Compare commits
1
Commits
next
..
3a4a6bb21f
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3a4a6bb21f |
@@ -116,14 +116,10 @@ alpine. We provide:
|
|||||||
`script/bootstrap`, then `script/install-precommit`
|
`script/bootstrap`, then `script/install-precommit`
|
||||||
- `script/projectname` — output the project name (our own extension); used by
|
- `script/projectname` — output the project name (our own extension); used by
|
||||||
`script/docker` for the image tag
|
`script/docker` for the image tag
|
||||||
- `script/test` —
|
- `script/test` — `docker build --no-cache --target test -t prompts-test .`,
|
||||||
`docker build --no-cache --target test --output type=cacheonly .`, building
|
building the `test` phase of the `Dockerfile` (no tests defined here)
|
||||||
the `test` phase of the `Dockerfile` without writing an image (no tests
|
- `script/lint` — `docker build --no-cache --target lint -t prompts-lint .`,
|
||||||
defined here)
|
building the `lint` phase, which runs prettier over the markdown files
|
||||||
- `script/lint` —
|
|
||||||
`docker build --no-cache --target lint --output type=cacheonly .`, building
|
|
||||||
the `lint` phase, which runs prettier over the markdown files, without writing
|
|
||||||
an image
|
|
||||||
- `script/fmt` — format all markdown files with prettier (writes; native, not in
|
- `script/fmt` — format all markdown files with prettier (writes; native, not in
|
||||||
a container)
|
a container)
|
||||||
- `script/fmt-check` — check formatting (read-only; native)
|
- `script/fmt-check` — check formatting (read-only; native)
|
||||||
|
|||||||
@@ -21,23 +21,6 @@ fmt-check, and commit.
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
- 2026-10-07: The `script/cibuild` item in `NEW_REPO_CHECKLIST.md` now matches
|
|
||||||
the canonical `script/cibuild` (issue 125). Its image build carries the tag,
|
|
||||||
`-t "$tag"`, and the item says that `$version` comes from
|
|
||||||
`git describe --tags --always --dirty` (`unknown` if empty) and `$tag` from
|
|
||||||
`script/projectname`, each assigned on its own line before the build. A
|
|
||||||
repository written from the checklist got an untagged build, which leaves a
|
|
||||||
dangling image behind on every run, and was never told where `$version` comes
|
|
||||||
from. The other `docker build` commands the checklists and `REPO_POLICIES.md`
|
|
||||||
give for `script/` already matched their scripts.
|
|
||||||
- 2026-10-07: `script/lint` and `script/test` now build with
|
|
||||||
`--output type=cacheonly` in place of a tag (issue 123), so they still run
|
|
||||||
their phase uncached and fail on a failing step but write no image. Nothing
|
|
||||||
used those images, and writing one out cost about 16 seconds of a Go
|
|
||||||
repository's test build. `script/cibuild` and `script/docker` keep their tags.
|
|
||||||
`REPO_POLICIES.md`, both checklists and the README no longer say the gate
|
|
||||||
builds are tagged. Not yet tried on the shared runner. Repositories pick this
|
|
||||||
up on their next re-vendor.
|
|
||||||
- 2026-10-07: The canonical `.gitea/workflows/check.yml` now sets
|
- 2026-10-07: The canonical `.gitea/workflows/check.yml` now sets
|
||||||
`timeout-minutes: 20` on its `check` job (issue 120), so a hung build frees
|
`timeout-minutes: 20` on its `check` job (issue 120), so a hung build frees
|
||||||
the shared runner instead of holding it until the runner's own limit.
|
the shared runner instead of holding it until the runner's own limit.
|
||||||
|
|||||||
@@ -132,19 +132,16 @@ with your task.
