The canonical .dockerignore and .gitignore both omitted the in-repo agent scratch directory, which holds one worktree per in-flight agent, so under `COPY . .` an entire extra checkout of the repo reached the image. The two entries are deliberately different shapes: anchored in .dockerignore, where the `**/` form would also delete a legitimately named nested directory, and unanchored in .gitignore, where a pattern already matches at every depth. Anchoring leaves a gap where agents run in subdirectories, stated in the vendored file itself. The second half is the consequence of excluding .git: `git describe` in a build stage yields an empty version without erroring, so the version is now computed on the host and passed in. Model: opus-5
22 lines
768 B
Bash
Executable File
22 lines
768 B
Bash
Executable File
#!/bin/sh
|
|
# script/cibuild: run the CI build. --no-cache because the checks are
|
|
# RUN steps: on an unchanged tree Docker serves them from cache and the
|
|
# build exits 0 having run nothing.
|
|
set -eu
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
|
|
|
main() {
|
|
cd "$ROOT"
|
|
# Own line: a failing command substitution inside an argument does
|
|
# not trip `set -e`, so the inline form degrades silently to an
|
|
# empty constant. VERSION is computed here because .dockerignore
|
|
# excludes .git, so `git describe` in a build stage yields an empty
|
|
# version without failing.
|
|
version="$(git describe --tags --always --dirty 2>/dev/null || true)"
|
|
[ -n "$version" ] || version="unknown"
|
|
docker build --no-cache --build-arg VERSION="$version" .
|
|
}
|
|
|
|
main "$@"
|