Compare commits

..
1 Commits
Author SHA1 Message Date
sneak d98b1a55db Re-vendor the canonical files from sneak/prompts at dd4027b (closes #213)
check / check (push) Successful in 18m13s
Linting and testing become the lint and test phases of the Dockerfile,
and the build stage depends on both. Dockerfile.lint, CHECK_EPOCH and
the tests that checked them are removed. Every docker build in script/
passes --no-cache, and script/cibuild runs script/bootstrap first. A
host without Go gets the go.mod version from script/install-go in
.tool/go, where script/fmt and script/fmt-check also look; fmt-check
reads only the Go files git lists. The image takes its version from the
VERSION build arg or git describe, dev without .git. This repo's own
entries follow the canonical content in .gitignore and .editorconfig.
The golangci-lint v2.14.0 findings are fixed. The rules in CLAUDE.md
move into AGENTS.md. IsDevVersion counts "unknown".

Model: opus-5-5
2026-10-06 04:27:37 +00:00
6 changed files with 25 additions and 44 deletions
-3
View File
@@ -1,8 +1,5 @@
.PHONY: all bootstrap setup check test lint lint-fix fmt fmt-check build clean deps test-coverage local install release release-snapshot docker hooks .PHONY: all bootstrap setup check test lint lint-fix fmt fmt-check build clean deps test-coverage local install release release-snapshot docker hooks
# Where script/bootstrap installs Go when the host has none.
export PATH := $(PATH):$(CURDIR)/.tool/go/bin
# Version number, derived from git by script/version (`git describe # Version number, derived from git by script/version (`git describe
# --tags --always --dirty`). This used to be a hardcoded # --tags --always --dirty`). This used to be a hardcoded
# constant, which meant every local build claimed to be a release that # constant, which meant every local build claimed to be a release that
+9 -12
View File
@@ -765,10 +765,9 @@ them. We provide:
* `script/bootstrap` — install all development dependencies (Go, Go * `script/bootstrap` — install all development dependencies (Go, Go
module download). A host without Go gets the `go.mod` version through module download). A host without Go gets the `go.mod` version through
`script/install-go`, in `.tool/go`, which the `Makefile`, `script/fmt`, `script/install-go`, in `.tool/go`, which `script/fmt` and
`script/fmt-check` and `script/precommit` add to their `PATH`. It `script/fmt-check` also look in. It deliberately does not install
deliberately does not install `golangci-lint`; see `script/lint` `golangci-lint`; see `script/lint` below.
below.
* `script/setup` — make a fresh clone ready for development: runs * `script/setup` — make a fresh clone ready for development: runs
`script/bootstrap`, then `script/install-precommit` `script/bootstrap`, then `script/install-precommit`
* `script/projectname` — print the project name (used for the Docker * `script/projectname` — print the project name (used for the Docker
@@ -783,14 +782,12 @@ them. We provide:
`script/bootstrap` insists on. `script/bootstrap` insists on.
* `script/install-go` — install the Go toolchain named by `go.mod`'s * `script/install-go` — install the Go toolchain named by `go.mod`'s
`go` directive into `.tool/go` from a sha256-verified `go.dev` `go` directive into `.tool/go` from a sha256-verified `go.dev`
archive, for Linux or macOS on amd64 or arm64. Idempotent. On a CI archive, and put it on `PATH`. Idempotent. Called by the release
runner it also puts `.tool/go/bin` on `PATH` for the steps that workflow, which needs a host Go for `goreleaser` to shell out to, and
follow. Called by the release workflow, which needs a host Go for by `script/bootstrap` on a host without Go. `actions/setup-go` is not
`goreleaser` to shell out to, and by `script/bootstrap` on a host used because it verifies the downloaded toolchain against no value in
without Go. `actions/setup-go` is not used because it verifies the this repo. Bumping Go edits `go.mod`, the checksum in this script, and
downloaded toolchain against no value in this repo. Bumping Go edits the two `golang` digests in the `Dockerfile` together.
`go.mod`, the checksums in this script, and the two `golang` digests
in the `Dockerfile` together.
* `script/release` — cross-compile and publish the release artifacts * `script/release` — cross-compile and publish the release artifacts
with the pinned `goreleaser`. Refuses a `goreleaser` on `PATH` whose with the pinned `goreleaser`. Refuses a `goreleaser` on `PATH` whose
version is not the pinned one, on the same reasoning as `script/lint`. version is not the pinned one, on the same reasoning as `script/lint`.
+1 -2
View File
@@ -106,8 +106,7 @@ main() {
# Go toolchain: the host's own, or else the version go.mod names, # Go toolchain: the host's own, or else the version go.mod names,
# hash-verified, in .tool/go. That directory is not on the caller's # hash-verified, in .tool/go. That directory is not on the caller's
# PATH; the Makefile, script/fmt, script/fmt-check and # PATH, so script/fmt and script/fmt-check look there too.
# script/precommit add it to theirs.
if missing go; then if missing go; then
"$ROOT/script/install-go" "$ROOT/script/install-go"
PATH="$PATH:$ROOT/.tool/go/bin" PATH="$PATH:$ROOT/.tool/go/bin"
+2 -8
View File
@@ -10,14 +10,8 @@ main() {
# Where script/bootstrap installs Go when the host has none. # Where script/bootstrap installs Go when the host has none.