|
|||||||
`script/install-precommit`, shimmed by `make hooks`) runs it
|
`script/install-precommit`, shimmed by `make hooks`) runs it
|
||||||
- [ ] README has an **Entrypoints** section documenting the `script/`
|
- [ ] README has an **Entrypoints** section documenting the `script/`
|
||||||
entrypoints and linking the standard
|
entrypoints and linking the standard
|
||||||
- [ ] `script/lint` and `script/test` each run
|
- [ ] `script/lint` and `script/test` build their phase by name
|
||||||
`docker build --no-cache --target <phase> --output type=cacheonly .`,
|
(`docker build --no-cache --target <phase> -t <name>-<phase> .`), and no
|
||||||
which builds their phase by name and writes no image, and no host
|
host invocation anywhere in the repo can produce a lint verdict — grep for
|
||||||
invocation anywhere in the repo can produce a lint verdict — grep for the
|
the linter's own name across `script/`, the `Makefile` and CI config, not
|
||||||
linter's own name across `script/`, the `Makefile` and CI config, not just
|
just `script/lint`. A second path is likeliest here: a `make lint-fast`,
|
||||||
`script/lint`. A second path is likeliest here: a `make lint-fast`, an
|
an older host-versus-container branch, or a CI step calling the binary
|
||||||
older host-versus-container branch, or a CI step calling the binary
|
|
||||||
directly. `script/fmt` and `script/fmt-check` are expected hits and stay
|
directly. `script/fmt` and `script/fmt-check` are expected hits and stay
|
||||||
on the host.
|
on the host.
|
||||||
- [ ] No `docker build` in `script/` leaves a dangling image behind:
|
- [ ] Every `docker build` in `script/` is tagged — an untagged one leaves a
|
||||||
`script/lint` and `script/test` write no image, and `script/docker` and
|
dangling image behind on every run, on every host and CI runner
|
||||||
`script/cibuild` tag theirs. A build that writes an untagged image leaves
|
|
||||||
one behind on every run, on every host and CI runner.
|
|
||||||
- [ ] `script/cibuild` runs `script/bootstrap` before `script/check`, and builds
|
- [ ] `script/cibuild` runs `script/bootstrap` before `script/check`, and builds
|
||||||
the image with `--no-cache`. Without the bootstrap the CI run dies in
|
the image with `--no-cache`. Without the bootstrap the CI run dies in
|
||||||
`script/fmt-check`, which runs the formatter on the host and finds nothing
|
`script/fmt-check`, which runs the formatter on the host and finds nothing
|
||||||
|
|||||||
@@ -143,14 +143,11 @@ are thin shims calling them. Model scripts:
|
|||||||
it
|
it
|
||||||
- [ ] `script/setup` / `make setup` — readies a fresh clone: runs `bootstrap`,
|
- [ ] `script/setup` / `make setup` — readies a fresh clone: runs `bootstrap`,
|
||||||
then `install-precommit`, plus repo-specific init
|
then `install-precommit`, plus repo-specific init
|
||||||
- [ ] `script/test` / `make test` —
|
- [ ] `script/test` / `make test` — `docker build --no-cache --target test .`,
|
||||||
`docker build --no-cache --target test --output type=cacheonly .`, which
|
tagged; the phase runs real tests, not a no-op (90-second timeout,
|
||||||
writes no image; the phase runs real tests, not a no-op (90-second
|
60-second hard cap on wall time)
|
||||||
timeout, 60-second hard cap on wall time)
|
- [ ] `script/lint` / `make lint` — `docker build --no-cache --target lint .`,
|
||||||
- [ ] `script/lint` / `make lint` —
|
tagged. No lint verdict may come from a host invocation of the linter.
|
||||||
`docker build --no-cache --target lint --output type=cacheonly .`, which
|
|
||||||
writes no image. No lint verdict may come from a host invocation of the
|
|
||||||
linter.
