Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
11 changes: 8 additions & 3 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -1,12 +1,15 @@
# What the image build does not need.
#
# The Dockerfile ends with `COPY . /go/src/...`, so without this every build
# The Dockerfile ends with `COPY . .`, so without this every build
# ships the whole working tree to the daemon. The build stage runs `go build`
# and nothing else -- no tests, no generators -- so anything `go build` ignores
# is freight.
#
# vendor/ is deliberately absent from this list. The build is `-mod vendor` and
# fails without it.
# Dependencies are not in the context at all: the build stage downloads them
# against go.sum (MAPCO-11521). vendor/ is listed below for the same reason it
# is gitignored: a local `go mod vendor` would otherwise be copied in, and go
# build switches to vendor mode by itself whenever vendor/modules.txt exists,
# so the image would build from that local copy instead of the download.

# By far the largest single thing in the context, and of no use to a build that
# takes its version, branch and revision as build arguments.
Expand All @@ -24,6 +27,8 @@ internal/ttools
provider/test
server/testcert

vendor

# CI, docs and local development. None of it is compiled.
.github
.devcontainer
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/ogc_cite.yml
Original file line number Diff line number Diff line change
Expand Up @@ -89,7 +89,7 @@ jobs:
- name: Build shigola
env:
CGO_ENABLED: 0
run: go build -mod vendor -o "${{ runner.temp }}/shigola" ./cmd/shigola
run: go build -o "${{ runner.temp }}/shigola" ./cmd/shigola

# Pulled before shigola starts so the ~1 GB download is not counted against
# the readiness timeouts in run.sh.
Expand Down
28 changes: 14 additions & 14 deletions .github/workflows/on_pr_push.yml
Original file line number Diff line number Diff line change
Expand Up @@ -42,8 +42,8 @@ jobs:
env:
CGO_ENABLED: 0
run: |
go build -mod vendor ./...
go test -run '^$' -mod vendor ./...
go build ./...
go test -run '^$' ./...

# `up -d` returns as soon as the containers start, not when the fixture is
# loaded, so the suite could begin against a half-restored database. The
Expand Down Expand Up @@ -96,7 +96,7 @@ jobs:
# race *detection*. The cache write path runs a goroutine pool, detached
# contexts and a concurrent tier fan-out, none of which -covermode checks.
run: |
go test -mod vendor -race -covermode atomic -coverprofile=profile.cov ./...
go test -race -covermode atomic -coverprofile=profile.cov ./...

- name: Send coverage report to Coveralls
env:
Expand All @@ -109,7 +109,7 @@ jobs:
echo "Skipping Coveralls upload: no GitHub token is available"
exit 0
fi
go install -mod=vendor github.com/mattn/goveralls
go install github.com/mattn/goveralls
$(go env GOPATH)/bin/goveralls -coverprofile=profile.cov -service=github

# Deliberately after the Coveralls upload rather than before it: when this
Expand All @@ -132,7 +132,7 @@ jobs:
# real finding rather than a reason to lower the floor -- read the
# per-package rows to see which package lost coverage.
- name: Check coverage against the floor
run: go run -mod vendor ./ci/coverage
run: go run ./ci/coverage

# always(): the coverage gate above can fail the job, and a teardown that
# only runs on success leaves the fixture containers behind.
Expand Down Expand Up @@ -200,7 +200,7 @@ jobs:
# it a passing run prints one "ok" line, which cannot tell a suite that
# verified twenty things apart from one that silently verified none --
# the exact failure this job exists to rule out.
run: go test -mod vendor -race -v ./server/tilecontent/
run: go test -race -v ./server/tilecontent/

- name: Tear down test environment
if: always()
Expand All @@ -221,30 +221,30 @@ jobs:
go-version-file: 'go.mod'
check-latest: true

