Run golangci-lint only in docker, on every run (closes #55) #79

Merged
clawbot merged 1 commits from issue-55-docker-lint into next 2026-10-04 07:07:53 +02:00
Collaborator

Every lint run now happens in docker through script/lint; no host golangci-lint path remains (#55).

  • New Dockerfile.lint, on the same pinned golangci-lint image as the Dockerfile lint stage: a deps stage downloads the modules, a lint stage copies the tree and runs golangci-lint run --config .golangci.yml ./... as a build step, so a successful build is a clean lint.
  • script/lint builds it with --no-cache-filter=lint, so the linter runs on every call, an unchanged tree included, while the module download stays cached. --target lint names the same stage, so renaming it fails the build instead of --no-cache-filter silently matching nothing. --output=type=cacheonly keeps no image.
  • Dockerfile lint stage: make lint is replaced by the same direct golangci-lint run, since make lint now starts a docker build. Stage order and script/cibuild with its memlock ulimit are unchanged, so script/cibuild still lints. The lint image runs no tests and needs no memlock ulimit.
  • script/bootstrap no longer installs golangci-lint; README.md Entrypoints and TODO.md updated.

golangci-lint config verify is left out: it fetches its JSON schema live over unpinned HTTPS, against the hash-pinning policy, and would fail lint on any network outage.

Deviation: the Dockerfile lint stage no longer runs make lint as the pattern in REPO_POLICIES.md shows; that shared file is left as is.

Unverified: make lint goes to the remote daemon the Makefile sets in DOCKER_HOST; only script/lint against the local daemon was run.

Not here: .golangci.yml (#66), the cached green in script/cibuild (#54).

Model: opus-5-5

Every lint run now happens in docker through `script/lint`; no host golangci-lint path remains (https://git.eeqj.de/sneak/secret/issues/55). - New `Dockerfile.lint`, on the same pinned golangci-lint image as the `Dockerfile` lint stage: a `deps` stage downloads the modules, a `lint` stage copies the tree and runs `golangci-lint run --config .golangci.yml ./...` as a build step, so a successful build is a clean lint. - `script/lint` builds it with `--no-cache-filter=lint`, so the linter runs on every call, an unchanged tree included, while the module download stays cached. `--target lint` names the same stage, so renaming it fails the build instead of `--no-cache-filter` silently matching nothing. `--output=type=cacheonly` keeps no image. - `Dockerfile` lint stage: `make lint` is replaced by the same direct `golangci-lint run`, since `make lint` now starts a docker build. Stage order and `script/cibuild` with its memlock ulimit are unchanged, so `script/cibuild` still lints. The lint image runs no tests and needs no memlock ulimit. - `script/bootstrap` no longer installs golangci-lint; `README.md` Entrypoints and `TODO.md` updated. `golangci-lint config verify` is left out: it fetches its JSON schema live over unpinned HTTPS, against the hash-pinning policy, and would fail lint on any network outage. Deviation: the `Dockerfile` lint stage no longer runs `make lint` as the pattern in `REPO_POLICIES.md` shows; that shared file is left as is. Unverified: `make lint` goes to the remote daemon the `Makefile` sets in `DOCKER_HOST`; only `script/lint` against the local daemon was run. Not here: `.golangci.yml` (https://git.eeqj.de/sneak/secret/issues/66), the cached green in `script/cibuild` (https://git.eeqj.de/sneak/secret/issues/54). Model: opus-5-5
clawbot added the needs-review label 2026-10-04 04:24:41 +02:00
clawbot self-assigned this 2026-10-04 04:24:41 +02:00
Author
Collaborator

PASS: script/lint now runs golangci-lint only in docker on every run. The main Dockerfile still lints, and nothing installs or runs golangci-lint on the host.

  • Rebase: TODO.md conflicts with current next. Both sides add a Completed Steps entry, so keep both. I resolved it locally to review the code.
  • Unverified: make lint against the remote docker daemon the Makefile sets in DOCKER_HOST.

Model: opus-5-5

PASS: `script/lint` now runs golangci-lint only in docker on every run. The main `Dockerfile` still lints, and nothing installs or runs golangci-lint on the host. - Rebase: `TODO.md` conflicts with current `next`. Both sides add a Completed Steps entry, so keep both. I resolved it locally to review the code. - Unverified: `make lint` against the remote docker daemon the `Makefile` sets in `DOCKER_HOST`. Model: opus-5-5
clawbot force-pushed issue-55-docker-lint from a75dc54b78 to fc115f31b5 2026-10-04 06:34:35 +02:00 Compare
clawbot added 1 commit 2026-10-04 07:03:21 +02:00
script/lint builds the new Dockerfile.lint, where golangci-lint runs as
a build step. The lint stage is rebuilt on every run, so an unchanged
tree is linted too; the module download stays cached. script/bootstrap
no longer installs golangci-lint. The Dockerfile lint stage calls
golangci-lint directly, since make lint now starts a docker build.
golangci-lint config verify is not run: it fetches its schema live over
unpinned HTTPS.

Model: opus-5-5
clawbot force-pushed issue-55-docker-lint from fc115f31b5 to 9d4259afa3 2026-10-04 07:03:21 +02:00 Compare
clawbot merged commit 4e562f834f into next 2026-10-04 07:07:53 +02:00
clawbot deleted branch issue-55-docker-lint 2026-10-04 07:07:54 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/secret#79