docs: trim the lint-gate comments to the traps (closes #44)

Comments and documentation only; the docker build invocation and its three
flags are byte-identical and .dockerignore's effective rules are unchanged.

script/lint and Dockerfile.lint stated how the shape was derived — why two
stages, why `golangci-lint config verify` was omitted, what earlier drafts
of the comments claimed. That is in the history. What survives is the three
traps, each of which yields a green run over an unlinted or partly linted
tree: --target and --no-cache-filter must both stay with $stage matching the
stage name in Dockerfile.lint; --target checks that the stage exists, not
that it runs golangci-lint, and halts the build there; and .dockerignore
decides what reaches the container, so excluding a self-contained Go file
drops it from the lint silently.

The TODO.md entry loses its "Hardened" and "Corrected" paragraphs, which
argued with earlier versions of themselves, and keeps the flags, the durable
property, the three unguarded seams, and the evidence that the gate was
verified rather than assumed.
This commit is contained in:
2026-08-10 13:36:58 +00:00
parent 9f079ab594
commit 6f997b8d5c
4 changed files with 37 additions and 121 deletions

View File

@@ -1,39 +1,20 @@
# Lint-only image: used by script/lint on machines where the docker
# daemon is remote (no bind mounts possible) — the repo is COPYed into
# the build context and golangci-lint runs as a build step, so a
# successful build means a clean lint.
#
# Two stages on purpose. script/lint builds with --no-cache-filter=lint so
# that the lint stage re-executes on every run, including on an unchanged
# tree (caching of the lint result is explicitly waived: a cached build
# lints nothing). Keeping `go mod download` in a separate `deps` stage
# means busting the lint stage does not also re-fetch the module cache
# over the network every time.
# Lint image, built by script/lint: golangci-lint runs as a build step, so
# a successful build is a clean lint.
# golangci/golangci-lint:v2.12.2 (Debian-based), 2026-08-07
FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS deps
WORKDIR /src
# Copy go mod files first for better layer caching
COPY go.mod go.sum ./
RUN go mod download
# This stage must stay the one that runs golangci-lint, and its name must
# match $stage in script/lint, which passes that single name to both
# --target and --no-cache-filter. Renaming here without updating script/lint
# fails the build loudly (--target rejects a name that is not in this file),
# so a mismatch cannot pass silently — but moving the lint step to another
# stage, or adding a stage after this one, would not be caught. Change the
# two files together.
# match $stage in script/lint. --target halts the build at this stage, so
# moving the lint step to another stage, or adding a stage after this one,
# is not caught.
FROM deps AS lint
# Copy source code
COPY . .
# No `golangci-lint config verify` step here, deliberately (sneak/homoicon
# has one). It resolves its JSON schema over a live, unpinned HTTPS call:
# an unpinned network input inside the one step whose whole purpose is a
# pinned, reproducible gate, and a schema-host outage would show up as a
# red build. `golangci-lint run` already fails on a malformed config.
RUN golangci-lint run --config .golangci.yml ./...