Type-check and lint the macOS build from Linux (closes #50)
check / check (push) Failing after 1s
check / check (push) Failing after 1s
script/lint-darwin (make lint-darwin; run by script/check, and its commands by the Dockerfile lint stage) runs go vet and golangci-lint with GOOS=darwin and cgo off. Compiling cgo for macOS needs Apple's SDK, and keychainunlocker.go uses go-keychain, which is cgo there, so it and its tests are now built only with cgo on macOS, like internal/macse; their stubs serve a macOS build without cgo. checkMacOSAvailable moves to seunlocker_darwin.go. The findings in the newly checked files are fixed, and lines over 88 columns in the unchecked ones are wrapped. Model: opus-5-5
This commit is contained in:
@@ -25,6 +25,22 @@ Bring the repo into policy compliance in one commit:
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: `script/lint-darwin` (`make lint-darwin`) runs `go vet` and
|
||||
`golangci-lint` in docker on the code as a macOS build compiles it
|
||||
(`GOOS=darwin`), with cgo off
|
||||
(https://git.eeqj.de/sneak/secret/issues/50). `script/check` runs it,
|
||||
and the `Dockerfile` lint stage runs its commands, so `script/cibuild`
|
||||
does too. Before, CI on Linux never compiled the files built only for
|
||||
macOS. Compiling cgo code for macOS needs Apple's SDK headers, and both
|
||||
`internal/macse` and `github.com/keybase/go-keychain`, which
|
||||
`keychainunlocker.go` uses, are cgo on macOS. So `keychainunlocker.go`
|
||||
and its tests are now built only with cgo on macOS, like
|
||||
`macse_darwin.go`, and the keychain and `macse` stubs serve a macOS
|
||||
build without cgo, which before did not compile. `checkMacOSAvailable`
|
||||
moved to `seunlocker_darwin.go`. The check covers the Secure Enclave
|
||||
unlocker and the macOS-only tests `seunlocker_test.go` and
|
||||
`pgpunlock_test.go`, whose lint findings are fixed; lines over 88
|
||||
columns in the macOS files it cannot check are wrapped.
|
||||
- 2026-10-04: A vault name may use only lowercase ASCII letters, digits,
|
||||
`.`, `-` and `_`, and must not be empty, `.` or `..`
|
||||
(https://git.eeqj.de/sneak/secret/issues/68); the error and `README.md`
|
||||
@@ -248,11 +264,15 @@ Bring the repo into policy compliance in one commit:
|
||||
- Cover mnemonic-vs-xprv identity consistency in
|
||||
`pkg/agehd/agehd_test.go` `TestMnemonicVsXPRVConsistency` (was an
|
||||
in-code FIXME removed for godox).
|
||||
- Darwin-gated files (`internal/secret/keychainunlocker.go`,
|
||||
`seunlocker_darwin.go`, `internal/macse/macse_darwin.go`, related
|
||||
tests) are not linted on the Linux CI runner and still contain lines
|
||||
over the new 88-column limit; they will surface if lint ever runs on
|
||||
macOS.
|
||||
- CI does not compile, lint or test the files built only with cgo on
|
||||
macOS, since compiling them needs Apple's SDK:
|
||||
`internal/secret/keychainunlocker.go` with `keychainunlocker_test.go`,
|
||||
`validation_darwin_test.go` and `derivation_index_test.go`, and
|
||||
`internal/macse` (`macse_darwin.go`, `macse_test.go`, the Objective-C
|
||||
sources). Lint has never run on them, so it would likely find more
|
||||
there than the line lengths. No macOS test runs in CI. A macOS runner
|
||||
would cover all of it (asked on
|
||||
https://git.eeqj.de/sneak/secret/issues/50).
|
||||
- Merge secure-enclave-unlocker to main once review is done.
|
||||
- 1.0 critical security blockers (from repo TODO.md):
|
||||
- Command injection: GPG key IDs passed unescaped to exec.Command
|
||||
|
||||
Reference in New Issue
Block a user