Run lint and tests as the lint and test phases of the Dockerfile, built with --no-cache (closes #202) #218

Merged
clawbot merged 1 commits from issue-202-dockerfile-check-phases into next 2026-10-05 03:41:51 +02:00
Collaborator

Lint and tests now run as the lint and test phases of the Dockerfile, and every docker build in script/ passes --no-cache, as REPO_POLICIES.md asks.

  • script/check, script/cibuild, script/docker, script/lint, script/test, script/setup and script/install-precommit are byte-identical copies from sneak/prompts main.
  • lint phase: golangci-lint from the image digest the policy names; that image is Debian, so libvips-dev comes from apt-get, not apk.
  • test phase: the alpine Go image, script/bootstrap --cgo, then the tests with a 90-second timeout and the verbose rerun. The build stage depends on both phases.
  • script/bootstrap installs git, make and Go, refreshing apt's package lists before its first apt install; only with --cgo, which the test phase and the build stage pass, also the C compiler and the libvips and libheif libraries.
  • Dockerfile.lint and CHECK_EPOCH are gone; the gofmt check stays on the host. make docker-versioned and make docker-test call the scripts, so the dev image is now tagged pixa, not pixad.

Not canonical, on purpose: script/bootstrap, script/fmt and script/fmt-check (gofmt; the canonical ones run prettier through yarn), script/precommit (the go mod tidy guard), script/projectname.

  • Kept on purpose, per #166: without VERSION the build stage takes the version from git describe, so the copied scripts' comment that .dockerignore excludes .git does not hold here.
  • Judgement call: make docker-test now equals make test; kept, as the plan says to call the scripts.
  • Unchanged: on nix, script/bootstrap --cgo reinstalls the image libraries every run, as pkg-config does not find what nix-env installs.

Model: opus-5-5

Lint and tests now run as the `lint` and `test` phases of the `Dockerfile`, and every `docker build` in `script/` passes `--no-cache`, as `REPO_POLICIES.md` asks. - `script/check`, `script/cibuild`, `script/docker`, `script/lint`, `script/test`, `script/setup` and `script/install-precommit` are byte-identical copies from `sneak/prompts` `main`. - `lint` phase: golangci-lint from the image digest the policy names; that image is Debian, so `libvips-dev` comes from `apt-get`, not `apk`. - `test` phase: the alpine Go image, `script/bootstrap --cgo`, then the tests with a 90-second timeout and the verbose rerun. The build stage depends on both phases. - `script/bootstrap` installs git, make and Go, refreshing apt's package lists before its first apt install; only with `--cgo`, which the `test` phase and the build stage pass, also the C compiler and the libvips and libheif libraries. - `Dockerfile.lint` and `CHECK_EPOCH` are gone; the `gofmt` check stays on the host. `make docker-versioned` and `make docker-test` call the scripts, so the dev image is now tagged `pixa`, not `pixad`. Not canonical, on purpose: `script/bootstrap`, `script/fmt` and `script/fmt-check` (`gofmt`; the canonical ones run prettier through yarn), `script/precommit` (the `go mod tidy` guard), `script/projectname`. - Kept on purpose, per https://git.eeqj.de/sneak/pixa/issues/166: without `VERSION` the build stage takes the version from `git describe`, so the copied scripts' comment that `.dockerignore` excludes `.git` does not hold here. - Judgement call: `make docker-test` now equals `make test`; kept, as the plan says to call the scripts. - Unchanged: on nix, `script/bootstrap --cgo` reinstalls the image libraries every run, as `pkg-config` does not find what `nix-env` installs. Model: opus-5-5
clawbot added the needs-review label 2026-10-05 01:57:56 +02:00
clawbot self-assigned this 2026-10-05 01:57:56 +02:00
Author
Collaborator

FAIL (needs-rework)

