check / check (push) Failing after 4s
Linting and testing become the lint and test phases of the Dockerfile, and the build stage depends on both. Dockerfile.lint, CHECK_EPOCH and the tests that checked them are removed. Every docker build in script/ passes --no-cache, and script/cibuild runs script/bootstrap first. The image takes its version from the VERSION build arg or git describe, and still stamps the commit and its date from .git. The golangci-lint v2.14.0 findings are fixed in the code. The rules in CLAUDE.md move into AGENTS.md. IsDevVersion now counts "unknown", the version script/docker stamps outside a git checkout. Model: opus-5-5
136 lines
4.5 KiB
Bash
Executable File
136 lines
4.5 KiB
Bash
Executable File
#!/bin/sh
|
|
# script/bootstrap: install all dependencies needed to build and develop
|
|
# this repo. Idempotent: every install is guarded by a check so already
|
|
# installed tools are skipped. Base tooling comes from nix, apt, brew,
|
|
# or apk (detected in that order); assumes NOTHING is present (not git,
|
|
# make, or go).
|
|
set -eu
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
|
|
|
PKGMGR=""
|
|
SUDO=""
|
|
|
|
detect_pkgmgr() {
|
|
[ -n "$PKGMGR" ] && return 0
|
|
if command -v nix-env >/dev/null 2>&1; then
|
|
PKGMGR="nix"
|
|
elif command -v apt-get >/dev/null 2>&1; then
|
|
PKGMGR="apt"
|
|
elif command -v brew >/dev/null 2>&1; then
|
|
PKGMGR="brew"
|
|
elif command -v apk >/dev/null 2>&1; then
|
|
PKGMGR="apk"
|
|
else
|
|
echo "bootstrap: no supported package manager (nix, apt, brew, apk)" >&2
|
|
exit 1
|
|
fi
|
|
if [ "$PKGMGR" = "apt" ]; then
|
|
export DEBIAN_FRONTEND=noninteractive
|
|
if [ "$(id -u)" != "0" ]; then
|
|
SUDO="sudo"
|
|
fi
|
|
fi
|
|
}
|
|
|
|
# pkg_install <nix-attr> <apt-pkg> <brew-formula> <apk-pkg>
|
|
pkg_install() {
|
|
detect_pkgmgr
|
|
case "$PKGMGR" in
|
|
nix) nix-env -iA "nixpkgs.$1" ;;
|
|
apt) $SUDO env DEBIAN_FRONTEND=noninteractive apt-get install -y "$2" ;;
|
|
brew) brew install "$3" ;;
|
|
apk) apk add --no-cache "$4" ;;
|
|
esac
|
|
}
|
|
|
|
missing() {
|
|
! command -v "$1" >/dev/null 2>&1
|
|
}
|
|
|
|
# Docker is a hard requirement, not a nice-to-have: script/lint and
|
|
# script/test build the lint and test phases of the Dockerfile, the only
|
|
# place the linter and the tests run, and script/check and
|
|
# script/precommit both run them. A bootstrap that prints "bootstrap
|
|
# complete" on a machine where `make check` cannot run is a false
|
|
# success, so this fails instead.
|
|
#
|
|
# Installing docker from here was considered and rejected: it needs root,
|
|
# a running daemon, and on macOS a GUI cask, so an attempt would itself
|
|
# fail in the common case - trading one false success for a second
|
|
# failure mode. Naming exactly what breaks is more useful.
|
|
# Prints the problem and returns 0 when docker cannot be used; returns
|
|
# 1 (and prints nothing) when it can.
|
|
docker_problem() {
|
|
if missing docker; then
|
|
echo "docker is not installed"
|
|
return 0
|
|
fi
|
|
if ! docker info >/dev/null 2>&1; then
|
|
echo "the docker daemon is not reachable"
|
|
return 0
|
|
fi
|
|
return 1
|
|
}
|
|
|
|
require_docker() {
|
|
reason="$(docker_problem)" || return 0
|
|
cat >&2 <<EOF
|
|
bootstrap: FAILED - $reason.
|
|
|
|
Docker is required to develop this repo. Without it these do not work:
|
|
|
|
script/lint builds the lint phase of the Dockerfile, which runs
|
|
the linter as a build step in a digest-pinned
|
|
golangci-lint image
|
|
script/test builds the test phase of the Dockerfile
|
|
script/check runs script/test and script/lint
|
|
script/precommit runs script/check, so commits are blocked by the
|
|
pre-commit hook installed by script/setup
|
|
script/cibuild runs script/check and builds the image, which is
|
|
what CI runs
|
|
|
|
Install docker (and start the daemon, checking DOCKER_HOST and your
|
|
group membership), then re-run script/bootstrap. golangci-lint on PATH
|
|
is deliberately not a substitute: script/lint will not use it.
|
|
EOF
|
|
exit 1
|
|
}
|
|
|
|
main() {
|
|
cd "$ROOT"
|
|
|
|
# Base tooling (every repo)
|
|
if missing git; then pkg_install git git git git; fi
|
|
if missing make; then pkg_install gnumake make make make; fi
|
|
|
|
# Go toolchain
|
|
if missing go; then pkg_install go golang go go; fi
|
|
|
|
# golangci-lint is deliberately NOT installed: script/lint lints by
|
|
# building the lint phase of the Dockerfile, whose digest-pinned
|
|
# image is the only place the linter runs, so whatever a package
|
|
# manager happens to ship would only be a shadow of the pinned
|
|
# version that could drift from CI. Nothing on the host is ever used
|
|
# as a linter, at any version, so installing one here would buy
|
|
# nothing.
|
|
|
|
# goreleaser, at the version pinned by script/install-goreleaser and
|
|
# verified against a hardcoded sha256. Package managers are not used
|
|
# for it: they ship whatever version they happen to carry, and the
|
|
# tool that builds a release has to be a known one. The install is
|
|
# its own script because the release workflow needs goreleaser
|
|
# without needing the Docker requirement below.
|
|
"$ROOT/script/install-goreleaser"
|
|
|
|
go mod download
|
|
|
|
# Last, so that everything installable is installed before the one
|
|
# thing this script cannot install decides the outcome.
|
|
require_docker
|
|
|
|
echo "bootstrap complete"
|
|
}
|
|
|
|
main "$@"
|