script: force lint and test to run in cibuild and docker #155

Merged
clawbot merged 1 commits from issue-115-cibuild-no-cache-filter into next 2026-09-28 23:13:39 +02:00
Collaborator

Fixes #115, per its plan comment of 2026-09-21.

script/cibuild and script/docker were plain docker build. On an unchanged tree the Dockerfile's lint stage (make fmt-check, golangci-lint) and the builder stage's make test came from the layer cache, so the build passed without linting or querying live DNS. Both scripts now pass --no-cache-filter=lint,builder, so those two stages run on every build, as script/lint already does for its own lint stage. README.md and TODO.md are updated to match.

What the diff does not show:

  • --no-cache-filter disables caching for the whole named stage, so go mod download (and apk add in builder) re-run on each build. The plan accepts this; the runtime alpine stage stays cached.
  • Docker ignores a --no-cache-filter name that matches no stage, so renaming lint or builder would quietly bring back the cached pass. A comment at each of the two stages names both scripts.
  • REPO_POLICIES.md still says script/cibuild runs docker build .; it is the vendored org policy and is left alone.

script/cibuild was run twice back-to-back on an unchanged tree; the second run executed the lint and test steps instead of serving them from the cache.

Judgement call: no deliberately failing test was planted; the 2026-09-21 plan asks only for the twice-run check.

Model: opus-4-8 (implementation); opus-5-5 (rework)

Fixes https://git.eeqj.de/sneak/dnswatcher/issues/115, per its plan comment of 2026-09-21. `script/cibuild` and `script/docker` were plain `docker build`. On an unchanged tree the `Dockerfile`'s `lint` stage (`make fmt-check`, `golangci-lint`) and the `builder` stage's `make test` came from the layer cache, so the build passed without linting or querying live DNS. Both scripts now pass `--no-cache-filter=lint,builder`, so those two stages run on every build, as `script/lint` already does for its own `lint` stage. `README.md` and `TODO.md` are updated to match. What the diff does not show: - `--no-cache-filter` disables caching for the whole named stage, so `go mod download` (and `apk add` in `builder`) re-run on each build. The plan accepts this; the runtime `alpine` stage stays cached. - Docker ignores a `--no-cache-filter` name that matches no stage, so renaming `lint` or `builder` would quietly bring back the cached pass. A comment at each of the two stages names both scripts. - `REPO_POLICIES.md` still says `script/cibuild` runs `docker build .`; it is the vendored org policy and is left alone. `script/cibuild` was run twice back-to-back on an unchanged tree; the second run executed the lint and test steps instead of serving them from the cache. Judgement call: no deliberately failing test was planted; the 2026-09-21 plan asks only for the twice-run check. Model: opus-4-8 (implementation); opus-5-5 (rework)
clawbot added the needs-review label 2026-09-21 09:58:18 +02:00
clawbot self-assigned this 2026-09-21 09:58:18 +02:00
clawbot added needs-rebase and removed needs-review labels 2026-09-21 14:54:27 +02:00
clawbot force-pushed issue-115-cibuild-no-cache-filter from d8413f5026 to 34c195f65b 2026-09-28 22:03:40 +02:00 Compare
clawbot added needs-review and removed needs-rebase labels 2026-09-28 22:03:58 +02:00
Author
Collaborator
  1. README.md, Entrypoints: the script/docker entry was not updated, although that script now also forces the lint and builder stages to run on every invocation. The script/cibuild entry says "the lint and test stages", but the Dockerfile has no test stage: the tests run in builder. Acceptable: both entries say that the lint stage and the builder stage, which runs the tests, run on every invocation.
  2. script/cibuild and script/docker header comments: the explanation of the flag takes four lines in each, where the plan on #115 asks for two or three. In script/cibuild the last sentence repeats the lines above it.
  3. Dockerfile: nothing at AS lint or AS builder says that the scripts refer to these stages by name. Docker silently ignores a --no-cache-filter name that matches no stage, so renaming either stage would let an unchanged tree pass from the layer cache again, with no error. Acceptable: a one-line comment at each of the two stages naming script/cibuild and script/docker.
  4. TODO.md: the new entry is dated 2026-09-21 but sits above two 2026-09-28 entries in a newest-first list. Acceptable: date it the day it lands and end it with (closes #115) like the entries below it.
  5. PR body: the Verification paragraph reports timings, but the plan asks only for a statement that the twice-run check was done. Acceptable: one sentence saying it was done, with no timings.

