From c246bfc455e6f1c3316e5e05d95fafaa77caa0c3 Mon Sep 17 00:00:00 2001 From: sneak Date: Tue, 7 Jul 2026 01:57:08 +0200 Subject: [PATCH] Adopt scripts-to-rule-them-all: script/ entrypoints, Makefile shims --- .gitea/workflows/check.yml | 2 +- Makefile | 28 +++++-- README.md | 30 +++++++ TODO.md | 2 + script/bootstrap | 155 +++++++++++++++++++++++++++++++++++++ script/check | 15 ++++ script/cibuild | 15 ++++ script/docker | 15 ++++ script/fmt | 12 +++ script/fmt-check | 17 ++++ script/install-precommit | 17 ++++ script/lint | 14 ++++ script/precommit | 20 +++++ script/projectname | 12 +++ script/setup | 14 ++++ script/test | 15 ++++ 16 files changed, 374 insertions(+), 9 deletions(-) create mode 100755 script/bootstrap create mode 100755 script/check create mode 100755 script/cibuild create mode 100755 script/docker create mode 100755 script/fmt create mode 100755 script/fmt-check create mode 100755 script/install-precommit create mode 100755 script/lint create mode 100755 script/precommit create mode 100755 script/projectname create mode 100755 script/setup create mode 100755 script/test diff --git a/.gitea/workflows/check.yml b/.gitea/workflows/check.yml index 3c94fae..a55bc55 100644 --- a/.gitea/workflows/check.yml +++ b/.gitea/workflows/check.yml @@ -6,4 +6,4 @@ jobs: steps: # actions/checkout v4.2.2, 2026-02-28 - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 - - run: docker build --ulimit memlock=-1:-1 . + - run: script/cibuild diff --git a/Makefile b/Makefile index 542966d..79558aa 100644 --- a/Makefile +++ b/Makefile @@ -7,8 +7,16 @@ GIT_COMMIT := $(shell git rev-parse HEAD 2>/dev/null || echo "unknown") LDFLAGS := -X 'git.eeqj.de/sneak/secret/internal/cli.Version=$(VERSION)' \ -X 'git.eeqj.de/sneak/secret/internal/cli.GitCommit=$(GIT_COMMIT)' +.PHONY: default bootstrap setup test lint fmt fmt-check check docker hooks vet + default: check +bootstrap: + @script/bootstrap + +setup: + @script/setup + build: ./secret ./secret: ./internal/*/*.go ./pkg/*/*.go ./cmd/*/*.go ./go.* @@ -17,24 +25,25 @@ build: ./secret vet: go vet ./... -test: vet - go test ./... || go test -v ./... +test: + @script/test fmt: - go fmt ./... + @script/fmt lint: - golangci-lint run --timeout 5m + @script/lint -check: build lint test fmt-check +check: + @script/check # Build Docker container docker: - docker build -t sneak/secret . + @script/docker # Run Docker container interactively docker-run: - docker run --rm -it sneak/secret + docker run --rm -it "$$(./script/projectname)" # Clean build artifacts clean: @@ -44,4 +53,7 @@ install: ./secret cp ./secret $(HOME)/bin/secret fmt-check: - @test -z "$$(gofmt -l .)" || (echo "Files need formatting:" && gofmt -l . && exit 1) + @script/fmt-check + +hooks: + @script/install-precommit diff --git a/README.md b/README.md index 8eaaf0e..d64a5de 100644 --- a/README.md +++ b/README.md @@ -486,6 +486,36 @@ go test ./... # Unit tests go test -tags=integration -v ./internal/cli # Integration tests ``` +## Entrypoints + +This repository adheres to the +[Scripts to Rule Them All](https://github.com/github/scripts-to-rule-them-all) +standard: normalized scripts in `script/` are the entrypoints for the +development workflow, and the Makefile targets are thin shims that call +them. We provide: + +- `script/bootstrap` — install all dependencies (Go, golangci-lint, Go + module download), idempotently +- `script/setup` — make a fresh clone ready for development: runs + `script/bootstrap`, then `script/install-precommit` +- `script/projectname` — output the project name (`secret`); used by + other scripts such as `script/docker` +- `script/test` — run `go vet` and the test suite (verbose rerun on + failure) +- `script/lint` — run `golangci-lint` +- `script/fmt` — format all Go code (writes) +- `script/fmt-check` — check formatting without writing +- `script/check` — run `script/test`, `script/lint`, and + `script/fmt-check` +- `script/docker` — build the Docker image tagged with the project name +- `script/cibuild` — CI entrypoint: `docker build --ulimit + memlock=-1:-1 .