From 4248cd1dc1a14124a1d9d4b7e41d444898903b47 Mon Sep 17 00:00:00 2001 From: sneak Date: Mon, 21 Sep 2026 07:48:58 +0000 Subject: [PATCH] script: force lint and test to run in cibuild and docker (closes #115) script/cibuild and script/docker were plain docker build. On an unchanged tree the lint stage and the builder stage, which runs make test, came from the layer cache, so the build passed without linting or querying live DNS. Both scripts now pass --no-cache-filter=lint,builder so those stages run on every build, as script/lint already does for its own lint stage. Dependency downloads inside those stages re-run each build. Each of the two stages in the Dockerfile now notes that the scripts name it. README and TODO.md updated to match. Model: opus-4-8 (implementation); opus-5-5 (rework) --- Dockerfile | 2 ++ README.md | 10 +++++++--- TODO.md | 3 +++ script/cibuild | 8 ++++++-- script/docker | 8 ++++++-- 5 files changed, 24 insertions(+), 7 deletions(-) diff --git a/Dockerfile b/Dockerfile index 48b467e..b4f7273 100644 --- a/Dockerfile +++ b/Dockerfile @@ -2,6 +2,7 @@ # The linter is invoked directly rather than through `make lint`: that # target shells out to `docker build -f Dockerfile.lint`, and there is # no docker daemon inside a docker build. +# script/cibuild and script/docker name this stage in --no-cache-filter. # golangci/golangci-lint:v2.12.2 (Debian-based), 2026-08-10 FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS lint @@ -15,6 +16,7 @@ RUN make fmt-check RUN golangci-lint run --config .golangci.yml ./... # Build stage +# script/cibuild and script/docker name this stage in --no-cache-filter. # golang 1.25-alpine, 2026-02-28 FROM golang@sha256:f6751d823c26342f9506c03797d2527668d095b0a15f1862cddb4d927a7a4ced AS builder diff --git a/README.md b/README.md index 08d7d55..13c9ebb 100644 --- a/README.md +++ b/README.md @@ -465,9 +465,13 @@ them. We provide: - `script/fmt` — format all code (gofmt -s, goimports) - `script/fmt-check` — check formatting (read-only) - `script/check` — run test, lint, and fmt-check -- `script/docker` — build the Docker image tagged via - `script/projectname` -- `script/cibuild` — CI entrypoint: plain `docker build .` +- `script/docker` — build the Docker image tagged via `script/projectname`, with + `--no-cache-filter=lint,builder` so the lint stage and the builder stage, + which runs the tests, run on every invocation +- `script/cibuild` — CI entrypoint: `docker build` with + `--no-cache-filter=lint,builder`, so the lint stage and the builder stage, + which runs the tests, run on every invocation, because a cached build lints + nothing and queries no DNS - `script/precommit` — run by the git pre-commit hook; `go mod tidy` guard, then `script/check` - `script/install-precommit` — install the git pre-commit hook diff --git a/TODO.md b/TODO.md index 10c50d2..575b959 100644 --- a/TODO.md +++ b/TODO.md @@ -23,6 +23,9 @@ Rationale, Design, TODO, License, Author) if any are still missing. # Completed Steps +- 2026-09-28: `script/cibuild` and `script/docker` now pass + `--no-cache-filter=lint,builder` so lint and tests run every build (closes + #115). - 2026-09-28: the server timeout test now drives `Run` and checks the `http.Server` it serves carries the timeouts; corrected the `ReadTimeout` note in that test (closes #120). diff --git a/script/cibuild b/script/cibuild index 1b9e57d..29bea03 100755 --- a/script/cibuild +++ b/script/cibuild @@ -1,14 +1,18 @@ #!/bin/sh # script/cibuild: run the CI build. The Dockerfile's lint stage runs # make fmt-check and golangci-lint; its builder stage runs make test -# and make build. A successful build implies all of those passed. +# and make build. +# +# --no-cache-filter=lint,builder runs both stages on every invocation; +# otherwise an unchanged tree is served from the layer cache and passes +# without linting or querying live DNS. set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" main() { cd "$ROOT" - docker build . + docker build --no-cache-filter=lint,builder . } main "$@" diff --git a/script/docker b/script/docker index 9b9ea86..4f1fd14 100755 --- a/script/docker +++ b/script/docker @@ -1,6 +1,10 @@ #!/bin/sh # script/docker: build the Docker image tagged with the project name. -# Identical in all repos; the tag comes from script/projectname. +# The tag comes from script/projectname. +# +# --no-cache-filter=lint,builder runs the lint stage and the builder +# stage (make test) on every invocation; otherwise an unchanged tree is +# served from the layer cache without linting or querying live DNS. set -eu SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" @@ -8,7 +12,7 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)" main() { cd "$ROOT" - docker build -t "$("$SCRIPT_DIR/projectname")" . + docker build --no-cache-filter=lint,builder -t "$("$SCRIPT_DIR/projectname")" . } main "$@" -- 2.54.0