All checks were successful
check / check (push) Successful in 6s
Bring the repo into conformance with the scripts-to-rule-them-all (STRTA) scaffold. The real logic that lived inline in the Makefile now lives in POSIX-sh entrypoints under script/, and the Makefile's standard targets are thin @script/NAME shims. - script/: bootstrap, setup, projectname, test, lint, fmt, fmt-check, check, docker, precommit, install-precommit, cibuild. All are executable #!/bin/sh entrypoints; the go mod tidy guard from the old inline hooks recipe moved into script/precommit. - Makefile: the nine standard targets (bootstrap, setup, test, lint, fmt, fmt-check, check, docker, hooks) are now thin shims; the repo-specific sfdupes/build/clean targets and the CGO_ENABLED export are preserved. - .gitea/workflows/check.yml: run script/cibuild instead of a bare docker build. - Dockerfile: run make check (and the build) as an unprivileged builder user rather than root. We should never build or run as root, and doing so also lets the permission-denied tests run legitimately: root bypasses the chmod(0) that TestScanHardlinkRunFailsTogether relies on, which made the in-image make check fail. HOME and the Go caches point at the user's home so go build/test and golangci-lint can write. make check passes locally and docker build . is green (the in-image non-root make check passes, including the hardlink permission test).
54 lines
1.6 KiB
Docker
54 lines
1.6 KiB
Docker
# Lint stage — fast feedback on formatting and lint issues
|
|
# golangci/golangci-lint:v2.12.1, 2026-07-23
|
|
FROM golangci/golangci-lint@sha256:c9843d374ca80ecbac86081ec4dd7fe2bb6187b03224f59a0cc2f80759e1845b AS lint
|
|
WORKDIR /src
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
COPY . .
|
|
RUN make fmt-check
|
|
RUN make lint
|
|
|
|
# Build stage
|
|
# golang:1.25-alpine, 2026-07-23
|
|
FROM golang@sha256:56961d79ea8129efddcc0b8643fd8a5416b4e6228cfd477e3fd61deb2672c587 AS builder
|
|
|
|
RUN apk add --no-cache make
|
|
|
|
# We never build or run as root. Create an unprivileged user and point
|
|
# HOME and the Go caches at its home so go build/test and golangci-lint
|
|
# can write their caches when we drop to it below.
|
|
RUN adduser -D -u 1000 builder
|
|
ENV HOME=/home/builder
|
|
ENV GOPATH=/home/builder/go
|
|
ENV GOCACHE=/home/builder/.cache/go-build
|
|
|
|
WORKDIR /src
|
|
|
|
# Reuse the linter binary from the lint stage; the copy also forces
|
|
# BuildKit to complete linting before this stage proceeds.
|
|
COPY --from=lint /usr/bin/golangci-lint /usr/local/bin/golangci-lint
|
|
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
COPY . .
|
|
|
|
# Hand the sources and caches to the unprivileged user, then drop root
|
|
# before running any checks or builds.
|
|
RUN chown -R builder:builder /src /home/builder
|
|
USER builder
|
|
|
|
# Fail the build unless the branch is green. Runs as non-root so the
|
|
# permission-denied test paths are exercised legitimately (root would
|
|
# bypass the chmod(0) the tests rely on).
|
|
RUN make check
|
|
|
|
RUN make build
|
|
|
|
# Runtime stage
|
|
# alpine:3.22, 2026-07-23
|
|
FROM alpine@sha256:14358309a308569c32bdc37e2e0e9694be33a9d99e68afb0f5ff33cc1f695dce
|
|
|
|
COPY --from=builder /src/sfdupes /usr/local/bin/sfdupes
|
|
|
|
ENTRYPOINT ["sfdupes"]
|