script/lint and script/test build their Dockerfile phase with -t "$tag-lint" / -t "$tag-test", so every run writes the phase out as an image and unpacks it. Nothing uses those images. On this host that step alone takes about 16 seconds of a Go repository's test build: sneak/dnswatcher's test phase took 53–67 s tagged and 48–49 s without the image, against the 60-second make test cap. The images are also large, since the test phase holds the Go toolchain and the compiled packages.
Fix
script/lint and script/test build with --output type=cacheonly in place of -t: the phase still runs uncached and a failing step still fails the build, but no image is written, so nothing is left dangling either. Drop the tag line where it is no longer used.
script/cibuild and script/docker keep their tags: they build the image that ships.
prompts/REPO_POLICIES.md: the script/lint/script/test example and the "Every docker build in script/ is tagged" paragraph say the gate builds write no image and why; the checklists, prompts/CODE_STYLEGUIDE_GO.md and the README's Entrypoints section follow wherever they say the gate builds are tagged. last_modified bumped; a TODO.md Completed Steps entry.
Definition of done
script/lint and script/test leave no image behind, and a planted lint finding and a planted failing test each still fail them.
No document says the gate builds are tagged.
Disclosed: not tried on the Gitea runner.
This does not settle the cap for larger Go repositories; that is #113.
Model: opus-5-5
`script/lint` and `script/test` build their `Dockerfile` phase with `-t "$tag-lint"` / `-t "$tag-test"`, so every run writes the phase out as an image and unpacks it. Nothing uses those images. On this host that step alone takes about 16 seconds of a Go repository's test build: `sneak/dnswatcher`'s test phase took 53–67 s tagged and 48–49 s without the image, against the 60-second `make test` cap. The images are also large, since the test phase holds the Go toolchain and the compiled packages.
## Fix
- `script/lint` and `script/test` build with `--output type=cacheonly` in place of `-t`: the phase still runs uncached and a failing step still fails the build, but no image is written, so nothing is left dangling either. Drop the tag line where it is no longer used.
- `script/cibuild` and `script/docker` keep their tags: they build the image that ships.
- `prompts/REPO_POLICIES.md`: the `script/lint`/`script/test` example and the "Every `docker build` in `script/` is tagged" paragraph say the gate builds write no image and why; the checklists, `prompts/CODE_STYLEGUIDE_GO.md` and the README's Entrypoints section follow wherever they say the gate builds are tagged. `last_modified` bumped; a `TODO.md` Completed Steps entry.
## Definition of done
- `script/lint` and `script/test` leave no image behind, and a planted lint finding and a planted failing test each still fail them.
- No document says the gate builds are tagged.
- Disclosed: not tried on the Gitea runner.
This does not settle the cap for larger Go repositories; that is https://git.eeqj.de/sneak/prompts/issues/113.
Model: opus-5-5
clawbot
self-assigned this 2026-10-07 10:49:51 +02:00
#124 builds the lint and test phases with --output type=cacheonly, so they write no image, and updates the policy text, both checklists and the README to match.
Model: opus-5-5
https://git.eeqj.de/sneak/prompts/pulls/124 builds the lint and test phases with `--output type=cacheonly`, so they write no image, and updates the policy text, both checklists and the README to match.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
script/lintandscript/testbuild theirDockerfilephase with-t "$tag-lint"/-t "$tag-test", so every run writes the phase out as an image and unpacks it. Nothing uses those images. On this host that step alone takes about 16 seconds of a Go repository's test build:sneak/dnswatcher's test phase took 53–67 s tagged and 48–49 s without the image, against the 60-secondmake testcap. The images are also large, since the test phase holds the Go toolchain and the compiled packages.Fix
script/lintandscript/testbuild with--output type=cacheonlyin place of-t: the phase still runs uncached and a failing step still fails the build, but no image is written, so nothing is left dangling either. Drop the tag line where it is no longer used.script/cibuildandscript/dockerkeep their tags: they build the image that ships.prompts/REPO_POLICIES.md: thescript/lint/script/testexample and the "Everydocker buildinscript/is tagged" paragraph say the gate builds write no image and why; the checklists,prompts/CODE_STYLEGUIDE_GO.mdand the README's Entrypoints section follow wherever they say the gate builds are tagged.last_modifiedbumped; aTODO.mdCompleted Steps entry.Definition of done
script/lintandscript/testleave no image behind, and a planted lint finding and a planted failing test each still fail them.This does not settle the cap for larger Go repositories; that is #113.
Model: opus-5-5
#124 builds the lint and test phases with
--output type=cacheonly, so they write no image, and updates the policy text, both checklists and the README to match.Model: opus-5-5