Files
teleport/.golangci.yml
rosstimothy 0e7339eb21 Guard against enterprise code being imported in OSS (#432)
Export-Source-Commit: 3c11f109f6efba5f875993e47171e52119ed9378
2026-08-25 11:35:10 -05:00

625 lines
26 KiB
YAML

version: '2'
run:
timeout: 15m
linters:
default: none
enable:
- bodyclose
- depguard
- errorlint
- forbidigo
- forcetypeassert
- govet
- ineffassign
- misspell
- nolintlint
- revive
- sloglint
- staticcheck
- testifylint
- unconvert
- unused
- usetesting
settings:
depguard:
rules:
api_constants_defaults:
files:
- '!$test'
- '${config-path}/api/*'
- '${config-path}/api/constants/*'
- '${config-path}/api/defaults/*'
list-mode: strict
allow:
- 'encoding/json$'
- 'github.com/coreos/go-semver/semver$'
- 'github.com/gravitational/teleport/api/constants$'
- 'github.com/gravitational/teleport/api/defaults$'
- 'github.com/gravitational/teleport/api$'
- 'github.com/gravitational/trace$'
- 'os$'
- 'sync$'
- 'time$'
cgo:
files:
- '!$test'
- '**/tool/tbot/**'
- '**/lib/client/**'
- '!**/lib/integrations/**'
- '**/integrations/**'
deny:
- pkg: github.com/gravitational/teleport/lib/bpf
desc: '"lib/bpf" requires CGO'
- pkg: github.com/gravitational/teleport/lib/backend/lite
desc: '"lib/backend/lite" requires CGO'
- pkg: github.com/gravitational/teleport/lib/cgroup
desc: '"lib/cgroup" requires CGO'
- pkg: github.com/gravitational/teleport/lib/config
desc: '"lib/config" requires CGO via "session/pam" and "lib/backend/lite"'
- pkg: github.com/gravitational/teleport/lib/desktop/rdp/rdpclient
desc: '"lib/desktop/rdp/rdpclient" requires CGO'
- pkg: github.com/gravitational/teleport/lib/devicetrust/authn$
desc: '"lib/devicetrust/authn" requires CGO on darwin'
- pkg: github.com/gravitational/teleport/lib/devicetrust/enroll
desc: '"lib/devicetrust/enroll" requires CGO on darwin'
- pkg: github.com/gravitational/teleport/lib/devicetrust/native
desc: '"lib/devicetrust/native" requires CGO on darwin'
- pkg: github.com/gravitational/teleport/lib/inventory/metadata
desc: '"lib/inventory/metadata" requires CGO'
- pkg: github.com/gravitational/teleport/session/pam$
desc: '"session/pam" requires CGO'
- pkg: github.com/gravitational/teleport/session/uacc$
desc: '"session/uacc" requires CGO'
- pkg: github.com/gravitational/teleport/lib/system/signal
desc: '"lib/system/signal" requires CGO'
- pkg: github.com/gravitational/teleport/lib/vnet/daemon
desc: '"vnet/daemon" requires CGO'
client-tools:
list-mode: lax
files:
- '!$test'
- '**/tool/tbot/**'
- '**/lib/tbot/**'
- '**/tool/tctl/**'
- '**/tool/tsh/**'
- '**/lib/client/**'
- '**/lib/services/**'
- '**/lib/service/servicecfg/**'
- '**/lib/reversetunnelclient/**'
- '**/lib/auth/authclient/**'
- '**/lib/cloud/imds/**'
allow:
- github.com/gravitational/teleport/lib/cloud/imds
- github.com/gravitational/teleport/lib/cloud/aws/config
deny:
- pkg: github.com/gravitational/teleport/lib/auth$
desc: lib/auth should not be imported to prevent increasing binary size, prefer lib/auth/authclient instead
- pkg: github.com/gravitational/teleport/lib/cloud
desc: lib/cloud should not be imported to prevent increasing binary size
- pkg: github.com/gravitational/teleport/lib/srv$
desc: lib/srv prevents client tools from build on non-linux platforms
- pkg: github.com/gravitational/teleport/lib/web$
desc: lib/web should not be imported to prevent increasing binary size
enterprise:
files:
- '!**/e/**'
deny:
- pkg: github.com/gravitational/teleport/e/
desc: enterprise packages should not be imported outside of the "e" directory
- pkg: github.com/gravitational/teleport/e$
desc: enterprise packages should not be imported outside of the "e" directory
go-cmp:
files:
- '!$test'
- '!**/integration/helpers/**'
- '!**/integrations/operator/controllers/resources/testlib/**'
- '!**/lib/auth/test/**'
- '!**/lib/services/suite/**'
