-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathMakefile
More file actions
116 lines (88 loc) · 4.27 KB
/
Copy pathMakefile
File metadata and controls
116 lines (88 loc) · 4.27 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
GO ?= go
PYTHON ?= python3
CARGO ?= cargo
export GOTOOLCHAIN ?= go1.26.6+auto
export CGO_ENABLED := 1
VERSION_VALUE := $(strip $(shell tr -d '\r\n' < VERSION))
COMMIT_VALUE := $(strip $(shell git rev-parse --verify HEAD 2>/dev/null || printf unknown))
LDFLAGS := -X github.com/GrayCodeAI/rover/internal/model.Version=$(VERSION_VALUE) -X github.com/GrayCodeAI/rover/internal/model.Commit=$(COMMIT_VALUE)
.PHONY: build test race vet fmt fmt-check check demo fuzz install clean cross-build sbom vulncheck toolchain-check version version-check manifest manifest-check rust-fmt-check rust-clippy rust-test rust-deps-check rust-check rust-sbom rust-notices
build:
mkdir -p bin
$(GO) build -trimpath -ldflags '$(LDFLAGS)' -o bin/rover ./cmd/rover
version:
@printf '%s\n' '$(VERSION_VALUE)'
version-check:
$(GO) test ./internal/model -run '^TestVersionSurfaces$$' -count=1
toolchain-check:
$(GO) test ./internal/model -run '^TestToolchainMinimum$$' -count=1
manifest:
$(PYTHON) scripts/generate_source_manifest.py
manifest-check:
$(PYTHON) -m unittest discover -s scripts -p 'test_generate_source_manifest.py'
$(PYTHON) scripts/generate_source_manifest.py --check
test:
$(GO) test -count=1 ./...
race:
$(GO) test -race -count=1 ./...
vet:
$(GO) vet ./...
fmt:
gofmt -w cmd internal
fmt-check:
@test -z "$$(gofmt -l cmd internal)" || (gofmt -l cmd internal; exit 1)
check: fmt-check vet test
rust-fmt-check:
$(CARGO) fmt --all -- --check
rust-clippy:
$(CARGO) clippy --workspace --all-targets --locked --offline -- -D warnings
rust-test:
$(CARGO) test --workspace --locked --offline
# The audit script runs `cargo metadata`/`cargo tree`; pass CARGO through so a
# `make rust-check CARGO='cargo +1.88.0'` audit uses the same toolchain.
rust-deps-check:
$(PYTHON) -m unittest discover -s scripts -p 'test_*.py'
CARGO='$(CARGO)' $(PYTHON) scripts/rust_dependency_audit.py --check
rust-check: rust-fmt-check rust-clippy rust-test rust-deps-check
rust-sbom:
mkdir -p bin
CARGO='$(CARGO)' $(PYTHON) scripts/rust_dependency_audit.py --sbom bin/rover-rust-sbom.cdx.json
rust-notices:
CARGO='$(CARGO)' $(PYTHON) scripts/rust_dependency_audit.py --refresh-notices
demo: build
$(PYTHON) scripts/demo.py --binary bin/rover
fuzz:
$(GO) test ./internal/config -run='^$$' -fuzz=FuzzDecode -fuzztime=3s -parallel=2
$(GO) test ./internal/source -run='^$$' -fuzz=FuzzSafeName -fuzztime=3s -parallel=2
$(GO) test ./internal/assurance -run='^$$' -fuzz=FuzzResultParser -fuzztime=3s -parallel=2
$(GO) test ./internal/agents -run='^$$' -fuzz=FuzzTranscript -fuzztime=3s -parallel=2
$(GO) test ./internal/mcp -run='^$$' -fuzz=FuzzEnvelope -fuzztime=3s -parallel=2
# Cross-compile for supported platforms. Linux uses CGO with system SQLite
# (host build). Darwin uses CGO_ENABLED=0 (terminal/pty are now pure-Go).
# Windows is not yet supported: the codebase uses syscall.O_NOFOLLOW which
# does not exist on Windows. See docs/acceptance/implementation-map.json.
cross-build:
CGO_ENABLED=1 GOOS=linux GOARCH=amd64 $(GO) build -trimpath -ldflags '$(LDFLAGS)' -o bin/rover-linux-amd64 ./cmd/rover
CGO_ENABLED=0 GOOS=darwin GOARCH=amd64 $(GO) build -trimpath -ldflags '$(LDFLAGS)' -o bin/rover-darwin-amd64 ./cmd/rover
CGO_ENABLED=0 GOOS=darwin GOARCH=arm64 $(GO) build -trimpath -ldflags '$(LDFLAGS)' -o bin/rover-darwin-arm64 ./cmd/rover
# Generate a Software Bill of Materials (SBOM) listing all module dependencies.
# Uses go's built-in module introspection — no external tools required.
# CycloneDX and SPDX consumers can map the JSON output in CI.
sbom:
mkdir -p bin
$(GO) list -m -json all > bin/rover-sbom.json
$(GO) version -m bin/rover > bin/rover-buildinfo.txt 2>/dev/null || true
# Run govulncheck to scan for known vulnerabilities in dependencies.
vulncheck:
$(GO) run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./...
# Explicit user-local installation; intentionally no sudo or network installer.
install: build
@test ! -e "$(HOME)/.local/bin/rover" || (echo "Refusing to overwrite existing rover. Use ./bin/rover or remove it explicitly."; exit 1)
install -d "$(HOME)/.local/bin"
install -m 0755 bin/rover "$(HOME)/.local/bin/rover"
# Only this source checkout's build output. Never deletes user state/worktrees.
clean:
rm -f bin/rover
.PHONY: demo-extended
demo-extended: build
python3 scripts/demo_extended.py --binary bin/rover