From 54014c88c83f2427504b4dafdead27e2823b1ece Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Mon, 21 Sep 2026 09:35:16 +0200 Subject: [PATCH] Run make check inside the Docker build with a pinned lint stage (closes #5) REPO_POLICIES.md requires the container build to run the checks; the Dockerfile only compiled the binary, so script/cibuild checked nothing. A new lint stage on the golangci-lint v2.7.2 image runs make fmt-check and make lint, and the build stage waits for it and then runs make test, so make docker now fails when formatting, lint or a test fails. All three base images are pinned by digest with their versions unchanged. The final image and how it starts are unchanged. make docker is now the gate to use on hosts where the installed linter is older than the Go toolchain and make lint cannot run directly. Model: opus-4-8 (implementation, review); fable-5-1 (summary) --- Dockerfile | 29 +++++++++++++++++++++++++++-- 1 file changed, 27 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index fa1460b..04e60ea 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,22 @@ +# Lint stage — fast feedback on formatting and lint issues. +# The golangci-lint image bundles Go, gcc and make, so it can run go vet on +# the CGO sqlite package and golangci-lint without extra installs. +# golangci/golangci-lint:v2.7.2 (Go 1.25.5), 2026-09-21 +FROM golangci/golangci-lint@sha256:5d6d5c70a61f1356adfd9dd6316ce286799fefc9d743421356ff1b00842368ba AS lint + +WORKDIR /src + +COPY go.mod go.sum ./ +RUN go mod download + +COPY . . + +RUN make fmt-check +RUN make lint + # Build stage -FROM golang:1.24-bookworm AS builder +# golang:1.24-bookworm, 2026-09-21 +FROM golang@sha256:1a6d4452c65dea36aac2e2d606b01b4a029ec90cc1ae53890540ce6173ea77ac AS builder # Install build dependencies (zstd for archive, gcc for CGO/sqlite3) RUN apt-get update && apt-get install -y --no-install-recommends \ @@ -10,12 +27,19 @@ RUN apt-get update && apt-get install -y --no-install-recommends \ WORKDIR /src +# Force BuildKit to run the lint stage before compiling or testing. +COPY --from=lint /src/go.sum /dev/null + # Copy everything COPY . . # Vendor dependencies (must be after copying source) RUN go mod download && go mod vendor +# Run the test suite in the build stage: -race needs cgo and the C compiler +# installed above. The suite is offline (the live-feed test is opt-in). +RUN make test + # Build the binary with CGO enabled (required for sqlite3) RUN CGO_ENABLED=1 GOOS=linux go build -o /routewatch ./cmd/routewatch @@ -26,7 +50,8 @@ RUN tar --zstd -cf /routewatch-source.tar.zst \ . # Runtime stage -FROM debian:bookworm-slim +# debian:bookworm-slim, 2026-09-21 +FROM debian@sha256:3783cc01769c7b2b1b83a5c5ad96c815348e28ed7da68e2e3687004faa906251 # Install runtime dependencies # - ca-certificates: for HTTPS connections