diff --git a/.gitea/workflows/test-pr.yaml b/.gitea/workflows/test-pr.yaml index 770fef5..2431599 100644 --- a/.gitea/workflows/test-pr.yaml +++ b/.gitea/workflows/test-pr.yaml @@ -1,24 +1,35 @@ -name: PR Check +name: CI on: - - pull_request + pull_request: + push: + branches: + - main jobs: check-and-test: runs-on: ubuntu-latest steps: - - uses: actions/checkout@main - - uses: actions/setup-go@main + - uses: actions/checkout@v4 + - uses: actions/setup-go@v5 with: - go-version-file: 'go.mod' + go-version: '1.26.7' - run: go mod tidy - run: go build ./... - run: go vet ./... - name: golangci-lint - uses: golangci/golangci-lint-action@v4 + uses: golangci/golangci-lint-action@v8 with: - version: latest + version: v2.12 args: --timeout=5m + - run: go test -race -v -shuffle=on -coverprofile=coverage.out -timeout=5m ./... + - run: go tool cover -func=coverage.out | tail -10 # basic coverage report + + vulncheck: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-go@v5 + with: + go-version: '1.27.0' - run: go install golang.org/x/vuln/cmd/govulncheck@latest - run: govulncheck ./... - - run: go test -race -v -shuffle=on -coverprofile=coverage.out -timeout=5m ./... - - run: go tool cover -func=coverage.out | tail -10 # basic coverage report \ No newline at end of file diff --git a/.golangci.yml b/.golangci.yml index e9b6c27..989a6cd 100644 --- a/.golangci.yml +++ b/.golangci.yml @@ -1,86 +1,94 @@ -# .golangci.yml - steamcache2 lint config +# .golangci.yml - steamcache2 lint config (golangci-lint v2) # Philosophy: enable reasonable linters by default (golangci curated set + key additions) # then use most specific suppressions possible (source //nosec with justification, # _ = discard for errcheck on unavoidable client writes, narrow exclude-rules only for tests). # This makes remaining accepted issues visible and actionable in the code. # Run with: make lint (or golangci-lint run ./...) -# Install: go install github.com/golangci/golangci-lint/cmd/golangci-lint@latest +version: "2" run: timeout: 5m modules-download-mode: readonly linters: - # No disable-all: use golangci defaults (errcheck, govet, ineffassign, staticcheck, unused, gosimple, etc.) + # No default: none — use golangci defaults (errcheck, govet, ineffassign, staticcheck, unused, etc.) # Explicitly enable the non-default linters we require for this LAN cache proxy. enable: - gosec # security checks (re-audited; see source //nosec for justified cases) - misspell # documentation hygiene - - goimports # import formatting (enforced) - # gofmt covered via linter or goimports; errcheck/govet etc. from defaults + settings: + errcheck: + check-type-assertions: false + check-blank: false + # gosec: keep source-level //nosec for G104/G115/G301/G304/G306. + # G704/G705 are new taint-analysis rules (SSRF/XSS) not present in v1.64.8; + # a CDN cache proxy forwards upstream URLs and response bodies by design. + gosec: + excludes: + - G704 + - G705 + # v1 staticcheck checks: ["all"] meant SA* only. v2 merged stylecheck (ST*) + # and quickfix (QF*) into staticcheck; keep the previous SA*+gosimple set. + staticcheck: + checks: + - all + - "-ST*" + - "-QF*" + govet: + enable-all: true + disable: + - fieldalignment # performance tuning not a priority for this proxy appliance + - shadow # common idiomatic "err" redeclarations in error-handling chains (large ServeHTTP, root, parse funcs); enabling adds noise with no real bugs; would require scope refactor for little gain + exclusions: + generated: lax + paths: + - dist + - bin + rules: + - path: _test\.go + linters: + - errcheck + - gosec # tests often use weak patterns intentionally (e.g. error injection, temp files) + # NOTE: narrow SA9003 exclude retained only for the one remaining intentional empty branch in test (best-effort status check; main assert is metrics side-effect). + - path: steamcache/steamcache_test.go + linters: + - staticcheck + text: "SA9003: