%s)-$$" \ --output=type=cacheonly \ -f Dockerfile.lint . fi } main "$@"