build: enforce portable line endings

This commit is contained in:
2026-08-04 14:33:45 +02:00
parent efda41aaa4
commit ad07a75490
5 changed files with 108 additions and 1 deletions
+9
View File
@@ -0,0 +1,9 @@
root = true
[*]
charset = utf-8
end_of_line = lf
insert_final_newline = true
[*.ps1]
end_of_line = crlf
+12
View File
@@ -0,0 +1,12 @@
* text=auto
*.sh text eol=lf
Dockerfile* text eol=lf
*.Dockerfile text eol=lf
*.yml text eol=lf
*.yaml text eol=lf
*.json text eol=lf
*.ts text eol=lf
*.tsx text eol=lf
*.py text eol=lf
*.md text eol=lf
*.ps1 text eol=crlf
+3 -1
View File
@@ -70,8 +70,10 @@ ENV PATH="/opt/venv/bin:/usr/local/bin:$PATH" \
PI_BIN=pi \
HOME=/home/thoth
COPY scripts/verify-line-endings.sh /usr/local/bin/verify-line-endings
COPY docker/core-entrypoint.sh docker/session-migrate.sh docker/ensure-pi-trust.mjs /app/docker/
RUN chmod +x /app/docker/core-entrypoint.sh /app/docker/session-migrate.sh
RUN /usr/local/bin/verify-line-endings /app/docker \
&& chmod +x /app/docker/core-entrypoint.sh /app/docker/session-migrate.sh
WORKDIR /app/backend
USER thoth
+41
View File
@@ -0,0 +1,41 @@
#!/usr/bin/env bash
set -euo pipefail
repo_root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
fixture_root="$(mktemp -d)"
trap 'rm -rf "$fixture_root"' EXIT
printf '#!/bin/sh\nexit 0\n' > "$fixture_root/ok.sh"
printf '#!/bin/sh\r\nexit 0\r\n' > "$fixture_root/bad.sh"
printf 'services:\r\n app:\r\n image: example\r\n' > "$fixture_root/compose.yaml"
printf 'FROM scratch\r\n' > "$fixture_root/Dockerfile"
set +e
output="$("$repo_root/scripts/verify-line-endings.sh" "$fixture_root" 2>&1)"
status=$?
set -e
if [[ $status -eq 0 ]]; then
echo "expected CRLF rejection" >&2
exit 1
fi
for expected_path in bad.sh compose.yaml Dockerfile; do
if ! grep -Fqx "$expected_path" <<< "$output"; then
echo "missing CRLF path: $expected_path" >&2
exit 1
fi
done
if grep -Fq 'ok.sh' <<< "$output"; then
echo "reported LF-only path: ok.sh" >&2
exit 1
fi
printf '#!/bin/sh\nexit 0\n' > "$fixture_root/bad.sh"
printf 'services:\n app:\n image: example\n' > "$fixture_root/compose.yaml"
printf 'FROM scratch\n' > "$fixture_root/Dockerfile"
"$repo_root/scripts/verify-line-endings.sh" "$fixture_root"
echo "line-ending verifier tests passed"
+43
View File
@@ -0,0 +1,43 @@
#!/usr/bin/env bash
set -euo pipefail
if [[ $# -gt 1 ]]; then
echo "usage: $0 [root]" >&2
exit 2
fi
if [[ $# -eq 1 ]]; then
root="$1"
fixture_mode=true
else
root="$(git rev-parse --show-toplevel)"
fixture_mode=false
fi
if [[ ! -d "$root" ]]; then
echo "not a directory: $root" >&2
exit 2
fi
root="$(cd "$root" && pwd)"
offenders=()
while IFS= read -r -d '' file; do
if LC_ALL=C grep -Il $'\r' "$file" >/dev/null; then
offenders+=("${file#"$root"/}")
fi
done < <(
if [[ "$fixture_mode" == true ]]; then
find "$root" -type f -print0
else
git -C "$root" ls-files -z | while IFS= read -r -d '' path; do
printf '%s\0' "$root/$path"
done
fi
)
if (( ${#offenders[@]} )); then
printf '%s\n' "CRLF line endings detected:" >&2
printf '%s\n' "${offenders[@]}" >&2
exit 1
fi