Let a plain docker build pass and stamp the git version (closes #57)
check / check (push) Successful in 46s

The size tests skip a case whose secret needs more locked memory than
RLIMIT_MEMLOCK allows: memguard panics otherwise, and a plain
`docker build .` runs under an 8 MiB limit. script/cibuild still runs
every case.

The build stage stamps the VERSION build argument, else
`git describe --tags --always`, and fails when .git is present but
yields no version. `make build` stamps `git describe` too instead of
the fixed 0.1.0. .dockerignore keeps .git/config out; script/docker is
now the canonical copy.

Model: opus-5-5
This commit is contained in:
2026-10-02 10:26:08 +00:00
parent 41cea400a7
commit 41078f1997
8 changed files with 75 additions and 7 deletions
+3 -2
View File
@@ -1,8 +1,9 @@
#!/bin/sh
# script/cibuild: run the CI build. The Dockerfile runs script/check
# (via make check), so a successful build implies all checks pass.
# The Gitea workflow runs this on push. The memlock ulimit is required
# because the test suite uses memguard, which mlocks memory.
# The Gitea workflow runs this on push. The memlock ulimit lets the tests
# that lock large secrets in memory (memguard mlocks them) run; under the
# lower limit of a plain `docker build .` they are skipped.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"