- '!**/build.assets/tooling/**'
- '!**/e/tests/antithesis/workloads/**'
deny:
- pkg: github.com/google/go-cmp/cmp
desc: '"github.com/google/go-cmp/cmp" should only be used in tests'
- pkg: github.com/google/go-cmp/cmp/cmpopts
desc: '"github.com/google/go-cmp/cmp/cmpopts" should only be used in tests'
integration:
list-mode: lax
files:
- '!$test'
- '!**/integration/**'
- '!**/e/tests/**'
- '!**/integrations/operator/controllers/resources/testlib/**'
allow:
- github.com/gravitational/teleport/integrations
deny:
- pkg: github.com/gravitational/teleport/integration
desc: integration test should not be imported outside of intergation tests
- pkg: github.com/gravitational/teleport/lib/srv/db/cassandra/protocoltest
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/gravitational/teleport/lib/utils/mcptest
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/testcontainers/testcontainers-go
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/testcontainers/testcontainers-go/modules/postgres
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/testcontainers/testcontainers-go/modules/mysql
desc: testing packages should not be imported outside of _test.go files
logging:
deny:
- pkg: github.com/sirupsen/logrus
desc: use "log/slog" instead
- pkg: github.com/siddontang/go-log/log
desc: use "log/slog" instead
- pkg: github.com/siddontang/go/log
desc: use "log/slog" instead
- pkg: github.com/mailgun/log
desc: use "log/slog" instead
- pkg: github.com/saferwall/pe/log
desc: use "log/slog" instead
- pkg: golang.org/x/exp/slog
desc: use "log/slog" instead
- pkg: github.com/aws/aws-sdk-go/
desc: 'use "aws-sdk-go-v2" instead'
- pkg: github.com/aws/aws-sdk-go$
desc: 'use "aws-sdk-go-v2" instead'
template:
deny:
- pkg: text/template
desc: 'text/template prevents DCE, use the following instead: template "github.com/DataDog/datadog-agent/pkg/template/text" instead'
- pkg: html/template
desc: 'html/template prevents DCE, use the following instead: template "github.com/DataDog/datadog-agent/pkg/template/html" instead'
main:
deny:
- pkg: io/ioutil
desc: use "io" or "os" packages instead
- pkg: math/rand$
desc: use "math/rand/v2" or "crypto/rand" instead
- pkg: github.com/golang/protobuf
desc: use "google.golang.org/protobuf"
- pkg: github.com/hashicorp/go-uuid
desc: use "github.com/google/uuid" instead
- pkg: github.com/pborman/uuid
desc: use "github.com/google/uuid" instead
- pkg: github.com/tj/assert
desc: use "github.com/stretchr/testify/assert" instead
- pkg: go.uber.org/atomic
desc: use "sync/atomic" instead
- pkg: golang.design
desc: experimental project, not to be confused with official Go packages
- pkg: golang.org/x/exp/slices
desc: use "slices" instead
- pkg: github.com/hashicorp/go-version
desc: use "coreos/go-semver/semver" instead
- pkg: golang.org/x/mod/semver
desc: use "coreos/go-semver/semver" instead
- pkg: github.com/microsoftgraph/msgraph-sdk-go
desc: use "github.com/gravitational/teleport/lib/msgraph" instead
- pkg: github.com/cloudflare/cfssl
desc: use "crypto" or "x/crypto" instead
- pkg: golang.org/x/net/context
desc: use "context" instead
- pkg: github.com/gogo/protobuf/jsonpb
desc: gogoproto jsonpb has inconsistent interactions with any
message that directly or indirectly makes use of
gogoproto.casttype, and will happily violate the protobuf json
encoding spec in those situations. It should only be used for
existing marshaling and unmarshaling that can't easily be
migrated away from jsonpb, but it should not be used by new
code. If you need to encode and decode a gogoproto-generated
message in protobuf json, use
google.golang.org/protobuf/encoding/protojson together with
google.golang.org/protobuf/protoadapt instead, or, better yet,
see if you can move the code generation for that message to the
modern protoc-gen-go.
