#!/bin/sh
# script/cibuild: run the CI build. The Dockerfile runs script/check
# (via make check), so a successful build implies all checks pass.
# The Gitea workflow runs this on push. The memlock ulimit lifts the limit
# on memory the tests lock (memguard mlocks secrets); they also pass under
# the lower limit of a plain `docker build .`.
# A cached build checks nothing: a new CHECK_EPOCH on every run makes the
# Dockerfile's check steps run again on an unchanged tree, while its base
# images, module downloads and the Go build cache that make test and make
# build use stay cached.
set -eu

ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"

main() {
    cd "$ROOT"
    docker build --ulimit memlock=-1:-1 \
        --build-arg CHECK_EPOCH="$(date +%s)" .
}

main "$@"
