Compare commits

..
1 Commits
Author SHA1 Message Date
sneak 376b76860e Re-vendor the canonical files from sneak/prompts at dd4027b (closes #213)
check / check (push) Successful in 20m36s
Linting and testing become the lint and test phases of the Dockerfile,
and the build stage depends on both. Dockerfile.lint, CHECK_EPOCH and
the tests that checked them are removed. Every docker build in script/
passes --no-cache, and script/cibuild runs script/bootstrap first. A
host without Go gets the go.mod version from script/install-go in
.tool/go, which the Makefile, script/fmt, script/fmt-check and
script/precommit add to PATH; fmt-check reads the Go files git lists.
The image takes its version from the VERSION build arg or git describe,
dev without .git. This repo's own entries follow the canonical content
in .gitignore and .editorconfig. The golangci-lint v2.14.0 findings are
fixed. The rules in CLAUDE.md move into AGENTS.md. IsDevVersion counts
"unknown".

Model: opus-5-5
2026-10-06 06:04:01 +00:00
6 changed files with 44 additions and 25 deletions
+3
View File
@@ -1,5 +1,8 @@
.PHONY: all bootstrap setup check test lint lint-fix fmt fmt-check build clean deps test-coverage local install release release-snapshot docker hooks .PHONY: all bootstrap setup check test lint lint-fix fmt fmt-check build clean deps test-coverage local install release release-snapshot docker hooks
# Where script/bootstrap installs Go when the host has none.
export PATH := $(PATH):$(CURDIR)/.tool/go/bin
# Version number, derived from git by script/version (`git describe # Version number, derived from git by script/version (`git describe
# --tags --always --dirty`). This used to be a hardcoded # --tags --always --dirty`). This used to be a hardcoded
# constant, which meant every local build claimed to be a release that # constant, which meant every local build claimed to be a release that
+12 -9
View File
@@ -765,9 +765,10 @@ them. We provide:
* `script/bootstrap` — install all development dependencies (Go, Go * `script/bootstrap` — install all development dependencies (Go, Go
module download). A host without Go gets the `go.mod` version through module download). A host without Go gets the `go.mod` version through
`script/install-go`, in `.tool/go`, which `script/fmt` and `script/install-go`, in `.tool/go`, which the `Makefile`, `script/fmt`,
`script/fmt-check` also look in. It deliberately does not install `script/fmt-check` and `script/precommit` add to their `PATH`. It
`golangci-lint`; see `script/lint` below. deliberately does not install `golangci-lint`; see `script/lint`
below.
* `script/setup` — make a fresh clone ready for development: runs * `script/setup` — make a fresh clone ready for development: runs
`script/bootstrap`, then `script/install-precommit` `script/bootstrap`, then `script/install-precommit`
* `script/projectname` — print the project name (used for the Docker * `script/projectname` — print the project name (used for the Docker
@@ -782,12 +783,14 @@ them. We provide:
`script/bootstrap` insists on. `script/bootstrap` insists on.
* `script/install-go` — install the Go toolchain named by `go.mod`'s * `script/install-go` — install the Go toolchain named by `go.mod`'s
`go` directive into `.tool/go` from a sha256-verified `go.dev` `go` directive into `.tool/go` from a sha256-verified `go.dev`
archive, and put it on `PATH`. Idempotent. Called by the release archive, for Linux or macOS on amd64 or arm64. Idempotent. On a CI
workflow, which needs a host Go for `goreleaser` to shell out to, and runner it also puts `.tool/go/bin` on `PATH` for the steps that
by `script/bootstrap` on a host without Go. `actions/setup-go` is not follow. Called by the release workflow, which needs a host Go for
used because it verifies the downloaded toolchain against no value in `goreleaser` to shell out to, and by `script/bootstrap` on a host
this repo. Bumping Go edits `go.mod`, the checksum in this script, and without Go. `actions/setup-go` is not used because it verifies the
the two `golang` digests in the `Dockerfile` together. downloaded toolchain against no value in this repo. Bumping Go edits
`go.mod`, the checksums in this script, and the two `golang` digests
in the `Dockerfile` together.
* `script/release` — cross-compile and publish the release artifacts * `script/release` — cross-compile and publish the release artifacts
with the pinned `goreleaser`. Refuses a `goreleaser` on `PATH` whose with the pinned `goreleaser`. Refuses a `goreleaser` on `PATH` whose
version is not the pinned one, on the same reasoning as `script/lint`. version is not the pinned one, on the same reasoning as `script/lint`.
+2 -1
View File
@@ -106,7 +106,8 @@ main() {
# Go toolchain: the host's own, or else the version go.mod names, # Go toolchain: the host's own, or else the version go.mod names,
# hash-verified, in .tool/go. That directory is not on the caller's # hash-verified, in .tool/go. That directory is not on the caller's
# PATH, so script/fmt and script/fmt-check look there too. # PATH; the Makefile, script/fmt, script/fmt-check and
# script/precommit add it to theirs.
if missing go; then if missing go; then
"$ROOT/script/install-go" "$ROOT/script/install-go"
PATH="$PATH:$ROOT/.tool/go/bin" PATH="$PATH:$ROOT/.tool/go/bin"
+8 -2
View File
@@ -10,8 +10,14 @@ main() {
# Where script/bootstrap installs Go when the host has none. # Where script/bootstrap installs Go when the host has none.