- pkg: golang.org/x/crypto/openpgp
desc: use "github.com/ProtonMail/go-crypto/openpgp" instead
oidc:
deny:
- pkg: github.com/coreos/go-oidc
desc: 'github.com/zitadel/oidc/v3 should be used instead'
- pkg: github.com/zitadel/oidc$
desc: 'github.com/zitadel/oidc/v3 should be used instead'
session_submodule:
files:
- '${config-path}/session/**'
list-mode: lax
allow:
- 'github.com/gravitational/teleport/api/constants$'
- 'github.com/gravitational/teleport/api/defaults$'
- 'github.com/gravitational/teleport/api$'
- 'github.com/gravitational/teleport/session/'
- 'github.com/gravitational/teleport/session$'
deny:
- pkg: 'github.com/gravitational/teleport/'
desc: the session submodule cannot import packages from the other modules
- pkg: 'github.com/gravitational/teleport$'
desc: the session submodule cannot import packages from the other modules
test_packages:
files:
- '!$test'
- '!**/e/lib/aws/identitycenter/test/**'
- '!**/e/lib/devicetrust/testenv/**'
- '!**/e/lib/idp/saml/testenv/**'
- '!**/e/lib/intune/testenv/**'
- '!**/e/lib/jamf/testenv/**'
- '!**/e/lib/operatortest/**'
- '!**/e/tests/**'
- '!**/integration/**'
- '!**/integrations/lib/testing/**'
- '!**/integrations/operator/controllers/resources/testlib/**.go'
- '!**/lib/auth/authtest/**'
- '!**/lib/services/samltest/**'
deny:
- pkg: github.com/gravitational/teleport/e/lib/aws/identitycenter/test
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/gravitational/teleport/e/lib/idp/operatortest
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/gravitational/teleport/lib/events/tests
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/gravitational/teleport/lib/teleterm/gatewaytest
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/gravitational/teleport/lib/utils/testutils
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/gravitational/teleport/lib/test
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/gravitational/teleport/integrations/operator/controllers/resources/testlib
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/gravitational/teleport/tool/teleport/testenv
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/gravitational/teleport/lib/srv/db/redis/protocoltest
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/gravitational/teleport/lib/srv/db/spanner/protocoltest
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/gravitational/teleport/lib/srv/db/clickhouse/protocoltest
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/gravitational/teleport/lib/modules/modulestest
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/gravitational/teleport/lib/utils/logtesttest
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/gravitational/teleport/lib/auth/authcatest
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/gravitational/teleport/lib/auth/authtest
