1 Commits
Author SHA1 Message Date
sneak f9ea5a74e9 Refresh apt package lists once in script/bootstrap (closes #115)
check / check (push) Successful in 36s
pkg_install ran apt-get install without apt-get update. The Gitea runner
image starts with empty package lists, so installing anything it lacks,
such as Go, failed with "Unable to locate package". The apt branch now
runs apt-get update before its first install and skips it on later
calls, so a repository's own section needs no refresh of its own.

Model: opus-5-5
2026-10-06 04:34:33 +00:00
5 changed files with 12 additions and 28 deletions
-2
View File
@@ -13,6 +13,4 @@ jobs:
# script/cibuild needs no token, so none is left in .git/config. # script/cibuild needs no token, so none is left in .git/config.
with: with:
persist-credentials: false persist-credentials: false
# All history and tags, so git describe finds the version tag.
fetch-depth: 0
- run: script/cibuild - run: script/cibuild
-8
View File
@@ -21,14 +21,6 @@ fmt-check, and commit.
# Completed Steps # Completed Steps
- 2026-10-06: The canonical `.gitea/workflows/check.yml` now sets
`fetch-depth: 0` on its checkout step (issue 110), so CI fetches the history
and tags that `git describe --tags --always` needs, and a tagged repository
stamps the same version in CI as in a local build. `REPO_POLICIES.md` and both
checklists name `fetch-depth: 0` among what the workflow does, next to
`persist-credentials: false` and the `concurrency` block, instead of asking
each tagged repository to add it. Not yet tried on the shared runner, which is
out of disk space. Repositories pick this up on their next re-vendor.
- 2026-10-06: The canonical `script/bootstrap` now runs `apt-get update` once, - 2026-10-06: The canonical `script/bootstrap` now runs `apt-get update` once,
before the first `apt-get install` of a run (issue 115). The Gitea runner before the first `apt-get install` of a run (issue 115). The Gitea runner
image starts with empty package lists, so installing anything it lacks, such image starts with empty package lists, so installing anything it lacks, such
+6 -8
View File
@@ -96,15 +96,13 @@ with your task.
directory outside the build context, so the build cannot read the version directory outside the build context, so the build cannot read the version
and a plain `docker build .` fails; pass the version with and a plain `docker build .` fails; pass the version with
`--build-arg VERSION=...`. `script/docker` and `script/cibuild` already `--build-arg VERSION=...`. `script/docker` and `script/cibuild` already
pass the version they compute on the host; it takes precedence. The pass the version they compute on the host; it takes precedence. A
canonical `.gitea/workflows/check.yml` sets `fetch-depth: 0` on its tag-derived version additionally needs `fetch-depth: 0` on the CI checkout
checkout step, which otherwise clones shallow and fetches no tags, so a CI step, which clones shallow and fetches no tags by default.
build finds the tag too.
- [ ] Gitea Actions workflow in `.gitea/workflows/` runs `script/cibuild` on - [ ] Gitea Actions workflow in `.gitea/workflows/` runs `script/cibuild` on
push, checks out with `persist-credentials: false` and with push, checks out with `persist-credentials: false`, and carries the
`fetch-depth: 0` (which fetches the tags `git describe` needs), and `concurrency` block that lets a new push cancel only the same branch's
carries the `concurrency` block that lets a new push cancel only the same older run — reference
branch's older run — reference
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml` `https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml`
- [ ] Language-specific config: - [ ] Language-specific config:
- [ ] Go: `go.mod`, `go.sum`, `.golangci.yml` (fetch from - [ ] Go: `go.mod`, `go.sum`, `.golangci.yml` (fetch from
+3 -4
View File
@@ -112,10 +112,9 @@ Template files can be fetched from:
- Non-server: the final stage brings up the dev environment - Non-server: the final stage brings up the dev environment
- Image pinned by sha256 hash with version/date comment - Image pinned by sha256 hash with version/date comment
- [ ] Gitea Actions workflow at `.gitea/workflows/check.yml` that runs - [ ] Gitea Actions workflow at `.gitea/workflows/check.yml` that runs
`script/cibuild` on push, checks out with `persist-credentials: false` and `script/cibuild` on push, checks out with `persist-credentials: false`,
with `fetch-depth: 0` (which fetches the tags `git describe` needs), and and carries the `concurrency` block that lets a new push cancel only the
carries the `concurrency` block that lets a new push cancel only the same same branch's older run — reference
branch's older run — reference
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml` `https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml`
- [ ] Language-specific: - [ ] Language-specific:
- [ ] Go: `go mod init sneak.berlin/go/<name>`, `.golangci.yml` (fetch from - [ ] Go: `go mod init sneak.berlin/go/<name>`, `.golangci.yml` (fetch from
+3 -6
View File
@@ -292,10 +292,7 @@ style conventions are in separate documents:
runs `script/cibuild` on push, and checks out the repo as its only other step, runs `script/cibuild` on push, and checks out the repo as its only other step,
with `persist-credentials: false`: `script/cibuild` needs no token, and with `persist-credentials: false`: `script/cibuild` needs no token, and
without it the checkout leaves the job's token in `.git/config` for every without it the checkout leaves the job's token in `.git/config` for every
later step. The checkout step also sets `fetch-depth: 0`, which fetches the later step. Its `concurrency` block groups runs by workflow and branch
tags `git describe` needs: by default it clones shallow with no tags, and a
tagged repository's CI build would stamp a bare short commit id. The
workflow's `concurrency` block groups runs by workflow and branch
(`${{ github.workflow }}-${{ github.ref }}`) with `cancel-in-progress: true`, (`${{ github.workflow }}-${{ github.ref }}`) with `cancel-in-progress: true`,
so a new push cancels the older run on the same branch, queued or running, and so a new push cancels the older run on the same branch, queued or running, and
no other: runs for replaced commits do not hold up the shared runner. no other: runs for replaced commits do not hold up the shared runner.
@@ -475,8 +472,8 @@ style conventions are in separate documents:
there because `ARG` is stage-scoped; passing `VERSION` to a repo whose there because `ARG` is stage-scoped; passing `VERSION` to a repo whose
Dockerfile declares no such `ARG` is ignored and costs nothing, which is why Dockerfile declares no such `ARG` is ignored and costs nothing, which is why
the scripts stay byte-identical. One consequence for CI: the standard the scripts stay byte-identical. One consequence for CI: the standard
checkout action clones shallow and fetches no tags, so the canonical checkout action clones shallow and fetches no tags, so a repo that embeds a
`.gitea/workflows/check.yml` sets `fetch-depth: 0` on its checkout step. tag-derived version must set `fetch-depth: 0` on its checkout step.
- **Verify `.dockerignore` by enumerating the image, not by reading the - **Verify `.dockerignore` by enumerating the image, not by reading the
patterns.** Plant files at the root _and_ at least two directories deep, build patterns.** Plant files at the root _and_ at least two directories deep, build