PATH="$PATH:$ROOT/.tool/go/bin" PATH="$PATH:$ROOT/.tool/go/bin"
# The Go files git lists, which leaves out the sources of that # The Go files git lists, which leaves out the sources of that
# toolchain in the ignored .tool/go. git still lists a tracked file # toolchain in the ignored .tool/go.
# whose deletion is not staged yet, and gofmt fails on a missing file. files="$(git ls-files --cached --others --exclude-standard '*.go')"
files=""
for f in $(git ls-files --cached --others --exclude-standard '*.go'); do
if [ -e "$f" ]; then
files="$files $f"
fi
done
# shellcheck disable=SC2086 # one argument per file name # shellcheck disable=SC2086 # one argument per file name
unformatted="$(gofmt -l $files)" unformatted="$(gofmt -l $files)"
if [ -n "$unformatted" ]; then if [ -n "$unformatted" ]; then
+13 -17
View File
@@ -19,11 +19,11 @@
# The version is go.mod's `go` directive, the single source of truth for # The version is go.mod's `go` directive, the single source of truth for
# the toolchain. GO_VERSION below MUST equal it, and this script fails # the toolchain. GO_VERSION below MUST equal it, and this script fails
# when they disagree -- so bumping Go is one reviewed change touching # when they disagree -- so bumping Go is one reviewed change touching
# go.mod, the checksums here, and the Dockerfile's two golang digests # go.mod, the checksum here, and the Dockerfile's two golang digests
# together. # together.
# #
# Linux and macOS, each on amd64 and arm64: the four archives whose # Linux only, because that is what both runners are. A darwin dev uses
# checksums are committed below. # their own Go; supporting an OS means adding its checksums.
set -eu set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
@@ -34,8 +34,6 @@ ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
GO_VERSION="1.26.1" GO_VERSION="1.26.1"
SHA256_LINUX_AMD64="031f088e5d955bab8657ede27ad4e3bc5b7c1ba281f05f245bcc304f327c987a" SHA256_LINUX_AMD64="031f088e5d955bab8657ede27ad4e3bc5b7c1ba281f05f245bcc304f327c987a"
SHA256_LINUX_ARM64="a290581cfe4fe28ddd737dde3095f3dbeb7f2e4065cab4eae44dfc53b760c2f7" SHA256_LINUX_ARM64="a290581cfe4fe28ddd737dde3095f3dbeb7f2e4065cab4eae44dfc53b760c2f7"
SHA256_DARWIN_AMD64="65773dab2f8cc4cd23d93ba6d0a805de150ca0b78378879292be0b903b8cdd08"
SHA256_DARWIN_ARM64="353df43a7811ce284c8938b5f3c7df40b7bfb6f56cb165b150bc40b5e2dd541f"
GOROOT_DIR="$ROOT/.tool/go" GOROOT_DIR="$ROOT/.tool/go"
GOCMD="$GOROOT_DIR/bin/go" GOCMD="$GOROOT_DIR/bin/go"
@@ -104,28 +102,26 @@ main() {
arch="$(uname -m)" arch="$(uname -m)"
case "$os" in case "$os" in
Linux) os="linux" ;; Linux) os="linux" ;;
Darwin) os="darwin" ;;
*) *)
echo "install-go: unsupported OS $os" >&2 echo "install-go: unsupported OS $os (release runner is Linux)" >&2
exit 1 exit 1
;; ;;
esac esac
case "$arch" in case "$arch" in
x86_64 | amd64) arch="amd64" ;; x86_64 | amd64)
arm64 | aarch64) arch="arm64" ;; arch="amd64"
sum="$SHA256_LINUX_AMD64"
;;
arm64 | aarch64)
arch="arm64"
sum="$SHA256_LINUX_ARM64"
;;
*) *)
echo "install-go: unsupported architecture $arch" >&2 echo "install-go: no pinned checksum for architecture $arch" >&2
exit 1 exit 1
;; ;;
esac esac
case "${os}-${arch}" in
linux-amd64) sum="$SHA256_LINUX_AMD64" ;;
linux-arm64) sum="$SHA256_LINUX_ARM64" ;;
darwin-amd64) sum="$SHA256_DARWIN_AMD64" ;;
darwin-arm64) sum="$SHA256_DARWIN_ARM64" ;;
esac
archive="go${GO_VERSION}.${os}-${arch}.tar.gz" archive="go${GO_VERSION}.${os}-${arch}.tar.gz"
url="https://go.dev/dl/${archive}" url="https://go.dev/dl/${archive}"
-2
View File
@@ -9,8 +9,6 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
main() { main() {
cd "$ROOT" cd "$ROOT"
# Where script/bootstrap installs Go when the host has none.
PATH="$PATH:$ROOT/.tool/go/bin"
go mod tidy go mod tidy
go fmt ./... go fmt ./...
git diff --exit-code -- go.mod go.sum || { git diff --exit-code -- go.mod go.sum || {