Keep Go's build cache between builds for make test (closes #124)
check / check (push) Successful in 1m23s

The Dockerfile runs make test with Go's build cache in a BuildKit cache
mount, so a build compiles only what changed since the last one instead
of the standard library and every dependency from nothing. script/test
passes -count=1, so no test result is taken from the cache.

Model: opus-5-5
This commit is contained in:
2026-10-06 05:25:30 +00:00
parent 4ff0d20c10
commit a64614f5ce
5 changed files with 23 additions and 5 deletions
+5 -1
View File
@@ -50,7 +50,11 @@ ARG CHECK_EPOCH
COPY . .
RUN make test
# Go's build cache is kept between builds in this cache mount, so make test
# compiles only what changed since the last build, not the standard library
# and every dependency from nothing. script/test passes -count=1, so test
# results are never taken from it.
RUN --mount=type=cache,target=/root/.cache/go-build make test
# The version stamped into the binary: the VERSION build argument when one
# is given, otherwise `git describe --tags --always` of the .git the build
+4 -2
View File
@@ -604,7 +604,8 @@ provide:
- `script/build` — build the `secret` binary into the repo root, stamping the
version (`VERSION` from the environment, else `git describe`) and the git
commit
- `script/test` — run `go vet` and the test suite (verbose rerun on failure)
- `script/test` — run `go vet` and the test suite (verbose rerun on failure),
every test on every run, never a result from Go's test cache
- `script/lint` — run `golangci-lint` in docker only: builds `Dockerfile.lint`,
where the linter is a build step that runs on every call, also on an unchanged
tree
@@ -624,7 +625,8 @@ provide:
- `script/cibuild` — CI entrypoint: `docker build --ulimit memlock=-1:-1 .`
(memguard needs mlock; the Dockerfile runs the checks), with a new
`CHECK_EPOCH` build argument on every run so the checks run again on an
unchanged tree
unchanged tree; the `Dockerfile` keeps Go's build cache between builds, so
`make test` compiles only what changed
- `script/precommit` — pre-commit checks: `go mod tidy` verification, then
`script/check`
- `script/install-precommit` — install the git pre-commit hook that runs
+9
View File
@@ -18,6 +18,15 @@ https://git.eeqj.de/sneak/secret/milestone/12
# Completed Steps
- 2026-10-06: `make test` in `script/cibuild` no longer compiles the standard
library and every dependency from nothing on every build
(https://git.eeqj.de/sneak/secret/issues/124). The `Dockerfile` runs it with
Go's build cache in a BuildKit cache mount, which docker keeps between builds,
locally and on the Gitea runner alike, so it compiles only what changed since
the last build. `script/test` passes `-count=1`, so every test runs on every
build and no result comes from Go's test cache. A build with an empty cache,
such as the first after docker's build cache is cleared, compiles everything
in `make test` as before.
- 2026-10-06: The tests run quickly with the race detector on
(https://git.eeqj.de/sneak/secret/issues/120). Most of their time went to
deriving keys from passphrases with scrypt, which is slow on purpose. The new
+2 -1
View File
@@ -6,7 +6,8 @@
# the lower limit of a plain `docker build .`.
# A cached build checks nothing: a new CHECK_EPOCH on every run makes the
# Dockerfile's check steps run again on an unchanged tree, while its base
# images and module downloads stay cached.
# images, module downloads and the Go build cache that make test uses stay
# cached.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
+3 -1
View File
@@ -9,7 +9,9 @@ main() {
# CGO is required (Makefile exports this too)
export CGO_ENABLED=1
go vet ./...
go test ./... || go test -v ./...
# -count=1: run every test, never take a result from Go's test cache,
# which the Dockerfile keeps between builds
go test -count=1 ./... || go test -count=1 -v ./...
}
main "$@"