1 Commits
Author SHA1 Message Date
sneak 376b76860e Re-vendor the canonical files from sneak/prompts at dd4027b (closes #213)
check / check (push) Successful in 20m36s
Linting and testing become the lint and test phases of the Dockerfile,
and the build stage depends on both. Dockerfile.lint, CHECK_EPOCH and
the tests that checked them are removed. Every docker build in script/
passes --no-cache, and script/cibuild runs script/bootstrap first. A
host without Go gets the go.mod version from script/install-go in
.tool/go, which the Makefile, script/fmt, script/fmt-check and
script/precommit add to PATH; fmt-check reads the Go files git lists.
The image takes its version from the VERSION build arg or git describe,
dev without .git. This repo's own entries follow the canonical content
in .gitignore and .editorconfig. The golangci-lint v2.14.0 findings are
fixed. The rules in CLAUDE.md move into AGENTS.md. IsDevVersion counts
"unknown".

Model: opus-5-5
2026-10-06 06:04:01 +00:00
6 changed files with 44 additions and 25 deletions
+3
View File
@@ -1,5 +1,8 @@
.PHONY: all bootstrap setup check test lint lint-fix fmt fmt-check build clean deps test-coverage local install release release-snapshot docker hooks
# Where script/bootstrap installs Go when the host has none.
export PATH := $(PATH):$(CURDIR)/.tool/go/bin
# Version number, derived from git by script/version (`git describe
# --tags --always --dirty`). This used to be a hardcoded
# constant, which meant every local build claimed to be a release that
+12 -9
View File
@@ -765,9 +765,10 @@ them. We provide:
* `script/bootstrap` — install all development dependencies (Go, Go
module download). A host without Go gets the `go.mod` version through
`script/install-go`, in `.tool/go`, which `script/fmt` and
`script/fmt-check` also look in. It deliberately does not install
`golangci-lint`; see `script/lint` below.
`script/install-go`, in `.tool/go`, which the `Makefile`, `script/fmt`,
`script/fmt-check` and `script/precommit` add to their `PATH`. It
deliberately does not install `golangci-lint`; see `script/lint`
below.
* `script/setup` — make a fresh clone ready for development: runs
`script/bootstrap`, then `script/install-precommit`
* `script/projectname` — print the project name (used for the Docker
@@ -782,12 +783,14 @@ them. We provide:
`script/bootstrap` insists on.
* `script/install-go` — install the Go toolchain named by `go.mod`'s
`go` directive into `.tool/go` from a sha256-verified `go.dev`
archive, and put it on `PATH`. Idempotent. Called by the release
workflow, which needs a host Go for `goreleaser` to shell out to, and
by `script/bootstrap` on a host without Go. `actions/setup-go` is not
used because it verifies the downloaded toolchain against no value in
this repo. Bumping Go edits `go.mod`, the checksum in this script, and
the two `golang` digests in the `Dockerfile` together.
archive, for Linux or macOS on amd64 or arm64. Idempotent. On a CI
runner it also puts `.tool/go/bin` on `PATH` for the steps that
follow. Called by the release workflow, which needs a host Go for
`goreleaser` to shell out to, and by `script/bootstrap` on a host
without Go. `actions/setup-go` is not used because it verifies the
downloaded toolchain against no value in this repo. Bumping Go edits
`go.mod`, the checksums in this script, and the two `golang` digests
in the `Dockerfile` together.
* `script/release` — cross-compile and publish the release artifacts
with the pinned `goreleaser`. Refuses a `goreleaser` on `PATH` whose
version is not the pinned one, on the same reasoning as `script/lint`.
