diff --git a/Dockerfile b/Dockerfile index 31c56bf..d7d21fe 100644 --- a/Dockerfile +++ b/Dockerfile @@ -6,7 +6,8 @@ COPY go.mod go.sum ./ RUN go mod download COPY . . RUN make fmt-check -RUN make lint +# Called directly: make lint is itself a docker build of this stage. +RUN golangci-lint run --config .golangci.yml ./... # Test stage: run full test suite # golang 1.22.12 (2025-02-04) diff --git a/README.md b/README.md index 4cd1a4f..5f1334b 100644 --- a/README.md +++ b/README.md @@ -113,24 +113,26 @@ development workflow, and the Makefile targets are thin shims that call them. The scripts are POSIX sh (not bash) so they run in minimal containers such as alpine. We provide: -- `script/bootstrap` — install all dependencies (go and golangci-lint if - missing, then `go mod download`) +- `script/bootstrap` — install all dependencies (go if missing, then + `go mod download`); golangci-lint is not installed, since it runs only in + Docker - `script/setup` — set up the repo for development after a fresh clone: runs `script/bootstrap`, then `script/install-precommit` - `script/projectname` — output the project name (our own extension); used by `script/docker` for the image tag - `script/test` — run the test suite (`go test -v ./...`) -- `script/lint` — run golangci-lint -- `script/fmt` — format all files (goimports plus `golangci-lint run --fix`; - writes) +- `script/lint` — run golangci-lint in Docker by building only the `lint` + stage of the `Dockerfile` (which also runs the format check), without the + build cache, so every run lints; the image is tagged `simplelog-lint` +- `script/fmt` — format all files with goimports (writes) - `script/fmt-check` — check formatting (read-only); fails if `gofmt -l` reports files - `script/check` — run all checks: `test`, `lint`, `fmt-check` (our own extension) -- `script/docker` — build the Docker image, tagged via `script/projectname` - (byte-identical across repos) -- `script/cibuild` — cd to the repo root and `docker build .` (what CI runs; - the image build runs the checks) +- `script/docker` — build the Docker image without the build cache, tagged + via `script/projectname` (byte-identical across repos) +- `script/cibuild` — cd to the repo root and `docker build --no-cache .` (what + CI runs; the image build runs the checks) - `script/precommit` — run by the git pre-commit hook (our own extension); runs a `go mod tidy` guard, then `script/check` - `script/install-precommit` — installs the git pre-commit hook (our own diff --git a/TODO.md b/TODO.md index 7cfdd45..9444eb9 100644 --- a/TODO.md +++ b/TODO.md @@ -24,6 +24,10 @@ files it depends on: .golangci.yml, REPO_POLICIES.md, .editorconfig, # Completed Steps +* 2026-10-06: the linter runs only in Docker: `script/lint` builds the + `lint` stage of the `Dockerfile`, every `docker build` in `script/` + runs without the build cache, and `script/bootstrap` no longer + installs golangci-lint * 2026-08-10: fixed every handler discarding slog attributes: console, JSON and webhook handlers now emit record attributes, accumulate WithAttrs without mutating the receiver, and honour WithGroup; diff --git a/script/bootstrap b/script/bootstrap index afece87..d0f3814 100755 --- a/script/bootstrap +++ b/script/bootstrap @@ -54,12 +54,7 @@ main() { if missing git; then pkg_install git git git git; fi if missing go; then pkg_install go golang go go; fi - # golangci-lint is packaged in nix, brew, and apk; there is no apt - # package (on apt hosts, install it from a hash-verified GitHub - # release archive manually, never curl | sh). - if missing golangci-lint; then - pkg_install golangci-lint golangci-lint golangci-lint golangci-lint - fi + # golangci-lint is not installed: it runs only in docker (script/lint). go mod download diff --git a/script/cibuild b/script/cibuild index 75cc3e6..79e180e 100755 --- a/script/cibuild +++ b/script/cibuild @@ -1,13 +1,14 @@ #!/bin/sh -# script/cibuild: run the CI build. The Dockerfile runs script/check, so -# a successful build implies all checks pass. +# script/cibuild: run the CI build. The Dockerfile runs the format check, +# the linter and the tests, so a successful build means they all pass. +# --no-cache because a cached check step is a check that did not run. set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" main() { cd "$ROOT" - docker build . + docker build --no-cache . } main "$@" diff --git a/script/docker b/script/docker index 9b9ea86..0d05036 100755 --- a/script/docker +++ b/script/docker @@ -1,6 +1,7 @@ #!/bin/sh # script/docker: build the Docker image tagged with the project name. # Identical in all repos; the tag comes from script/projectname. +# --no-cache because a cached check step is a check that did not run. set -eu SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" @@ -8,7 +9,7 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)" main() { cd "$ROOT" - docker build -t "$("$SCRIPT_DIR/projectname")" . + docker build --no-cache -t "$("$SCRIPT_DIR/projectname")" . } main "$@" diff --git a/script/fmt b/script/fmt index 216a8aa..64817df 100755 --- a/script/fmt +++ b/script/fmt @@ -7,7 +7,6 @@ ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" main() { cd "$ROOT" goimports -l -w . - golangci-lint run --fix } main "$@" diff --git a/script/lint b/script/lint index 004c999..44efda2 100755 --- a/script/lint +++ b/script/lint @@ -1,12 +1,19 @@ #!/bin/sh -# script/lint: run the linter. +# script/lint: run the linter, in docker only, by building the lint stage +# of the Dockerfile and nothing else; the build fails on any finding. +# --no-cache makes every run execute the linter: a cached build of an +# unchanged tree succeeds without linting anything. The tag makes each +# build replace the previous image instead of leaving an untagged one. set -eu -ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" +SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" +ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)" main() { cd "$ROOT" - golangci-lint run + docker build --no-cache \ + --target lint \ + -t "$("$SCRIPT_DIR/projectname")-lint" . } main "$@"