  1. script/bootstrap cannot finish on the Gitea runner, so script/cibuild, now the workflow's build step, stops before script/check. The runner image (docker.gitea.com/runner-images:ubuntu-latest: Ubuntu 24.04, root, no Go, no apt package lists) takes bootstrap's apt branch, which never runs apt-get update; the first install (golang) fails with "Unable to locate package", and libvips-dev would too. Acceptable: bootstrap refreshes the package lists once before its first apt install and completes on that image.
  2. script/cibuild now installs the CGO image libraries (C compiler, pkg-config, libvips, libheif) on any host that lacks them, though nothing on the host compiles pixa any more: lint and tests are Dockerfile phases, and the host needs only git, make, Go (gofmt, the go mod tidy guard) and Docker. Nothing in REPO_POLICIES.md needs them there. On a nix host the installs repeat on every run: nix-env -iA nixpkgs.vips links no .pc files into the profile, so the pkg-config --exists guards in ensure_cgo_deps never pass. Acceptable: the CGO libraries are installed only where pixa is compiled (the test phase and the build stage), in one plain way REPO_POLICIES.md allows, and README.md (the paragraph on running outside Docker, the script/bootstrap and script/cibuild lines) says what is installed where.
  3. Dockerfile, lint phase comment: "has no apk, so they come from apt-get rather than script/bootstrap" gives a wrong reason, since script/bootstrap has an apt branch. Acceptable: a comment that states only true reasons.
  4. Makefile lines 6-7: the nix-shell comment's example "inside a Docker build" no longer happens; no Docker stage runs make now. Acceptable: drop that example.
  5. PR body is about 270 words, over the limit of about 250. Acceptable: at most about 250 words, with the script/cibuild and "Not verified" lines updated for points 1 and 2.
  6. TODO.md: after rebasing onto next, the new entry sits below the entries for #212 and #208. Acceptable: it is the top entry of Completed Steps.

Gated head 468439a, rebased onto next at c434581; TODO.md was the only file in conflict, resolved locally by keeping both entries.
Not verified: script/cibuild as a single run.

Model: opus-5-5

**FAIL** (needs-rework) 1. `script/bootstrap` cannot finish on the Gitea runner, so `script/cibuild`, now the workflow's build step, stops before `script/check`. The runner image (`docker.gitea.com/runner-images:ubuntu-latest`: Ubuntu 24.04, root, no Go, no apt package lists) takes bootstrap's apt branch, which never runs `apt-get update`; the first install (`golang`) fails with "Unable to locate package", and `libvips-dev` would too. Acceptable: bootstrap refreshes the package lists once before its first apt install and completes on that image. 2. `script/cibuild` now installs the CGO image libraries (C compiler, `pkg-config`, libvips, libheif) on any host that lacks them, though nothing on the host compiles pixa any more: lint and tests are `Dockerfile` phases, and the host needs only git, make, Go (`gofmt`, the `go mod tidy` guard) and Docker. Nothing in `REPO_POLICIES.md` needs them there. On a nix host the installs repeat on every run: `nix-env -iA nixpkgs.vips` links no `.pc` files into the profile, so the `pkg-config --exists` guards in `ensure_cgo_deps` never pass. Acceptable: the CGO libraries are installed only where pixa is compiled (the `test` phase and the build stage), in one plain way `REPO_POLICIES.md` allows, and `README.md` (the paragraph on running outside Docker, the `script/bootstrap` and `script/cibuild` lines) says what is installed where. 3. `Dockerfile`, lint phase comment: "has no apk, so they come from apt-get rather than script/bootstrap" gives a wrong reason, since `script/bootstrap` has an apt branch. Acceptable: a comment that states only true reasons. 4. `Makefile` lines 6-7: the `nix-shell` comment's example "inside a Docker build" no longer happens; no Docker stage runs `make` now. Acceptable: drop that example. 5. PR body is about 270 words, over the limit of about 250. Acceptable: at most about 250 words, with the `script/cibuild` and "Not verified" lines updated for points 1 and 2. 6. `TODO.md`: after rebasing onto `next`, the new entry sits below the entries for https://git.eeqj.de/sneak/pixa/issues/212 and https://git.eeqj.de/sneak/pixa/issues/208. Acceptable: it is the top entry of Completed Steps. Gated head `468439a`, rebased onto `next` at `c434581`; `TODO.md` was the only file in conflict, resolved locally by keeping both entries. Not verified: `script/cibuild` as a single run. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-05 02:41:27 +02:00
clawbot force-pushed issue-202-dockerfile-check-phases from 468439a229 to 60939f4c84 2026-10-05 03:05:22 +02:00 Compare
clawbot added 1 commit 2026-10-05 03:13:34 +02:00
script/check, cibuild, docker, lint, test, setup and install-precommit
are now the sneak/prompts main copies, unchanged: lint and test each
build their Dockerfile phase with --no-cache. The lint phase runs
golangci-lint from the image REPO_POLICIES.md names, with libvips-dev
from apt-get; the test phase runs the tests with a 90-second timeout;
the build stage depends on both. script/bootstrap installs the C
compiler and image libraries only with --cgo, which the test phase and
build stage pass, and refreshes the apt lists before its first apt
install. Dockerfile.lint and CHECK_EPOCH are gone, and make
docker-versioned and docker-test call the scripts. Without VERSION the
build stage still uses git describe, per issue 166.

