diff --git a/README.md b/README.md index 370a06e..867e9d2 100644 --- a/README.md +++ b/README.md @@ -116,10 +116,14 @@ alpine. We provide: `script/bootstrap`, then `script/install-precommit` - `script/projectname` — output the project name (our own extension); used by `script/docker` for the image tag -- `script/test` — `docker build --no-cache --target test -t prompts-test .`, - building the `test` phase of the `Dockerfile` (no tests defined here) -- `script/lint` — `docker build --no-cache --target lint -t prompts-lint .`, - building the `lint` phase, which runs prettier over the markdown files +- `script/test` — + `docker build --no-cache --target test --output type=cacheonly .`, building + the `test` phase of the `Dockerfile` without writing an image (no tests + defined here) +- `script/lint` — + `docker build --no-cache --target lint --output type=cacheonly .`, building + the `lint` phase, which runs prettier over the markdown files, without writing + an image - `script/fmt` — format all markdown files with prettier (writes; native, not in a container) - `script/fmt-check` — check formatting (read-only; native) diff --git a/TODO.md b/TODO.md index a486347..7265754 100644 --- a/TODO.md +++ b/TODO.md @@ -21,6 +21,14 @@ fmt-check, and commit. # Completed Steps +- 2026-10-07: `script/lint` and `script/test` now build with + `--output type=cacheonly` in place of a tag (issue 123), so they still run + their phase uncached and fail on a failing step but write no image. Nothing + used those images, and writing one out cost about 16 seconds of a Go + repository's test build. `script/cibuild` and `script/docker` keep their tags. + `REPO_POLICIES.md`, both checklists and the README no longer say the gate + builds are tagged. Not yet tried on the shared runner. Repositories pick this + up on their next re-vendor. - 2026-10-07: The canonical `.gitea/workflows/check.yml` now sets `timeout-minutes: 20` on its `check` job (issue 120), so a hung build frees the shared runner instead of holding it until the runner's own limit. diff --git a/prompts/EXISTING_REPO_CHECKLIST.md b/prompts/EXISTING_REPO_CHECKLIST.md index 9cfc861..3027bac 100644 --- a/prompts/EXISTING_REPO_CHECKLIST.md +++ b/prompts/EXISTING_REPO_CHECKLIST.md @@ -132,16 +132,19 @@ with your task. `script/install-precommit`, shimmed by `make hooks`) runs it - [ ] README has an **Entrypoints** section documenting the `script/` entrypoints and linking the standard -- [ ] `script/lint` and `script/test` build their phase by name - (`docker build --no-cache --target -t - .`), and no - host invocation anywhere in the repo can produce a lint verdict — grep for - the linter's own name across `script/`, the `Makefile` and CI config, not - just `script/lint`. A second path is likeliest here: a `make lint-fast`, - an older host-versus-container branch, or a CI step calling the binary +- [ ] `script/lint` and `script/test` each run + `docker build --no-cache --target --output type=cacheonly .`, + which builds their phase by name and writes no image, and no host + invocation anywhere in the repo can produce a lint verdict — grep for the + linter's own name across `script/`, the `Makefile` and CI config, not just + `script/lint`. A second path is likeliest here: a `make lint-fast`, an + older host-versus-container branch, or a CI step calling the binary directly. `script/fmt` and `script/fmt-check` are expected hits and stay on the host. -- [ ] Every `docker build` in `script/` is tagged — an untagged one leaves a - dangling image behind on every run, on every host and CI runner +- [ ] No `docker build` in `script/` leaves a dangling image behind: + `script/lint` and `script/test` write no image, and `script/docker` and + `script/cibuild` tag theirs. A build that writes an untagged image leaves + one behind on every run, on every host and CI runner. - [ ] `script/cibuild` runs `script/bootstrap` before `script/check`, and builds the image with `--no-cache`. Without the bootstrap the CI run dies in `script/fmt-check`, which runs the formatter on the host and finds nothing diff --git a/prompts/NEW_REPO_CHECKLIST.md b/prompts/NEW_REPO_CHECKLIST.md index d9bc2da..6a2e471 100644 --- a/prompts/NEW_REPO_CHECKLIST.md +++ b/prompts/NEW_REPO_CHECKLIST.md @@ -143,11 +143,14 @@ are thin shims calling them. Model scripts: it - [ ] `script/setup` / `make setup` — readies a fresh clone: runs `bootstrap`, then `install-precommit`, plus repo-specific init -- [ ] `script/test` / `make test` — `docker build --no-cache --target test .`, - tagged; the phase runs real tests, not a no-op (90-second timeout, - 60-second hard cap on wall time) -- [ ] `script/lint` / `make lint` — `docker build --no-cache --target lint .`, - tagged. No lint verdict may come from a host invocation of the linter. +- [ ] `script/test` / `make test` — + `docker build --no-cache --target test --output type=cacheonly .`, which + writes no image; the phase runs real tests, not a no-op (90-second + timeout, 60-second hard cap on wall time) +- [ ] `script/lint` / `make lint` — + `docker build --no-cache --target lint --output type=cacheonly .