Force check layers to execute on every cibuild run (closes #89)
All checks were successful
check / check (push) Successful in 29s

script/cibuild ran a bare "docker build .". The Dockerfile does "COPY . ."
and then runs the checks, so on an unchanged tree every check layer was a
cache hit: the suite never executed and the build still exited 0. A green
from script/cibuild did not mean the checks had passed, only that they had
passed at some point in the past.

Declare "ARG CHECK_EPOCH" in each stage that runs a check, positioned below
the dependency layers and immediately above the first check, and have
script/cibuild pass a fresh "$(date +%s)" on every invocation. A changed
build arg invalidates every layer below its declaration, so the checks
always execute while the base images, "go mod download" and the "yarn
install" in mdfmt stay cached.

All three check-running stages are covered: lint (fmt-check-go, lint),
mdfmt (prettier --check) and builder (test). ARG is scoped per stage, so a
stage without its own declaration would keep serving a cached pass and be
indistinguishable from a working fix at the exit code.

"--no-cache" was not used: it would also discard "go mod download" and the
yarn install, for no additional guarantee.

The README's build-status claim is accurate again and now says why.
This commit is contained in:
clawbot
2026-09-03 20:39:30 +00:00
parent 5683d0f4ff
commit b7cb8cd9d0
3 changed files with 26 additions and 3 deletions

View File

@@ -23,8 +23,12 @@ javascript library is planned.
# Build Status
CI runs via `script/cibuild` (`docker build .`), which executes `make check`
(formatting, linting, tests). The `main` branch must always be green.
CI runs via `script/cibuild`, which builds the Dockerfile. Every stage that runs
a check declares an `ARG CHECK_EPOCH` above it, and `script/cibuild` passes a
fresh value on every invocation, so the check layers cannot be served from the
Docker layer cache. A successful build therefore implies that formatting,
linting, and tests actually ran and passed on the current tree. The `main`
branch must always be green.
# Entrypoints