Drop the lint-guard shell scanner, keep the Dockerfile.lint checks (closes #121)
The guard test in cmd/vaultik/lintdocker_test.go tried to prove that no script runs the linter outside the container by parsing shell scripts with a hand-written scanner. Four reviews each found another spelling it missed; such a parser cannot be complete, and nobody could follow it in one reading. The scanner, its helpers and their tests are deleted. The plain Dockerfile.lint assertions stay: the linter image is pinned by digest, config verify runs before run, and the per-run value reaches both steps. TODO.md no longer claims a test proves the property; script/lint is the only lint entry point, and keeping it so is a review matter. Judgement call: this drops a guard two reviewers asked to harden. model: claude-opus-4-8 (implementation, review); claude-fable-5-1 (decision, merge)
This commit was merged in pull request #135.
This commit is contained in:
@@ -88,10 +88,11 @@ release" is exactly the contradiction
|
||||
into each check command, and a fresh `$(date +%s%N)$$` per invocation
|
||||
computed as a bare assignment. `cmd/vaultik/lintdocker_test.go`
|
||||
parses both Dockerfiles and both scripts and fails if any part of
|
||||
that is dropped, because every way of losing it is silent. Its
|
||||
host-lint assertion is structural — no script runs `golangci-lint`
|
||||
except through `docker` — rather than a search for the one retired
|
||||
variable name, which nothing could ever reintroduce.
|
||||
that is dropped, because every way of losing it is silent. No test
|
||||
asserts that no script runs the host linter: `script/lint` is the one
|
||||
lint entry point and runs `golangci-lint` only inside the container,
|
||||
and keeping it that way is a review matter, not something a test
|
||||
proves.
|
||||
|
||||
The product `Dockerfile` lost its lint stage rather than gaining a
|
||||
second linter pin: `make lint` is now `docker build`, so the stage
|
||||
|
||||
Reference in New Issue
Block a user