Re-vendor the canonical files from sneak/prompts at dd4027b (closes #213)
check / check (push) Successful in 13m48s

Linting and testing become the lint and test phases of the Dockerfile,
and the build stage depends on both. Dockerfile.lint, CHECK_EPOCH and
the tests that checked them are removed. Every docker build in script/
passes --no-cache, and script/cibuild runs script/bootstrap first. A
host without Go gets the go.mod version from script/install-go in
.tool/go, which bootstrap, the Makefile, fmt, fmt-check, precommit and
release add to PATH; fmt-check skips .tool. The image takes its version
from the VERSION build arg or git describe, dev without .git. This
repo's own entries follow the canonical content in .gitignore and
.editorconfig. The golangci-lint v2.14.0 findings are fixed. The rules
in CLAUDE.md move into AGENTS.md. IsDevVersion counts "unknown".

Model: opus-5-5
This commit is contained in:
2026-10-06 09:32:09 +00:00
parent c4adb72d80
commit 53926fbea5
40 changed files with 892 additions and 1217 deletions
+27 -20
View File
@@ -48,12 +48,12 @@ missing() {
! command -v "$1" >/dev/null 2>&1
}
# Docker is a hard requirement, not a nice-to-have: script/lint lints by
# building Dockerfile.lint, whose digest-pinned golangci-lint image is
# the only place the linter runs, and script/check and script/precommit
# both run script/lint. A bootstrap that prints "bootstrap complete" on a
# machine where `make check` cannot run is a false success, so this fails
# instead.
# Docker is a hard requirement, not a nice-to-have: script/lint and
# script/test build the lint and test phases of the Dockerfile, the only
# place the linter and the tests run, and script/check and
# script/precommit both run them. A bootstrap that prints "bootstrap
# complete" on a machine where `make check` cannot run is a false
# success, so this fails instead.
#
# Installing docker from here was considered and rejected: it needs root,
# a running daemon, and on macOS a GUI cask, so an attempt would itself
@@ -80,15 +80,15 @@ bootstrap: FAILED - $reason.
Docker is required to develop this repo. Without it these do not work:
script/lint builds Dockerfile.lint, which runs the linter as a
build step in a digest-pinned golangci-lint image.
That FROM line is the single source of truth for the
linter version
script/check runs script/lint
script/lint builds the lint phase of the Dockerfile, which runs
the linter as a build step in a digest-pinned
golangci-lint image
script/test builds the test phase of the Dockerfile
script/check runs script/test and script/lint
script/precommit runs script/check, so commits are blocked by the
pre-commit hook installed by script/setup
script/cibuild builds Dockerfile.lint and Dockerfile, which is what
CI runs
script/cibuild runs script/check and builds the image, which is
what CI runs
Install docker (and start the daemon, checking DOCKER_HOST and your
group membership), then re-run script/bootstrap. golangci-lint on PATH
@@ -104,15 +104,22 @@ main() {
if missing git; then pkg_install git git git git; fi
if missing make; then pkg_install gnumake make make make; fi
# Go toolchain
if missing go; then pkg_install go golang go go; fi
# Go toolchain: the host's own, or else the version go.mod names,
# hash-verified, in .tool/go. That directory is not on the caller's
# PATH; this script, the Makefile, script/fmt, script/fmt-check,
# script/precommit and script/release add it to theirs.
if missing go; then
"$ROOT/script/install-go"
PATH="$PATH:$ROOT/.tool/go/bin"
fi
# golangci-lint is deliberately NOT installed: script/lint lints by
# building Dockerfile.lint, whose digest-pinned image is the only
# place the linter runs, so whatever a package manager happens to
# ship would only be a shadow of the pinned version that could drift
# from CI. Nothing on the host is ever used as a linter, at any
# version, so installing one here would buy nothing.
# building the lint phase of the Dockerfile, whose digest-pinned
# image is the only place the linter runs, so whatever a package
# manager happens to ship would only be a shadow of the pinned
# version that could drift from CI. Nothing on the host is ever used
# as a linter, at any version, so installing one here would buy
# nothing.
# goreleaser, at the version pinned by script/install-goreleaser and
# verified against a hardcoded sha256. Package managers are not used