Let a plain docker build pass and stamp the git version (closes #57)
check / check (push) Failing after 20s

The size tests skip a case whose secret needs more locked memory than
RLIMIT_MEMLOCK allows: memguard panics otherwise, and a plain
`docker build .` runs under an 8 MiB limit. script/cibuild still runs
every case.

The build stage stamps the VERSION build argument, else
`git describe --tags --always`, and fails when .git is present but
yields no version. `make build` stamps `git describe` too instead of
the fixed 0.1.0. .dockerignore keeps .git/config out; script/docker is
now the canonical copy.

Model: opus-5-5
This commit is contained in:
2026-10-02 10:21:22 +00:00
parent 41cea400a7
commit b4eed47511
8 changed files with 74 additions and 7 deletions
+6
View File
@@ -1,3 +1,9 @@
# .git is sent without its config. Without a VERSION build argument the
# stage that compiles runs `git describe --tags --always` on .git, which
# does not need .git/config; that file can hold a credential, such as a
# password in a remote URL or the token the CI checkout step stores there.
.git/config
# Build artifacts
secret
coverage.out