Re-vendor the canonical files from sneak/prompts at dd4027b (closes #213)
check / check (push) Failing after 26s

Linting and testing become the lint and test phases of the Dockerfile,
and the build stage depends on both. Dockerfile.lint, CHECK_EPOCH and
the tests that checked them are removed. Every docker build in script/
passes --no-cache, and script/cibuild runs script/bootstrap first. A
host without Go gets the go.mod version from script/install-go in
.tool/go, which the Makefile, script/fmt, script/fmt-check and
script/precommit add to PATH; fmt-check reads the Go files git lists.
The image takes its version from the VERSION build arg or git describe,
dev without .git. This repo's own entries follow the canonical content
in .gitignore and .editorconfig. The golangci-lint v2.14.0 findings are
fixed. The rules in CLAUDE.md move into AGENTS.md. IsDevVersion counts
"unknown".

Model: opus-5-5
This commit is contained in:
2026-10-06 07:57:02 +00:00
parent 4a167e153a
commit 94c577e22a
39 changed files with 903 additions and 1217 deletions
-2
View File
@@ -16,8 +16,6 @@ var (
// Size represents a byte size that can be specified in configuration files.
// It can unmarshal from both numeric values (interpreted as bytes) and
// human-readable strings like "10MB", "2.5GB", or "1TB".
//
//nolint:recvcheck // UnmarshalYAML requires a pointer; String/Int64 are value reads
type Size int64
// UnmarshalYAML implements yaml.Unmarshaler for Size, allowing it to be
+1 -1
View File
@@ -220,7 +220,7 @@ func (r *ChunkFileRepository) CreateBatch(
cf.ChunkHash.String(), cf.FileID.String(), cf.FileOffset, cf.Length)
}
query += querySb183.String() //nolint:gosec // G202: appends "?" placeholders only
query += querySb183.String()
query += " ON CONFLICT(chunk_hash, file_id) DO NOTHING"
+1 -1
View File
@@ -98,7 +98,7 @@ func (r *ChunkRepository) GetByHashes(
args[i] = hash
}
query += querySb75.String() //nolint:gosec // G202: appends "?" placeholders only
query += querySb75.String()
query += ") ORDER BY chunk_hash"
+1 -1
View File
@@ -253,7 +253,7 @@ func (r *FileChunkRepository) CreateBatch(
args = append(args, fc.FileID.String(), fc.Idx, fc.ChunkHash.String())
}
query += querySb211.String() //nolint:gosec // G202: appends "?" placeholders only
query += querySb211.String()
query += " ON CONFLICT(file_id, idx) DO NOTHING"
+1 -1
View File
@@ -391,7 +391,7 @@ func (r *FileRepository) CreateBatch(
f.LinkTarget.String())
}
query += querySb325.String() //nolint:gosec // G202: appends "?" placeholders only
query += querySb325.String()
query += ` ON CONFLICT(path) DO UPDATE SET
source_path = excluded.source_path,
+1 -1
View File
@@ -395,7 +395,7 @@ func (r *SnapshotRepository) AddFilesByIDBatch(
args = append(args, snapshotID, fileID.String())
}
query += querySb312.String() //nolint:gosec // G202: appends "?" placeholders only
query += querySb312.String()
var err error
if tx != nil {
+11 -4
View File
@@ -18,14 +18,19 @@ var Appname = "vaultik" //nolint:gochecknoglobals // set via -ldflags at build t
// deliberately not a number.
const DevVersion = "dev"
// Unknown is what Commit and CommitDate hold when the build did not
// stamp them, and the version script/docker and script/cibuild stamp
// when the host has no git checkout.
const Unknown = "unknown"
// Version is the application version, populated from main().
var Version = DevVersion //nolint:gochecknoglobals // set via -ldflags at build time
// Commit is the git commit hash, populated from main().
var Commit = "unknown" //nolint:gochecknoglobals // set via -ldflags at build time
var Commit = Unknown //nolint:gochecknoglobals // set via -ldflags at build time
// CommitDate is the ISO-8601 date of the commit, populated from main().
var CommitDate = "unknown" //nolint:gochecknoglobals // set via -ldflags at build time
var CommitDate = Unknown //nolint:gochecknoglobals // set via -ldflags at build time
// Author identifies the upstream author of vaultik.
const Author = "Jeffrey Paul <sneak@sneak.berlin>"
@@ -72,9 +77,11 @@ func New() (*Globals, error) {
// safe reading of "we could not establish that this is a release" is
// that it is not one. The Makefile refuses to build at all in that
// case; this is the second line of defence, for a binary linked by
// something other than the Makefile.
// something other than the Makefile. Unknown counts for the same
// reason.
func IsDevVersion(v string) bool {
if v == "" || v == DevVersion || strings.HasPrefix(v, DevVersion+"-") ||
if v == "" || v == Unknown || v == DevVersion ||
strings.HasPrefix(v, DevVersion+"-") ||
strings.HasSuffix(v, "-dirty") {
return true
}
+3
View File
@@ -74,6 +74,9 @@ func TestIsDevVersion(t *testing.T) {
// as one. The Makefile refuses to build when script/version
// yields nothing; this covers a binary linked some other way.
{"", true},
// What script/docker and script/cibuild stamp when the host
// has no git checkout.
{"unknown", true},
}
for _, tc := range cases {
+1 -2
View File
@@ -1377,8 +1377,7 @@ func (s *Scanner) processFileWithErrorHandling(
// record a file whose chunk is in no blob and cannot be restored, so
// abort the run even under --skip-errors. Only open and read errors
// are skipped below.
var pErr *packerError
if errors.As(err, &pErr) {
if _, ok := errors.AsType[*packerError](err); ok {
return false, fmt.Errorf("processing file %s: %w", fileToProcess.Path, err)
}
// Handle files that were deleted between scan and process phases
+1 -2
View File
@@ -161,8 +161,7 @@ func rejectUnknownParams(query url.Values, allowed ...string) error {
// *url.Error that url.Parse returns embeds the raw URL in its message, so
// wrapping it directly would echo a credential-bearing URL into logs.
func wrapParseError(err error) error {
var uerr *url.Error
if errors.As(err, &uerr) {
if uerr, ok := errors.AsType[*url.Error](err); ok {
return fmt.Errorf("invalid URL: %w", uerr.Err)
}