# vendor/ is committed and is not `gofmt -s` clean, so `gofmt -s -l .`
# would report hundreds of files nobody here owns. List the tracked Go
# files outside it instead -- a filter on gofmt's output would have to
# Tracked Go files rather than `gofmt -s -l .`: the gate is about what a
# pull request can change, so an untracked tree on disk -- a local
# `go mod vendor`, which is ignored and never -s clean -- cannot fail it.
# Listing files beats filtering gofmt's output, which would have to
# survive grep exiting 1 on the clean run under the runner's pipefail.
- name: Check formatting
run: |
unformatted=$(git ls-files -z '*.go' ':!:vendor/**' | xargs -0 gofmt -s -l)
unformatted=$(git ls-files -z '*.go' | xargs -0 gofmt -s -l)
if [ -n "$unformatted" ]; then
echo "::error::these files are not gofmt -s clean:"
echo "$unformatted"
exit 1
fi

# The default analyzers, nothing added: the tree was brought clean against
# exactly these (MAPCO-11498), so a finding here is new. vet skips vendor/
# on its own; ./... never matches it.
# exactly these (MAPCO-11498), so a finding here is new.
#
# Twice, because vet only sees the files the build tags select. The second
# run sets every opt-out tag plus pprof, so the stub files that stand in
# for a compiled-out backend are vetted too, not only the default build.
- name: Vet
run: |
go vet -mod vendor ./...
go vet -mod vendor -tags 'noS3Cache noRedisCache noAzblobCache noGCSCache noGpkgProvider noPostgisProvider noPrometheusObserver pprof' ./...
go vet ./...
go vet -tags 'noS3Cache noRedisCache noAzblobCache noGCSCache noGpkgProvider noPostgisProvider noPrometheusObserver pprof' ./...

govulncheck:
name: Run govulncheck
Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/on_release_publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -78,7 +78,7 @@ jobs:
GOOS: linux
run: |
cd cmd/shigola
go build -mod vendor -ldflags "-w -X ${BUILD_PKG}.Version=${VERSION} -X ${BUILD_PKG}.GitRevision=${GIT_REVISION} -X ${BUILD_PKG}.GitBranch=${GIT_BRANCH}"
go build -ldflags "-w -X ${BUILD_PKG}.Version=${VERSION} -X ${BUILD_PKG}.GitRevision=${GIT_REVISION} -X ${BUILD_PKG}.GitBranch=${GIT_BRANCH}"

- name: Upload artifact
uses: ./.github/actions/upload-artifact
Expand Down Expand Up @@ -108,7 +108,7 @@ jobs:
GOARCH: arm64
run: |
cd cmd/shigola
go build -mod vendor -ldflags "-w -X ${BUILD_PKG}.Version=${VERSION} -X ${BUILD_PKG}.GitRevision=${GIT_REVISION} -X ${BUILD_PKG}.GitBranch=${GIT_BRANCH}"
go build -ldflags "-w -X ${BUILD_PKG}.Version=${VERSION} -X ${BUILD_PKG}.GitRevision=${GIT_REVISION} -X ${BUILD_PKG}.GitBranch=${GIT_BRANCH}"

- name: Upload artifact
uses: ./.github/actions/upload-artifact
Expand Down Expand Up @@ -145,7 +145,7 @@ jobs:
GOARCH: amd64
run: |
cd cmd/shigola_lambda
go build -mod vendor -tags lambda.norpc \
go build -tags lambda.norpc \
-ldflags "-w -X ${BUILD_PKG}.Version=${VERSION} -X ${BUILD_PKG}.GitRevision=${GIT_REVISION} -X ${BUILD_PKG}.GitBranch=${GIT_BRANCH}" \
-o bootstrap

Expand Down Expand Up @@ -185,7 +185,7 @@ jobs:
GOARCH: arm64
run: |
cd cmd/shigola_lambda
go build -mod vendor -tags lambda.norpc \
go build -tags lambda.norpc \
-ldflags "-w -X ${BUILD_PKG}.Version=${VERSION} -X ${BUILD_PKG}.GitRevision=${GIT_REVISION} -X ${BUILD_PKG}.GitBranch=${GIT_BRANCH}" \
-o bootstrap

