From 588803fa36984fc2f85ed8129e58e7e689affc1e Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Sat, 3 Oct 2026 15:53:10 +0000 Subject: [PATCH] Run the checks on every script/cibuild and script/docker build (closes #101) Both scripts pass a new CHECK_EPOCH, which the Dockerfile's make fmt-check, make lint and make test steps name in their commands. On an unchanged tree Docker used to serve those steps from its build cache, so a run could pass without checking anything. The script/bootstrap steps stay cached. A plain docker build . still works, as upaas builds the image that way: it leaves CHECK_EPOCH empty and reuses the check steps only for an identical build context. Model: opus-5-5 --- Dockerfile | 16 +++++++++++----- README.md | 5 +++-- TODO.md | 9 +++++++++ script/cibuild | 11 +++++++---- script/docker | 10 +++++++--- 5 files changed, 37 insertions(+), 14 deletions(-) diff --git a/Dockerfile b/Dockerfile index 91e4731..424ee87 100644 --- a/Dockerfile +++ b/Dockerfile @@ -18,9 +18,14 @@ COPY . . # Tells script/lint it is inside a container, so it runs the linter. ENV container=docker -# Run formatting check and linter -RUN make fmt-check -RUN make lint +# Run formatting check and linter. script/cibuild and script/docker pass +# a new CHECK_EPOCH on every run, and each check step names it in its +# command, so a new value reruns the step instead of reusing a cached +# success that checked nothing. A plain `docker build .` leaves it empty +# and reuses the check steps only for an identical build context. +ARG CHECK_EPOCH +RUN echo "check epoch: ${CHECK_EPOCH}" && make fmt-check +RUN echo "check epoch: ${CHECK_EPOCH}" && make lint # Build stage # golang:1.25.4-alpine, 2026-02-25 @@ -39,8 +44,9 @@ RUN script/bootstrap # Copy source code COPY . . -# Run tests -RUN make test +# Run tests; a new CHECK_EPOCH reruns them, as in the lint stage. +ARG CHECK_EPOCH +RUN echo "check epoch: ${CHECK_EPOCH}" && make test # VERSION is declared here, not earlier: a new value reruns only the # build, not script/bootstrap or the tests. Given none, the version is diff --git a/README.md b/README.md index ba1def6..76a1ef3 100644 --- a/README.md +++ b/README.md @@ -353,8 +353,9 @@ them. We provide: - `script/check` — run test, lint, and fmt-check - `script/docker` — build the Docker image tagged via `script/projectname` - `script/docker-smoke` — build the image, start it, wait for it to be healthy -- `script/cibuild` — CI entrypoint: `docker build .` (the Dockerfile - runs the checks, so a green build implies a green repo) +- `script/cibuild` — CI entrypoint: `docker build .` with a new + `CHECK_EPOCH` on every run, so the Dockerfile's checks run instead of + coming from the build cache, and a green run implies a green repo - `script/precommit` — pre-commit checks (`go mod tidy` guard, then `script/check`) - `script/install-precommit` — install the git pre-commit hook that diff --git a/TODO.md b/TODO.md index 2400fe7..cebef13 100644 --- a/TODO.md +++ b/TODO.md @@ -29,6 +29,15 @@ P2: security: referer blacklist # Completed Steps +- 2026-10-03 every `script/cibuild` and `script/docker` run executes the checks + (closes #101): the `Dockerfile` declares `CHECK_EPOCH` above `make fmt-check` + and `make lint` in the lint stage and above `make test` in the build stage, + and each of those steps names it in its command; both scripts pass a new value + on every run, so Docker runs the checks instead of reusing cached results, + while the `script/bootstrap` steps stay cached; a plain `docker build .` still + works, leaves it empty, and reuses the check steps only for an identical build + context; the `script/cibuild` comment and `README.md` no longer say that any + successful build implies a green repo. - 2026-09-29 share concurrent misses (closes #65): requests that miss the same variant at once (the same cache key, so quality and fit included) share one upstream fetch or cached source read and one transcode through diff --git a/script/cibuild b/script/cibuild index e20e047..948134c 100755 --- a/script/cibuild +++ b/script/cibuild @@ -1,15 +1,18 @@ #!/bin/sh # script/cibuild: run the CI build. The Dockerfile runs the checks -# (make fmt-check, lint, test), so a successful build implies a green -# repo. Generic: needs no adaptation. The Gitea workflow runs this on -# push. +# (make fmt-check, lint, test) as build steps. This script passes a new +# CHECK_EPOCH on every run, so Docker runs those steps instead of +# reusing cached results: a successful run means the checks ran and +# passed on this tree. Generic: needs no adaptation. The Gitea workflow +# runs this on push. set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" main() { cd "$ROOT" - docker build . + epoch="$(date +%s)$$" + docker build --build-arg CHECK_EPOCH="$epoch" . } main "$@" diff --git a/script/docker b/script/docker index 2884e41..b9907d8 100755 --- a/script/docker +++ b/script/docker @@ -1,7 +1,9 @@ #!/bin/sh # script/docker: build the Docker image tagged with the project name. -# Identical in all repos; the tag comes from script/projectname. -# Generic: needs no adaptation. +# Identical in all repos; the tag comes from script/projectname. Like +# script/cibuild, it passes a new CHECK_EPOCH, so the build runs the +# checks instead of reusing cached results. Generic: needs no +# adaptation. set -eu SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" @@ -9,7 +11,9 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)" main() { cd "$ROOT" - docker build -t "$("$SCRIPT_DIR/projectname")" . + epoch="$(date +%s)$$" + docker build --build-arg CHECK_EPOCH="$epoch" \ + -t "$("$SCRIPT_DIR/projectname")" . } main "$@"