.github/workflows/ci.yml:
- Go version: 1.22 -> 1.23.4 (matches go.mod's 'go 1.23.0' declaration).
- Split into four jobs with explicit names:
* test-backend: go vet + go build + go test
* scan-backend: staticcheck + govulncheck (installed from pinned tags)
* test-frontend: npm ci + eslint + tsc --noEmit + next build
* gitleaks: full-history secret scan on every PR
- Branches triggered: master + main + develop (master is the repo
default; the previous workflow only triggered on main/develop and
would never have run on the repo's actual PRs).
- actions/checkout@v4, actions/setup-go@v5, actions/setup-node@v4.
- Concurrency group cancels stale runs on the same ref.
- Node and Go caches enabled for faster CI.
.gitleaks.toml (new):
- Extends gitleaks defaults.
- Custom rule 'explorer-legacy-db-password-L@ker' keeps the historical
password pattern L@kers?\$?2010 wedged in the detection set even
after rotation, so any re-introduction (via copy-paste from old
branches, stale docs, etc.) fails CI.
- Allowlists docs/SECURITY.md and CHANGELOG.md where the string is
cited in rotation context.
backend/staticcheck.conf (new):
- Enables the full SA* correctness set.
- Temporarily disables ST1000/1003/1005/1020/1021/1022, U1000, S1016,
S1031. These are stylistic/cosmetic checks; the project has a long
tail of pre-existing hits there that would bloat every PR. Each is
commented so the disable can be reverted in a dedicated cleanup.
Legit correctness issues surfaced by staticcheck and fixed in this PR:
- backend/analytics/token_distribution.go: 'best-effort MV refresh'
block no longer dereferences a shadowed 'err'; scope-tight 'if err :='
used for the subsequent QueryRow.
- backend/api/rest/middleware.go: compressionMiddleware() was parsing
Accept-Encoding and doing nothing with it. Now it's a literal
pass-through with a TODO comment pointing at gorilla/handlers.
- backend/api/rest/mission_control.go: shadowed 'err' from
json.Unmarshal was assigned to an ignored outer binding via
fmt.Errorf; replaced with a scoped 'if uerr :=' that lets the RPC
fallback run as intended.
- backend/indexer/traces/tracer.go: best-effort CREATE TABLE no longer
discards the error implicitly.
- backend/indexer/track2/block_indexer.go: 'latestBlock - uint64(i) >= 0'
was a tautology on uint64. Replaced with an explicit
'if uint64(i) > latestBlock { break }' guard so operators running
count=1000 against a shallow chain don't underflow.
- backend/tracing/tracer.go: introduces a local ctxKey type and two
constants so WithValue calls stop tripping SA1029.
Verification:
- go build ./... clean.
- go vet ./... clean.
- go test ./... all existing tests PASS.
- staticcheck ./... clean except for the SA1029 hits in
api/middleware/auth.go and api/track4/operator_scripts_test.go,
which are resolved by PR #4 once it merges to master.
Advances completion criterion 4 (CI in good health).
106 lines
2.7 KiB
Go
106 lines
2.7 KiB
Go
package track2
|
|
|
|
import (
|
|
"context"
|
|
"fmt"
|
|
"math/big"
|
|
"time"
|
|
|
|
"github.com/ethereum/go-ethereum/ethclient"
|
|
"github.com/jackc/pgx/v5/pgxpool"
|
|
)
|
|
|
|
// BlockIndexer indexes blocks for Track 2
|
|
type BlockIndexer struct {
|
|
db *pgxpool.Pool
|
|
client *ethclient.Client
|
|
chainID int
|
|
}
|
|
|
|
// NewBlockIndexer creates a new block indexer
|
|
func NewBlockIndexer(db *pgxpool.Pool, client *ethclient.Client, chainID int) *BlockIndexer {
|
|
return &BlockIndexer{
|
|
db: db,
|
|
client: client,
|
|
chainID: chainID,
|
|
}
|
|
}
|
|
|
|
// IndexBlock indexes a single block
|
|
func (bi *BlockIndexer) IndexBlock(ctx context.Context, blockNumber uint64) error {
|
|
block, err := bi.client.BlockByNumber(ctx, big.NewInt(int64(blockNumber)))
|
|
if err != nil {
|
|
return fmt.Errorf("failed to get block: %w", err)
|
|
}
|
|
|
|
// Check if block already indexed
|
|
var exists bool
|
|
checkQuery := `SELECT EXISTS(SELECT 1 FROM blocks WHERE chain_id = $1 AND number = $2)`
|
|
err = bi.db.QueryRow(ctx, checkQuery, bi.chainID, blockNumber).Scan(&exists)
|
|
if err != nil {
|
|
return fmt.Errorf("failed to check block existence: %w", err)
|
|
}
|
|
|
|
if exists {
|
|
return nil // Already indexed
|
|
}
|
|
|
|
// Insert block
|
|
insertQuery := `
|
|
INSERT INTO blocks (
|
|
chain_id, number, hash, parent_hash, miner, difficulty, total_difficulty,
|
|
size, gas_limit, gas_used, timestamp, transaction_count, base_fee_per_gas
|
|
) VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11, $12, $13)
|
|
ON CONFLICT (chain_id, number) DO NOTHING
|
|
`
|
|
|
|
_, err = bi.db.Exec(ctx, insertQuery,
|
|
bi.chainID,
|
|
block.Number().Int64(),
|
|
block.Hash().Hex(),
|
|
block.ParentHash().Hex(),
|
|
block.Coinbase().Hex(),
|
|
block.Difficulty().String(),
|
|
"0", // total_difficulty
|
|
block.Size(),
|
|
block.GasLimit(),
|
|
block.GasUsed(),
|
|
time.Unix(int64(block.Time()), 0),
|
|
len(block.Transactions()),
|
|
block.BaseFee(),
|
|
)
|
|
|
|
if err != nil {
|
|
return fmt.Errorf("failed to insert block: %w", err)
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
// IndexLatestBlocks indexes the latest N blocks
|
|
func (bi *BlockIndexer) IndexLatestBlocks(ctx context.Context, count int) error {
|
|
header, err := bi.client.HeaderByNumber(ctx, nil)
|
|
if err != nil {
|
|
return fmt.Errorf("failed to get latest header: %w", err)
|
|
}
|
|
|
|
latestBlock := header.Number.Uint64()
|
|
|
|
// `count` may legitimately reach back farther than latestBlock (e.g.
|
|
// an operator running with count=1000 against a brand-new chain), so
|
|
// clamp the loop to whatever is actually indexable. The previous
|
|
// "latestBlock-uint64(i) >= 0" guard was a no-op on an unsigned type.
|
|
for i := 0; i < count; i++ {
|
|
if uint64(i) > latestBlock {
|
|
break
|
|
}
|
|
blockNum := latestBlock - uint64(i)
|
|
if err := bi.IndexBlock(ctx, blockNum); err != nil {
|
|
// Log error but continue
|
|
fmt.Printf("Failed to index block %d: %v\n", blockNum, err)
|
|
}
|
|
}
|
|
|
|
return nil
|
|
}
|