` (memguard needs mlock; the Dockerfile runs the + checks) +- `script/precommit` — pre-commit checks: `go mod tidy` verification, + then `script/check` +- `script/install-precommit` — install the git pre-commit hook that + runs `script/precommit` + ## Features - **Multiple Authentication Methods**: Supports passphrase, PGP, macOS Keychain, and Secure Enclave unlockers diff --git a/TODO.md b/TODO.md index 0a23b23..909a91e 100644 --- a/TODO.md +++ b/TODO.md @@ -25,6 +25,8 @@ Bring the repo into policy compliance in one commit: # Completed Steps +- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints, + Makefile shims, README Entrypoints section - 2026-03-11: Secure Enclave unlocker for hardware-backed secret protection, plus review fixes (stub panics, derivation index, tests, README) on branch secure-enclave-unlocker. diff --git a/script/bootstrap b/script/bootstrap new file mode 100755 index 0000000..c40c5e5 --- /dev/null +++ b/script/bootstrap @@ -0,0 +1,155 @@ +#!/bin/sh +# script/bootstrap: install all dependencies needed to build and develop +# this repo. Idempotent: every install is guarded by a check so already +# installed tools are skipped. Base tooling comes from nix, apt, brew, +# or apk (detected in that order); assumes NOTHING is present (not git, +# make, node, yarn, go, or python). Node is used directly if installed; +# otherwise a pinned version is installed via nvm (installing nvm +# itself first, from a hash-verified release archive, never curl | sh). +# +# Uncomment the language sections in main() that apply to this repo. +set -eu + +ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" + +# Pinned versions, 2026-07-06. Never "latest" or "lts"; exact versions. +NODE_VERSION="22.17.0" +NVM_VERSION="0.40.3" +# sha256 of https://github.com/nvm-sh/nvm/archive/refs/tags/v0.40.3.tar.gz +NVM_SHA256="5f4d6aaa04a177dc93c985e31dbc411ab6b8c6e1e21d8015dbc1372625fcd1d0" +YARN_VERSION="1.22.22" + +PKGMGR="" +SUDO="" + +detect_pkgmgr() { + [ -n "$PKGMGR" ] && return 0 + if command -v nix-env >/dev/null 2>&1; then + PKGMGR="nix" + elif command -v apt-get >/dev/null 2>&1; then + PKGMGR="apt" + elif command -v brew >/dev/null 2>&1; then + PKGMGR="brew" + elif command -v apk >/dev/null 2>&1; then + PKGMGR="apk" + else + echo "bootstrap: no supported package manager (nix, apt, brew, apk)" >&2 + exit 1 + fi + if [ "$PKGMGR" = "apt" ]; then + export DEBIAN_FRONTEND=noninteractive + if [ "$(id -u)" != "0" ]; then + SUDO="sudo" + fi + fi +} + +# pkg_install +pkg_install() { + detect_pkgmgr + case "$PKGMGR" in + nix) nix-env -iA "nixpkgs.$1" ;; + apt) $SUDO env DEBIAN_FRONTEND=noninteractive apt-get install -y "$2" ;; + brew) brew install "$3" ;; + apk) apk add --no-cache "$4" ;; + esac +} + +missing() { + ! command -v "$1" >/dev/null 2>&1 +} + +# verify_sha256 +verify_sha256() { + if command -v sha256sum >/dev/null 2>&1; then + actual="$(sha256sum "$1" | cut -d' ' -f1)" + else + actual="$(shasum -a 256 "$1" | cut -d' ' -f1)" + fi + if [ "$actual" != "$2" ]; then + echo "bootstrap: sha256 mismatch for $1" >&2 + echo " expected: $2" >&2 + echo " actual: $actual" >&2 + exit 1 + fi +} + +# nvm is a bash script; run a command in a bash with nvm loaded +nvm_sh() { + bash -c ". \"\$HOME/.nvm/nvm.sh\" && $*" +} + +ensure_nvm() { + [ -s "$HOME/.nvm/nvm.sh" ] && return 0 + # nvm prerequisites; nvm itself requires bash, so install it too + if missing bash; then pkg_install bash bash bash bash; fi + if