Make script/test fail on flaky failures and enable -race (closes #32)
check / check (push) Waiting to run

script/test ended with a verbose rerun whose exit status became the
script's, so a test that failed once and passed on the retry gave a
green build. It now follows the REPO_POLICIES.md pattern: go vet, then
go test -count=1 -timeout 30s -race -cover; on failure a verbose rerun
for the details, then exit 1. -count=1 stays on both go test lines
because the Dockerfile keeps Go's build cache between builds.

The tests that gave the secret binary a minute, and the PGP unlocker
test's 30-second timer, now use 10 seconds, so a hang fails with the
test's own message before the package's 30-second timeout. The README
describes the new run.

Model: opus-5-5
This commit is contained in:
2026-10-07 00:28:27 +00:00
parent b109c4e5e1
commit 585a7c1993
6 changed files with 41 additions and 18 deletions
+4 -2
View File
@@ -604,8 +604,10 @@ provide:
- `script/build` — build the `secret` binary into the repo root, stamping the
version (`VERSION` from the environment, else `git describe`) and the git
commit
- `script/test` — run `go vet` and the test suite (verbose rerun on failure),
every test on every run, never a result from Go's test cache
- `script/test` — run `go vet`, then the test suite with the race detector, a
30-second timeout per package and coverage, every test on every run, never a
result from Go's test cache; on failure it reruns the tests verbosely for the
details and fails even when the rerun passes
- `script/lint` — run `golangci-lint` in docker only: builds `Dockerfile.lint`,
where the linter is a build step that runs on every call, also on an unchanged
tree