docker build . stamps the git tag or short commit, not dev (closes #154)
check / check (push) Failing after 46s
check / check (push) Failing after 46s
A plain `docker build .` now stamps the version from git rather than `dev`/`0.0.0`. After `tsc`, `script/build` writes into `dist/package.json` the version `script/version` decides: `VERSION` when given, otherwise `git describe --tags --always` (the tag; or tag, commits since and short commit; or the short commit), otherwise `package.json`'s. A checkout with `.git` that yields an empty, `dev` or `unknown` version fails the build. `.dockerignore` sends `.git` but not `.git/config`, so no remote URL or credential reaches the image. `ARG VERSION` has no default, and the host scripts' version still wins. Not changed: `REPO_POLICIES.md` still says `ARG VERSION=dev` until the shared policy changes. Model: opus-5-5 Co-authored-by: clawbot <sneak+clawbot@sneak.cloud>
This commit was merged in pull request #157.
This commit is contained in:
@@ -9,8 +9,10 @@
|
||||
// Excluding too much: Prettier 3 reads `.gitignore` as a default ignore file,
|
||||
// so dropping it from the context silently changes which files the lint
|
||||
// phase's prettier check looks at compared to `make fmt-check` on the host.
|
||||
// And without `.git`, a `docker build .` given no `VERSION` build arg cannot
|
||||
// derive the version (`script/version`) and stamps `package.json`'s instead.
|
||||
//
|
||||
// Neither shows up as a build failure, so they are asserted here.
|
||||
// None of these shows up as a build failure, so they are asserted here.
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { existsSync, readFileSync } from "node:fs";
|
||||
import { fileURLToPath } from "node:url";
|
||||
@@ -47,6 +49,17 @@ describe(".dockerignore", () => {
|
||||
expect(dockerignore).not.toContain(".gitignore");
|
||||
});
|
||||
|
||||
it("leaves .git in the build context for the version", () => {
|
||||
expect(dockerignore).not.toContain(".git");
|
||||
expect(dockerignore).not.toContain(".git/");
|
||||
});
|
||||
|
||||
// The build stage is the final image, so a .git/config sent in would
|
||||
// ship the clone's remote URL and any credential in it.
|
||||
it("sends .git without its config", () => {
|
||||
expect(dockerignore).toContain(".git/config");
|
||||
});
|
||||
|
||||
// BuildKit lets a `Dockerfile.dockerignore` shadow the root one; such a
|
||||
// file would silently give the build a different, unreviewed context —
|
||||
// and eslint's flat config does not ignore dot-directories, so a stray
|
||||
|
||||
@@ -0,0 +1,137 @@
|
||||
// `script/version` prints the version `script/build` stamps into
|
||||
// `dist/package.json`, which is what `quak --version` reports from a build.
|
||||
// A `docker build .` of a clone is given no `VERSION` build arg, so the
|
||||
// version has to come from the `.git` in its context: the tag on a tagged
|
||||
// commit; the tag, the commits since it and the short commit on a later commit;
|
||||
// the short commit when no tag is reachable. A checkout with `.git` that still
|
||||
// yields no usable version must fail the build, not ship a version nobody can
|
||||
// trace back to its commit.
|
||||
//
|
||||
// Each test copies the script into a fresh directory, which the script then
|
||||
// treats as the checkout, and executes it there.
|
||||
import { afterEach, describe, expect, it } from "vitest";
|
||||
import { execFileSync, spawnSync } from "node:child_process";
|
||||
import {
|
||||
chmodSync,
|
||||
copyFileSync,
|
||||
mkdirSync,
|
||||
mkdtempSync,
|
||||
rmSync,
|
||||
writeFileSync,
|
||||
} from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
import { join } from "node:path";
|
||||
import { fileURLToPath } from "node:url";
|
||||
|
||||
const repoRoot = fileURLToPath(new URL("../../", import.meta.url));
|
||||
|
||||
let checkout = "";
|
||||
|
||||
afterEach(() => {
|
||||
rmSync(checkout, { recursive: true, force: true });
|
||||
});
|
||||
|
||||
// A checkout holding the script and a package.json that declares 0.0.0, with
|
||||
// no .git yet.
