Cut the narration from TODO.md and the script and Dockerfile comments (closes #49)
check / check (push) Failing after 3s
check / check (push) Failing after 3s
Completed Steps entries keep what landed, the traps, every disclosure and every record that a check ran; the argument and history go, with bare issue numbers turned into full links. Comment blocks in script/, Dockerfile and Dockerfile.lint keep the trap and drop the defence of past decisions. TODO.md Workflow now branches from next, targets next, and leaves merging next to main to the owner. Only comments and Markdown change. Model: opus-5-5
This commit was merged in pull request #94.
This commit is contained in:
+21
-35
@@ -1,14 +1,12 @@
|
||||
# Lint-only image: this is how the linter runs, everywhere. The repo is
|
||||
# COPYed into the pinned golangci-lint image and the linter runs as a
|
||||
# build step, so a successful build IS a clean lint. golangci-lint is
|
||||
# never installed on a host — one toolchain, pinned by digest, identical
|
||||
# on a laptop and in CI — and this works even when the docker daemon is
|
||||
# remote and bind mounts are impossible.
|
||||
# Lint-only image, built by script/lint: the repo is copied into the
|
||||
# pinned golangci-lint image and the linter runs as a build step, so a
|
||||
# successful build is a clean lint. No bind mount, so it works when the
|
||||
# docker daemon is remote.
|
||||
#
|
||||
# script/lint builds this file. It is a separate image from the lint
|
||||
# stage of the main Dockerfile because script/lint must not depend on
|
||||
# the rest of that build; the two FROM lines are kept identical by
|
||||
# script/verify-lint-image-pin, run as a gate below.
|
||||
# It is separate from the main Dockerfile's lint stage because
|
||||
# script/lint must not depend on the rest of that build; the two FROM
|
||||
# lines are kept identical by script/verify-lint-image-pin, run as a
|
||||
# gate below.
|
||||
# golangci/golangci-lint:v2.12.2, 2026-08-07
|
||||
FROM golangci/golangci-lint@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240
|
||||
|
||||
@@ -20,38 +18,26 @@ RUN go mod download
|
||||
|
||||
COPY . .
|
||||
|
||||
# Cache-buster for the gate layers, and only for them. Caching of the
|
||||
# lint run is waived by ruling: COPY is invalidated only by changed
|
||||
# content, so on an unchanged tree the gates below would be served from
|
||||
# cache and this build would exit 0 in under a second having run no
|
||||
# linter at all. That exact false green has bitten this repo twice
|
||||
# already (#32, #39). script/lint passes a fresh value on every
|
||||
# Cache-buster for the gate layers, and only for them; caching of the
|
||||
# lint run is waived by ruling. On an unchanged tree the gates below
|
||||
# would be served from cache and this build would exit 0 in under a
|
||||
# second having run no linter. script/lint passes a fresh value on every
|
||||
# invocation.
|
||||
#
|
||||
# Each gate RUN must reference the value, because BuildKit hashes the
|
||||
# expanded command and not the ARG declaration: a declared but
|
||||
# unreferenced ARG invalidates nothing. The ARG sits below the
|
||||
# dependency layers deliberately — everything above it keeps its cache,
|
||||
# only the gates go cold.
|
||||
# Each gate RUN must reference the value: BuildKit hashes the expanded
|
||||
# command, so a declared but unreferenced ARG invalidates nothing. Keep
|
||||
# it below the dependency layers so they stay cached.
|
||||
ARG CHECK_EPOCH
|
||||
|
||||
# The linter version is pinned in two places, here and in the main
|
||||
# Dockerfile's lint stage. Nothing else keeps them in sync, so a
|
||||
# half-applied bump is a build failure; see the script.
|
||||
# Fails the build when the FROM above and the main Dockerfile's lint
|
||||
# stage pin different linter images.
|
||||
RUN echo "gate lint-image-pin, epoch ${CHECK_EPOCH}" && \
|
||||
script/verify-lint-image-pin
|
||||
|
||||
# Validates .golangci.yml against golangci-lint's JSON schema. The
|
||||
# concern about this step was that it fetches that schema over a live,
|
||||
# unpinned HTTPS call; measured on the pinned image, it does not. The
|
||||
# binary carries the schema for its own version, so under
|
||||
# `--network none` this both passes on a valid config and still rejects
|
||||
# an invalid one with the jsonschema error. That holds for the gate
|
||||
# steps generally — none of them makes a network call — but not for
|
||||
# this build as a whole: `go mod download` above needs the network on a
|
||||
# cold cache, and under `--network none` a first build fails there
|
||||
# before reaching any gate. That layer stays cached, so only a warm
|
||||
# cache lints offline, until go.mod or go.sum changes.
|
||||
# Validates .golangci.yml against golangci-lint's JSON schema, which the
|
||||
# pinned binary embeds: measured under `--network none`, it passes a
|
||||
# valid config and rejects an invalid one. No gate step makes a network
|
||||
# call, but `go mod download` above needs the network on a cold cache.
|
||||
RUN echo "gate config verify, epoch ${CHECK_EPOCH}" && \
|
||||
golangci-lint config verify --config .golangci.yml
|
||||
|
||||
|
||||
Reference in New Issue
Block a user