Adopt repo standards: scaffold, policies, lint-clean (closes #1)
check / check (push) Failing after 0s

Add the standard scaffold and bring the tree to a clean lint under the
vendored `default: all` config: `script/` Scripts-to-Rule-Them-All
entrypoints with the `Makefile` as thin shims; a `Dockerfile` whose
`lint` and `test` phases gate the build; `.gitea/workflows/` CI running
`script/cibuild`; `REPO_POLICIES.md`, `.editorconfig`, `.dockerignore`,
`LICENSE` (WTFPL), `TODO.md`, `.gitignore`. The `.golangci.yml` is
byte-identical to the canonical copy in the `prompts` repo
(`https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml`).

The 211 lint findings were fixed, not suppressed: package globals became
functions/fields/a command constructor, magic numbers became named
constants, `ctx` threads into the probes, loop functions were split to
cut complexity. Behavior is unchanged; the log file mode stays `0644`.
Four `//nolint:gosec` remain — G204 on the fixed-argv subprocess calls,
G304 on the operator-chosen log file — matching the reference repos.

`make check` is green (lint and tests run in Docker).

Model: opus-4-8
This commit is contained in:
2026-09-21 07:13:37 +00:00
parent cf9dc39053
commit 18b27dc48c
34 changed files with 2172 additions and 884 deletions
Executable
+16
View File
@@ -0,0 +1,16 @@
#!/bin/sh
# script/lint: run the linter. golangci-lint is never installed on the host;
# it runs only in docker, as the `lint` phase of the Dockerfile. --no-cache
# forces the phase to re-execute, so a cached layer cannot report a pass it
# did not earn. The build is tagged so no dangling image is left behind.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
docker build --no-cache --target lint \
-t "$(script/projectname)-lint" .
}
main "$@"