Keep Go's build cache between builds for make test (closes #124)
check / check (push) Successful in 1m23s

The Dockerfile runs make test with Go's build cache in a BuildKit cache
mount, so a build compiles only what changed since the last one instead
of the standard library and every dependency from nothing. script/test
passes -count=1, so no test result is taken from the cache.

Model: opus-5-5
This commit is contained in:
2026-10-06 05:25:30 +00:00
parent 4ff0d20c10
commit a64614f5ce
5 changed files with 23 additions and 5 deletions
+5 -1
View File
@@ -50,7 +50,11 @@ ARG CHECK_EPOCH
COPY . . COPY . .
RUN make test # Go's build cache is kept between builds in this cache mount, so make test
# compiles only what changed since the last build, not the standard library
# and every dependency from nothing. script/test passes -count=1, so test
# results are never taken from it.
RUN --mount=type=cache,target=/root/.cache/go-build make test
# The version stamped into the binary: the VERSION build argument when one # The version stamped into the binary: the VERSION build argument when one
# is given, otherwise `git describe --tags --always` of the .git the build # is given, otherwise `git describe --tags --always` of the .git the build
+4 -2
View File
@@ -604,7 +604,8 @@ provide:
- `script/build` — build the `secret` binary into the repo root, stamping the - `script/build` — build the `secret` binary into the repo root, stamping the
version (`VERSION` from the environment, else `git describe`) and the git version (`VERSION` from the environment, else `git describe`) and the git
commit commit
- `script/test` — run `go vet` and the test suite (verbose rerun on failure) - `script/test` — run `go vet` and the test suite (verbose rerun on failure),
every test on every run, never a result from Go's test cache
- `script/lint` — run `golangci-lint` in docker only: builds `Dockerfile.lint`, - `script/lint` — run `golangci-lint` in docker only: builds `Dockerfile.lint`,
where the linter is a build step that runs on every call, also on an unchanged where the linter is a build step that runs on every call, also on an unchanged
tree tree
@@ -624,7 +625,8 @@ provide:
- `script/cibuild` — CI entrypoint: `docker build --ulimit memlock=-1:-1 .` - `script/cibuild` — CI entrypoint: `docker build --ulimit memlock=-1:-1 .`
(memguard needs mlock; the Dockerfile runs the checks), with a new (memguard needs mlock; the Dockerfile runs the checks), with a new
`CHECK_EPOCH` build argument on every run so the checks run again on an `CHECK_EPOCH` build argument on every run so the checks run again on an
unchanged tree unchanged tree; the `Dockerfile` keeps Go's build cache between builds, so
`make test` compiles only what changed
- `script/precommit` — pre-commit checks: `go mod tidy` verification, then - `script/precommit` — pre-commit checks: `go mod tidy` verification, then
`script/check` `script/check`
- `script/install-precommit` — install the git pre-commit hook that runs - `script/install-precommit` — install the git pre-commit hook that runs
+9
View File
@@ -18,6 +18,15 @@ https://git.eeqj.de/sneak/secret/milestone/12
# Completed Steps # Completed Steps
- 2026-10-06: `make test` in `script/cibuild` no longer compiles the standard
library and every dependency from nothing on every build
(https://git.eeqj.de/sneak/secret/issues/124). The `Dockerfile` runs it with
Go's build cache in a BuildKit cache mount, which docker keeps between builds,
locally and on the Gitea runner alike, so it compiles only what changed since
the last build. `script/test` passes `-count=1`, so every test runs on every
build and no result comes from Go's test cache. A build with an empty cache,
such as the first after docker's build cache is cleared, compiles everything
in `make test` as before.
- 2026-10-06: The tests run quickly with the race detector on - 2026-10-06: The tests run quickly with the race detector on
(https://git.eeqj.de/sneak/secret/issues/120). Most of their time went to (https://git.eeqj.de/sneak/secret/issues/120). Most of their time went to
deriving keys from passphrases with scrypt, which is slow on purpose. The new deriving keys from passphrases with scrypt, which is slow on purpose. The new
+2 -1
View File
@@ -6,7 +6,8 @@
# the lower limit of a plain `docker build .`. # the lower limit of a plain `docker build .`.
# A cached build checks nothing: a new CHECK_EPOCH on every run makes the # A cached build checks nothing: a new CHECK_EPOCH on every run makes the
# Dockerfile's check steps run again on an unchanged tree, while its base # Dockerfile's check steps run again on an unchanged tree, while its base
# images and module downloads stay cached. # images, module downloads and the Go build cache that make test uses stay
# cached.
set -eu set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
+3 -1
View File
@@ -9,7 +9,9 @@ main() {
# CGO is required (Makefile exports this too) # CGO is required (Makefile exports this too)
export CGO_ENABLED=1 export CGO_ENABLED=1
go vet ./... go vet ./...
go test ./... || go test -v ./... # -count=1: run every test, never take a result from Go's test cache,
# which the Dockerfile keeps between builds
go test -count=1 ./... || go test -count=1 -v ./...
} }
main "$@" main "$@"