Check / check (pull_request) Successful in 1m29s
Per the owner ruling, linting now runs only inside Docker with the pinned golangci-lint (v2.12.2). A root Dockerfile.lint runs the linter as a build step; script/lint just builds it. A GATE_RUN build arg forces the lint layer to execute every run so a cached build cannot report a false clean. script/bootstrap no longer installs golangci-lint (the goimports install stays). The main Dockerfile lint stage calls golangci-lint directly (no docker-in-docker) and still gates the build. config verify is omitted because it fetches its schema over an unpinned HTTPS call. Model: opus-4-8
97 lines
3.0 KiB
Bash
Executable File
97 lines
3.0 KiB
Bash
Executable File
#!/bin/sh
|
|
# script/bootstrap: install all dependencies needed to build and develop
|
|
# this repo. Idempotent: every install is guarded by a check so already
|
|
# installed tools are skipped. Base tooling comes from nix, apt, brew,
|
|
# or apk (detected in that order); assumes NOTHING is present (not git,
|
|
# make, or go). goimports is installed with `go install` at a pinned
|
|
# version (integrity via the Go module checksum database) into
|
|
# /usr/local/bin so it is on PATH. The linter is not installed here: it
|
|
# runs only in Docker via script/lint, so docker is its sole prerequisite.
|
|
set -eu
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
|
|
|
# Pinned versions. Never "latest"; exact versions only.
|
|
# golang.org/x/tools goimports, 2026-08-13. v0.49.0 requires Go 1.25 (matches
|
|
# go.mod); v0.50.0 needs Go 1.26. Integrity via the Go module checksum database.
|
|
GOIMPORTS_VERSION="v0.49.0"
|
|
|
|
PKGMGR=""
|
|
SUDO=""
|
|
|
|
detect_pkgmgr() {
|
|
[ -n "$PKGMGR" ] && return 0
|
|
if command -v nix-env >/dev/null 2>&1; then
|
|
PKGMGR="nix"
|
|
elif command -v apt-get >/dev/null 2>&1; then
|
|
PKGMGR="apt"
|
|
elif command -v brew >/dev/null 2>&1; then
|
|
PKGMGR="brew"
|
|
elif command -v apk >/dev/null 2>&1; then
|
|
PKGMGR="apk"
|
|
else
|
|
echo "bootstrap: no supported package manager (nix, apt, brew, apk)" >&2
|
|
exit 1
|
|
fi
|
|
if [ "$PKGMGR" = "apt" ]; then
|
|
export DEBIAN_FRONTEND=noninteractive
|
|
if [ "$(id -u)" != "0" ]; then
|
|
SUDO="sudo"
|
|
fi
|
|
fi
|
|
}
|
|
|
|
# pkg_install <nix-attr> <apt-pkg> <brew-formula> <apk-pkg>
|
|
pkg_install() {
|
|
detect_pkgmgr
|
|
case "$PKGMGR" in
|
|
nix) nix-env -iA "nixpkgs.$1" ;;
|
|
apt) $SUDO env DEBIAN_FRONTEND=noninteractive apt-get install -y "$2" ;;
|
|
brew) brew install "$3" ;;
|
|
apk) apk add --no-cache "$4" ;;
|
|
esac
|
|
}
|
|
|
|
missing() {
|
|
! command -v "$1" >/dev/null 2>&1
|
|
}
|
|
|
|
# goimports is not packaged uniformly across nix/apt/brew/apk, so install it
|
|
# with `go install` at a pinned version and place the binary in /usr/local/bin
|
|
# so it is on PATH regardless of shell config. Requires go, which main
|
|
# installs first.
|
|
ensure_goimports() {
|
|
if ! missing goimports; then return 0; fi
|
|
detect_pkgmgr
|
|
tmp="$(mktemp -d)"
|
|
GOBIN="$tmp" go install "golang.org/x/tools/cmd/goimports@${GOIMPORTS_VERSION}"
|
|
$SUDO install -m 0755 "$tmp/goimports" /usr/local/bin/goimports
|
|
rm -rf "$tmp"
|
|
}
|
|
|
|
main() {
|
|
cd "$ROOT"
|
|
|
|
# Base tooling
|
|
if missing git; then pkg_install git git git git; fi
|
|
if missing make; then pkg_install gnumake make make make; fi
|
|
|
|
# Go toolchain
|
|
if missing go; then pkg_install go golang go go; fi
|
|
ensure_goimports
|
|
|
|
# The linter runs only in Docker (script/lint). Warn, don't fail: the
|
|
# rest of the repo works without it.
|
|
if missing docker; then
|
|
echo "bootstrap: WARNING: docker not found; make lint and" >&2
|
|
echo "bootstrap: make check require it. Install docker to run" >&2
|
|
echo "bootstrap: the linter." >&2
|
|
fi
|
|
|
|
go mod download
|
|
|
|
echo "bootstrap complete"
|
|
}
|
|
|
|
main "$@"
|