desc: testing packages should not be imported outside of _test.go files
- pkg: github.com/gravitational/teleport/lib/cryptosuites/cryptosuitestest
desc: testing packages should not be imported outside of _test.go files
testify:
files:
- '!$test'
- '!**/api/testhelpers/**'
- '!**/e/lib/auth/ssotestlib.go'
- '!**/e/lib/aws/identitycenter/test/**'
- '!**/e/lib/idp/saml/testenv/**'
- '!**/e/lib/intune/testenv/**'
- '!**/e/lib/operatortest/**'
- '!**/e/tests/**'
- '!**/integration/appaccess/fixtures.go'
- '!**/integration/appaccess/jwt.go'
- '!**/integration/appaccess/pack.go'
- '!**/integration/db/fixture.go'
- '!**/integration/helpers/**'
- '!**/integration/hsm/helpers.go'
- '!**/integration/proxy/proxy_helpers.go'
- '!**/integrations/access/datadog/testlib/**'
- '!**/integrations/access/discord/testlib/**'
- '!**/integrations/access/email/testlib/**'
- '!**/integrations/access/jira/testlib/**'
- '!**/integrations/access/mattermost/testlib/**'
- '!**/integrations/access/msteams/testlib/**'
- '!**/integrations/access/opsgenie/testlib/**'
- '!**/integrations/access/pagerduty/testlib/**'
- '!**/integrations/access/servicenow/testlib/**'
- '!**/integrations/access/slack/testlib/**'
- '!**/integrations/lib/testing/integration/accessrequestsuite.go'
- '!**/integrations/lib/testing/integration/app.go'
- '!**/integrations/lib/testing/integration/authhelper.go'
- '!**/integrations/lib/testing/integration/suite.go'
- '!**/integrations/operator/controllers/resources/testlib/**'
- '!**/lib/auth/helpers.go'
- '!**/lib/auth/keystore/testhelpers.go'
- '!**/lib/backend/test/**'
- '!**/lib/events/test/**'
- '!**/lib/services/suite/**'
- '!**/lib/subca/testenv/**'
- '!**/lib/tbot/workloadidentity/workloadattest/sigstore/sigstoretest/sigstoretest.go'
- '!**/lib/teleterm/gatewaytest/**'
- '!**/lib/utils/mcptest/**'
- '!**/lib/utils/testutils/**'
- '!**/lib/services/samltest/**'
deny:
- pkg: github.com/stretchr/testify
desc: testify should not be imported outside of test code
testing:
files:
- '!$test'
- '!**/api/testhelpers/**'
- '!**/e/lib/auth/ssotestlib.go'
- '!**/e/lib/aws/identitycenter/test/**'
- '!**/e/lib/devicetrust/storage/storage.go'
- '!**/e/lib/devicetrust/testenv/**'
- '!**/e/lib/idp/saml/testenv/**'
- '!**/e/lib/intune/testenv/**'
- '!**/e/lib/jamf/testenv/**'
- '!**/e/lib/okta/api/oktaapitest/**'
- '!**/e/lib/operatortest/**'
- '!**/e/tests/**'
- '!**/integration/**'
- '!**/integrations/access/email/testlib/**'
- '!**/integrations/access/msteams/testlib/**'
- '!**/integrations/access/slack/testlib/**'
- '!**/integrations/operator/controllers/resources/testlib/**'
- '!**/lib/auth/authtest/**'
- '!**/lib/auth/helpers.go'
- '!**/lib/auth/keystore/testhelpers.go'
- '!**/lib/backend/test/**'
- '!**/lib/cryptosuites/internal/rsa/rsa.go'