PATH="$PATH:$ROOT/.tool/go/bin" PATH="$PATH:$ROOT/.tool/go/bin"
# The Go files git lists, which leaves out the sources of that # The Go files git lists, which leaves out the sources of that
# toolchain in the ignored .tool/go. # toolchain in the ignored .tool/go. git still lists a tracked file
files="$(git ls-files --cached --others --exclude-standard '*.go')" # whose deletion is not staged yet, and gofmt fails on a missing file.
files=""
for f in $(git ls-files --cached --others --exclude-standard '*.go'); do
if [ -e "$f" ]; then
files="$files $f"
fi
done
# shellcheck disable=SC2086 # one argument per file name # shellcheck disable=SC2086 # one argument per file name
unformatted="$(gofmt -l $files)" unformatted="$(gofmt -l $files)"
if [ -n "$unformatted" ]; then if [ -n "$unformatted" ]; then
+17 -13
View File
@@ -19,11 +19,11 @@
# The version is go.mod's `go` directive, the single source of truth for # The version is go.mod's `go` directive, the single source of truth for
# the toolchain. GO_VERSION below MUST equal it, and this script fails # the toolchain. GO_VERSION below MUST equal it, and this script fails
# when they disagree -- so bumping Go is one reviewed change touching # when they disagree -- so bumping Go is one reviewed change touching
# go.mod, the checksum here, and the Dockerfile's two golang digests # go.mod, the checksums here, and the Dockerfile's two golang digests
# together. # together.
# #
# Linux only, because that is what both runners are. A darwin dev uses # Linux and macOS, each on amd64 and arm64: the four archives whose
# their own Go; supporting an OS means adding its checksums. # checksums are committed below.
set -eu set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
@@ -34,6 +34,8 @@ ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
GO_VERSION="1.26.1" GO_VERSION="1.26.1"
SHA256_LINUX_AMD64="031f088e5d955bab8657ede27ad4e3bc5b7c1ba281f05f245bcc304f327c987a" SHA256_LINUX_AMD64="031f088e5d955bab8657ede27ad4e3bc5b7c1ba281f05f245bcc304f327c987a"
SHA256_LINUX_ARM64="a290581cfe4fe28ddd737dde3095f3dbeb7f2e4065cab4eae44dfc53b760c2f7" SHA256_LINUX_ARM64="a290581cfe4fe28ddd737dde3095f3dbeb7f2e4065cab4eae44dfc53b760c2f7"
SHA256_DARWIN_AMD64="65773dab2f8cc4cd23d93ba6d0a805de150ca0b78378879292be0b903b8cdd08"
SHA256_DARWIN_ARM64="353df43a7811ce284c8938b5f3c7df40b7bfb6f56cb165b150bc40b5e2dd541f"
GOROOT_DIR="$ROOT/.tool/go" GOROOT_DIR="$ROOT/.tool/go"
GOCMD="$GOROOT_DIR/bin/go" GOCMD="$GOROOT_DIR/bin/go"
@@ -102,26 +104,28 @@ main() {
arch="$(uname -m)" arch="$(uname -m)"
case "$os" in case "$os" in
Linux) os="linux" ;; Linux) os="linux" ;;
Darwin) os="darwin" ;;
*) *)
echo "install-go: unsupported OS $os (release runner is Linux)" >&2 echo "install-go: unsupported OS $os" >&2
exit 1 exit 1
;; ;;
esac esac
case "$arch" in case "$arch" in
x86_64 | amd64) x86_64 | amd64) arch="amd64" ;;
arch="amd64" arm64 | aarch64) arch="arm64" ;;
sum="$SHA256_LINUX_AMD64"
;;
arm64 | aarch64)
arch="arm64"
sum="$SHA256_LINUX_ARM64"
;;
*) *)
echo "install-go: no pinned checksum for architecture $arch" >&2 echo "install-go: unsupported architecture $arch" >&2
exit 1 exit 1
;; ;;
esac esac
case "${os}-${arch}" in
linux-amd64) sum="$SHA256_LINUX_AMD64" ;;
linux-arm64) sum="$SHA256_LINUX_ARM64" ;;
darwin-amd64) sum="$SHA256_DARWIN_AMD64" ;;
darwin-arm64) sum="$SHA256_DARWIN_ARM64" ;;
esac
archive="go${GO_VERSION}.${os}-${arch}.tar.gz" archive="go${GO_VERSION}.${os}-${arch}.tar.gz"
url="https://go.dev/dl/${archive}" url="https://go.dev/dl/${archive}"
+2
View File
@@ -9,6 +9,8 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
main() { main() {
cd "$ROOT" cd "$ROOT"
# Where script/bootstrap installs Go when the host has none.
PATH="$PATH:$ROOT/.tool/go/bin"
go mod tidy go mod tidy
go fmt ./... go fmt ./...
git diff --exit-code -- go.mod go.sum || { git diff --exit-code -- go.mod go.sum || {