missing curl; then pkg_install curl curl curl curl; fi + if missing git; then pkg_install git git git git; fi + tmp="$(mktemp -d)" + curl -fsSL -o "$tmp/nvm.tar.gz" \ + "https://github.com/nvm-sh/nvm/archive/refs/tags/v${NVM_VERSION}.tar.gz" + verify_sha256 "$tmp/nvm.tar.gz" "$NVM_SHA256" + mkdir -p "$HOME/.nvm" + tar -xzf "$tmp/nvm.tar.gz" -C "$HOME/.nvm" --strip-components=1 + rm -rf "$tmp" +} + +ensure_node() { + if ! missing node; then return 0; fi + ensure_nvm + nvm_sh "nvm install $NODE_VERSION" +} + +ensure_yarn() { + if ! missing yarn; then return 0; fi + if ! missing corepack; then + corepack enable + corepack prepare "yarn@$YARN_VERSION" --activate + elif [ -s "$HOME/.nvm/nvm.sh" ]; then + nvm_sh "nvm use $NODE_VERSION >/dev/null && corepack enable && \ + corepack prepare yarn@$YARN_VERSION --activate" + else + npm install -g "yarn@$YARN_VERSION" + fi +} + +install_js_deps() { + if missing yarn && [ -s "$HOME/.nvm/nvm.sh" ]; then + nvm_sh "nvm use $NODE_VERSION >/dev/null && cd \"$ROOT\" && \ + yarn install --frozen-lockfile" + else + yarn install --frozen-lockfile + fi +} + +main() { + cd "$ROOT" + + # Base tooling (every repo) + if missing git; then pkg_install git git git git; fi + if missing make; then pkg_install gnumake make make make; fi + + # ---- JS / docs repos ---- + # ensure_node + # ensure_yarn + # install_js_deps + + # ---- Go repos ---- + if missing go; then pkg_install go golang go go; fi + # golangci-lint: packaged in nix, brew, and apk. On apt there is no + # package: download a specific release archive from GitHub and + # verify its hash (verify_sha256), never curl | sh. + if missing golangci-lint; then + pkg_install golangci-lint golangci-lint golangci-lint golangci-lint + fi + go mod download + + # ---- Python repos ---- + # if missing python3; then pkg_install python3 python3 python3 python3; fi + # python3 -m venv .venv + # ./.venv/bin/pip install -e '.[dev]' + + echo "bootstrap complete" +} + +main "$@" diff --git a/script/check b/script/check new file mode 100755 index 0000000..cc046f7 --- /dev/null +++ b/script/check @@ -0,0 +1,15 @@ +#!/bin/sh +# script/check: run all checks (test, lint, fmt-check). Our own +# extension to scripts-to-rule-them-all. Must not modify any files. +# Generic: usually needs no adaptation. +set -eu + +SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" + +main() { + "$SCRIPT_DIR/test" + "$SCRIPT_DIR/lint" + "$SCRIPT_DIR/fmt-check" +} + +main "$@" diff --git a/script/cibuild b/script/cibuild new file mode 100755 index 0000000..ea520d9 --- /dev/null +++ b/script/cibuild @@ -0,0 +1,15 @@ +#!/bin/sh +# script/cibuild: run the CI build. The Dockerfile runs script/check +# (via make check), so a successful build implies all checks pass. +# The Gitea workflow runs this on push. The memlock ulimit is required +# because the test suite uses memguard, which mlocks memory. +set -eu + +ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" + +main() { + cd "$ROOT" + docker build --ulimit memlock=-1:-1 . +} + +main "$@" diff --git a/script/docker b/script/docker new file mode 100755 index 0000000..2884e41 --- /dev/null +++ b/script/docker @@ -0,0 +1,15 @@ +#!/bin/sh +# script/docker: build the Docker image tagged with the project name. +# Identical in all repos; the tag comes from script/projectname. +# Generic: needs no adaptation. +set -eu + +SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" +ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)" + +main() { + cd "$ROOT" + docker build -t "$("$SCRIPT_DIR/projectname")" . +} + +main "$@" diff --git a/script/fmt b/script/fmt new file mode 100755 index 0000000..e95d111 --- /dev/null +++ b/script/fmt @@ -0,0 +1,12 @@ +#!