- '!**/lib/cryptosuites/precompute.go'
- '!**/lib/events/test/**'
- '!**/lib/modules/modulestest/**'
- '!**/lib/modules/test.go'
- '!**/lib/service/service.go'
- '!**/lib/services/local/users.go'
- '!**/lib/services/suite/**'
- '!**/lib/subca/testenv/**'
- '!**/lib/tbot/workloadidentity/workloadattest/sigstore/sigstoretest/sigstoretest.go'
- '!**/lib/teleterm/gatewaytest/**'
- '!**/lib/utils/cli.go'
- '!**/lib/utils/mcptest/**'
- '!**/lib/utils/testutils/**'
- '!**/lib/services/samltest/**'
deny:
- pkg: testing
desc: testing should not be imported outside of tests
errorlint:
errorf: true
asserts: true
comparison: true
forbidigo:
forbid:
- pattern: ^rsa\.GenerateKey$
pkg: ^crypto/rsa$
msg: generating RSA keys is slow, use lib/cryptosuites to generate an appropriate key type
- pattern: ^common\.StringToRegion$
msg: use oraclejoincommon.StringToRegion to avoid OCI SDK data races
- pattern: ^iam\.NewFromConfig$
msg: Use iamutils.NewFromConfig
- pattern: ^sts\.NewFromConfig$
msg: Use stsutils.NewFromConfig
- pattern: ^sts\.New$
msg: Use stsutils.NewV1
- pattern: ^stscreds\.NewCredentials$
msg: Use stsutils.NewCredentials
- pattern: ^protojson\.Unmarshal$
msg: use protojson.UnmarshalOptions and consider enabling DiscardUnknown
- pattern: ^jsonpb\.(?:Unmarshal|UnmarshalString|UnmarshalNext)$
msg: use protojson if possible, or use jsonpb.Unmarshaler and consider enabling AllowUnknownFields
- pattern: ^semver\.New$
pkg: ^github.com/coreos/go-semver/semver$
msg: construct a semver.Version manually or use semver.NewVersion
- pattern: ^[^\.]+\.LoadDefaultConfig$
pkg: ^github.com/aws/aws-sdk-go-v2/config$
msg: use github.com/gravitational/teleport/lib/cloud/aws/config.LoadDefaultConfig to ensure region validation
- pattern: ^ssh\.(Dial|NewClient|NewClientConn)$
pkg: ^golang\.org/x/crypto/ssh$
msg: Use api/ssh package to construct SSH clients with proper defaults
- pkg: '^os/user$'
pattern: '^user\.(Lookup|LookupId|LookupGroup|LookupGroupId|Current|User\.GroupIds)$'
msg: 'os/user lookup APIs potentially unsafe; use the session/host/user wrapper instead'
- pattern: ^ssh\.(Dial|NewClientWithTimeout|NewClientConnWithTimeout)$
pkg: ^github\.com/gravitational/teleport/api/observability/tracing/ssh$
msg: Use api/ssh package to construct SSH clients with proper defaults
analyze-types: true
misspell:
locale: US
nolintlint:
require-explanation: true
require-specific: true
allow-unused: true
revive:
rules:
- name: unused-parameter
disabled: true
sloglint:
context: all
static-msg: true
key-naming-case: snake
forbidden-keys:
- level
- msg
- source
- time
testifylint:
disable-all: true
enable:
- bool-compare
- compares
- empty
- error-is-as
- error-nil
- expected-actual
- float-compare
- len
- suite-extra-assert-call
- suite-thelper
usetesting:
