Build with --no-cache so the check layer actually runs (closes #26)

script/cibuild was a plain `docker build .` and the Dockerfile does
`COPY . .` followed by `RUN make check`, so on an unchanged tree Docker
served the check layer from cache: the suite never ran and the build
still exited 0. Measured here before the change, a second run on a
byte-identical tree returned in 0.286s with `RUN make check` CACHED.
script/cibuild and script/docker now pass --no-cache. The canonical text
asserting that a bare `docker build .` proves the checks ran was wrong in
REPO_POLICIES.md, both checklists and the Go styleguide, and is corrected
in all of them.

Model: opus-5
This commit is contained in:
2026-09-09 11:44:58 +00:00
parent 58eafaf4c2
commit 58f75147be
8 changed files with 55 additions and 26 deletions
+8 -3
View File
@@ -1,6 +1,6 @@
---
title: New Repo Checklist
last_modified: 2026-07-06
last_modified: 2026-09-08
---
Use this checklist when creating a new repository from scratch. Follow the steps
@@ -90,8 +90,11 @@ are thin shims calling them. Model scripts:
- [ ] `script/projectname` — outputs the project name (used by `script/docker`
for the image tag)
- [ ] `script/docker` / `make docker` — builds Docker image, tagged via
`script/projectname` (byte-identical across repos)
- [ ] `script/cibuild` — cd to repo root, `docker build .` (what CI runs)
`script/projectname` (byte-identical across repos); passes `--no-cache`
like `script/cibuild`
- [ ] `script/cibuild` — cd to repo root, `docker build --no-cache .` (what CI
runs; without `--no-cache` an unchanged tree serves the check layers from
cache and the build reports a green it never ran)
- [ ] `script/precommit` — called by the pre-commit hook; runs `script/check`
- [ ] `script/install-precommit` — installs the pre-commit hook that runs
`script/precommit`
@@ -103,6 +106,8 @@ are thin shims calling them. Model scripts:
- [ ] `make check` passes
- [ ] `make docker` succeeds
- [ ] `script/cibuild` succeeds and demonstrably executed the checks — a
sub-second build, or `CACHED` on a check layer, means nothing ran
- [ ] No secrets in repo
- [ ] No mutable image/package references
- [ ] No unnecessary files in repo root