#!/bin/sh # script/verify-lint-image-pin: fail unless the golangci-lint image # referenced by Dockerfile.lint and the one referenced by the main # Dockerfile's lint stage are the same image at the same digest. Our own # extension to scripts-to-rule-them-all, not one of its entrypoints; run # as a gate in both files. Nothing else keeps the two pins in sync, and # a bump applied to one alone would lint the same tree against different # rulesets, both green. # # Do not hardcode the expected digest here: that is a third copy to keep # in sync. # # A reference that cannot be read is a hard failure, not a skip: two # empty strings compare equal. set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" LINT_DOCKERFILE="Dockerfile.lint" MAIN_DOCKERFILE="Dockerfile" # Echo the single golangci-lint image reference in the named Dockerfile. # Scans every argument of every FROM instruction rather than assuming a # field position, so `FROM --platform=... img AS stage` reads correctly. # Exits non-zero, with a diagnosis, unless there is exactly one. lint_image_ref() { file="$1" if [ ! -f "$file" ]; then echo "verify-lint-image-pin: $file: not found" >&2 return 1 fi refs="$( awk ' toupper($1) == "FROM" { for (i = 2; i <= NF; i++) { if ($i ~ /^golangci\/golangci-lint[:@]/) { print $i } } } ' "$file" )" count="$(printf '%s' "$refs" | grep -c . || true)" if [ "$count" -ne 1 ]; then echo "verify-lint-image-pin: $file: expected exactly one" \ "golangci/golangci-lint FROM reference, found $count" >&2 return 1 fi printf '%s\n' "$refs" } main() { cd "$ROOT" lint_ref="$(lint_image_ref "$LINT_DOCKERFILE")" main_ref="$(lint_image_ref "$MAIN_DOCKERFILE")" if [ "$lint_ref" != "$main_ref" ]; then echo "verify-lint-image-pin: the linter image is pinned twice and" \ "the two pins disagree:" >&2 echo "verify-lint-image-pin: $LINT_DOCKERFILE: $lint_ref" >&2 echo "verify-lint-image-pin: $MAIN_DOCKERFILE: $main_ref" >&2 echo "verify-lint-image-pin: bump both FROM lines together so" \ "script/lint and the Dockerfile lint stage keep running the" \ "same linter" >&2 exit 1 fi echo "verify-lint-image-pin: $LINT_DOCKERFILE and $MAIN_DOCKERFILE" \ "agree on $lint_ref" } main "$@"