Expand Down Expand Up @@ -216,7 +216,7 @@ jobs:
GOOS: darwin
run: |
cd cmd/shigola
go build -mod vendor -ldflags "-w -X ${BUILD_PKG}.Version=${VERSION} -X ${BUILD_PKG}.GitRevision=${GIT_REVISION} -X ${BUILD_PKG}.GitBranch=${GIT_BRANCH}"
go build -ldflags "-w -X ${BUILD_PKG}.Version=${VERSION} -X ${BUILD_PKG}.GitRevision=${GIT_REVISION} -X ${BUILD_PKG}.GitBranch=${GIT_BRANCH}"

- name: Upload artifact
uses: ./.github/actions/upload-artifact
Expand Down
5 changes: 5 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -28,3 +28,8 @@ cmd/shigola_lambda/shigola_lambda
# Coverage profiles. The measured baseline in ci/coverage-baseline.txt is
# committed; the profile it is derived from is a build artifact and is not.
profile.cov

# Dependencies resolve from the module cache against go.sum; nothing is
# vendored (MAPCO-11521). Ignored so a local `go mod vendor` cannot creep back
# into a commit -- see CONTRIBUTING.md, "Dependencies".
/vendor/
58 changes: 42 additions & 16 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -258,14 +258,11 @@ request is in range and returns a real tile. The failure mode is wrong imagery,

## Building from source

`vendor/` is committed, so **always build and test with `-mod vendor`** — every command in this
repository does.

```bash
git clone https://github.com/MapColonies/shigola
cd shigola

go build -mod vendor ./cmd/shigola
go build ./cmd/shigola
./shigola serve --config=path/to/config.toml
```

Expand All @@ -279,12 +276,41 @@ cd internal/build && go generate
Optional features compile out behind `noS3Cache`, `noRedisCache`, `noAzblobCache`, `noGCSCache`,
`noPostgisProvider` and `noPrometheusObserver`; `pprof` opts in.

### Dependencies

**Nothing is vendored.** Dependencies resolve from the Go module cache, and `go.sum` pins every one
of them cryptographically — a download that does not match it fails the build. Change them with
`go get` and `go mod tidy`, and commit `go.mod` and `go.sum` together.

`vendor/` is in `.gitignore`, and that is deliberate (MAPCO-11521). The fork inherited vendoring
from Tegola, which vendors, and kept it only while it was tracking Tegola. The costs outlived that
reason: the directory was 88% of the tracked files and 72% of the bytes, and it is never
`gofmt -s` clean, so the formatting gate had to carve it out and a `gofmt -s -w .` at the root
rewrote 257 files of other people's code. What it bought was **availability, not integrity** —
`go.sum` already provided the integrity.

The consequence is that **a build needs the module proxy, or a module cache that already holds
what `go.sum` names.** CI, the release builds and the container build all have network, so none of
them needs anything arranged. For a build that has to run offline, seed it rather than reinstating
`vendor/`:

```bash
go mod download # with network, fills $(go env GOMODCACHE)
GOPROXY=off go build ./cmd/shigola # offline, from that cache alone
```

Or point `GOPROXY` at an internal proxy the offline network can reach. Either keeps the tree free of
a copy of its dependencies.

If you do run `go mod vendor` locally, remove the result when you are done: while
`vendor/modules.txt` exists, `go build` switches to vendor mode on its own and builds from that copy,
not from `go.sum`.