+2 -1
View File
@@ -106,7 +106,8 @@ main() {
# Go toolchain: the host's own, or else the version go.mod names,
# hash-verified, in .tool/go. That directory is not on the caller's
# PATH, so script/fmt and script/fmt-check look there too.
# PATH; the Makefile, script/fmt, script/fmt-check and
# script/precommit add it to theirs.
if missing go; then
"$ROOT/script/install-go"
PATH="$PATH:$ROOT/.tool/go/bin"
+8 -2
View File
@@ -10,8 +10,14 @@ main() {
# Where script/bootstrap installs Go when the host has none.
PATH="$PATH:$ROOT/.tool/go/bin"
# The Go files git lists, which leaves out the sources of that
# toolchain in the ignored .tool/go.
files="$(git ls-files --cached --others --exclude-standard '*.go')"
# toolchain in the ignored .tool/go. git still lists a tracked file
# whose deletion is not staged yet, and gofmt fails on a missing file.
files=""
for f in $(git ls-files --cached --others --exclude-standard '*.go'); do
if [ -e "$f" ]; then
files="$files $f"
fi
done
# shellcheck disable=SC2086 # one argument per file name
unformatted="$(gofmt -l $files)"
if [ -n "$unformatted" ]; then
+17 -13
View File
@@ -19,11 +19,11 @@
# The version is go.mod's `go` directive, the single source of truth for
# the toolchain. GO_VERSION below MUST equal it, and this script fails
# when they disagree -- so bumping Go is one reviewed change touching
# go.mod, the checksum here, and the Dockerfile's two golang digests
# go.mod, the checksums here, and the Dockerfile's two golang digests
# together.
#
# Linux only, because that is what both runners are. A darwin dev uses
# their own Go; supporting an OS means adding its checksums.
# Linux and macOS, each on amd64 and arm64: the four archives whose
# checksums are committed below.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
@@ -34,6 +34,8 @@ ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
GO_VERSION="1.26.1"
SHA256_LINUX_AMD64="031f088e5d955bab8657ede27ad4e3bc5b7c1ba281f05f245bcc304f327c987a"
SHA256_LINUX_ARM64="a290581cfe4fe28ddd737dde3095f3dbeb7f2e4065cab4eae44dfc53b760c2f7"
SHA256_DARWIN_AMD64="65773dab2f8cc4cd23d93ba6d0a805de150ca0b78378879292be0b903b8cdd08"
SHA256_DARWIN_ARM64="353df43a7811ce284c8938b5f3c7df40b7bfb6f56cb165b150bc40b5e2dd541f"
GOROOT_DIR="$ROOT/.tool/go"
GOCMD="$GOROOT_DIR/bin/go"
@@ -102,26 +104,28 @@ main() {
arch="$(uname -m)"
case "$os" in
Linux) os="linux" ;;
Darwin) os="darwin" ;;
*)
echo "install-go: unsupported OS $os (release runner is Linux)" >&2
echo "install-go: unsupported OS $os" >&2
exit 1
;;
esac
case "$arch" in
x86_64 | amd64)
arch="amd64"
sum="$SHA256_LINUX_AMD64"
;;
arm64 | aarch64)
arch="arm64"
sum="$SHA256_LINUX_ARM64"
;;
x86_64 | amd64) arch="amd64" ;;
arm64 | aarch64) arch="arm64" ;;
*)
echo "install-go: no pinned checksum for architecture $arch" >&2
echo "install-go: unsupported architecture $arch" >&2
exit 1
;;
esac
case "${os}-${arch}" in
linux-amd64) sum="$SHA256_LINUX_AMD64" ;;
linux-arm64) sum="$SHA256_LINUX_ARM64" ;;
darwin-amd64) sum="$SHA256_DARWIN_AMD64" ;;
darwin-arm64) sum="$SHA256_DARWIN_ARM64" ;;
esac
archive="go${GO_VERSION}.${os}-${arch}.tar.gz"
url="https://go.dev/dl/${archive}"
+2
View File
@@ -9,6 +9,8 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
main() {
cd "$ROOT"
# Where script/bootstrap installs Go when the host has none.
PATH="$PATH:$ROOT/.tool/go/bin"
go mod tidy
go fmt ./...
git diff --exit-code -- go.mod go.sum || {