Files
handler/.mise.toml
tester bcf4f7b0f7 gate: define the build-image pre-push task (daemonless Dockerfile check)
The git-push gate (handler.hooks.gate -> verify.run_build) shells
`mise run build-image`, but .mise.toml never defined that task, so every agent
push was hard-blocked with "no task build-image found". Define it.

The agent sandbox and control image ship no container daemon or builder (by
design — no Docker socket, no --privileged), so a real image build can't run at
push time. Use hadolint as a daemonless soundness check on both Dockerfiles,
with .hadolint.yaml pinning the failure threshold to errors so genuine
Dockerfile mistakes block the push while the deliberate, commented style
choices (unpinned apt/npm/go) don't. The authoritative end-to-end multi-arch
build-and-push stays in CI (.github/workflows/docker*.yml) on every PR to main.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-24 02:46:52 +00:00

30 lines
1.2 KiB
TOML

# Handler dogfoods its own gate: this repo defines the canonical `test` and `build-image`
# tasks the control layer enforces (the Stop hook runs `test`; the git-push gate runs
# `test` then `build-image`). Any project Handler manages carries these.
[tools]
python = "3.11"
# Backs the daemonless `build-image` gate below (see that task).
hadolint = "2.14.0"
[tasks.test]
description = "Run the test suite"
run = "pytest"
[tasks.lint]
description = "Lint the codebase"
run = "ruff check ."
[tasks.verify]
description = "Lint then test"
depends = ["lint", "test"]
# The pre-push gate (handler.hooks.gate -> verify.run_build) shells `mise run build-image`
# to prove the Dockerfiles are sound before a push. The agent sandbox and control image
# ship no container daemon/builder (by design — no Docker socket, no --privileged), so this
# is a daemonless soundness check via hadolint rather than a real image build. The
# authoritative end-to-end multi-arch build-and-push runs in CI (.github/workflows/docker*.yml)
# on every PR to main. Failure threshold is pinned to errors in .hadolint.yaml.
[tasks.build-image]
description = "Validate the Dockerfiles are sound (daemonless pre-push gate)"
run = "hadolint Dockerfile Dockerfile.control"