## Code conventions

* **`gofmt -s` and `go vet` are required**, and CI enforces both (see [Required checks](#required-checks)).
Never run `gofmt -s -w .` at the root: it rewrites `vendor/`. Format the paths you changed, and if
that produces changes in parts of the tree you are not working on, send those in a separate pull
request.
Format the paths you changed, and if that produces changes in parts of the tree you are not
working on, send those in a separate pull request.
* **Error variables** take the form `var ErrErrorName = errors.New("provider: canceled")` — the text
all lowercase, with no punctuation at the end.
* **Table-driven subtests keyed by name**, with a `fn := func(tc tcase) func(*testing.T)` closure.
Expand Down Expand Up @@ -312,7 +338,7 @@ it:
docker compose up -d
docker wait migration # must print 0 before going on

go test -mod vendor -race ./...
go test -race ./...
docker compose down
```

Expand All @@ -322,17 +348,17 @@ true. Leave it unset: `go test -race` links a C runtime for its detector and nee
That the tree still *builds* without a C toolchain is checked separately, and CI checks it:

```bash
CGO_ENABLED=0 go build -mod vendor ./...
CGO_ENABLED=0 go test -run '^$' -mod vendor ./... # links every test binary, runs none
CGO_ENABLED=0 go build ./...
CGO_ENABLED=0 go test -run '^$' ./... # links every test binary, runs none
```

### Required checks

CI fails a pull request on any of these, so run them before you push:

```bash
git ls-files -z '*.go' ':!:vendor/**' | xargs -0 gofmt -s -l # vendor/ is never -s clean; must print nothing
go vet -mod vendor ./... # the default analyzers; the tree is clean against them
git ls-files -z '*.go' | xargs -0 gofmt -s -l # must print nothing
go vet ./... # the default analyzers; the tree is clean against them
govulncheck ./...
```

Expand Down Expand Up @@ -382,7 +408,7 @@ docker wait migration # must print 0 before going on
RUN_DATA_TESTS=yes \
PGURI="postgres://postgres:postgres@localhost:5432/shigola?sslmode=disable" \
PGSSLMODE=disable \
go test -mod vendor ./server/tilecontent/
go test ./server/tilecontent/
```

They live in a package of their own so CI can name the whole set without naming the tests in it: the
Expand Down Expand Up @@ -437,9 +463,9 @@ RUN_POSTGIS_TESTS=yes RUN_REDIS_TESTS=yes \
PGURI="postgres://postgres:postgres@localhost:5432/shigola?sslmode=disable" \
PGURI_NO_ACCESS="postgres://shigola_no_access:postgres@localhost:5432/shigola?sslmode=disable" \
PGSSLMODE=disable \
go test -mod vendor -race -covermode atomic -coverprofile=profile.cov ./...
go test -race -covermode atomic -coverprofile=profile.cov ./...

go run -mod vendor ./ci/coverage # check the profile against the floor
go run ./ci/coverage # check the profile against the floor
```

`-race` alongside `-covermode atomic` is not redundant: atomic is race-safe *counting*, not race
Expand All @@ -466,7 +492,7 @@ ran the tests — it records the `RUN_*_TESTS` gates it finds set, so the baseli
its numbers came from:

```bash
go run -mod vendor ./ci/coverage -write
go run ./ci/coverage -write
```

Regenerating keeps the recorded floor unless you pass `-floor` — lowering it is meant to be an
Expand Down
14 changes: 11 additions & 3 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -46,14 +46,22 @@ ENV BUILD_PKG="${BUILDPKG}"
# install that used to precede this build for roughly 1:30.
ENV CGO_ENABLED=0

WORKDIR /go/src/github.com/MapColonies/shigola

# Dependencies before source, in a layer of their own, so that a source-only
# change reuses the downloaded module cache instead of fetching it again. This
# step is the build's one network dependency: nothing is vendored, and go.sum
# is what makes the download trustworthy (MAPCO-11521).
COPY go.mod go.sum ./
RUN go mod download

# Set up source for compilation
RUN mkdir -p /go/src/github.com/MapColonies/shigola
COPY . /go/src/github.com/MapColonies/shigola
COPY . .

RUN env

# Build binary
RUN cd /go/src/github.com/MapColonies/shigola/cmd/shigola \
RUN cd cmd/shigola \
&& go build -v \
-ldflags "-w -X '${BUILD_PKG}.Version=${VERSION}' -X '${BUILD_PKG}.GitRevision=${GIT_REVISION}' -X '${BUILD_PKG}.GitBranch=${GIT_BRANCH}'" \
-gcflags "-N -l" \
Expand Down
6 changes: 3 additions & 3 deletions LICENSE.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,6 +66,6 @@ full, unmodified, at tms/LICENSE-morecantile.

--------------------------------------------------------------------------------

Vendored Go dependencies under vendor/ retain their own licence files within
their module directories. See NOTICE.md for the complete list of third-party
works redistributed with this software.
Third-party Go modules compiled into this software retain their own licence
files within their module sources; go.mod pins their versions. See NOTICE.md
for the complete list of third-party works redistributed with this software.
8 changes: 4 additions & 4 deletions NOTICE.md
Original file line number Diff line number Diff line change
Expand Up @@ -46,11 +46,11 @@ as the port's correctness oracle.

---

## Vendored Go dependencies
## Go module dependencies

Third-party Go modules are vendored under [`vendor/`](vendor/). Each retains its
own license file within its module directory; see [`go.mod`](go.mod) for the
full list and versions. These include, among others:
Third-party Go modules are compiled into Shigola's binaries. Each retains its
own license file within its module source; [`go.mod`](go.mod) lists them and
their versions, alongside a few tool-only modules that are not compiled in. These include, among others:

- `github.com/go-spatial/geom`, `github.com/go-spatial/proj`,
`github.com/go-spatial/cobra` — Go Spatial, MIT
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -398,7 +398,7 @@ To build shigola from the source, make sure you have Go installed and have clone
Navigate to the repository then run the following command:

```bash
go generate ... && cd cmd/shigola/ && go build -mod vendor
go generate ... && cd cmd/shigola/ && go build
```

You will now have a binary named `shigola` in the current directory which is [ready to run](#running-shigola-as-a-vector-tile-server).
Expand Down
2 changes: 1 addition & 1 deletion cache/s3/s3.go
Original file line number Diff line number Diff line change
Expand Up @@ -338,7 +338,7 @@ func (s3c *Cache) Set(ctx context.Context, key *cache.Key, val []byte) error {
// write-pool slot forever, so enough of them over a process lifetime
// empty the pool and every write is dropped until a restart.
//
// In the vendored SDK the only difference between the two calls is
// In the pinned SDK the only difference between the two calls is
// req.SetContext(ctx).
_, err = s3c.Client.PutObjectWithContext(ctx, &input)
if err != nil {
Expand Down
2 changes: 1 addition & 1 deletion docs/ogc-api-tiles.md
Original file line number Diff line number Diff line change
Expand Up @@ -271,7 +271,7 @@ The suite's data source is the Athens OSM extract in the PostGIS fixture, served

```sh
docker compose up -d && docker wait migration # the Athens fixture, in PostGIS
go build -mod vendor -o /tmp/shigola ./cmd/shigola
go build -o /tmp/shigola ./cmd/shigola
/tmp/shigola serve --config .github/cite/config.toml --port ":8081" &
.github/cite/run.sh WebMercatorQuad 14 6324 9271
.github/cite/run.sh WorldCRS84Quad 14 4740 18542
Expand Down
3 changes: 2 additions & 1 deletion internal/build/cgo_free_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,8 @@ import (
// Shared by the two tests below because both are properties of the whole
// repository rather than of any one package, and both therefore have to read
// the tree rather than build it. The skips are the same for both: vendor/ is
// other people's code and neither test says anything about it.
// never committed (MAPCO-11521), but a local `go mod vendor` would still put
// other people's code on disk, and neither test says anything about it.
func walkTree(t *testing.T, keep func(name string) bool, check func(rel, body string)) {
t.Helper()

Expand Down
2 changes: 0 additions & 2 deletions vendor/cel.dev/expr/.bazelversion

This file was deleted.

2 changes: 0 additions & 2 deletions vendor/cel.dev/expr/.gitattributes

This file was deleted.

2 changes: 0 additions & 2 deletions vendor/cel.dev/expr/.gitignore

This file was deleted.

Loading
Loading