empty branch" + # Narrow gosec excludes for unavoidable classes after re-audit (LAN proxy threat model): + # - G115: int64<->uint casts in eviction/GC math (all sizes positive, guarded by capacity checks; API uses uint for bytesNeeded) + # - G304: path vars for Read/Open/Remove under trusted disk.root or user config file (sanitized keys, no traversal, no arbitrary inclusion from untrusted URLs) + # G306 for config WriteFile kept as source //nosec (one site). + # G301 fixed at source (0700 dirs). G104 addressed via errcheck fixes. + - path: vfs/memory/memory.go + linters: + - gosec + text: "G115" + - path: vfs/disk/disk.go + linters: + - gosec + text: "G115" + - path: vfs/gc/gc.go + linters: + - gosec + text: "G115" + - path: config/config.go + linters: + - gosec + text: "G304" + - path: vfs/disk/disk.go + linters: + - gosec + text: "G304" -linters-settings: - errcheck: - check-type-assertions: false - check-blank: false - gosec: - # Broad global excludes removed (G104/G115/G301/G304/G306). - # - G301 addressed by switching cache MkdirAll to 0700 (least privilege for CDN content). - # - Remaining justified cases documented with precise //nosec (or #nosec) + comments at the call sites. - # - G104 largely eliminated by errcheck + explicit _ = handling (or defer wrappers). - staticcheck: - checks: ["all"] # SA1019 exclusion removed (no deprecated API usages in tree) - govet: - enable-all: true - disable: - - fieldalignment # performance tuning not a priority for this proxy appliance - - shadow # common idiomatic "err" redeclarations in error-handling chains (large ServeHTTP, root, parse funcs); enabling adds noise with no real bugs; would require scope refactor for little gain - -# Old global errcheck disable + aspirational "re-enable after refactors" comments deleted. -# errcheck is now on via defaults. Unavoidable cases handled at source with _ = or (rarely) narrow rules. +formatters: + enable: + - goimports + exclusions: + generated: lax + paths: + - dist + - bin issues: max-issues-per-linter: 0 max-same-issues: 0 - exclude-use-default: false - exclude-dirs: - - dist - - bin - exclude-rules: - - path: _test\.go - linters: - - errcheck - - gosec # tests often use weak patterns intentionally (e.g. error injection, temp files) - # NOTE: narrow SA9003 exclude retained only for the one remaining intentional empty branch in test (best-effort status check; main assert is metrics side-effect). - # The config one was a truly redundant check (already errored above); deleted surgically in Fix Round 1 (Issue 1), eliminating its exclude-rule. - - path: steamcache/steamcache_test.go - linters: - - staticcheck - text: "SA9003: empty branch" - # Narrow gosec excludes for unavoidable classes after re-audit (LAN proxy threat model): - # - G115: int64<->uint casts in eviction/GC math (all sizes positive, guarded by capacity checks; API uses uint for bytesNeeded) - # - G304: path vars for Read/Open/Remove under trusted disk.root or user config file (sanitized keys, no traversal, no arbitrary inclusion from untrusted URLs) - # G306 for config WriteFile kept as source //nosec (one site). - # G301 fixed at source (0700 dirs). G104 addressed via errcheck fixes. - - path: vfs/memory/memory.go - linters: - - gosec - text: "G115" - - path: vfs/disk/disk.go - linters: - - gosec - text: "G115" - - path: vfs/gc/gc.go - linters: - - gosec - text: "G115" - - path: config/config.go - linters: - - gosec - text: "G304" - - path: vfs/disk/disk.go - linters: - - gosec - text: "G304" - # Predictive/* rules deleted: vfs/predictive/ removed in commit 0dbb2e0; rules were stale/dead. - # All other suppressions use source-level //nosec (gosec) or _= (errcheck) for precision and visibility. diff --git a/go.mod b/go.mod index c2d1097..8c20542 100644 --- a/go.mod +++ b/go.mod @@ -1,6 +1,6 @@ module s1d3sw1ped/steamcache2 -go 1.23.0 +go 1.26.0 require ( github.com/docker/go-units v0.5.0