On an unchanged tree Docker served the make fmt-check, make lint and make test steps of the Dockerfile from its build cache, so script/cibuild could succeed without checking anything (#101).
Dockerfile: ARG CHECK_EPOCH directly above the check steps in the lint stage and in the build stage. Each of the three check steps names it in its command, so a new value reruns all three; the script/bootstrap steps come before it and stay cached.
script/cibuild and script/docker pass a new value (the time and the process id) on every run.
The script/cibuild header comment and README.md no longer say that any successful build implies a green repo.
TODO.md: Completed Steps entry.
Not visible in the diff:
In CI, script/docker-smoke builds through script/docker after script/cibuild; that second build now runs the checks again instead of taking them from the first build's cache.
make docker-versioned, make docker-test and REPO_POLICIES.md (which still says a successful build implies the checks pass) are left as they were.
Deviation: unlike the addendum on the issue, no step fails the build when CHECK_EPOCH is unset. A plain docker build . must keep working: upaas builds that way, and #166 asked for that build to stamp the right version. Such a build reuses the check steps only for a byte-identical build context, .git included.
Unverified: the 5-minute Docker build budget on the CI runner. On this busy shared host a build that also reruns script/bootstrap exceeds it; this change adds no step to such a build.
Model: opus-5-5
On an unchanged tree Docker served the `make fmt-check`, `make lint` and `make test` steps of the `Dockerfile` from its build cache, so `script/cibuild` could succeed without checking anything (https://git.eeqj.de/sneak/pixa/issues/101).
- `Dockerfile`: `ARG CHECK_EPOCH` directly above the check steps in the lint stage and in the build stage. Each of the three check steps names it in its command, so a new value reruns all three; the `script/bootstrap` steps come before it and stay cached.
- `script/cibuild` and `script/docker` pass a new value (the time and the process id) on every run.
- The `script/cibuild` header comment and `README.md` no longer say that any successful build implies a green repo.
- `TODO.md`: Completed Steps entry.
Not visible in the diff:
- In CI, `script/docker-smoke` builds through `script/docker` after `script/cibuild`; that second build now runs the checks again instead of taking them from the first build's cache.
- `make docker-versioned`, `make docker-test` and `REPO_POLICIES.md` (which still says a successful build implies the checks pass) are left as they were.
Deviation: unlike the addendum on the issue, no step fails the build when `CHECK_EPOCH` is unset. A plain `docker build .` must keep working: upaas builds that way, and https://git.eeqj.de/sneak/pixa/issues/166 asked for that build to stamp the right version. Such a build reuses the check steps only for a byte-identical build context, `.git` included.
Unverified: the 5-minute Docker build budget on the CI runner. On this busy shared host a build that also reruns `script/bootstrap` exceeds it; this change adds no step to such a build.
Model: opus-5-5
Both scripts pass a new CHECK_EPOCH, which the Dockerfile's make
fmt-check, make lint and make test steps name in their commands. On an
unchanged tree Docker used to serve those steps from its build cache, so
a run could pass without checking anything. The script/bootstrap steps
stay cached. A plain docker build . still works, as upaas builds the
image that way: it leaves CHECK_EPOCH empty and reuses the check steps
only for an identical build context.
Model: opus-5-5
PASS588803fa36984fc2f85ed8129e58e7e689affc1e, rebased onto next at 697c14633b0ebc394c89d84ce902ca19013f17f6.
Judgement call: CI's second run of the checks (script/docker-smoke building through script/docker) is acceptable, not a defect: the plan has script/docker pass a new value, a build with no value would rerun the checks anyway because it cannot reuse steps built with one, and avoiding the second run means changing the workflow, which this issue does not cover.
Not verified: the 5-minute Docker build budget on the CI runner; on this shared host any build that runs the checks takes longer than that, with or without this change.
Model: opus-5-5
**PASS** `588803fa36984fc2f85ed8129e58e7e689affc1e`, rebased onto `next` at `697c14633b0ebc394c89d84ce902ca19013f17f6`.
Judgement call: CI's second run of the checks (`script/docker-smoke` building through `script/docker`) is acceptable, not a defect: the plan has `script/docker` pass a new value, a build with no value would rerun the checks anyway because it cannot reuse steps built with one, and avoiding the second run means changing the workflow, which this issue does not cover.
Not verified: the 5-minute Docker build budget on the CI runner; on this shared host any build that runs the checks takes longer than that, with or without this change.
Model: opus-5-5
clawbot
merged commit b402eaf88c into next2026-10-04 03:58:37 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
On an unchanged tree Docker served the
make fmt-check,make lintandmake teststeps of theDockerfilefrom its build cache, soscript/cibuildcould succeed without checking anything (#101).Dockerfile:ARG CHECK_EPOCHdirectly above the check steps in the lint stage and in the build stage. Each of the three check steps names it in its command, so a new value reruns all three; thescript/bootstrapsteps come before it and stay cached.script/cibuildandscript/dockerpass a new value (the time and the process id) on every run.script/cibuildheader comment andREADME.mdno longer say that any successful build implies a green repo.TODO.md: Completed Steps entry.Not visible in the diff:
script/docker-smokebuilds throughscript/dockerafterscript/cibuild; that second build now runs the checks again instead of taking them from the first build's cache.make docker-versioned,make docker-testandREPO_POLICIES.md(which still says a successful build implies the checks pass) are left as they were.Deviation: unlike the addendum on the issue, no step fails the build when
CHECK_EPOCHis unset. A plaindocker build .must keep working: upaas builds that way, and #166 asked for that build to stamp the right version. Such a build reuses the check steps only for a byte-identical build context,.gitincluded.Unverified: the 5-minute Docker build budget on the CI runner. On this busy shared host a build that also reruns
script/bootstrapexceeds it; this change adds no step to such a build.Model: opus-5-5
PASS
588803fa36984fc2f85ed8129e58e7e689affc1e, rebased ontonextat697c14633b0ebc394c89d84ce902ca19013f17f6.Judgement call: CI's second run of the checks (
script/docker-smokebuilding throughscript/docker) is acceptable, not a defect: the plan hasscript/dockerpass a new value, a build with no value would rerun the checks anyway because it cannot reuse steps built with one, and avoiding the second run means changing the workflow, which this issue does not cover.Not verified: the 5-minute Docker build budget on the CI runner; on this shared host any build that runs the checks takes longer than that, with or without this change.
Model: opus-5-5