From bbf73fe31dcf669138a4361bf09e2b1b07410748 Mon Sep 17 00:00:00 2001 From: sneak Date: Tue, 6 Oct 2026 03:11:54 +0000 Subject: [PATCH] Run the linter only in Docker (closes #20) script/lint now builds only the lint stage of the Dockerfile, without the build cache, so every run executes the linter; the image is tagged simplelog-lint. The lint stage calls golangci-lint directly, since make lint is itself a docker build of that stage. script/cibuild and script/docker also build without the cache, so their check steps always run. script/fmt no longer runs golangci-lint --fix, and script/bootstrap no longer installs it. golangci-lint config verify is left out, on the owner's ruling. The README, TODO.md and the script/cibuild comment say what now runs. Model: opus-5-5 --- Dockerfile | 3 ++- README.md | 21 ++++++++++++--------- TODO.md | 4 ++++ script/bootstrap | 7 +------ script/cibuild | 10 ++++++---- script/docker | 3 ++- script/fmt | 1 - script/lint | 13 ++++++++++--- 8 files changed, 37 insertions(+), 25 deletions(-) diff --git a/Dockerfile b/Dockerfile index 31c56bf..d7d21fe 100644 --- a/Dockerfile +++ b/Dockerfile @@ -6,7 +6,8 @@ COPY go.mod go.sum ./ RUN go mod download COPY . . RUN make fmt-check -RUN make lint +# Called directly: make lint is itself a docker build of this stage. +RUN golangci-lint run --config .golangci.yml ./... # Test stage: run full test suite # golang 1.22.12 (2025-02-04) diff --git a/README.md b/README.md index 4cd1a4f..c6b5e83 100644 --- a/README.md +++ b/README.md @@ -113,24 +113,27 @@ development workflow, and the Makefile targets are thin shims that call them. The scripts are POSIX sh (not bash) so they run in minimal containers such as alpine. We provide: -- `script/bootstrap` — install all dependencies (go and golangci-lint if - missing, then `go mod download`) +- `script/bootstrap` — install all dependencies (go if missing, then + `go mod download`); golangci-lint is not installed, since it runs only in + Docker - `script/setup` — set up the repo for development after a fresh clone: runs `script/bootstrap`, then `script/install-precommit` - `script/projectname` — output the project name (our own extension); used by `script/docker` for the image tag - `script/test` — run the test suite (`go test -v ./...`) -- `script/lint` — run golangci-lint -- `script/fmt` — format all files (goimports plus `golangci-lint run --fix`; - writes) +- `script/lint` — run golangci-lint in Docker by building only the `lint` + stage of the `Dockerfile` (which also runs the format check), without the + build cache, so every run lints; the image is tagged `simplelog-lint` +- `script/fmt` — format all files with goimports (writes) - `script/fmt-check` — check formatting (read-only); fails if `gofmt -l` reports files - `script/check` — run all checks: `test`, `lint`, `fmt-check` (our own extension) -- `script/docker` — build the Docker image, tagged via `script/projectname` - (byte-identical across repos) -- `script/cibuild` — cd to the repo root and `docker build .` (what CI runs; - the image build runs the checks) +- `script/docker` — build the Docker image without the build cache, tagged + via `script/projectname` (byte-identical across repos) +- `script/cibuild` — cd to the repo root and build the Docker image without the + build cache, tagged via `script/projectname` (what CI runs; the image build + runs the checks) - `script/precommit` — run by the git pre-commit hook (our own extension); runs a `go mod tidy` guard, then `script/check` - `script/install-precommit` — installs the git pre-commit hook (our own diff --git a/TODO.md b/TODO.md index 7cfdd45..9444eb9 100644 --- a/TODO.md +++ b/TODO.md @@ -24,6 +24,10 @@ files it depends on: .golangci.yml, REPO_POLICIES.md, .editorconfig, # Completed Steps +* 2026-10-06: the linter runs only in Docker: `script/lint` builds the + `lint` stage of the `Dockerfile`, every `docker build` in `script/` + runs without the build cache, and `script/bootstrap` no longer + installs golangci-lint * 2026-08-10: fixed every handler discarding slog attributes: console, JSON and webhook handlers now emit record attributes, accumulate WithAttrs without mutating the receiver, and honour WithGroup; diff --git a/script/bootstrap b/script/bootstrap index afece87..d0f3814 100755 --- a/script/bootstrap +++ b/script/bootstrap @@ -54,12 +54,7 @@ main() { if missing git; then pkg_install git git git git; fi if missing go; then pkg_install go golang go go; fi - # golangci-lint is packaged in nix, brew, and apk; there is no apt - # package (on apt hosts, install it from a hash-verified GitHub - # release archive manually, never curl | sh). - if missing golangci-lint; then - pkg_install golangci-lint golangci-lint golangci-lint golangci-lint - fi + # golangci-lint is not installed: it runs only in docker (script/lint). go mod download diff --git a/script/cibuild b/script/cibuild index 75cc3e6..8b13f21 100755 --- a/script/cibuild +++ b/script/cibuild @@ -1,13 +1,15 @@ #!/bin/sh -# script/cibuild: run the CI build. The Dockerfile runs script/check, so -# a successful build implies all checks pass. +# script/cibuild: run the CI build. The Dockerfile runs the format check, +# the linter and the tests, so a successful build means they all pass. +# --no-cache because a cached check step is a check that did not run. set -eu -ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" +SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" +ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)" main() { cd "$ROOT" - docker build . + docker build --no-cache -t "$("$SCRIPT_DIR/projectname")" . } main "$@" diff --git a/script/docker b/script/docker index 9b9ea86..0d05036 100755 --- a/script/docker +++ b/script/docker @@ -1,6 +1,7 @@ #!/bin/sh # script/docker: build the Docker image tagged with the project name. # Identical in all repos; the tag comes from script/projectname. +# --no-cache because a cached check step is a check that did not run. set -eu SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" @@ -8,7 +9,7 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)" main() { cd "$ROOT" - docker build -t "$("$SCRIPT_DIR/projectname")" . + docker build --no-cache -t "$("$SCRIPT_DIR/projectname")" . } main "$@" diff --git a/script/fmt b/script/fmt index 216a8aa..64817df 100755 --- a/script/fmt +++ b/script/fmt @@ -7,7 +7,6 @@ ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" main() { cd "$ROOT" goimports -l -w . - golangci-lint run --fix } main "$@" diff --git a/script/lint b/script/lint index 004c999..44efda2 100755 --- a/script/lint +++ b/script/lint @@ -1,12 +1,19 @@ #!/bin/sh -# script/lint: run the linter. +# script/lint: run the linter, in docker only, by building the lint stage +# of the Dockerfile and nothing else; the build fails on any finding. +# --no-cache makes every run execute the linter: a cached build of an +# unchanged tree succeeds without linting anything. The tag makes each +# build replace the previous image instead of leaving an untagged one. set -eu -ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" +SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" +ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)" main() { cd "$ROOT" - golangci-lint run + docker build --no-cache \ + --target lint \ + -t "$("$SCRIPT_DIR/projectname")-lint" . } main "$@"