From 8f880943078312e7a945ee5c77400a1a9edcbc81 Mon Sep 17 00:00:00 2001 From: sneak Date: Tue, 22 Sep 2026 07:51:55 +0000 Subject: [PATCH] Install pinned goimports in script/bootstrap (closes #184) script/fmt runs gofmt, goimports, and npx prettier, but bootstrap installed only git, make, go, and golangci-lint, so `make fmt` failed with `goimports: not found` on a fresh machine. bootstrap's contract is to install all dependencies idempotently. Add ensure_goimports: it skips when goimports is already on PATH, otherwise `go install`s golang.org/x/tools/cmd/goimports at a pinned exact version (v0.49.0; integrity via the Go module checksum database) and places the binary in /usr/local/bin so it is on PATH regardless of shell config, mirroring the golangci-lint release install. v0.49.0 requires Go 1.25, matching go.mod; v0.50.0 would force a Go 1.26 toolchain download. Model: opus-4-8 --- TODO.md | 3 +++ script/bootstrap | 21 ++++++++++++++++++++- 2 files changed, 23 insertions(+), 1 deletion(-) diff --git a/TODO.md b/TODO.md index 06257f2..0f7610e 100644 --- a/TODO.md +++ b/TODO.md @@ -25,6 +25,9 @@ main cannot regress. - 2026-09-22: Fixed the gosec G703 path-traversal finding in the deploy log download handler by verifying the resolved path stays within the deploy log directory before serving, returning 404 on escape (#177). +- 2026-09-22: `script/bootstrap` now installs a pinned `goimports` + (`golang.org/x/tools` v0.49.0) into `/usr/local/bin`, so `make fmt` + succeeds on a fresh machine after `make bootstrap` (#184). - 2026-09-09: Fixed four deployability blockers found by QA: CSRF origin check over plain HTTP (`UPAAS_PLAINTEXT_HTTP`, #189), pulling the git image when absent (#190), the env-var editor CSRF token lookup (#191), diff --git a/script/bootstrap b/script/bootstrap index f1b3e30..34b2b13 100755 --- a/script/bootstrap +++ b/script/bootstrap @@ -5,7 +5,9 @@ # or apk (detected in that order); assumes NOTHING is present (not git, # make, or go). golangci-lint is packaged in nix, brew, and apk; on apt # it is installed from a hash-verified GitHub release archive (never -# curl | sh). +# curl | sh). goimports is installed with `go install` at a pinned +# version (integrity via the Go module checksum database) into +# /usr/local/bin so it is on PATH. set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" @@ -15,6 +17,9 @@ GOLANGCI_LINT_VERSION="2.12.2" # sha256 of golangci-lint-2.12.2-linux-.tar.gz release archives GOLANGCI_LINT_SHA256_AMD64="8df580d2670fed8fa984aac0507099af8df275e665215f5c7a2ae3943893a553" GOLANGCI_LINT_SHA256_ARM64="44cd40a8c76c86755375adfeea52cfd3533cb43d7bd647771e0ae065e166df3a" +# golang.org/x/tools goimports, 2026-08-13. v0.49.0 requires Go 1.25 (matches +# go.mod); v0.50.0 needs Go 1.26. Integrity via the Go module checksum database. +GOIMPORTS_VERSION="v0.49.0" PKGMGR="" SUDO="" @@ -102,6 +107,19 @@ ensure_golangci_lint() { esac } +# goimports is not packaged uniformly across nix/apt/brew/apk, so install it +# with `go install` at a pinned version and place the binary in /usr/local/bin +# so it is on PATH regardless of shell config, as the golangci-lint release +# install does. Requires go, which main installs first. +ensure_goimports() { + if ! missing goimports; then return 0; fi + detect_pkgmgr + tmp="$(mktemp -d)" + GOBIN="$tmp" go install "golang.org/x/tools/cmd/goimports@${GOIMPORTS_VERSION}" + $SUDO install -m 0755 "$tmp/goimports" /usr/local/bin/goimports + rm -rf "$tmp" +} + main() { cd "$ROOT" @@ -112,6 +130,7 @@ main() { # Go toolchain and linter if missing go; then pkg_install go golang go go; fi ensure_golangci_lint + ensure_goimports go mod download -- 2.54.0