Let a plain docker build pass and stamp the git version (closes #57)
check / check (push) Failing after 20s

The size tests skip a case whose secret needs more locked memory than
RLIMIT_MEMLOCK allows: memguard panics otherwise, and a plain
`docker build .` runs under an 8 MiB limit. script/cibuild still runs
every case.

The build stage stamps the VERSION build argument, else
`git describe --tags --always`, and fails when .git is present but
yields no version. `make build` stamps `git describe` too instead of
the fixed 0.1.0. .dockerignore keeps .git/config out; script/docker is
now the canonical copy.

Model: opus-5-5
This commit is contained in:
2026-10-02 10:21:22 +00:00
parent 41cea400a7
commit b4eed47511
8 changed files with 74 additions and 7 deletions
+8
View File
@@ -25,6 +25,14 @@ Bring the repo into policy compliance in one commit:
# Completed Steps
- 2026-10-02: A plain `docker build .` builds again: the size tests
skip a case that needs more locked memory than the limit allows,
and run every case under `script/cibuild`. The image stamps the
`VERSION` build argument, else `git describe --tags --always`, into
`Version`, and fails if `.git` is present but yields no version;
`make build` stamps `git describe` too, not a fixed `0.1.0`.
`.dockerignore` keeps `.git/config` out; `script/docker` is the
canonical copy.
- 2026-08-07: Updated golangci-lint to v2.12.2 with the canonical
`.golangci.yml` (all linters enabled minus the standard disable
list, `lll` 88, tests linted); bumped the `Dockerfile` lint-stage