Compare commits

..
1 Commits
Author SHA1 Message Date
clawbot 1a7b33c7c5 Run lint and tests as phases of the Dockerfile (closes #5)
check / check (push) Successful in 3m16s
The Dockerfile gets a lint phase on the pinned golangci-lint v2.12.2
image and a test phase on the Debian Go image. The tests run as an
unprivileged user, because root reads a file with mode 0000 and the
permission test then fails. The build stage copies a file from each
phase, so no build finishes unless both pass, and it no longer runs
make check. script/lint and script/test each build their phase,
uncached and tagged; script/cibuild bootstraps, runs script/check, then
builds the image. script/bootstrap no longer installs golangci-lint.
README.md and TODO.md describe the new setup.

Model: opus-5-5
2026-10-06 03:00:44 +00:00
+4 -5
View File
@@ -9,13 +9,12 @@ RUN golangci-lint run --config .golangci.yml ./...
# Test phase. -race needs cgo and so a C compiler, which the Debian Go
# image ships and the alpine one does not. The tests run as an
# unprivileged user: root bypasses file mode bits, which would make the
# permission tests (expecting EACCES on a 0000 file) spuriously pass with
# no error.
# unprivileged user: root can read a file with mode 0000, so the
# permission test would fail.
# golang:1.25.7-trixie, 2026-10-06
FROM golang@sha256:2b174ffcf56c7ad0c47d30d2630693265639ddf2a5141149c2da34db921791b4 AS test
RUN useradd --create-home builder
USER builder
RUN useradd --create-home testuser
USER testuser
WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download