Lint and tests do not run as the lint and test phases of the Dockerfile, built with --no-cache #202

Open
opened 2026-10-04 22:29:51 +02:00 by clawbot · 2 comments
Collaborator

The canonical REPO_POLICIES.md, re-vendored under #196, now has lint and tests run as two phases of the Dockerfile, named lint and test, with the stage that compiles depending on both. script/lint and script/test each build one phase and nothing else (docker build --no-cache --target lint -t "$(script/projectname)-lint" ., and the same for test). Every build that runs checks passes --no-cache and a tag, and script/cibuild runs script/bootstrap, then script/check, then builds the image with the version. The canonical scripts are in sneak/prompts under script/, identical across repos.

What pixa does instead, on next at 8314099:

  • Dockerfile.lint is a separate lint file; the policy says there is none. script/lint builds it with a CACHEBUST argument and --output=type=cacheonly.
  • script/test runs go test on the host, through nix-shell when pkg-config is missing, with -timeout 30s and no -count=1. The policy puts the test command in the test phase, with a 90-second timeout.
  • The Dockerfile has no test stage: make test runs inside the builder stage. The lint stage runs make fmt-check and make lint; the policy runs golangci-lint directly in the phase and keeps the formatting check on the host, in script/check.
  • The lint stage is based on golangci/golangci-lint:v2.12.2-alpine@sha256:91b27804…; the policy names golangci/golangci-lint@sha256:5cceeef0…, the same v2.12.2. The copy of the policy on sneak/prompts next says that image has no apk and the vips libraries go in with apt-get.
  • Checks rerun through a CHECK_EPOCH build argument instead of --no-cache. script/cibuild is an untagged docker build that runs neither script/bootstrap nor script/check; neither it nor script/docker passes --no-cache or VERSION.
  • The Makefile's docker-versioned and docker-test targets run docker build themselves, without --no-cache.

Not part of this: the stage that compiles keeps taking the version from git describe when no VERSION is given, per #166, so the canonical scripts' comments saying .dockerignore excludes .git do not hold for pixa.

These rules cannot be met one at a time: dropping CHECK_EPOCH without --no-cache in all four scripts lets a cached build skip the checks.

Model: opus-5-5

The canonical `REPO_POLICIES.md`, re-vendored under https://git.eeqj.de/sneak/pixa/issues/196, now has lint and tests run as two phases of the `Dockerfile`, named `lint` and `test`, with the stage that compiles depending on both. `script/lint` and `script/test` each build one phase and nothing else (`docker build --no-cache --target lint -t "$(script/projectname)-lint" .`, and the same for `test`). Every build that runs checks passes `--no-cache` and a tag, and `script/cibuild` runs `script/bootstrap`, then `script/check`, then builds the image with the version. The canonical scripts are in `sneak/prompts` under `script/`, identical across repos. What pixa does instead, on `next` at `8314099`: - `Dockerfile.lint` is a separate lint file; the policy says there is none. `script/lint` builds it with a `CACHEBUST` argument and `--output=type=cacheonly`. - `script/test` runs `go test` on the host, through `nix-shell` when `pkg-config` is missing, with `-timeout 30s` and no `-count=1`. The policy puts the test command in the `test` phase, with a 90-second timeout. - The `Dockerfile` has no `test` stage: `make test` runs inside the `builder` stage. The lint stage runs `make fmt-check` and `make lint`; the policy runs `golangci-lint` directly in the phase and keeps the formatting check on the host, in `script/check`. - The lint stage is based on `golangci/golangci-lint:v2.12.2-alpine@sha256:91b27804…`; the policy names `golangci/golangci-lint@sha256:5cceeef0…`, the same v2.12.2. The copy of the policy on `sneak/prompts` `next` says that image has no `apk` and the `vips` libraries go in with `apt-get`. - Checks rerun through a `CHECK_EPOCH` build argument instead of `--no-cache`. `script/cibuild` is an untagged `docker build` that runs neither `script/bootstrap` nor `script/check`; neither it nor `script/docker` passes `--no-cache` or `VERSION`. - The Makefile's `docker-versioned` and `docker-test` targets run `docker build` themselves, without `--no-cache`. Not part of this: the stage that compiles keeps taking the version from `git describe` when no `VERSION` is given, per https://git.eeqj.de/sneak/pixa/issues/166, so the canonical scripts' comments saying `.dockerignore` excludes `.git` do not hold for pixa. These rules cannot be met one at a time: dropping `CHECK_EPOCH` without `--no-cache` in all four scripts lets a cached build skip the checks. Model: opus-5-5
clawbot self-assigned this 2026-10-04 22:29:51 +02:00
Author
Collaborator

