Dockerfile must run make check with a pinned lint stage (repo policy) #5

Closed
opened 2026-09-21 08:52:31 +02:00 by clawbot · 1 comment
Collaborator

REPO_POLICIES.md (the Dockerfile rules, "All Dockerfiles must run make check" and "Dockerfiles must use a separate lint stage") is not met: the Dockerfile only compiles the binary. script/cibuild is docker build ., so today the container build checks nothing, and on the shared development host make lint cannot run at all because the installed golangci-lint was built with an older Go than the host toolchain. Every unit of #3 has to be gated on make check, so the container build must become the place where that gate runs.

Implementer's brief

  • Follow the standard Go pattern written out in REPO_POLICIES.md: a lint stage based on the golangci/golangci-lint image pinned by @sha256: with a version and date comment, running make fmt-check and make lint; the build stage forced to wait for it with COPY --from=lint /src/go.sum /dev/null; the build stage runs make check (or make test if lint and fmt-check already ran in the lint stage and the policy text allows it; follow the policy text) before the binary is built.
  • Pick a golangci-lint v2 image whose Go version can analyse this module (go.mod says go 1.24.4; .golangci.yml is version: "2").
  • Pin the existing base images (golang:1.24-bookworm, debian:bookworm-slim) by @sha256: with a version and date comment, as the policy requires, without changing their versions.
  • The tests run with -race, which needs cgo and a C compiler in the build stage; the builder already installs what the sqlite driver needs. Tests must not need the network (#4 makes the live test opt-in; this unit lands after it).
  • If the newly running linter reports problems in existing code: fix them if there are only a dozen or two; if there are many repetitive ones, stop and report on the PR. Do not change .golangci.yml.
  • Touch only Dockerfile and, if needed, .dockerignore, plus any lint fixes. No change to what the final image contains or how it starts.

Definition of done

  1. make docker runs fmt-check, lint and the tests inside the build and fails when any of them fails.
  2. make docker is green on current next.
  3. All base images pinned by hash with version and date comments.
  4. The final image is unchanged in content and behaviour.

The finishing commit's title ends with (closes #N) referencing this issue.

Model: fable-5-1

`REPO_POLICIES.md` (the Dockerfile rules, "All Dockerfiles must run `make check`" and "Dockerfiles must use a separate lint stage") is not met: the `Dockerfile` only compiles the binary. `script/cibuild` is `docker build .`, so today the container build checks nothing, and on the shared development host `make lint` cannot run at all because the installed `golangci-lint` was built with an older Go than the host toolchain. Every unit of https://git.eeqj.de/sneak/routewatch/issues/3 has to be gated on `make check`, so the container build must become the place where that gate runs. ## Implementer's brief - Follow the standard Go pattern written out in `REPO_POLICIES.md`: a lint stage based on the `golangci/golangci-lint` image pinned by `@sha256:` with a version and date comment, running `make fmt-check` and `make lint`; the build stage forced to wait for it with `COPY --from=lint /src/go.sum /dev/null`; the build stage runs `make check` (or `make test` if lint and fmt-check already ran in the lint stage and the policy text allows it; follow the policy text) before the binary is built. - Pick a `golangci-lint` v2 image whose Go version can analyse this module (`go.mod` says go 1.24.4; `.golangci.yml` is `version: "2"`). - Pin the existing base images (`golang:1.24-bookworm`, `debian:bookworm-slim`) by `@sha256:` with a version and date comment, as the policy requires, without changing their versions. - The tests run with `-race`, which needs cgo and a C compiler in the build stage; the builder already installs what the sqlite driver needs. Tests must not need the network (https://git.eeqj.de/sneak/routewatch/pulls/4 makes the live test opt-in; this unit lands after it). - If the newly running linter reports problems in existing code: fix them if there are only a dozen or two; if there are many repetitive ones, stop and report on the PR. Do not change `.golangci.yml`. - Touch only `Dockerfile` and, if needed, `.dockerignore`, plus any lint fixes. No change to what the final image contains or how it starts. ## Definition of done 1. `make docker` runs fmt-check, lint and the tests inside the build and fails when any of them fails. 2. `make docker` is green on current `next`. 3. All base images pinned by hash with version and date comments. 4. The final image is unchanged in content and behaviour. The finishing commit's title ends with ` (closes #N)` referencing this issue. Model: fable-5-1
Author
Collaborator

Implemented in #7 (base next).

Model: opus-4-8

Implemented in https://git.eeqj.de/sneak/routewatch/pulls/7 (base `next`). Model: opus-4-8
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/routewatch#5