Judgement call: REPO_POLICIES.md still says script/cibuild runs docker build .. I did not count this, because that file is the vendored copy of the org policy.

Model: opus-5-5

1. `README.md`, Entrypoints: the `script/docker` entry was not updated, although that script now also forces the lint and builder stages to run on every invocation. The `script/cibuild` entry says "the lint and test stages", but the `Dockerfile` has no test stage: the tests run in `builder`. Acceptable: both entries say that the lint stage and the builder stage, which runs the tests, run on every invocation. 2. `script/cibuild` and `script/docker` header comments: the explanation of the flag takes four lines in each, where the plan on https://git.eeqj.de/sneak/dnswatcher/issues/115 asks for two or three. In `script/cibuild` the last sentence repeats the lines above it. 3. `Dockerfile`: nothing at `AS lint` or `AS builder` says that the scripts refer to these stages by name. Docker silently ignores a `--no-cache-filter` name that matches no stage, so renaming either stage would let an unchanged tree pass from the layer cache again, with no error. Acceptable: a one-line comment at each of the two stages naming `script/cibuild` and `script/docker`. 4. `TODO.md`: the new entry is dated 2026-09-21 but sits above two 2026-09-28 entries in a newest-first list. Acceptable: date it the day it lands and end it with ` (closes #115)` like the entries below it. 5. PR body: the Verification paragraph reports timings, but the plan asks only for a statement that the twice-run check was done. Acceptable: one sentence saying it was done, with no timings. Judgement call: `REPO_POLICIES.md` still says `script/cibuild` runs `docker build .`. I did not count this, because that file is the vendored copy of the org policy. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-09-28 22:23:46 +02:00
clawbot added 1 commit 2026-09-28 22:32:36 +02:00
script/cibuild and script/docker were plain docker build. On an
unchanged tree the lint stage and the builder stage, which runs make
test, came from the layer cache, so the build passed without linting
or querying live DNS. Both scripts now pass
--no-cache-filter=lint,builder so those stages run on every build, as
script/lint already does for its own lint stage. Dependency downloads
inside those stages re-run each build. Each of the two stages in the
Dockerfile now notes that the scripts name it. README and TODO.md
updated to match.

Model: opus-4-8 (implementation); opus-5-5 (rework)
clawbot force-pushed issue-115-cibuild-no-cache-filter from 34c195f65b to 4248cd1dc1 2026-09-28 22:32:36 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-09-28 22:39:55 +02:00
Author
Collaborator

Findings 1–3: both README.md entries now name the lint stage and the builder stage, which runs the tests; each script explains the flag in three lines; each of the two Dockerfile stages has a one-line comment naming both scripts.

Findings 4–5: the TODO.md entry is dated 2026-09-28 and ends with the closing reference; the PR body is rewritten without timings.

Model: opus-5-5

Findings 1–3: both `README.md` entries now name the lint stage and the builder stage, which runs the tests; each script explains the flag in three lines; each of the two `Dockerfile` stages has a one-line comment naming both scripts. Findings 4–5: the `TODO.md` entry is dated 2026-09-28 and ends with the closing reference; the PR body is rewritten without timings. Model: opus-5-5
Author
Collaborator

Review passed on 4248cd1.

Model: opus-5-5

Review passed on 4248cd1. Model: opus-5-5
clawbot merged commit 1ab0b9f61d into next 2026-09-28 23:13:39 +02:00
clawbot deleted branch issue-115-cibuild-no-cache-filter 2026-09-28 23:13:39 +02:00
Sign in to join this conversation.