Model: opus-5-5
clawbot force-pushed issue-202-dockerfile-check-phases from 60939f4c84 to fe3063663c 2026-10-05 03:13:34 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-05 03:14:06 +02:00
Author
Collaborator

Rework of #218 (comment), rebased onto next:

  1. script/bootstrap runs apt-get update once, before its first apt install.
  2. The C compiler and the image libraries are installed only by script/bootstrap --cgo, which the test phase and the build stage run; plain script/bootstrap (host, script/setup, script/cibuild) installs git, make and Go. README.md says what is installed where.
  3. The comment now gives only the true reasons: the policy has the lint phase install the headers itself, and the image is Debian.
  4. Example dropped.
  5. Body rewritten, about 250 words, with the script/bootstrap and disclosure lines updated.
  6. The entry is the top one under Completed Steps.

Model: opus-5-5

Rework of https://git.eeqj.de/sneak/pixa/pulls/218#issuecomment-126060, rebased onto `next`: 1. `script/bootstrap` runs `apt-get update` once, before its first apt install. 2. The C compiler and the image libraries are installed only by `script/bootstrap --cgo`, which the `test` phase and the build stage run; plain `script/bootstrap` (host, `script/setup`, `script/cibuild`) installs git, make and Go. `README.md` says what is installed where. 3. The comment now gives only the true reasons: the policy has the lint phase install the headers itself, and the image is Debian. 4. Example dropped. 5. Body rewritten, about 250 words, with the `script/bootstrap` and disclosure lines updated. 6. The entry is the top one under Completed Steps. Model: opus-5-5
Author
Collaborator

PASS fe30636, rebased onto next at 55cf7f4.

Judgement call: make test is now an uncached build of the test phase and takes well over the 60-second cap in REPO_POLICIES.md; that follows from the policy's own layout, not from this change, so it is not counted against it.
Not verified: script/bootstrap --cgo on a nix host, as libvips may not be installed here.

Model: opus-5-5

**PASS** `fe30636`, rebased onto `next` at `55cf7f4`. Judgement call: `make test` is now an uncached build of the `test` phase and takes well over the 60-second cap in `REPO_POLICIES.md`; that follows from the policy's own layout, not from this change, so it is not counted against it. Not verified: `script/bootstrap --cgo` on a nix host, as libvips may not be installed here. Model: opus-5-5
clawbot merged commit a941a80bf9 into next 2026-10-05 03:41:51 +02:00
clawbot deleted branch issue-202-dockerfile-check-phases 2026-10-05 03:41:51 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#218