diff --git a/Dockerfile b/Dockerfile index df5ea97..99f5bc5 100644 --- a/Dockerfile +++ b/Dockerfile @@ -6,6 +6,11 @@ WORKDIR /src COPY go.mod go.sum ./ RUN go mod download +# script/cibuild sets CHECK_EPOCH to the current time, so every step below +# runs again on each build, an unchanged tree included, while the steps +# above stay cached. ARG is per stage: the build stage declares it too. +ARG CHECK_EPOCH + COPY . . RUN make fmt-check @@ -25,6 +30,9 @@ WORKDIR /build COPY go.mod go.sum ./ RUN go mod download +# As in the lint stage: the steps below run again on each script/cibuild. +ARG CHECK_EPOCH + COPY . . RUN make test diff --git a/README.md b/README.md index 2c2bfaa..2ef45c3 100644 --- a/README.md +++ b/README.md @@ -521,7 +521,8 @@ them. We provide: - `script/docker` — build the Docker image tagged with the project name - `script/cibuild` — CI entrypoint: `docker build --ulimit memlock=-1:-1 .` (memguard needs mlock; the Dockerfile runs the - checks) + checks), with a new `CHECK_EPOCH` build argument on every run so the + checks run again on an unchanged tree - `script/precommit` — pre-commit checks: `go mod tidy` verification, then `script/check` - `script/install-precommit` — install the git pre-commit hook that diff --git a/TODO.md b/TODO.md index 3612f96..b8dd593 100644 --- a/TODO.md +++ b/TODO.md @@ -25,6 +25,14 @@ Bring the repo into policy compliance in one commit: # Completed Steps +- 2026-10-04: `script/cibuild` runs the checks again on an unchanged + tree (https://git.eeqj.de/sneak/secret/issues/54). It passes the + current time as the `CHECK_EPOCH` build argument, which both the lint + and the build stage of the `Dockerfile` declare after their module + download, so every step from `COPY . .` on runs on each build while + the base images and module downloads stay cached. Before, a second run + on the same tree took every check from the build cache and reported + success having run nothing. - 2026-10-04: `secret get` keeps the secret in locked memory until it writes it out (https://git.eeqj.de/sneak/secret/issues/37): `Vault.GetSecret` and `Vault.GetSecretVersion` return a diff --git a/script/cibuild b/script/cibuild index 3316194..58bf15f 100755 --- a/script/cibuild +++ b/script/cibuild @@ -4,13 +4,17 @@ # The Gitea workflow runs this on push. The memlock ulimit lets the tests # that lock large secrets in memory (memguard mlocks them) run; under the # lower limit of a plain `docker build .` they are skipped. +# A cached build checks nothing: a new CHECK_EPOCH on every run makes the +# Dockerfile's check steps run again on an unchanged tree, while its base +# images and module downloads stay cached. set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" main() { cd "$ROOT" - docker build --ulimit memlock=-1:-1 . + docker build --ulimit memlock=-1:-1 \ + --build-arg CHECK_EPOCH="$(date +%s)" . } main "$@"