Re-vendor the standard files from sneak/prompts dd4027b (closes #33)
check / check (push) Failing after 5s

REPO_POLICIES.md, .golangci.yml, the CI workflow and the scripts the
policy keeps identical across repositories are copies of the files at
that commit. .gitignore, .editorconfig and the new .dockerignore are the
canonical files followed by this repository's own entries. The lint
stage moves to the golangci-lint image the policy pins, in the same
commit as .golangci.yml. The format check leaves the lint stage and runs
on the host from script/check, which script/cibuild now runs after
script/bootstrap. The last Dockerfile stage runs script/bootstrap.
script/fmt runs goimports with go run at a pinned commit.

Model: opus-5-5
This commit is contained in:
2026-10-06 12:49:32 +00:00
parent 16fc20b81c
commit d193c99cb7
14 changed files with 639 additions and 126 deletions
+1
View File
@@ -55,6 +55,7 @@ main() {
if missing go; then pkg_install go golang go go; fi
# golangci-lint is not installed: it runs only in docker (script/lint).
# Nor is goimports: script/fmt runs it with `go run` at a pinned commit.
go mod download
+3 -1
View File
@@ -1,6 +1,8 @@
#!/bin/sh
# script/check: run all checks (test, lint, fmt-check). Our own
# extension to scripts-to-rule-them-all. Must not modify any files.
# extension to scripts-to-rule-them-all. test and lint are Docker
# phases; fmt-check is native, because a formatter writes the working
# tree. Must not modify any files.
set -eu
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
+17 -4
View File
@@ -1,7 +1,10 @@
#!/bin/sh
# script/cibuild: run the CI build. The Dockerfile runs the format check,
# the linter and the tests, so a successful build means they all pass.
# --no-cache because a cached check step is a check that did not run.
# script/cibuild: run the CI build. It bootstraps first: a CI runner
# checks out and runs this and nothing else, and script/fmt-check runs
# the formatter on the host, which a pristine checkout cannot do.
# --no-cache for the same reason as script/docker: the gate phases the
# final stage depends on are RUN steps, and a cached one is a check that
# did not run.
set -eu
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
@@ -9,7 +12,17 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
main() {
cd "$ROOT"
docker build --no-cache -t "$("$SCRIPT_DIR/projectname")" .
"$SCRIPT_DIR/bootstrap"
"$SCRIPT_DIR/check"
# Own line: a failing command substitution inside an argument does
# not trip `set -e`, so the inline form degrades silently to an
# empty constant. The VERSION build argument takes precedence over
# the version a build stage derives from the .git in the context.
version="$(git describe --tags --always --dirty 2>/dev/null || true)"
[ -n "$version" ] || version="unknown"
docker build --no-cache \
--build-arg VERSION="$version" \
-t "$("$SCRIPT_DIR/projectname")" .
}
main "$@"
+2 -3
View File
@@ -12,9 +12,8 @@ main() {
cd "$ROOT"
# Own line: a failing command substitution inside an argument does
# not trip `set -e`, so the inline form degrades silently to an
# empty constant. VERSION is computed here because .dockerignore
# excludes .git, so `git describe` in a build stage yields an empty
# version without failing.
# empty constant. The VERSION build argument takes precedence over
# the version a build stage derives from the .git in the context.
version="$(git describe --tags --always --dirty 2>/dev/null || true)"
[ -n "$version" ] || version="unknown"
docker build --no-cache \
+7 -2
View File
@@ -1,12 +1,17 @@
#!/bin/sh
# script/fmt: format all files (writes).
# script/fmt: format all files (writes). goimports runs with `go run` at
# a pinned commit, so nothing installs it and every machine formats with
# the same version.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
# goimports from golang.org/x/tools v0.51.0, 2026-10-02
GOIMPORTS="golang.org/x/tools/cmd/goimports@ea2f152dc35325e4b9b639583972375972350a84"
main() {
cd "$ROOT"
goimports -l -w .
go run "$GOIMPORTS" -l -w .
}
main "$@"