scriptlint

package
v1.138.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 29, 2026 License: Apache-2.0 Imports: 11 Imported by: 0

Documentation

Overview

Package scriptlint holds the authoring gates a managed script's source is put through on every save (#1913): the formatter's output is what is stored (#1937), a script created since #1944 keeps its work in main(), and the structural lint and limits below apply to every script (#1938).

The gates are for the agent writing the script. A finding carries a rule, a line and a hint in the shape the validator already returns, so a refused save is fixed in the same loop the script is written in. There is no configuration: the limits are the platform's, the same for every deployment and every script.

The gates run on a save and never on a run: a script saved before them keeps running as it is, and its next version is held to every rule.

Index

Constants

View Source
const (
	RuleEntryPoint       = "entry-point"
	RuleTopLevelWork     = "top-level-work"
	RuleCyclomatic       = "cyclomatic-complexity"
	RuleCognitive        = "cognitive-complexity"
	RuleFunctionLength   = "function-length"
	RuleNestingDepth     = "nesting-depth"
	RuleUnusedVariable   = "unused-variable"
	RuleUnusedParameter  = "unused-parameter"
	RuleShadowedName     = "shadowed-name"
	RuleMissingDocstring = "missing-docstring"
	RuleSQLFromValues    = "sql-built-from-values"
	RuleCallInLoop       = "call-in-loop"
	RuleStateWithoutRead = "save-state-without-read"
	RuleLibraryEffect    = "library-effect"
)

The rules. Each is the Rule of the findings it produces, which is what an agent reads to know which of its habits a finding is about.

View Source
const (
	MaxCyclomatic = 10
	MaxCognitive  = 15
	MaxStatements = 40
	MaxNesting    = 4
)

The limits, the ones this repository holds its own Go to where the two have a counterpart.

View Source
const (
	RuleTestModuleOutsideTest = "test-module-outside-test"
	RuleTestCalled            = "test-called"
	RuleConstantAssertion     = "constant-assertion"
)

The rules that keep a script's tests apart from what it runs (#1939).

Variables

This section is empty.

Functions

func CheckDestinations

func CheckDestinations(report scriptrun.Report, declared []script.Destination) []scriptrun.Finding

CheckDestinations reports each destination a source names literally that the deployment does not declare.

scriptrun.Validate is deployment-independent — it parses source and reads what the code reaches — so this is a separate pass over its report, applied by the surfaces that know the configured set. Splitting it that way keeps a save working when configuration changes underneath a stored script, while the surface whose job is answering "would this run" answers it (#1415).

It reads report.Destinations, which holds only the destinations named as string literals in the source. A call that computes its destination is invisible there and is reported by report.DynamicDestinations instead: its address is not readable from the source, so there is nothing to check.

The refusal is scriptdest.Resolve's, so validate and the run say the same thing about the same script.

func Detail

func Detail(refused []scriptrun.Finding) string

Detail renders the refused findings as one message, for a surface that shows a refusal as text: each with its line, rule and hint, since the person fixing the script needs all of them.

func DraftRefusal

func DraftRefusal(source string, destinations []script.Destination) string

DraftRefusal is why a draft of source is not run, or "" when it is: the static read every surface applies before a draft executes, so a draft refuses what the rest of the surface refuses -- a source that cannot parse, one carrying an inline credential, one naming a destination this deployment does not declare -- and the destination refusal arrives before the script's queries have run rather than after (#1415). The authoring gates are not applied: a draft is how an author tries source before it is finished.

func Merge

func Merge(report scriptrun.Report, res Result) scriptrun.Report

Merge folds the gates' findings into a validation report, sorted by line, with OK recomputed as whether a save of the source would go through: every surface that validates reports the gates the same way.

func WithDestinationCheck

func WithDestinationCheck(report scriptrun.Report, declared []script.Destination) scriptrun.Report

WithDestinationCheck returns report with CheckDestinations' findings folded in and OK recomputed, which is the whole of what a validating surface does with them. It exists so the tool arm and the portal editor cannot fold them in differently.

Types

type Result

type Result struct {
	// Source is the formatted source, which is what a save stores.
	Source string
	// Findings is every finding on Source, each an error.
	Findings []scriptrun.Finding
	// Refused is the findings that refuse the save: every one of Findings.
	// Empty means it goes through.
	Refused []scriptrun.Finding
}

Result is what the gates made of a source.

func Check

func Check(source string) Result

Check formats source and holds it to the gates. A source that does not parse or resolve yields no findings here: the validator reports that, and a save is refused for it before this matters.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL