Three findings remain that cannot be fixed without making a repo-wide
naming decision, so each carries a per-site //nolint directive with its
justification.
revive var-naming (internal/log, internal/crypto, internal/types):
fixing these means renaming packages across the whole codebase, which
is the repo owner's call, not a lint fix. Neither stdlib log nor stdlib
crypto is imported anywhere in the repo, so nothing is actually
shadowed today. The rename decision is tracked in issue #76. revive
reports a package-name failure only once per package directory, on
whichever file it happens to lint first, so every file of the affected
packages carries the directive and lists nolintlint alongside revive so
the ones that lose the race are not reported as unused.
No gosec directives are needed: the pinned golangci-lint v2.12.2 that
CI and the Dockerfile use reports nothing at the term.IsTerminal
conversions in internal/log and internal/ui or at the os.Remove calls
in internal/vaultik/verify.go, so suppressing there would itself fail
nolintlint as an unused directive.
Verification is script/cibuild, which builds the hash-pinned lint
image: it exits 0, with make lint reporting "0 issues" under the
canonical .golangci.yml (sha256
021cc83f4e6fc7c31b95b34b846723dfcf20b66b7baeea1dc40406e643346bcb,
unmodified), plus make fmt-check, make test and the release build. That
also unblocks issue #59. make check is not a valid gate here: script/lint
runs whatever golangci-lint is on PATH rather than the pinned version,
which is tracked in issue #78.
Also corrects the capacity comment in collectBatchFlushData: an empty
file contributes no chunk mappings, so the pending-file count is a
rough starting capacity, not a lower bound.
TODO.md: record this work, note that the previous next step (reconciling
uncommitted ARCHITECTURE.md edits) needed no work because the tree is
clean, and move the next step on to the stale-branch triage.
collectBatchFlushData now sizes the file-chunk and chunk-file slices to
the number of pending files, a safe lower bound since every file
contributes at least one mapping of each kind. The chunker test sizes
its reconstruction buffer to the input length, which is exactly what it
ends up holding. Append semantics and results are unchanged.
The ten sqlclosecheck findings were not leaks: every one of these
queries already deferred a close through the package-local CloseRows
helper. sqlclosecheck only recognises a Close call on the rows value
in the function that produced it (directly deferred, or inside a
deferred closure), so a call that hands rows to a helper reads as
unhandled.
Rather than keep a helper the linter cannot see through, drop
CloseRows and defer a closure that calls rows.Close() directly at each
of the eighteen call sites, keeping the existing fatal-on-close-error
behaviour byte for byte. The close still runs exactly once, on
function exit, after the rows have been read.
Fatalf stays; it is still used by the transaction helpers.
Insert the blank line wsl_v5 requires above `defer` and `go`
statements that share no variables with the statement above them.
Applied mechanically via `make lint-fix`; the diff is 60 added blank
lines and nothing else.