cibuild: the org model, which runs every check uncached (closes #37)
check / check (push) Failing after 16s

script/cibuild was a plain docker build ., so on a tree Docker had
seen before every check step came from the build cache and the build
still passed. It is now the org model from sneak/prompts, byte for
byte: it runs script/bootstrap and script/check, then builds the image
with --no-cache and the git describe version as the VERSION build
argument, which the Dockerfile's builder stage already declares.
README.md's entry for the script says what it now does.

Model: opus-5-5
This commit is contained in:
2026-09-29 08:31:41 +00:00
parent d81da05748
commit 994c83334a
3 changed files with 28 additions and 7 deletions
+2 -1
View File
@@ -65,7 +65,8 @@ halves, so the root `make check` fails if either one is broken. We provide:
`script/check`: it needs Docker and takes minutes. `script/check`: it needs Docker and takes minutes.
- `script/docker` — build the image from `Dockerfile` without the build cache, - `script/docker` — build the image from `Dockerfile` without the build cache,
tagged `netwatch` via `script/projectname` tagged `netwatch` via `script/projectname`
- `script/cibuild` — CI entrypoint: builds the image - `script/cibuild` — CI entrypoint: runs `script/bootstrap` and `script/check`,
then builds the image as `script/docker` does, without the build cache
- `script/precommit` — run by the git pre-commit hook; runs `script/check` - `script/precommit` — run by the git pre-commit hook; runs `script/check`
- `script/install-precommit` — install the git pre-commit hook - `script/install-precommit` — install the git pre-commit hook
+6
View File
@@ -23,6 +23,12 @@ latest run passes.
# Completed Steps # Completed Steps
- 2026-09-29: CI can no longer pass on checks that did not run (issue #37):
`script/cibuild` is now the org model, byte for byte. It runs
`script/bootstrap` and `script/check`, then builds the image with `--no-cache`
and the version from `git describe` as the `VERSION` build argument, where it
used to be a plain `docker build .` whose check steps could come from the
build cache
- 2026-09-29: nginx sends the security headers `REPO_POLICIES.md` requires on - 2026-09-29: nginx sends the security headers `REPO_POLICIES.md` requires on
every response (issue #18), including errors, `/assets/` and what it passes on every response (issue #18), including errors, `/assets/` and what it passes on
from the backend, whose own copies it drops so each header goes out once. They from the backend, whose own copies it drops so each header goes out once. They
+20 -6
View File
@@ -1,15 +1,29 @@
#!/bin/sh #!/bin/sh
# script/cibuild: run the CI build: build the one image from Dockerfile, # script/cibuild: run the CI build. It bootstraps first: a CI runner
# whose stages run the checks as build steps (the backend's fmt-check, # checks out and runs this and nothing else, and script/fmt-check runs
# lint and tests, and the frontend's test, lint and fmt-check). This is # the formatter on the host, which a pristine checkout cannot do.
# the only build step the Gitea workflow runs. # --no-cache for the same reason as script/docker: the gate phases the
# final stage depends on are RUN steps, and a cached one is a check that
# did not run.
set -eu set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
main() { main() {
cd "$ROOT" cd "$ROOT"
timeout 300 docker build . "$SCRIPT_DIR/bootstrap"
"$SCRIPT_DIR/check"
# Own line: a failing command substitution inside an argument does
# not trip `set -e`, so the inline form degrades silently to an
# empty constant. VERSION is computed here because .dockerignore
# excludes .git, so `git describe` in a build stage yields an empty
# version without failing.
version="$(git describe --tags --always --dirty 2>/dev/null || true)"
[ -n "$version" ] || version="unknown"
docker build --no-cache \
--build-arg VERSION="$version" \
-t "$("$SCRIPT_DIR/projectname")" .
} }
main "$@" main "$@"