All checks were successful
check / check (push) Successful in 2m16s
Closes #110. CleanupLocalSnapshots wrote three prose lines to stdout with no --json awareness, covering every branch, so `vaultik prune --json | jq` failed on any input. -q never helped either: printlnStdout and stdoutf write straight to v.Stdout and never consult v.UI, which is what SetQuiet affects. It now takes *PruneOptions, symmetric with its sibling phase PruneBlobs, and gates all three writes. Threading opts.JSON was chosen over moving the lines to log.Info, because internal/log/log.go defaults the level to Warn: log.Info would not have relocated them to stderr, it would have deleted them from a plain `vaultik prune`, and "Removing stale local record" narrates the deletion of local index rows. The stale-record count is deliberately not added to PruneBlobsResult - every field there is blob-scoped and produced by the phase that runs after this reconciliation, so adding it would change a published --json schema as a side effect of a stream fix. Note for anyone reading the --json contract: under --json the stale-record removal now produces no signal in either stream. stdout is correctly gated, stderr is level-pinned to Warn because --json sets Quiet, and the count is not in the document. That is inherited behaviour - PruneBlobs' own log.Info calls are equally invisible under --json - not something this change introduced, and it is tracked separately. make build exited 0 and produced nothing: .PHONY listed build with no build: rule, and a phony target with no prerequisites and no recipe is considered already satisfied, which turns what would be a hard error into a silent success. In a repo where `make build` is the documented way to build, a caller checking the exit code concluded the build worked. Now `build: vaultik`, verified in both directions - a clean build produces the binary, a deliberately broken one exits non-zero and produces none. All 19 .PHONY names were audited; build was the only one lacking a rule. TestPhonyTargetsAllHaveRules keeps that true for names added later, so the class is closed rather than the instance.
127 lines
4.3 KiB
Makefile
127 lines
4.3 KiB
Makefile
.PHONY: all bootstrap setup check test lint lint-fix fmt fmt-check build clean deps test-coverage local install release release-snapshot docker hooks
|
||
|
||
# Version number, derived from git by script/version -- the tag when
|
||
# HEAD is on one, otherwise dev-<sha>. This used to be a hardcoded
|
||
# constant, which meant every local build claimed to be a release that
|
||
# had never been tagged.
|
||
VERSION := $(shell script/version)
|
||
|
||
# $(shell) discards exit status, so a script/version that is missing,
|
||
# non-executable or broken would otherwise leave VERSION empty and every
|
||
# binary built here would print "vaultik " with no version at all. A
|
||
# build that cannot determine what it is must not produce an artifact.
|
||
ifeq ($(strip $(VERSION)),)
|
||
$(error script/version produced no version string; a build that cannot \
|
||
determine its version will not be made. Check that script/version exists \
|
||
and is executable)
|
||
endif
|
||
|
||
# Build variables
|
||
GIT_REVISION := $(shell git rev-parse HEAD 2>/dev/null || echo "unknown")
|
||
GIT_COMMIT_DATE := $(shell git show -s --format=%cs HEAD 2>/dev/null || echo "unknown")
|
||
|
||
# Linker flags
|
||
LDFLAGS := -X 'sneak.berlin/go/vaultik/internal/globals.Version=$(VERSION)' \
|
||
-X 'sneak.berlin/go/vaultik/internal/globals.Commit=$(GIT_REVISION)' \
|
||
-X 'sneak.berlin/go/vaultik/internal/globals.CommitDate=$(GIT_COMMIT_DATE)'
|
||
|
||
# Default target
|
||
all: vaultik
|
||
|
||
# Install all development dependencies.
|
||
bootstrap:
|
||
@script/bootstrap
|
||
|
||
# Prepare a fresh clone: bootstrap plus pre-commit hook.
|
||
setup:
|
||
@script/setup
|
||
|
||
# Combined pre-commit/CI gate: tests, lint, format check.
|
||
check:
|
||
@script/check
|
||
|
||
# Run tests only. This runs the ENTIRE suite -- there is no separate
|
||
# integration target and no build-tagged subset held back. In
|
||
# particular internal/vaultik/integration_test.go, which does full
|
||
# chunk -> pack -> encrypt -> upload -> restore round-trips, runs here.
|
||
# A `test-integration` target used to exist and was removed: no file in
|
||
# the repo carried a build tag, so `-tags=integration` selected nothing
|
||
# extra and the target was an exact duplicate of this one.
|
||
test:
|
||
@script/test
|
||
|
||
# Check if code is formatted (read-only).
|
||
fmt-check:
|
||
@script/fmt-check
|
||
|
||
# Format code.
|
||
fmt:
|
||
@script/fmt
|
||
|
||
# Run linter only.
|
||
lint:
|
||
@script/lint
|
||
|
||
# Apply the linter's autofixes (rewrites files).
|
||
lint-fix:
|
||
@script/lint-fix
|
||
|
||
# Build binary. `build` is the name the org convention reaches for and
|
||
# the one a caller checks the exit code of; `vaultik` is the file rule
|
||
# that does the work, so an unchanged tree still short-circuits.
|
||
#
|
||
# This alias is not decorative. `build` was listed in .PHONY with no
|
||
# rule, and a phony target with no prerequisites and no recipe is
|
||
# already satisfied: `make build` printed "Nothing to be done" and
|
||
# exited 0 without producing a binary (issue #110). Every name in
|
||
# .PHONY needs a rule for that reason; TestPhonyTargetsAllHaveRules in
|
||
# cmd/vaultik keeps it that way.
|
||
build: vaultik
|
||
|
||
vaultik: internal/*/*.go cmd/vaultik/*.go
|
||
go build -ldflags "$(LDFLAGS)" -o $@ ./cmd/vaultik
|
||
|
||
# Clean build artifacts.
|
||
clean:
|
||
rm -f vaultik
|
||
go clean
|
||
|
||
# Install dependencies. The linter is deliberately not installed here:
|
||
# script/lint runs the digest-pinned golangci-lint image declared by the
|
||
# Dockerfile's lint stage, which is the single source of truth for the
|
||
# linter version. A second, separately pinned copy on PATH could drift
|
||
# from it and make a local `make lint` disagree with CI.
|
||
deps:
|
||
go mod download
|
||
|
||
# Run tests with coverage. -count=1 for the same reason script/test
|
||
# uses it: without it an unchanged package is served from Go's test
|
||
# result cache, and a coverage profile assembled from cached results
|
||
# describes a run that did not happen.
|
||
test-coverage:
|
||
go test -v -count=1 -coverprofile=coverage.out ./...
|
||
go tool cover -html=coverage.out -o coverage.html
|
||
|
||
local:
|
||
VAULTIK_CONFIG=$(HOME)/etc/vaultik/config.yml ./vaultik snapshot --debug list 2>&1
|
||
VAULTIK_CONFIG=$(HOME)/etc/vaultik/config.yml ./vaultik snapshot --debug create 2>&1
|
||
|
||
install: vaultik
|
||
cp ./vaultik $(HOME)/bin/
|
||
|
||
# Build and publish release artifacts (linux/darwin × amd64/arm64) via goreleaser.
|
||
release:
|
||
@script/release
|
||
|
||
# Dry-run a release build without publishing or tagging.
|
||
release-snapshot:
|
||
@script/release-snapshot
|
||
|
||
# Build Docker image.
|
||
docker:
|
||
@script/docker
|
||
|
||
# Install pre-commit hook.
|
||
hooks:
|
||
@script/install-precommit
|