cibuild: the org model, which runs every check uncached (closes #37)
check / check (push) Successful in 2m2s
check / check (push) Successful in 2m2s
script/cibuild was a plain docker build ., so on a tree Docker had seen before every check step came from the build cache and the build still passed. It is now the org model from sneak/prompts, byte for byte: script/bootstrap, script/check, then docker build --no-cache with the git describe version as the VERSION build argument. The workflow puts ~/.local/bin, where bootstrap links what it installs, on the step's PATH. Bootstrap now installs its pinned node when the installed one is older than 22.12.0, the oldest the frontend's dependencies accept (puppeteer-core's engines field), as it already does for Go against backend/go.mod. Model: opus-5-5
This commit is contained in:
+25
-7
@@ -3,12 +3,12 @@
|
||||
# this repo. Idempotent: every install is guarded by a check so already
|
||||
# installed tools are skipped. Base tooling comes from nix, apt, brew,
|
||||
# or apk (detected in that order); assumes nothing is present. Node is
|
||||
# used directly if installed; otherwise it is installed at a pinned
|
||||
# version via nvm (installing nvm itself first, from a hash-verified
|
||||
# release archive, never curl | sh). Go, with its gofmt, is used
|
||||
# directly if it is at least the version backend/go.mod asks for;
|
||||
# otherwise the pinned Go release is installed from its hash-verified
|
||||
# archive.
|
||||
# used directly if it is at least NODE_MIN_VERSION; otherwise it is
|
||||
# installed at a pinned version via nvm (installing nvm itself first,
|
||||
# from a hash-verified release archive, never curl | sh). Go, with its
|
||||
# gofmt, is used directly if it is at least the version backend/go.mod
|
||||
# asks for; otherwise the pinned Go release is installed from its
|
||||
# hash-verified archive.
|
||||
#
|
||||
# What this script installs outside the system package manager lives
|
||||
# under $HOME and is linked into ~/.local/bin, where make and the git
|
||||
@@ -23,6 +23,10 @@ ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
# Pinned versions, 2026-07-07
|
||||
NODE_VERSION="22.17.0"
|
||||
# The oldest node the frontend's dependencies accept: the "engines"
|
||||
# field of puppeteer-core 25.5.0, the most demanding of them, asks for
|
||||
# 22.12.0 or newer, 2026-09-29. An older installed node is not used.
|
||||
NODE_MIN_VERSION="22.12.0"
|
||||
NVM_VERSION="0.40.3"
|
||||
# sha256 of https://github.com/nvm-sh/nvm/archive/refs/tags/v0.40.3.tar.gz
|
||||
NVM_SHA256="5f4d6aaa04a177dc93c985e31dbc411ab6b8c6e1e21d8015dbc1372625fcd1d0"
|
||||
@@ -136,8 +140,22 @@ ensure_nvm() {
|
||||
rm -rf "$tmp"
|
||||
}
|
||||
|
||||
# node_ok: the node on PATH is at least NODE_MIN_VERSION. node itself
|
||||
# compares the two: major, then minor, then patch.
|
||||
node_ok() {
|
||||
if missing node; then return 1; fi
|
||||
node -e '
|
||||
const have = process.versions.node.split(".").map(Number);
|
||||
const want = process.argv[1].split(".").map(Number);
|
||||
for (let i = 0; i < 3; i++) {
|
||||
if (have[i] !== want[i]) process.exit(have[i] > want[i] ? 0 : 1);
|
||||
}
|
||||
' "$NODE_MIN_VERSION"
|
||||
}
|
||||
|
||||
# ensure_node: unless node_ok, install NODE_VERSION and link its node.
|
||||
ensure_node() {
|
||||
if ! missing node; then return 0; fi
|
||||
if node_ok; then return 0; fi
|
||||
ensure_nvm
|
||||
nvm_sh "nvm install $NODE_VERSION"
|
||||
link_bin "$HOME/.nvm/versions/node/v$NODE_VERSION/bin/node" node
|
||||
|
||||
+20
-6
@@ -1,15 +1,29 @@
|
||||
#!/bin/sh
|
||||
# script/cibuild: run the CI build: build the one image from Dockerfile,
|
||||
# whose stages run the checks as build steps (the backend's fmt-check,
|
||||
# lint and tests, and the frontend's test, lint and fmt-check). This is
|
||||
# the only build step the Gitea workflow runs.
|
||||
# script/cibuild: run the CI build. It bootstraps first: a CI runner
|
||||
# checks out and runs this and nothing else, and script/fmt-check runs
|
||||
# the formatter on the host, which a pristine checkout cannot do.
|
||||
# --no-cache for the same reason as script/docker: the gate phases the
|
||||
# final stage depends on are RUN steps, and a cached one is a check that
|
||||
# did not run.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
timeout 300 docker build .
|
||||
"$SCRIPT_DIR/bootstrap"
|
||||
"$SCRIPT_DIR/check"
|
||||
# Own line: a failing command substitution inside an argument does
|
||||
# not trip `set -e`, so the inline form degrades silently to an
|
||||
# empty constant. VERSION is computed here because .dockerignore
|
||||
# excludes .git, so `git describe` in a build stage yields an empty
|
||||
# version without failing.
|
||||
version="$(git describe --tags --always --dirty 2>/dev/null || true)"
|
||||
[ -n "$version" ] || version="unknown"
|
||||
docker build --no-cache \
|
||||
--build-arg VERSION="$version" \
|
||||
-t "$("$SCRIPT_DIR/projectname")" .
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
Reference in New Issue
Block a user