check / check (push) Successful in 12s
make lint calls script/lint, the only way golangci-lint is run. Inside a container it runs the linter; anywhere else it builds Dockerfile.lint, whose last step runs script/lint again. Both Dockerfiles set container=docker to mark the container, since /.dockerenv is missing in build steps and present on hosts that are themselves containers. The Dockerfile lint stage runs make lint. A new CACHEBUST build-arg on every run keeps the lint step from being served from cache; a tmpfs mount keeps Go's and golangci-lint's caches out of that step's layer, so runs do not pile up build cache. script/bootstrap and the nix-shell package lists no longer carry golangci-lint. golangci-lint config verify is not run: it fetches its schema over an unpinned live HTTPS call. Model: opus-4-8 (implementation); opus-5-5 (rework)
38 lines
1.3 KiB
Bash
Executable File
38 lines
1.3 KiB
Bash
Executable File
#!/bin/sh
|
|
# script/lint: run golangci-lint over the whole tree. This is the only
|
|
# way the linter is run, everywhere; it is never installed on the host.
|
|
#
|
|
# Inside a container it runs the linter. Anywhere else it builds
|
|
# Dockerfile.lint, whose last step runs this script again inside that
|
|
# container.
|
|
#
|
|
# Dockerfile.lint and the Dockerfile lint stage set container=docker
|
|
# (the systemd convention for marking a container) to say where we are.
|
|
# /.dockerenv cannot: it is missing inside build steps, and present on
|
|
# hosts that are themselves containers.
|
|
set -eu
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
|
|
|
main() {
|
|
cd "$ROOT"
|
|
if [ "${container:-}" = docker ]; then
|
|
# `golangci-lint config verify` is not run: it fetches its JSON
|
|
# schema over an unpinned live HTTPS call, which REPO_POLICIES.md
|
|
# forbids.
|
|
echo "Running linter..."
|
|
golangci-lint run --config .golangci.yml ./...
|
|
else
|
|
# A new CACHEBUST on every run means the lint step is never
|
|
# served from cache (see Dockerfile.lint). The cacheonly output
|
|
# leaves no image behind.
|
|
docker build \
|
|
--progress=plain \
|
|
--build-arg CACHEBUST="$(date +%s)-$$" \
|
|
--output=type=cacheonly \
|
|
-f Dockerfile.lint .
|
|
fi
|
|
}
|
|
|
|
main "$@"
|