Plan, checked against next at ef828f7 (with the canonical REPO_POLICIES.md now on it). Adopt the canonical layout from sneak/prompts rather than adapting pixa's:

  • script/cibuild, script/check, script/lint, script/test and the other scripts the canonical set has are copied unchanged from sneak/prompts main (script/), each in its own commit or together, as long as each file is byte-identical. Where pixa needs something the canonical script does not do (libvips for its build), it goes in the Dockerfile or script/bootstrap as the policy allows, not in a changed copy of a canonical script; say in the PR which files differ from canonical and why.
  • Dockerfile: a lint phase (golangci-lint run directly, from the image digest the policy names, with the vips libraries installed the way that image allows) and a test phase (the tests, with the policy's timeout); the stage that compiles depends on both; the final image as now. Dockerfile.lint goes. The formatting check moves to the host in script/check, as the policy says.
  • The CHECK_EPOCH argument from #101 goes: --no-cache in the scripts now forces the checks. The Makefile's docker-versioned and docker-test call the scripts instead of running docker build themselves.
  • Kept on purpose, per #166: the stage that compiles still falls back to git describe when no VERSION is given, so a plain docker build . stamps the right version. Say so in the PR and the TODO.md entry.
  • README.md "Entrypoints" says what each script does now. The gate after this is the new script/cibuild; run it, and script/check on its own.

This is larger than the other policy units; keep each commit plain and reviewable. If a canonical script cannot work for pixa unchanged, stop and say so on this issue.

Model: opus-5-5

Plan, checked against `next` at `ef828f7` (with the canonical `REPO_POLICIES.md` now on it). Adopt the canonical layout from `sneak/prompts` rather than adapting pixa's: - `script/cibuild`, `script/check`, `script/lint`, `script/test` and the other scripts the canonical set has are copied unchanged from `sneak/prompts` `main` (`script/`), each in its own commit or together, as long as each file is byte-identical. Where pixa needs something the canonical script does not do (libvips for its build), it goes in the `Dockerfile` or `script/bootstrap` as the policy allows, not in a changed copy of a canonical script; say in the PR which files differ from canonical and why. - `Dockerfile`: a `lint` phase (golangci-lint run directly, from the image digest the policy names, with the `vips` libraries installed the way that image allows) and a `test` phase (the tests, with the policy's timeout); the stage that compiles depends on both; the final image as now. `Dockerfile.lint` goes. The formatting check moves to the host in `script/check`, as the policy says. - The `CHECK_EPOCH` argument from https://git.eeqj.de/sneak/pixa/issues/101 goes: `--no-cache` in the scripts now forces the checks. The Makefile's `docker-versioned` and `docker-test` call the scripts instead of running `docker build` themselves. - Kept on purpose, per https://git.eeqj.de/sneak/pixa/issues/166: the stage that compiles still falls back to `git describe` when no `VERSION` is given, so a plain `docker build .` stamps the right version. Say so in the PR and the `TODO.md` entry. - `README.md` "Entrypoints" says what each script does now. The gate after this is the new `script/cibuild`; run it, and `script/check` on its own. This is larger than the other policy units; keep each commit plain and reviewable. If a canonical script cannot work for pixa unchanged, stop and say so on this issue. Model: opus-5-5
Author
Collaborator

Implemented in #218; its description lists the scripts that stay different from the canonical copies, and why.

Model: opus-5-5

Implemented in https://git.eeqj.de/sneak/pixa/pulls/218; its description lists the scripts that stay different from the canonical copies, and why. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#202