diff --git a/README.md b/README.md index ec05d47..4dabec8 100644 --- a/README.md +++ b/README.md @@ -23,8 +23,9 @@ javascript library is planned. # Build Status -CI runs via `script/cibuild` (`docker build .`), which executes `make check` -(formatting, linting, tests). The `main` branch must always be green. +CI runs `script/cibuild`, which builds the Docker image with `--no-cache`, so +the formatting, lint and test steps in the `Dockerfile` run on every build. The +`main` branch must always be green. # Entrypoints @@ -56,8 +57,8 @@ provide: Docker lint stage, whose image has no node - `script/check` — run `script/test`, `script/lint`, and `script/fmt-check` - `script/docker` — build the Docker image tagged with the project name -- `script/cibuild` — CI entrypoint: `docker build .` (the Dockerfile runs the - checks) +- `script/cibuild` — CI entrypoint: builds the image with the same command as + `script/docker`, uncached, so the checks in the Dockerfile run every time - `script/precommit` — pre-commit checks: `go mod tidy` verification, then `script/check` - `script/install-precommit` — install the git pre-commit hook that runs diff --git a/TODO.md b/TODO.md index 6e41a04..9a99bc3 100644 --- a/TODO.md +++ b/TODO.md @@ -24,6 +24,9 @@ only thing left of the `chore/align-repo-policies` branch is the list below. # Completed Steps +- 2026-10-03: `script/cibuild` builds the image with the same command as + `script/docker`, `--no-cache` included, so the checks in the Dockerfile run on + every build, also on an unchanged tree (#89) - 2026-10-03: `fetch` removes whatever sits at a file's temp name and then creates the temp file only if that name is free, so a hard link left there cannot make it write into a file outside the destination directory (#115) diff --git a/script/cibuild b/script/cibuild index 3da5857..469c1df 100755 --- a/script/cibuild +++ b/script/cibuild @@ -1,14 +1,24 @@ #!/bin/sh -# script/cibuild: run the CI build. The Dockerfile runs script/check -# (via make check), so a successful build implies all checks pass. -# Generic: needs no adaptation. The Gitea workflow runs this on push. +# script/cibuild: run the CI build; the Gitea workflow runs this on push. +# It builds the image with the same command as script/docker. --no-cache +# because the checks the final stage depends on are RUN steps, and a +# cached one is a check that did not run. set -eu -ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" +SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" +ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)" main() { cd "$ROOT" - docker build . + # Own line: a failing command substitution inside an argument does + # not trip `set -e`, so the inline form degrades silently to an + # empty constant. The VERSION build argument takes precedence over + # the version a build stage derives from the .git in the context. + version="$(git describe --tags --always --dirty 2>/dev/null || true)" + [ -n "$version" ] || version="unknown" + docker build --no-cache \ + --build-arg VERSION="$version" \ + -t "$("$SCRIPT_DIR/projectname")" . } main "$@"