From 34c195f65bf6c0cd55f2824f0b4b8e917c6c8179 Mon Sep 17 00:00:00 2001 From: sneak Date: Mon, 21 Sep 2026 07:48:58 +0000 Subject: [PATCH] script: force lint and test to run in cibuild and docker (closes #115) script/cibuild and script/docker were plain docker build. On an unchanged tree the lint stage and the builder stage's make test came from the layer cache, so the build reported success having linted nothing and queried no live DNS. Both scripts now pass --no-cache-filter=lint,builder, so those stages run on every build; this mirrors script/lint, which already does the same for the lint stage alone. Dependency downloads inside the disabled stages re-run, which the issue accepts. No pins, .golangci.yml, or test behaviour changed. README and TODO.md updated to match. Model: opus-4-8 (implementation); opus-5-5 (rebase) --- README.md | 5 ++++- TODO.md | 2 ++ script/cibuild | 9 +++++++-- script/docker | 9 +++++++-- 4 files changed, 20 insertions(+), 5 deletions(-) diff --git a/README.md b/README.md index 08d7d55..873ba36 100644 --- a/README.md +++ b/README.md @@ -467,7 +467,10 @@ them. We provide: - `script/check` — run test, lint, and fmt-check - `script/docker` — build the Docker image tagged via `script/projectname` -- `script/cibuild` — CI entrypoint: plain `docker build .` +- `script/cibuild` — CI entrypoint: `docker build` with + `--no-cache-filter=lint,builder`, forcing the lint and test stages to + run on every invocation, because a cached build lints nothing and + queries no DNS - `script/precommit` — run by the git pre-commit hook; `go mod tidy` guard, then `script/check` - `script/install-precommit` — install the git pre-commit hook diff --git a/TODO.md b/TODO.md index 10c50d2..332b9cd 100644 --- a/TODO.md +++ b/TODO.md @@ -23,6 +23,8 @@ Rationale, Design, TODO, License, Author) if any are still missing. # Completed Steps +- 2026-09-21: `script/cibuild` and `script/docker` now pass + `--no-cache-filter=lint,builder` so lint and tests run every build. - 2026-09-28: the server timeout test now drives `Run` and checks the `http.Server` it serves carries the timeouts; corrected the `ReadTimeout` note in that test (closes #120). diff --git a/script/cibuild b/script/cibuild index 1b9e57d..7ae48f0 100755 --- a/script/cibuild +++ b/script/cibuild @@ -1,14 +1,19 @@ #!/bin/sh # script/cibuild: run the CI build. The Dockerfile's lint stage runs # make fmt-check and golangci-lint; its builder stage runs make test -# and make build. A successful build implies all of those passed. +# and make build. +# +# --no-cache-filter=lint,builder forces both of those stages to run on +# every invocation. Without it an unchanged tree serves them from the +# layer cache, reporting success having linted nothing and queried no +# live DNS. A successful build then implies those stages actually ran. set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" main() { cd "$ROOT" - docker build . + docker build --no-cache-filter=lint,builder . } main "$@" diff --git a/script/docker b/script/docker index 9b9ea86..794eb5a 100755 --- a/script/docker +++ b/script/docker @@ -1,6 +1,11 @@ #!/bin/sh # script/docker: build the Docker image tagged with the project name. -# Identical in all repos; the tag comes from script/projectname. +# The tag comes from script/projectname. +# +# --no-cache-filter=lint,builder forces the lint stage and the builder +# stage (make test) to run on every invocation. Without it an unchanged +# tree serves them from the layer cache, producing an image whose build +# linted nothing and queried no live DNS. set -eu SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" @@ -8,7 +13,7 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)" main() { cd "$ROOT" - docker build -t "$("$SCRIPT_DIR/projectname")" . + docker build --no-cache-filter=lint,builder -t "$("$SCRIPT_DIR/projectname")" . } main "$@"