Repository navigation
[repository-quality] 🎯 Repository Quality Improvement Report - Custom Go Linter CI Enablement Gap (Second Follow-up) #62374
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by Repository Quality Improvement Agent. A newer discussion is available at Discussion #62655. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Analysis Date: 2026-09-21
Focus Area: Custom Go Linter CI Enablement Gap — Round 3
Strategy Type: Reused (highest-impact recurring finding)
Custom Area: Yes — third consecutive audit of
pkg/linters/registry.govs.github/workflows/cgo.yml's hand-typedLINTER_FLAGSallowlist, this time covering a different subset of the 72 registered analyzers than the 2026-09-07 and 2026-09-11 runs.Executive Summary
This is the third audit of the same structural defect first identified on 2026-09-07:
pkg/linters/registry.goregisters 72 customgo/analysislinters viaAll(), but.github/workflows/cgo.ymlonly ever runs a fixed, hand-typed 57-flag-x -y -zallowlist insidemake golint-custom. Any linter added to the registry is silently dark in CI unless someone remembers to also update the two multi-hundred-characterLINTER_FLAGSstrings incgo.yml(lines 1487 and 1490). Prior runs closed the gap formanualpathconcat,packagelevelmutableslicemap, andseenmapbool— but this run built the linter binary fresh and confirmed 13 linters remain completely unwired, 7 of which produce real, actionable findings today:largefunc(493),manualpathconcat(47 — regressed back into the gap list),typeassertionokdiscarded(175),bufioscannererunchecked(9),packagelevelmutableslicemap(8 — also regressed),blankassigncomma(14), andbufferresetbeforereuse(2). Six others (errorfwrapv,excessivefuncparams,hardcodedfilepath,stringsconcatloop,sprintferrdot,lenstringzero) report zero findings today, meaning they are safe to enable immediately with no remediation burden.Notably,
manualpathconcatandpackagelevelmutableslicemapwere reported fixed/enabled in the 2026-09-11 follow-up but are not present in the currentcgo.ymlflag list, and both now have live findings again (47 and 8 respectively) — evidence that CI wiring for this registry silently regresses wheneverregistry.goorcgo.ymlis touched without a keeping-in-sync check. This points to the same root cause repeatedly diagnosed: there is no automated test asserting that every linter inlinters.All()appears incgo.yml's flags, so drift is inevitable and undetected until the next manual audit.The recommended fix is no longer "add missing flags" (a treadmill that keeps resetting) but a structural guard: a Go test that fails CI whenever
registry.go's linter set andcgo.yml'sLINTER_FLAGSdiverge, closing the gap permanently instead of episodically.Full Analysis Report
Focus Area: Custom Go Linter CI Enablement Gap (Round 3)
Current State Assessment
Built
/tmp/gh-aw-lintersfrom./cmd/lintersand ran each linter individually against./cmd/... ./pkg/...with-test=false, comparing enabled analyzers against.github/workflows/cgo.yml's twoLINTER_FLAGSstrings (native build, line 1487; WASM cross-build, line 1490).Metrics Collected:
pkg/linters/registry.go)cgo.ymlLINTER_FLAGSmanualpathconcat,packagelevelmutableslicemap)Findings
Strengths
testdata/fixtures before trusting zero-count results (e.g.,errorfwrapvcorrectly flags 10/10 expected violations in its testdata, confirming the 0 finding count on realpkg//cmd/code is a genuine clean bill of health, not a broken analyzer).errorfwrapv,excessivefuncparams,hardcodedfilepath,stringsconcatloop,sprintferrdot, andlenstringzeroall report zero findings on current code — these can be added tocgo.ymltoday with no remediation PRs blocking them.errormessageandssljsonare intentionally excluded from the strict gate (used non-blocking viamake audit-error-messages), which is correct by design, not a gap.Areas for Improvement
largefunc— 493 unenforced findings for functions exceeding the 60-line guideline (e.g.buildUpdateCacheMemoryJobatpkg/workflow/cache_memory.go:419is 183 lines). This is the single largest wired-off linter by finding volume and directly duplicates the intent of the 2026-08-24 "Large File Decomposition Debt" focus area — the tooling to catch it already exists but isn't gating CI.typeassertionokdiscarded— 175 findings wherex, _ := y.(T)discards theokresult, risking silent zero-value bugs (e.g.pkg/typeutil/lookup.go:14).manualpathconcat(47) andpackagelevelmutableslicemap(8) — both regressed from "fixed" status claimed in the 2026-09-11 report; not present in currentcgo.ymlflags, confirming no regression guard exists.blankassigncomma(14) andbufioscannererunchecked(9) — both indicate silently discarded results/errors, matching the theme of prior "Vacuous Test Debt" and "Error Message Actionability" findings.bufferresetbeforereuse(2) andseenmapbool-adjacent single-digit-count linters — small blast radius but zero-cost to fix.len(linters.All()) == count(cgo.yml LINTER_FLAGS). Every prior round's "fix" (add N missing flags) is a point-in-time patch that silently erodes the next time either file changes.Detailed Analysis
Full gap list (13 linters absent from
cgo.ymlLINTER_FLAGS):largefunctypeassertionokdiscardedmanualpathconcatblankassigncommabufioscannereruncheckedpackagelevelmutableslicemapbufferresetbeforereuseseenmapboolerrorfwrapvexcessivefuncparamshardcodedfilepathstringsconcatloopsprintferrdotlenstringzero(
errormessageandssljsonintentionally run non-blocking viamake audit-error-messages, not counted as gaps.)Sample findings:
🤖 Tasks for Copilot Agent
NOTE TO PLANNER AGENT: Split the following tasks into individual work items.