context-todo: true
# TODO: Enable the following after the issues are fixed.
context-background: false
os-chdir: false
os-create-temp: false
os-mkdir-temp: false
os-setenv: false
os-temp-dir: false
exclusions:
generated: lax
presets:
- comments
- common-false-positives
- legacy
- std-error-handling
rules:
- linters:
- staticcheck
text: 'QF1008: could remove embedded field'
- linters:
- staticcheck
text: 'QF1008: could simplify selectors'
- linters:
- staticcheck
text: 'S1002: should omit comparison to bool constant'
- linters:
- revive
text: 'exported: exported const'
- linters:
- unused
path: integrations/operator/controllers/resources/(.+)_controller_test\.go
- linters:
- staticcheck
text: grpc.Dial is deprecated
- linters:
- staticcheck
text: grpc.DialContext is deprecated
- linters:
- staticcheck
path: (client/client.go|client/proxy/client_test.go)
text: this DialOption is not supported by NewClient
- linters:
- staticcheck
path: lib/kube/grpc/grpc_test.go
text: grpc.WithBlock is deprecated
- linters:
- staticcheck
path: lib/observability/tracing/client.go
text: grpc.WithBlock is deprecated
- linters:
- staticcheck
path: integrations/lib/config.go
text: grpc.WithReturnConnectionError is deprecated
- linters:
- staticcheck
path: lib/service/service_test.go
text: this DialOption is not supported by NewClient
- linters:
- staticcheck
path: integration/client_test.go
text: grpc.WithReturnConnectionError is deprecated
- linters:
- staticcheck
path: integration/integration_test.go
text: grpc.WithBlock is deprecated
- linters:
- staticcheck
path: lib/multiplexer/multiplexer_test.go
text: grpc.WithBlock is deprecated
- linters:
- staticcheck
path: provider/provider.go
text: grpc.WithReturnConnectionError is deprecated
- linters:
- staticcheck
text: 'BlockUntil is deprecated: New code should prefer BlockUntilContext'
- linters:
- forbidigo
path: lib/utils/aws/iamutils/iam.go
text: iam.NewFromConfig
- linters:
- forbidigo
path: lib/utils/aws/stsutils/sts.go
text: sts.NewFromConfig
- linters:
- forbidigo
path: lib/utils/aws/stsutils/sts_v1.go
text: sts.New
- linters:
- forbidigo
path: lib/utils/aws/stsutils/stscreds_v1.go
text: stscreds.NewCredentials
- linters:
- forbidigo
path: lib/cloud/aws/config/config.go
text: LoadDefaultConfig
- linters:
- forbidigo
path: examples/dynamoathenamigration/migration.go
text: LoadDefaultConfig
- linters:
- forbidigo
path: e/scripts/loadtest-login/main.go
text: LoadDefaultConfig
# Only the api/observability/tracing/ssh package is allowed to call x/crypto/ssh new client functions directly.
- linters:
- forbidigo
path: ^api/observability/tracing/ssh/
text: ssh.NewClient
- linters:
- forbidigo
path: ^api/observability/tracing/ssh/
text: ssh.NewClientConn
- linters:
- forbidigo
path: ^api/observability/tracing/ssh/
text: NewClientWithTimeout
- linters:
- forbidigo
path: ^api/observability/tracing/ssh/
text: NewClientConnWithTimeout
# Only the api/ssh package is allowed to call the api/observability/tracing/ssh package directly. All others must use the api/ssh package.
- linters:
- forbidigo
path: ^api/ssh/
text: tracessh.Dial
- linters:
- forbidigo
path: ^api/ssh/
text: tracessh.NewClientWithTimeout
- linters:
- forbidigo
path: ^api/ssh/
text: tracessh.NewClientConnWithTimeout
# Allow session/host/user and tests to use os/user functions directly.
- path: '(_test\.go$|^api/|^integration/helpers/|^lib/utils/testutils|^session/host/user/)'
text: "session/host/user"
linters:
- forbidigo
# TODO: Fix forced type assertions in the rest of the codebase and remove this exclusion so that the linter can
# enforce this rule everywhere.
- linters:
- forcetypeassert
path-except: ^lib/tlsca/ca\.go$
paths:
- (^|/)node_modules/
- ^api/gen/
- ^docs/
- ^gen/
- ^rfd/
- ^web/
issues:
max-issues-per-linter: 0
max-same-issues: 0
uniq-by-line: false
formatters:
enable:
- gci
- goimports
settings:
gci:
sections:
- standard
- default
- prefix(github.com/gravitational/teleport)
- prefix(github.com/gravitational/teleport/integrations/terraform,github.com/gravitational/teleport/integrations/event-handler)
custom-order: true
exclusions:
generated: lax
paths:
- (^|/)node_modules/
- ^api/gen/
- ^docs/
- ^gen/
- ^rfd/
- ^web/