/bin/sh +# script/fmt: format all files (writes). +set -eu + +ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" + +main() { + cd "$ROOT" + go fmt ./... +} + +main "$@" diff --git a/script/fmt-check b/script/fmt-check new file mode 100755 index 0000000..2e91588 --- /dev/null +++ b/script/fmt-check @@ -0,0 +1,17 @@ +#!/bin/sh +# script/fmt-check: check formatting (read-only). Same scope as +# script/fmt, but fails instead of writing. +set -eu + +ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" + +main() { + cd "$ROOT" + if [ -n "$(gofmt -l .)" ]; then + echo "Files need formatting:" + gofmt -l . + exit 1 + fi +} + +main "$@" diff --git a/script/install-precommit b/script/install-precommit new file mode 100755 index 0000000..3519de6 --- /dev/null +++ b/script/install-precommit @@ -0,0 +1,17 @@ +#!/bin/sh +# script/install-precommit: install the git pre-commit hook that runs +# script/precommit. Our own extension to scripts-to-rule-them-all. +# Generic: needs no adaptation. +set -eu + +ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" + +main() { + cd "$ROOT" + hook=".git/hooks/pre-commit" + printf '#!/bin/sh\nset -e\nscript/precommit\n' > .git/hooks/pre-commit + chmod +x .git/hooks/pre-commit + echo "pre-commit hook installed: runs script/precommit" +} + +main "$@" diff --git a/script/lint b/script/lint new file mode 100755 index 0000000..36162c8 --- /dev/null +++ b/script/lint @@ -0,0 +1,14 @@ +#!/bin/sh +# script/lint: run the linter. +set -eu + +ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" + +main() { + cd "$ROOT" + # CGO is required (Makefile exports this too) + export CGO_ENABLED=1 + golangci-lint run --timeout 5m +} + +main "$@" diff --git a/script/precommit b/script/precommit new file mode 100755 index 0000000..fc2c7e7 --- /dev/null +++ b/script/precommit @@ -0,0 +1,20 @@ +#!/bin/sh +# script/precommit: run by the git pre-commit hook; fails the commit if +# checks fail. Our own extension to scripts-to-rule-them-all. Go repo +# extras run first: go mod tidy and go fmt, failing the commit if they +# change go.mod or go.sum. +set -eu + +SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" +ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)" + +main() { + cd "$ROOT" + go mod tidy + go fmt ./... + git diff --exit-code -- go.mod go.sum || + { echo "go mod tidy changed files; stage and retry" >&2; exit 1; } + "$SCRIPT_DIR/check" +} + +main "$@" diff --git a/script/projectname b/script/projectname new file mode 100755 index 0000000..208d696 --- /dev/null +++ b/script/projectname @@ -0,0 +1,12 @@ +#!/bin/sh +# script/projectname: output the name of this project. Our own +# extension to scripts-to-rule-them-all. Other scripts that need the +# name (e.g. script/docker) call this, so they can stay identical +# across all repos. +set -eu + +main() { + echo "secret" +} + +main "$@" diff --git a/script/setup b/script/setup new file mode 100755 index 0000000..53327ba --- /dev/null +++ b/script/setup @@ -0,0 +1,14 @@ +#!/bin/sh +# script/setup: set up the repo for development after a fresh clone: +# installs dependencies (script/bootstrap) and the git pre-commit hook. +# Add any repo-specific initialization (db init, .env template) here. +set -eu + +SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" + +main() { + "$SCRIPT_DIR/bootstrap" + "$SCRIPT_DIR/install-precommit" +} + +main "$@" diff --git a/script/test b/script/test new file mode 100755 index 0000000..3735b43 --- /dev/null +++ b/script/test @@ -0,0 +1,15 @@ +#!/bin/sh +# script/test: run the test suite (vet first, verbose rerun on failure). +set -eu + +ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" + +main() { + cd "$ROOT" + # CGO is required (Makefile exports this too) + export CGO_ENABLED=1 + go vet ./... + go test ./... || go test -v ./... +} + +main "$@"