Improvement Tasks
Task 1: Add a registry/CI-flags parity guard test
Priority: High
Estimated Effort: Medium
Focus Area: CI/CD tooling reliability
Description: Write a Go test (e.g.
pkg/linters/registry_ci_sync_test.go) that parses.github/workflows/cgo.yml'sLINTER_FLAGSstring(s) and asserts every analyzer name returned bylinters.All()(excluding an explicit, documented allowlist for intentionally non-blocking linters likeerrormessageandssljson) appears as a-<name>flag. Fail the test with a clear diff of missing/extra names. This closes the recurring gap permanently instead of requiring a manual audit every few days.Acceptance Criteria:
.github/workflows/cgo.ymland extracts bothLINTER_FLAGSstringsmake test-unitincludes the new test in default runsCode Region:
pkg/linters/registry.go,.github/workflows/cgo.yml(lines 1487, 1490)Task 2: Enable the six zero-finding linters immediately
Priority: High
Estimated Effort: Small
Description: Add
-errorfwrapv -excessivefuncparams -hardcodedfilepath -stringsconcatloop -sprintferrdot -lenstringzeroto bothLINTER_FLAGSstrings in.github/workflows/cgo.yml(lines 1487 and 1490). These linters report zero findings against current code, so enabling them carries zero remediation cost and immediately prevents regression.Acceptance Criteria:
LINTER_FLAGSstrings updated with the six new flagsmake golint-custom LINTER_FLAGS="..."run locally confirms zero new findingscgo.ymlrun passes cleanlyCode Region:
.github/workflows/cgo.yml:1487,1490Task 3: Fix and re-enable manualpathconcat and packagelevelmutableslicemap (regression)
Priority: Medium
Estimated Effort: Medium
Description: These two linters were reported as fixed and enabled in the 2026-09-11 follow-up but are absent from the current
cgo.ymlflags and have live findings again (47 and 8 respectively). Fix the 55 combined findings (convert manual"/"concatenation tofilepath.Join/path.Join; convert wholesale package-level slice/map re-assignment to safer patterns, e.g.sync.Once-guarded read-only access or mutex-protected accessors) and add both flags back tocgo.yml.Acceptance Criteria:
manualpathconcatfindings resolved withfilepath.Join/path.Joinpackagelevelmutableslicemapfindings resolved or justified with(nolint/redacted):packagelevelmutableslicemap+ reason-manualpathconcat -packagelevelmutableslicemapadded to bothcgo.ymlLINTER_FLAGSstringsCode Region:
pkg/workflow/action_reference.go,pkg/workflow/model_aliases.go,pkg/workflow/runtime_definitions.go,pkg/cli/model_costs.go,pkg/cli/update_version_labels.go,.github/workflows/cgo.ymlTask 4: Remediate largefunc and typeassertionokdiscarded, the two largest gapped linters
Priority: Medium
Estimated Effort: Large
Description:
largefunc(493 findings) andtypeassertionokdiscarded(175 findings) are the highest-volume unenforced linters. Rather than a single massive PR, break remediation into per-package batches (prioritizepkg/workflowandpkg/cli, the largest offenders) and land-largefunc.max-lines=60 -typeassertionokdiscardedincgo.ymlonce each batch is clear, using(nolint/redacted)with justification for functions that are legitimately hard to split (e.g. generated code, large switch dispatchers).Acceptance Criteria:
pkg/workflowandpkg/clilargefunc findings reduced by at least 50% or justified with(nolint/redacted):largefuncpkg/typeutil,pkg/parsertypeassertionokdiscarded findings fixed (convert_ := x.(T)to checked form)cgo.ymlLINTER_FLAGSonce each package batch is cleanCode Region:
pkg/workflow/cache_memory.go,pkg/typeutil/lookup.go,pkg/parser/import_observability.go,.github/workflows/cgo.yml📊 Historical Context
Previous Focus Areas
🎯 Recommendations
Immediate Actions (This Week)
cgo.yml(Task 2) — Priority: HighShort-term Actions (This Month)
manualpathconcatandpackagelevelmutableslicemap(Task 3) — Priority: Mediumlargefuncandtypeassertionokdiscarded(Task 4) — Priority: MediumLong-term Actions (This Quarter)
cgo.yml'sLINTER_FLAGSfromregistry.goat compile/CI time instead of hand-maintaining two multi-hundred-character strings — Priority: Low📈 Success Metrics
(nolint/redacted)-justified)Next Steps
Generated by Repository Quality Improvement Agent
Next analysis: 2026-09-22 — Focus area selected by diversity algorithm
All reactions