|
|
||||||
- [ ] `script/fmt` / `make fmt` — formats code (writes; native, never in a
|
- [ ] `script/fmt` / `make fmt` — formats code (writes; native, never in a
|
||||||
container)
|
container)
|
||||||
- [ ] `script/fmt-check` / `make fmt-check` — checks formatting (read-only;
|
- [ ] `script/fmt-check` / `make fmt-check` — checks formatting (read-only;
|
||||||
@@ -164,20 +161,16 @@ are thin shims calling them. Model scripts:
|
|||||||
version as a build arg
|
version as a build arg
|
||||||
- [ ] `script/cibuild` — cd to repo root, run `script/bootstrap`, run
|
- [ ] `script/cibuild` — cd to repo root, run `script/bootstrap`, run
|
||||||
`script/check`, then
|
`script/check`, then
|
||||||
`docker build --no-cache --build-arg VERSION="$version" -t "$tag" .` (what
|
`docker build --no-cache --build-arg VERSION="$version" .` (what CI runs).
|
||||||
CI runs), with `$version` from `git describe --tags --always --dirty`
|
The bootstrap is required: CI checks out and runs this alone, and
|
||||||
(`unknown` if empty) and `$tag` from `script/projectname`, each assigned
|
`script/fmt-check` runs the formatter on the host.
|
||||||
on its own line before the build. The bootstrap is required: CI checks out
|
|
||||||
and runs this alone, and `script/fmt-check` runs the formatter on the
|
|
||||||
host.
|
|
||||||
- [ ] `script/fmt` and `script/fmt-check` source nvm for the pinned node version
|
- [ ] `script/fmt` and `script/fmt-check` source nvm for the pinned node version
|
||||||
before invoking `yarn`, as `script/bootstrap`'s own install step does.
|
before invoking `yarn`, as `script/bootstrap`'s own install step does.
|
||||||
`script/bootstrap` leaves the node and yarn it installs off the `PATH` of
|
`script/bootstrap` leaves the node and yarn it installs off the `PATH` of
|
||||||
the shell that called it, so a bare `yarn` exits 127 on a runner carrying
|
the shell that called it, so a bare `yarn` exits 127 on a runner carrying
|
||||||
nothing but docker and git.
|
nothing but docker and git.
|
||||||
- [ ] No `docker build` in `script/` leaves a dangling image behind:
|
- [ ] Every `docker build` in `script/` is tagged, so no invocation leaves a
|
||||||
`script/lint` and `script/test` write no image, and `script/docker` and
|
dangling image behind
|
||||||
`script/cibuild` tag theirs
|
|
||||||
- [ ] `script/precommit` — called by the pre-commit hook; runs `script/check`
|
- [ ] `script/precommit` — called by the pre-commit hook; runs `script/check`
|
||||||
- [ ] `script/install-precommit` — installs the pre-commit hook that runs
|
- [ ] `script/install-precommit` — installs the pre-commit hook that runs
|
||||||
`script/precommit`
|
`script/precommit`
|
||||||
|
|||||||
@@ -118,8 +118,9 @@ style conventions are in separate documents:
|
|||||||
and nothing else:
|
and nothing else:
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
docker build --no-cache --target lint --output type=cacheonly .
|
tag="$(script/projectname)"
|
||||||
docker build --no-cache --target test --output type=cacheonly .
|
docker build --no-cache --target lint -t "$tag-lint" .
|
||||||
|
docker build --no-cache --target test -t "$tag-test" .
|
||||||
```
|
```
|
||||||
|
|
||||||
**A stage that is not the last one in the file is built only when the final
|
**A stage that is not the last one in the file is built only when the final
|
||||||
@@ -129,15 +130,12 @@ style conventions are in separate documents:
|
|||||||
plain `docker build .` builds the last stage alone and exits 0 having linted
|
plain `docker build .` builds the last stage alone and exits 0 having linted
|
||||||
and tested nothing.
|
and tested nothing.
|
||||||
|
|
||||||
**The gate builds write no image.** With `--output type=cacheonly` the phase
|
**Every `docker build` in `script/` is tagged**, here and in
|
||||||
runs and a failing step fails the build, but the result is not exported.
