# .golangci.yml - steamcache2 lint config (golangci-lint v2) # Philosophy: enable reasonable linters by default (golangci curated set + key additions) # then use most specific suppressions possible (source //nosec with justification, # _ = discard for errcheck on unavoidable client writes, narrow exclude-rules only for tests). # This makes remaining accepted issues visible and actionable in the code. # Run with: make lint (or golangci-lint run ./...) version: "2" run: timeout: 5m modules-download-mode: readonly linters: # No default: none — use golangci defaults (errcheck, govet, ineffassign, staticcheck, unused, etc.) # Explicitly enable the non-default linters we require for this LAN cache proxy. enable: - gosec # security checks (re-audited; see source //nosec for justified cases) - misspell # documentation hygiene settings: errcheck: check-type-assertions: false check-blank: false # gosec: keep source-level //nosec for G104/G115/G301/G304/G306. # G704/G705 are new taint-analysis rules (SSRF/XSS) not present in v1.64.8; # a CDN cache proxy forwards upstream URLs and response bodies by design. gosec: excludes: - G704 - G705 # v1 staticcheck checks: ["all"] meant SA* only. v2 merged stylecheck (ST*) # and quickfix (QF*) into staticcheck; keep the previous SA*+gosimple set. staticcheck: checks: - all - "-ST*" - "-QF*" govet: enable-all: true disable: - fieldalignment # performance tuning not a priority for this proxy appliance - shadow # common idiomatic "err" redeclarations in error-handling chains (large ServeHTTP, root, parse funcs); enabling adds noise with no real bugs; would require scope refactor for little gain exclusions: generated: lax paths: - dist - bin rules: - path: _test\.go linters: - errcheck - gosec # tests often use weak patterns intentionally (e.g. error injection, temp files) # NOTE: narrow SA9003 exclude retained only for the one remaining intentional empty branch in test (best-effort status check; main assert is metrics side-effect). - path: steamcache/steamcache_test.go linters: - staticcheck text: "SA9003: empty branch" # Narrow gosec excludes for unavoidable classes after re-audit (LAN proxy threat model): # - G115: int64<->uint casts in eviction/GC math (all sizes positive, guarded by capacity checks; API uses uint for bytesNeeded) # - G304: path vars for Read/Open/Remove under trusted disk.root or user config file (sanitized keys, no traversal, no arbitrary inclusion from untrusted URLs) # G306 for config WriteFile kept as source //nosec (one site). # G301 fixed at source (0700 dirs). G104 addressed via errcheck fixes. - path: vfs/memory/memory.go linters: - gosec text: "G115" - path: vfs/disk/disk.go linters: - gosec text: "G115" - path: vfs/gc/gc.go linters: - gosec text: "G115" - path: config/config.go linters: - gosec text: "G304" - path: vfs/disk/disk.go linters: - gosec text: "G304" formatters: enable: - goimports exclusions: generated: lax paths: - dist - bin issues: max-issues-per-linter: 0 max-same-issues: 0