`, which + writes no image. No lint verdict may come from a host invocation of the + linter. - [ ] `script/fmt` / `make fmt` — formats code (writes; native, never in a container) - [ ] `script/fmt-check` / `make fmt-check` — checks formatting (read-only; @@ -169,8 +172,9 @@ are thin shims calling them. Model scripts: `script/bootstrap` leaves the node and yarn it installs off the `PATH` of the shell that called it, so a bare `yarn` exits 127 on a runner carrying nothing but docker and git. -- [ ] Every `docker build` in `script/` is tagged, so no invocation leaves a - dangling image behind +- [ ] No `docker build` in `script/` leaves a dangling image behind: + `script/lint` and `script/test` write no image, and `script/docker` and + `script/cibuild` tag theirs - [ ] `script/precommit` — called by the pre-commit hook; runs `script/check` - [ ] `script/install-precommit` — installs the pre-commit hook that runs `script/precommit` diff --git a/prompts/REPO_POLICIES.md b/prompts/REPO_POLICIES.md index d662eb2..62f417f 100644 --- a/prompts/REPO_POLICIES.md +++ b/prompts/REPO_POLICIES.md @@ -118,9 +118,8 @@ style conventions are in separate documents: and nothing else: ```sh - tag="$(script/projectname)" - docker build --no-cache --target lint -t "$tag-lint" . - docker build --no-cache --target test -t "$tag-test" . + docker build --no-cache --target lint --output type=cacheonly . + docker build --no-cache --target test --output type=cacheonly . ``` **A stage that is not the last one in the file is built only when the final @@ -130,12 +129,15 @@ style conventions are in separate documents: plain `docker build .` builds the last stage alone and exits 0 having linted and tested nothing. - **Every `docker build` in `script/` is tagged**, here and in - `script/cibuild` and `script/docker`. An untagged build leaves a dangling - image behind on every invocation, on every developer host and every CI - runner; a tagged one replaces the previous image. Each script assigns the - tag on its own line before the build, so `set -e` stops it where - `script/projectname` fails. + **The gate builds write no image.** With `--output type=cacheonly` the phase + runs and a failing step fails the build, but the result is not exported. + Nothing uses those images, and writing one out is slow: a Go test phase's + image holds the toolchain and every compiled package. A build given neither + `--output` nor `-t` writes an untagged image and leaves it dangling, on + every developer host and every CI runner. `script/cibuild` and + `script/docker` build the image that ships and tag it, so each build + replaces the previous image; each assigns the tag on its own line before the + build, so `set -e` stops it where `script/projectname` fails. Inside a phase the tool is invoked directly — `golangci-lint`, `go test`, `eslint`, `prettier` — never through `make lint` or `script/test`, which are diff --git a/script/lint b/script/lint index 634d4a2..a1cf92f 100755 --- a/script/lint +++ b/script/lint @@ -6,8 +6,8 @@ # # The phase is not the last stage in the file, so it is built only when # --target names it. --no-cache because a cached lint layer is a lint -# that did not run. The tag makes each build replace the previous image -# instead of leaving a dangling one behind. +# that did not run. --output type=cacheonly writes no image, since +# nothing uses one. set -eu SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" @@ -15,13 +15,9 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)" main() { cd "$ROOT" - # The tag gets its own line: a failing command substitution inside - # an argument does not trip `set -e`, so the inline form degrades - # silently to an empty constant. - tag="$("$SCRIPT_DIR/projectname")" docker build --no-cache \ --target lint \ - -t "$tag-lint" . + --output type=cacheonly . } main "$@" diff --git a/script/test b/script/test index 38fa1b3..1b17d40 100755 --- a/script/test +++ b/script/test @@ -2,8 +2,8 @@ # script/test: run the test suite. Testing is a phase of the Dockerfile # and this builds that phase alone, on the same terms as script/lint: # --target because a phase that is not the last stage is built only when -# named, --no-cache because a cached test layer is a test that did not -# run, and a tag so each build replaces the previous image. +# named, and --no-cache because a cached test layer is a test that did +# not run. --output type=cacheonly writes no image, since nothing uses one. set -eu SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" @@ -11,13 +11,9 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)" main() { cd "$ROOT" - # The tag gets its own line: a failing command substitution inside - # an argument does not trip `set -e`, so the inline form degrades - # silently to an empty constant. - tag="$("$SCRIPT_DIR/projectname")" docker build --no-cache \ --target test \ - -t "$tag-test" . + --output type=cacheonly . } main "$@"