|
||||
const makeCheckout = (): void => {
|
||||
checkout = mkdtempSync(join(tmpdir(), "quak-version-"));
|
||||
mkdirSync(join(checkout, "script"));
|
||||
copyFileSync(
|
||||
join(repoRoot, "script/version"),
|
||||
join(checkout, "script/version"),
|
||||
);
|
||||
chmodSync(join(checkout, "script/version"), 0o755);
|
||||
writeFileSync(join(checkout, "package.json"), '{ "version": "0.0.0" }\n');
|
||||
};
|
||||
|
||||
// git in the checkout, with an identity and no commit signing, whatever the
|
||||
// host's own git config says.
|
||||
const git = (...args: string[]): string =>
|
||||
execFileSync(
|
||||
"git",
|
||||
[
|
||||
"-c",
|
||||
"user.name=quak",
|
||||
"-c",
|
||||
"user.email=quak@example.invalid",
|
||||
"-c",
|
||||
"commit.gpgsign=false",
|
||||
...args,
|
||||
],
|
||||
{ cwd: checkout, encoding: "utf-8", stdio: ["ignore", "pipe", "pipe"] },
|
||||
).trim();
|
||||
|
||||
const makeCommittedCheckout = (): void => {
|
||||
makeCheckout();
|
||||
git("init", "-q");
|
||||
git("add", "package.json");
|
||||
git("commit", "-q", "-m", "first");
|
||||
};
|
||||
|
||||
// Runs the script with nothing in its environment but PATH and, when given,
|
||||
// VERSION.
|
||||
const runVersion = (version?: string) =>
|
||||
spawnSync(join(checkout, "script/version"), {
|
||||
cwd: checkout,
|
||||
encoding: "utf-8",
|
||||
env: { PATH: process.env.PATH, VERSION: version },
|
||||
});
|
||||
|
||||
describe("script/version", () => {
|
||||
it("prints the short commit of an untagged commit", () => {
|
||||
makeCommittedCheckout();
|
||||
expect(runVersion().stdout.trim()).toBe(
|
||||
git("rev-parse", "--short", "HEAD"),
|
||||
);
|
||||
});
|
||||
|
||||
it("prints the tag of a tagged commit", () => {
|
||||
makeCommittedCheckout();
|
||||
git("tag", "v1.2.3");
|
||||
expect(runVersion().stdout.trim()).toBe("v1.2.3");
|
||||
});
|
||||
|
||||
// script/docker and script/cibuild pass the version they resolve on the
|
||||
// host as the VERSION build arg.
|
||||
it("prints the VERSION it is given over what git would derive", () => {
|
||||
makeCommittedCheckout();
|
||||
expect(runVersion("x").stdout.trim()).toBe("x");
|
||||
});
|
||||
|
||||
// `--build-arg VERSION=` must not stamp an empty version.
|
||||
it("treats an empty VERSION as unset", () => {
|
||||
makeCommittedCheckout();
|
||||
expect(runVersion("").stdout.trim()).toBe(
|
||||
git("rev-parse", "--short", "HEAD"),
|
||||
);
|
||||
});
|
||||
|
||||
// A source tarball has no .git: it keeps the version package.json
|
||||
// declares, and must still build.
|
||||
it("prints package.json's version where there is no .git", () => {
|
||||
makeCheckout();
|
||||
const result = runVersion();
|
||||
expect(result.status).toBe(0);
|
||||
expect(result.stdout.trim()).toBe("0.0.0");
|
||||
});
|
||||
|
||||
// A repository with no commits stands in for any .git that git cannot
|
||||
// describe: git missing from the image, or refusing to read the checkout.
|
||||
it("fails where .git yields no version", () => {
|
||||
makeCheckout();
|
||||
git("init", "-q");
|
||||
const result = runVersion();
|
||||
expect(result.status).not.toBe(0);
|
||||
expect(result.stdout).toBe("");
|
||||
});
|
||||
|
||||
it.each(["dev", "unknown"])(
|
||||
"fails where there is .git and the version is %s",
|
||||
(version) => {
|
||||
makeCommittedCheckout();
|
||||
const result = runVersion(version);
|
||||
expect(result.status).not.toBe(0);
|
||||
expect(result.stdout).toBe("");
|
||||
},
|
||||
);
|
||||
});
|
||||
Reference in New Issue
Block a user