Type-check and lint the macOS build from Linux (closes #50)
check / check (push) Failing after 1s

script/lint-darwin (make lint-darwin; run by script/check, and its
commands by the Dockerfile lint stage) runs go vet and golangci-lint
with GOOS=darwin and cgo off. Compiling cgo for macOS needs Apple's SDK,
and keychainunlocker.go uses go-keychain, which is cgo there, so it and
its tests are now built only with cgo on macOS, like internal/macse;
their stubs serve a macOS build without cgo. checkMacOSAvailable moves
to seunlocker_darwin.go. The findings in the newly checked files are
fixed, and lines over 88 columns in the unchecked ones are wrapped.

Model: opus-5-5
This commit is contained in:
2026-10-04 12:08:28 +00:00
parent 007254a1f0
commit 6fc947c23f
18 changed files with 732 additions and 446 deletions
+25 -5
View File
@@ -25,6 +25,22 @@ Bring the repo into policy compliance in one commit:
# Completed Steps
- 2026-10-04: `script/lint-darwin` (`make lint-darwin`) runs `go vet` and
`golangci-lint` in docker on the code as a macOS build compiles it
(`GOOS=darwin`), with cgo off
(https://git.eeqj.de/sneak/secret/issues/50). `script/check` runs it,
and the `Dockerfile` lint stage runs its commands, so `script/cibuild`
does too. Before, CI on Linux never compiled the files built only for
macOS. Compiling cgo code for macOS needs Apple's SDK headers, and both
`internal/macse` and `github.com/keybase/go-keychain`, which
`keychainunlocker.go` uses, are cgo on macOS. So `keychainunlocker.go`
and its tests are now built only with cgo on macOS, like
`macse_darwin.go`, and the keychain and `macse` stubs serve a macOS
build without cgo, which before did not compile. `checkMacOSAvailable`
moved to `seunlocker_darwin.go`. The check covers the Secure Enclave
unlocker and the macOS-only tests `seunlocker_test.go` and
`pgpunlock_test.go`, whose lint findings are fixed; lines over 88
columns in the macOS files it cannot check are wrapped.
- 2026-10-04: A vault name may use only lowercase ASCII letters, digits,
`.`, `-` and `_`, and must not be empty, `.` or `..`
(https://git.eeqj.de/sneak/secret/issues/68); the error and `README.md`
@@ -248,11 +264,15 @@ Bring the repo into policy compliance in one commit:
- Cover mnemonic-vs-xprv identity consistency in
`pkg/agehd/agehd_test.go` `TestMnemonicVsXPRVConsistency` (was an
in-code FIXME removed for godox).
- Darwin-gated files (`internal/secret/keychainunlocker.go`,
`seunlocker_darwin.go`, `internal/macse/macse_darwin.go`, related
tests) are not linted on the Linux CI runner and still contain lines
over the new 88-column limit; they will surface if lint ever runs on
macOS.
- CI does not compile, lint or test the files built only with cgo on
macOS, since compiling them needs Apple's SDK:
`internal/secret/keychainunlocker.go` with `keychainunlocker_test.go`,
`validation_darwin_test.go` and `derivation_index_test.go`, and
`internal/macse` (`macse_darwin.go`, `macse_test.go`, the Objective-C
sources). Lint has never run on them, so it would likely find more
there than the line lengths. No macOS test runs in CI. A macOS runner
would cover all of it (asked on
https://git.eeqj.de/sneak/secret/issues/50).
- Merge secure-enclave-unlocker to main once review is done.
- 1.0 critical security blockers (from repo TODO.md):
- Command injection: GPG key IDs passed unescaped to exec.Command