All checks were successful
check / check (push) Successful in 3m7s
No tag could be cut at all: .goreleaser.yaml had no gitea_urls block, so
goreleaser defaulted to the GitHub API, and the repo has zero tags.
.goreleaser.yaml now points at git.eeqj.de. Version derives from git via
a new script/version - exact tag with any leading v stripped, else
dev-<12-char sha>, with a -dirty suffix when tracked files are modified -
replacing the hardcoded 1.0.0-rc.1 that every local build was stamping
regardless of git state. A tag-triggered .gitea/workflows/release.yml
runs goreleaser with a scoped token (RELEASE_TOKEN); script/bootstrap
installs a sha256-verified goreleaser, and make release / release-snapshot
become script shims like every other target.
Two fabrications were removed rather than merely replaced. goreleaser's
snapshot.version_template was `{{ incpatch .Version }}-next`, which
invents a release number from the last tag - and with no tags, from
goreleaser's own fabricated v0.0.0. And internal/cli/version.go gated its
development-build notice on Version == "dev" exactly, so the moment
untagged builds carried a sha that notice would have gone silent and an
unreleased binary would have read as a release. Replaced with a tested
IsDevVersion predicate, and closed at both layers: the Makefile now
refuses to build when script/version yields nothing, and an empty version
counts as a development build - reachable today via
`docker build --build-arg VERSION=`.
The release workflow installs Go from a sha-pinned actions/setup-go
(v5.6.0) using go-version-file, so the compiler that produces released
binaries is pinned like every other external reference. Without it the
first tag push would either fail at goreleaser's before-hook or compile
the published artifacts with whatever unpinned Go the runner happened to
carry - the one unpinned thing in a release path that already refuses an
unpinned goreleaser.
Known gap: the Go tarball setup-go fetches is version-pinned but not
checksum-verified against a value in this repo, unlike the goreleaser
install and the Dockerfile digest.
135 lines
4.5 KiB
Bash
Executable File
135 lines
4.5 KiB
Bash
Executable File
#!/bin/sh
|
|
# script/bootstrap: install all dependencies needed to build and develop
|
|
# this repo. Idempotent: every install is guarded by a check so already
|
|
# installed tools are skipped. Base tooling comes from nix, apt, brew,
|
|
# or apk (detected in that order); assumes NOTHING is present (not git,
|
|
# make, or go).
|
|
set -eu
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
|
|
|
PKGMGR=""
|
|
SUDO=""
|
|
|
|
detect_pkgmgr() {
|
|
[ -n "$PKGMGR" ] && return 0
|
|
if command -v nix-env >/dev/null 2>&1; then
|
|
PKGMGR="nix"
|
|
elif command -v apt-get >/dev/null 2>&1; then
|
|
PKGMGR="apt"
|
|
elif command -v brew >/dev/null 2>&1; then
|
|
PKGMGR="brew"
|
|
elif command -v apk >/dev/null 2>&1; then
|
|
PKGMGR="apk"
|
|
else
|
|
echo "bootstrap: no supported package manager (nix, apt, brew, apk)" >&2
|
|
exit 1
|
|
fi
|
|
if [ "$PKGMGR" = "apt" ]; then
|
|
export DEBIAN_FRONTEND=noninteractive
|
|
if [ "$(id -u)" != "0" ]; then
|
|
SUDO="sudo"
|
|
fi
|
|
fi
|
|
}
|
|
|
|
# pkg_install <nix-attr> <apt-pkg> <brew-formula> <apk-pkg>
|
|
pkg_install() {
|
|
detect_pkgmgr
|
|
case "$PKGMGR" in
|
|
nix) nix-env -iA "nixpkgs.$1" ;;
|
|
apt) $SUDO env DEBIAN_FRONTEND=noninteractive apt-get install -y "$2" ;;
|
|
brew) brew install "$3" ;;
|
|
apk) apk add --no-cache "$4" ;;
|
|
esac
|
|
}
|
|
|
|
missing() {
|
|
! command -v "$1" >/dev/null 2>&1
|
|
}
|
|
|
|
# Docker is a hard requirement, not a nice-to-have: script/lint runs the
|
|
# digest-pinned golangci-lint image from the Dockerfile's lint stage, and
|
|
# script/check and script/precommit both run script/lint. A bootstrap
|
|
# that prints "bootstrap complete" on a machine where `make check` cannot
|
|
# run is a false success, so this fails instead.
|
|
#
|
|
# Installing docker from here was considered and rejected: it needs root,
|
|
# a running daemon, and on macOS a GUI cask, so an attempt would itself
|
|
# fail in the common case - trading one false success for a second
|
|
# failure mode. Naming exactly what breaks is more useful.
|
|
# Prints the problem and returns 0 when docker cannot be used; returns
|
|
# 1 (and prints nothing) when it can.
|
|
docker_problem() {
|
|
if missing docker; then
|
|
echo "docker is not installed"
|
|
return 0
|
|
fi
|
|
if ! docker info >/dev/null 2>&1; then
|
|
echo "the docker daemon is not reachable"
|
|
return 0
|
|
fi
|
|
return 1
|
|
}
|
|
|
|
require_docker() {
|
|
reason="$(docker_problem)" || return 0
|
|
cat >&2 <<EOF
|
|
bootstrap: FAILED - $reason.
|
|
|
|
Docker is required to develop this repo. Without it these do not work:
|
|
|
|
script/lint runs the digest-pinned golangci-lint image declared
|
|
by the Dockerfile's lint stage, which is the single
|
|
source of truth for the linter version
|
|
script/check runs script/lint
|
|
script/precommit runs script/check, so commits are blocked by the
|
|
pre-commit hook installed by script/setup
|
|
script/cibuild builds the Dockerfile, which is what CI runs
|
|
|
|
Install docker (and start the daemon, checking DOCKER_HOST and your
|
|
group membership), then re-run script/bootstrap. golangci-lint on PATH
|
|
is deliberately not a substitute: script/lint will not use it.
|
|
EOF
|
|
exit 1
|
|
}
|
|
|
|
main() {
|
|
cd "$ROOT"
|
|
|
|
# Base tooling (every repo)
|
|
if missing git; then pkg_install git git git git; fi
|
|
if missing make; then pkg_install gnumake make make make; fi
|
|
|
|
# Go toolchain
|
|
if missing go; then pkg_install go golang go go; fi
|
|
|
|
# golangci-lint is deliberately NOT installed: script/lint runs the
|
|
# digest-pinned golangci-lint image from the Dockerfile's lint stage,
|
|
# so whatever a package manager happens to ship would only be a
|
|
# shadow of the pinned version that could drift from CI. script/lint
|
|
# will not use a PATH binary on a host at any version, so installing
|
|
# one here would buy nothing.
|
|
|
|
# sqlite3 CLI: the test suite shells out to it (VACUUM).
|
|
if missing sqlite3; then pkg_install sqlite sqlite3 sqlite sqlite; fi
|
|
|
|
# goreleaser, at the version pinned by script/install-goreleaser and
|
|
# verified against a hardcoded sha256. Package managers are not used
|
|
# for it: they ship whatever version they happen to carry, and the
|
|
# tool that builds a release has to be a known one. The install is
|
|
# its own script because the release workflow needs goreleaser
|
|
# without needing the Docker requirement below.
|
|
"$ROOT/script/install-goreleaser"
|
|
|
|
go mod download
|
|
|
|
# Last, so that everything installable is installed before the one
|
|
# thing this script cannot install decides the outcome.
|
|
require_docker
|
|
|
|
echo "bootstrap complete"
|
|
}
|
|
|
|
main "$@"
|