|
`script/cibuild` and `script/docker`. An untagged build leaves a dangling
|
||||||
Nothing uses those images, and writing one out is slow: a Go test phase's
|
image behind on every invocation, on every developer host and every CI
|
||||||
image holds the toolchain and every compiled package. A build given neither
|
runner; a tagged one replaces the previous image. Each script assigns the
|
||||||
`--output` nor `-t` writes an untagged image and leaves it dangling, on
|
tag on its own line before the build, so `set -e` stops it where
|
||||||
every developer host and every CI runner. `script/cibuild` and
|
`script/projectname` fails.
|
||||||
`script/docker` build the image that ships and tag it, so each build
|
|
||||||
replaces the previous image; each assigns the tag on its own line before the
|
|
||||||
build, so `set -e` stops it where `script/projectname` fails.
|
|
||||||
|
|
||||||
Inside a phase the tool is invoked directly — `golangci-lint`, `go test`,
|
Inside a phase the tool is invoked directly — `golangci-lint`, `go test`,
|
||||||
`eslint`, `prettier` — never through `make lint` or `script/test`, which are
|
`eslint`, `prettier` — never through `make lint` or `script/test`, which are
|
||||||
|
|||||||
+7
-3
@@ -6,8 +6,8 @@
|
|||||||
#
|
#
|
||||||
# The phase is not the last stage in the file, so it is built only when
|
# The phase is not the last stage in the file, so it is built only when
|
||||||
# --target names it. --no-cache because a cached lint layer is a lint
|
# --target names it. --no-cache because a cached lint layer is a lint
|
||||||
# that did not run. --output type=cacheonly writes no image, since
|
# that did not run. The tag makes each build replace the previous image
|
||||||
# nothing uses one.
|
# instead of leaving a dangling one behind.
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||||
@@ -15,9 +15,13 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
|||||||
|
|
||||||
main() {
|
main() {
|
||||||
cd "$ROOT"
|
cd "$ROOT"
|
||||||
|
# The tag gets its own line: a failing command substitution inside
|
||||||
|
# an argument does not trip `set -e`, so the inline form degrades
|
||||||
|
# silently to an empty constant.
|
||||||
|
tag="$("$SCRIPT_DIR/projectname")"
|
||||||
docker build --no-cache \
|
docker build --no-cache \
|
||||||
--target lint \
|
--target lint \
|
||||||
--output type=cacheonly .
|
-t "$tag-lint" .
|
||||||
}
|
}
|
||||||
|
|
||||||
main "$@"
|
main "$@"
|
||||||
|
|||||||
+7
-3
@@ -2,8 +2,8 @@
|
|||||||
# script/test: run the test suite. Testing is a phase of the Dockerfile
|
# script/test: run the test suite. Testing is a phase of the Dockerfile
|
||||||
# and this builds that phase alone, on the same terms as script/lint:
|
# and this builds that phase alone, on the same terms as script/lint:
|
||||||
# --target because a phase that is not the last stage is built only when
|
# --target because a phase that is not the last stage is built only when
|
||||||
# named, and --no-cache because a cached test layer is a test that did
|
# named, --no-cache because a cached test layer is a test that did not
|
||||||
# not run. --output type=cacheonly writes no image, since nothing uses one.
|
# run, and a tag so each build replaces the previous image.
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||||
@@ -11,9 +11,13 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
|||||||
|
|
||||||
main() {
|
main() {
|
||||||
cd "$ROOT"
|
cd "$ROOT"
|
||||||
|
# The tag gets its own line: a failing command substitution inside
|
||||||
|
# an argument does not trip `set -e`, so the inline form degrades
|
||||||
|
# silently to an empty constant.
|
||||||
|
tag="$("$SCRIPT_DIR/projectname")"
|
||||||
docker build --no-cache \
|
docker build --no-cache \
|
||||||
--target test \
|
--target test \
|
||||||
--output type=cacheonly .
|
-t "$tag-test" .
|
||||||
}
|
}
|
||||||
|
|
||||||
main "$@"
|
main "$@"
|
||||||
|
|||||||
Reference in New Issue
Block a user