check / check (push) Failing after 3s
Completed Steps entries keep what landed, the traps, every disclosure and every record that a check ran; the argument and history go, with bare issue numbers turned into full links. Comment blocks in script/, Dockerfile and Dockerfile.lint keep the trap and drop the defence of past decisions. TODO.md Workflow now branches from next, targets next, and leaves merging next to main to the owner. Only comments and Markdown change. Model: opus-5-5
78 lines
2.5 KiB
Bash
Executable File
78 lines
2.5 KiB
Bash
Executable File
#!/bin/sh
|
|
# script/verify-lint-image-pin: fail unless the golangci-lint image
|
|
# referenced by Dockerfile.lint and the one referenced by the main
|
|
# Dockerfile's lint stage are the same image at the same digest. Our own
|
|
# extension to scripts-to-rule-them-all, not one of its entrypoints; run
|
|
# as a gate in both files. Nothing else keeps the two pins in sync, and
|
|
# a bump applied to one alone would lint the same tree against different
|
|
# rulesets, both green.
|
|
#
|
|
# Do not hardcode the expected digest here: that is a third copy to keep
|
|
# in sync.
|
|
#
|
|
# A reference that cannot be read is a hard failure, not a skip: two
|
|
# empty strings compare equal.
|
|
set -eu
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
|
|
|
LINT_DOCKERFILE="Dockerfile.lint"
|
|
MAIN_DOCKERFILE="Dockerfile"
|
|
|
|
# Echo the single golangci-lint image reference in the named Dockerfile.
|
|
# Scans every argument of every FROM instruction rather than assuming a
|
|
# field position, so `FROM --platform=... img AS stage` reads correctly.
|
|
# Exits non-zero, with a diagnosis, unless there is exactly one.
|
|
lint_image_ref() {
|
|
file="$1"
|
|
|
|
if [ ! -f "$file" ]; then
|
|
echo "verify-lint-image-pin: $file: not found" >&2
|
|
return 1
|
|
fi
|
|
|
|
refs="$(
|
|
awk '
|
|
toupper($1) == "FROM" {
|
|
for (i = 2; i <= NF; i++) {
|
|
if ($i ~ /^golangci\/golangci-lint[:@]/) {
|
|
print $i
|
|
}
|
|
}
|
|
}
|
|
' "$file"
|
|
)"
|
|
|
|
count="$(printf '%s' "$refs" | grep -c . || true)"
|
|
if [ "$count" -ne 1 ]; then
|
|
echo "verify-lint-image-pin: $file: expected exactly one" \
|
|
"golangci/golangci-lint FROM reference, found $count" >&2
|
|
return 1
|
|
fi
|
|
|
|
printf '%s\n' "$refs"
|
|
}
|
|
|
|
main() {
|
|
cd "$ROOT"
|
|
|
|
lint_ref="$(lint_image_ref "$LINT_DOCKERFILE")"
|
|
main_ref="$(lint_image_ref "$MAIN_DOCKERFILE")"
|
|
|
|
if [ "$lint_ref" != "$main_ref" ]; then
|
|
echo "verify-lint-image-pin: the linter image is pinned twice and" \
|
|
"the two pins disagree:" >&2
|
|
echo "verify-lint-image-pin: $LINT_DOCKERFILE: $lint_ref" >&2
|
|
echo "verify-lint-image-pin: $MAIN_DOCKERFILE: $main_ref" >&2
|
|
echo "verify-lint-image-pin: bump both FROM lines together so" \
|
|
"script/lint and the Dockerfile lint stage keep running the" \
|
|
"same linter" >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "verify-lint-image-pin: $LINT_DOCKERFILE and $MAIN_DOCKERFILE" \
|
|
"agree on $lint_ref"
|
|
}
|
|
|
|
main "$@"
|