Re-vendor the canonical files from sneak/prompts at dd4027b (closes #121)
check / check (push) Waiting to run

The vendored files are copies from sneak/prompts dd4027b, with this
repository's own entries after the canonical content. golangci-lint is
v2.14.0. Lint and test are phases of the Dockerfile, which script/lint
and script/test build with --no-cache; Dockerfile.lint and
script/lint-darwin are gone, and the lint phase also checks the macOS
build. The tests run on the Debian Go image with cgo and the race
detector. script/cibuild bootstraps, runs script/check and builds the
image; CHECK_EPOCH and the memlock ulimit are gone. Go's build cache
stays in a cache mount, out of the test image's layer. Agent guidance
lives in AGENTS.md alone; the tool-specific file is gone.

Model: opus-5-5
This commit was merged in pull request #128.
This commit is contained in:
2026-10-07 05:42:59 +02:00
parent ed6af50ea5
commit 2c6fe7c368
18 changed files with 610 additions and 396 deletions
+4 -3
View File
@@ -1,6 +1,8 @@
#!/bin/sh
# script/check: run all checks (test, lint, lint-darwin, fmt-check). Our
# own extension to scripts-to-rule-them-all. Must not modify any files.
# script/check: run all checks (test, lint, fmt-check). Our own
# extension to scripts-to-rule-them-all. test and lint are Docker
# phases; fmt-check is native, because a formatter writes the working
# tree. Must not modify any files.
set -eu
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
@@ -8,7 +10,6 @@ SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
main() {
"$SCRIPT_DIR/test"
"$SCRIPT_DIR/lint"
"$SCRIPT_DIR/lint-darwin"
"$SCRIPT_DIR/fmt-check"
}
+19 -12
View File
@@ -1,21 +1,28 @@
#!/bin/sh
# script/cibuild: run the CI build. The Dockerfile runs script/check
# (via make check), so a successful build implies all checks pass.
# The Gitea workflow runs this on push. The memlock ulimit lifts the limit
# on memory the tests lock (memguard mlocks secrets); they also pass under
# the lower limit of a plain `docker build .`.
# A cached build checks nothing: a new CHECK_EPOCH on every run makes the
# Dockerfile's check steps run again on an unchanged tree, while its base
# images, module downloads and the Go build cache that make test and make
# build use stay cached.
# script/cibuild: run the CI build. It bootstraps first: a CI runner
# checks out and runs this and nothing else, and script/fmt-check runs
# the formatter on the host, which a pristine checkout cannot do.
# --no-cache for the same reason as script/docker: the gate phases the
# final stage depends on are RUN steps, and a cached one is a check that
# did not run.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
main() {
cd "$ROOT"
docker build --ulimit memlock=-1:-1 \
--build-arg CHECK_EPOCH="$(date +%s)" .
"$SCRIPT_DIR/bootstrap"
"$SCRIPT_DIR/check"
# Own line: a failing command substitution inside an argument does
# not trip `set -e`, so the inline form degrades silently to an
# empty constant. The VERSION build argument takes precedence over
# the version a build stage derives from the .git in the context.
version="$(git describe --tags --always --dirty 2>/dev/null || true)"
[ -n "$version" ] || version="unknown"
docker build --no-cache \
--build-arg VERSION="$version" \
-t "$("$SCRIPT_DIR/projectname")" .
}
main "$@"
+12 -13
View File
@@ -1,24 +1,23 @@
#!/bin/sh
# script/lint: run the linter, in docker only. Builds Dockerfile.lint,
# where golangci-lint runs as a build step.
# script/lint: run the linter. Linting is a phase of the Dockerfile and
# this builds that phase alone; the linter is never installed or run on
# a developer host, where a shared result cache and a host-global lock
# make its answer untrustworthy.
#
# A cached build lints nothing, so --no-cache-filter rebuilds the lint
# stage on every run, an unchanged tree included. It ignores a stage name
# that does not exist, so --target names the same stage: a rename then
# fails the build instead of serving the lint from cache. cacheonly keeps
# no image; only the build's success matters.
# The phase is not the last stage in the file, so it is built only when
# --target names it. --no-cache because a cached lint layer is a lint
# that did not run. The tag makes each build replace the previous image
# instead of leaving a dangling one behind.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
main() {
cd "$ROOT"
docker build \
--progress=plain \
docker build --no-cache \
--target lint \
--no-cache-filter=lint \
--output=type=cacheonly \
-f Dockerfile.lint .
-t "$("$SCRIPT_DIR/projectname")-lint" .
}
main "$@"
-26
View File
@@ -1,26 +0,0 @@
#!/bin/sh
# script/lint-darwin: type-check (go vet) and lint the code as a macOS
# build compiles it, from Linux, in docker only. CI runs on Linux, which
# never compiles the files built only for macOS. Builds the lint-darwin
# stage of Dockerfile.lint, rebuilt on every run as script/lint does.
#
# Cgo is off: compiling cgo code for macOS needs Apple's SDK headers. That
# leaves out the files built only with cgo on macOS: the keychain unlocker's
# calls into the keychain (keychainunlocker_cgo.go, and
# keychainunlocker_test.go) and the Secure Enclave bindings (internal/macse).
# Nothing on Linux checks those.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
docker build \
--progress=plain \
--target lint-darwin \
--no-cache-filter=lint-darwin \
--output=type=cacheonly \
-f Dockerfile.lint .
}
main "$@"
+10 -13
View File
@@ -1,22 +1,19 @@
#!/bin/sh
# script/test: run the test suite (vet first, then the tests with the race
# detector; a verbose rerun on failure).
# script/test: run the test suite. Testing is a phase of the Dockerfile
# and this builds that phase alone, on the same terms as script/lint:
# --target because a phase that is not the last stage is built only when
# named, --no-cache because a cached test layer is a test that did not
# run, and a tag so each build replaces the previous image.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
main() {
cd "$ROOT"
# CGO is required (Makefile exports this too)
export CGO_ENABLED=1
go vet ./...
# -count=1: run every test, never take a result from Go's test cache,
# which the Dockerfile keeps between builds. The rerun only prints
# details: `exit 1` keeps the script failing even if a flaky test
# passes on the second attempt.
go test -count=1 -timeout 30s -race -cover ./... || \
{ echo "--- Rerunning with -v for details ---"; \
go test -count=1 -timeout 30s -race -v ./...; exit 1; }
docker build --no-cache \
--target test \
-t "$("$SCRIPT_DIR/projectname")-test" .
}
main "$@"