Files
vaultik/script/lint-fix
T
sneak 6dc134a50e
check / check (push) Successful in 22m37s
Re-vendor the canonical files from sneak/prompts at dd4027b (closes #213)
Linting and testing become the lint and test phases of the Dockerfile,
and the build stage depends on both. Dockerfile.lint, CHECK_EPOCH and
the tests that checked them are removed. Every docker build in script/
passes --no-cache, and script/cibuild runs script/bootstrap first, which
now fetches apt package lists so a fresh CI runner can install Go. The
image takes its version from the VERSION build arg or git describe, and
still stamps the commit and its date from .git. The golangci-lint
v2.14.0 findings are fixed in the code. The rules in CLAUDE.md move into
AGENTS.md. IsDevVersion now counts "unknown", the version script/docker
stamps outside a git checkout.

Model: opus-5-5
2026-10-06 01:01:50 +00:00

56 lines
2.0 KiB
Bash
Executable File

#!/bin/sh
# script/lint-fix: run the linter's autofixer. Rewrites files in place
# for every finding the enabled linters know how to fix; findings
# without an autofix are reported but left alone.
#
# THIS IS A DEVELOPER CONVENIENCE AND NEVER A GATE. Nothing in
# script/check, script/precommit or script/cibuild calls it, and no gate
# reads its exit status. The gate is script/lint, which builds the lint
# phase of the Dockerfile; run that afterwards to find out whether the
# tree is actually clean.
#
# Unlike script/lint this cannot be a build step: a build step writes
# into an image, and fixes have to land in the worktree. So it runs the
# same pinned image as a container with the tree bind-mounted, which
# means it needs a LOCAL docker daemon -- a remote daemon has no access
# to these files, and this script will appear to do nothing there. The
# image reference is parsed out of the lint phase's FROM line, so the
# autofixer is always the same version as the linter that gates; fixes
# written by a different version are not necessarily fixes for the
# version that decides.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
DOCKERFILE="$ROOT/Dockerfile"
# The image reference from the FROM line ending `AS lint`, tag and
# digest included.
lint_image() {
awk '$1 == "FROM" && $NF == "lint" { print $2; exit }' "$DOCKERFILE"
}
main() {
cd "$ROOT"
image="$(lint_image)"
if [ -z "$image" ]; then
echo "lint-fix: no FROM ... AS lint line found in $DOCKERFILE" >&2
exit 1
fi
# Run as the invoking user so the rewritten files stay owned by
# them. HOME is set because the Go and golangci-lint caches default
# under it and that user has no home inside the container; those
# caches are per-container and discarded with it.
docker run --rm \
--user "$(id -u):$(id -g)" \
--env HOME=/tmp \
--env GOFLAGS=-buildvcs=false \
--volume "$ROOT:/src" \
--workdir /src \
"$image" \
golangci-lint run --config .golangci.yml --fix "$@" ./...
}
main "$@"