Author SHA1 Message Date
sneak 32b468af8a cibuild: run checks on unchanged trees via CHECK_EPOCH (closes #89)
check / check (push) Failing after 1s
A bare `docker build .` keyed `make fmt-check-go`, `make lint`, the
prettier check, and `make test` on the build context, so on an unchanged
tree every check layer was a cache hit: the build exited 0 in under a
second having run none of them.

Add `ARG CHECK_EPOCH` immediately above the first check RUN in all three
check stages (lint, mdfmt, builder), and have script/cibuild pass a fresh
`--build-arg CHECK_EPOCH` each run. The changing value busts the cache from
that point down, while `go mod download` and `yarn install` above it stay
cached, so the build does not regress to cold. The false claim in
script/cibuild's header comment is corrected.

Running the checks for real surfaces the pre-existing intermittent
internal/cli test timeout (the gpg-subprocess flake in #62 / #67); that
defect is out of scope here.

Model: opus-4-8
2026-09-21 07:47:22 +00:00
3 changed files with 23 additions and 4 deletions
+12
View File
@@ -11,6 +11,10 @@ COPY . .
# Touch .pb.go so make does not try to regenerate via protoc (file is committed)
RUN touch mfer/mf.pb.go
# Changing value from script/cibuild; forces the check steps below to
# re-run instead of being served from a stale layer cache.
ARG CHECK_EPOCH
# Go half of fmt-check only: this image has no node, so no prettier. The
# markdown half runs in the mdfmt stage below.
RUN make fmt-check-go
@@ -27,6 +31,10 @@ RUN yarn install --frozen-lockfile
COPY . .
# Changing value from script/cibuild; forces the check step below to
# re-run instead of being served from a stale layer cache.
ARG CHECK_EPOCH
# No make in this image; call the script entrypoint directly.
RUN script/prettier --check
@@ -47,6 +55,10 @@ COPY . .
# Touch .pb.go so make does not try to regenerate via protoc (file is committed)
RUN touch mfer/mf.pb.go
# Changing value from script/cibuild; forces the check steps below to
# re-run instead of being served from a stale layer cache.
ARG CHECK_EPOCH
RUN make test
RUN cd cmd/mfer && go build -tags urfave_cli_no_docs -o /mfer .
+2
View File
@@ -24,6 +24,8 @@ only thing left of the `chore/align-repo-policies` branch is the list below.
# Completed Steps
- 2026-09-21: made `script/cibuild` re-run the checks on an unchanged tree via a
changing `CHECK_EPOCH` build arg in each Dockerfile check stage (#89)
- 2026-08-09: added `.prettierrc`/`.prettierignore`, gave `script/fmt` and
`script/fmt-check` one shared prettier file set via `script/prettier`, dropped
the `|| true` that hid prettier failures, and added a node-based Dockerfile
+9 -4
View File
@@ -1,14 +1,19 @@
#!/bin/sh
# script/cibuild: run the CI build. The Dockerfile runs script/check
# (via make check), so a successful build implies all checks pass.
# Generic: needs no adaptation. The Gitea workflow runs this on push.
# script/cibuild: run the CI build. The Dockerfile runs make fmt-check-go,
# make lint, the prettier check, and make test as build steps. A bare
# `docker build .` would serve those steps from Docker's layer cache on an
# unchanged tree, exiting 0 without running them. CHECK_EPOCH is a build
# arg placed above the check steps in every check stage; passing a fresh
# value each run busts the cache for those steps (and nothing above them),
# so a green build means the checks actually ran. Dependency layers above
# the arg stay cached. The Gitea workflow runs this on push.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
docker build .
docker build --build-arg CHECK_EPOCH="$(date +%s)" .
}
main "$@"