Lint and test as phases of the Dockerfile (closes #38)
check / check (push) Failing after 7s

Linting and testing are now the lint and test phases of the one
Dockerfile, and the build stage copies a file from each, so a plain
docker build . cannot pass while either fails. Dockerfile.lint is gone.
REPO_POLICIES.md, script/lint, script/test, script/docker and
script/cibuild are the current copies from the next branch of
sneak/prompts: every docker build there is uncached and tagged,
script/test builds the test phase instead of running go vet and go test
on the host, and script/cibuild bootstraps, runs script/check, then
builds the image with the version from the host. The test phase
installs gcc and musl-dev because -race needs cgo. The version stamping
is unchanged. The issue's line leaves the README TODO list.

Model: opus-5-5
This commit is contained in:
2026-10-03 23:43:10 +00:00
parent 8d1c873bb7
commit fd1f80a8bc
9 changed files with 393 additions and 131 deletions
+41 -6
View File
@@ -1,10 +1,48 @@
# The formatting check, the tests and the build. Linting is not here:
# it runs in its own pinned image, see Dockerfile.lint and script/lint,
# which script/cibuild runs before this file.
# The lint phase, the test phase and the build. script/lint and
# script/test each build one phase alone; a plain `docker build .` builds
# both, because the build stage copies a file from each. Formatting is
# checked on the host by script/fmt-check, not here.
# Lint phase
# golangci/golangci-lint:v2.12.2, 2026-09-07
FROM golangci/golangci-lint@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS lint
WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN golangci-lint run --config .golangci.yml ./...
# Test phase
# golang:1.26-alpine, 2026-09-07
FROM golang@sha256:ce864e7223ac17b1775e6fd0b4c0db580c2eb50e7953a427916379e4b92a1628 AS test
# -race needs cgo, and cgo needs a C toolchain.
RUN apk add --no-cache gcc musl-dev
WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN go test -timeout 90s -race -cover ./... || \
{ echo "--- Rerunning with -v for details ---"; \
go test -timeout 90s -race -v ./...; exit 1; }
# Build stage. Nothing is wanted from either phase above; the copies
# are what make BuildKit build them first, so this stage cannot run
# unless lint and test passed.
# golang:1.26-alpine, 2026-09-07
FROM golang@sha256:ce864e7223ac17b1775e6fd0b4c0db580c2eb50e7953a427916379e4b92a1628 AS builder
COPY --from=lint /src/go.sum /dev/null
COPY --from=test /src/go.sum /dev/null
RUN apk add --no-cache make git
WORKDIR /src
@@ -14,9 +52,6 @@ RUN go mod download
COPY . .
RUN make fmt-check
RUN make test
# The version stamped into the binary: the VERSION build argument when one
# is given, otherwise `git describe --tags --always` of the .git in the
# build context. A context that carries .git and still yields no version