Compare commits

..
1 Commits
Author SHA1 Message Date
sneak c995ee45fb Keep Go's build cache between builds (closes #124)
check / check (push) Successful in 1m43s
The Dockerfile runs make test and make build with Go's build cache in a
BuildKit cache mount, so a build compiles only what changed since the
last one instead of the standard library and every dependency from
nothing. The mount has an id of its own, so builds of other repositories,
compiled against other C headers, do not share it. script/test passes
-count=1, so no test result is taken from the cache.

Model: opus-5-5
2026-10-06 12:05:07 +00:00
4 changed files with 25 additions and 17 deletions
+14 -7
View File
@@ -50,19 +50,26 @@ ARG CHECK_EPOCH
COPY . . COPY . .
# Go's build cache is kept between builds in this cache mount, so make test # Go's build cache is kept between builds in this cache mount, which make test
# compiles only what changed since the last build, not the standard library # and make build both use, so each compiles only what changed since the last
# and every dependency from nothing. script/test passes -count=1, so test # build, not the standard library and every dependency from nothing.
# results are never taken from it. # script/test passes -count=1, so test results are never taken from it.
RUN --mount=type=cache,target=/root/.cache/go-build make test # The mount has its own id because the default id, its path, is shared with
# other repositories' builds, and Go's cache does not notice changes to C
# libraries: an entry compiled there against other C headers could be reused
# here. It does not notice a change of this image's own C headers either.
RUN --mount=type=cache,id=sneak/secret/go-build,target=/root/.cache/go-build \
make test
# The version stamped into the binary: the VERSION build argument when one # The version stamped into the binary: the VERSION build argument when one
# is given, otherwise `git describe --tags --always` of the .git the build # is given, otherwise `git describe --tags --always` of the .git the build
# context carries: the tag on a tagged commit, tag-N-gHASH on a commit after # context carries: the tag on a tagged commit, tag-N-gHASH on a commit after
# one, the short commit when no tag is reachable. A context that carries .git # one, the short commit when no tag is reachable. A context that carries .git
# and still yields no version fails the build. # and still yields no version fails the build. make build uses the same Go
# build cache mount as make test.
ARG VERSION ARG VERSION
RUN version="${VERSION:-$(git describe --tags --always)}"; \ RUN --mount=type=cache,id=sneak/secret/go-build,target=/root/.cache/go-build \
version="${VERSION:-$(git describe --tags --always)}"; \
if [ -e .git ] && { [ -z "$version" ] || [ "$version" = dev ] || \ if [ -e .git ] && { [ -z "$version" ] || [ "$version" = dev ] || \
[ "$version" = unknown ]; }; then \ [ "$version" = unknown ]; }; then \
echo "no version could be derived although the build context carries .git" >&2; \ echo "no version could be derived although the build context carries .git" >&2; \
+1 -1
View File
@@ -626,7 +626,7 @@ provide:
(memguard needs mlock; the Dockerfile runs the checks), with a new (memguard needs mlock; the Dockerfile runs the checks), with a new
`CHECK_EPOCH` build argument on every run so the checks run again on an `CHECK_EPOCH` build argument on every run so the checks run again on an
unchanged tree; the `Dockerfile` keeps Go's build cache between builds, so unchanged tree; the `Dockerfile` keeps Go's build cache between builds, so
`make test` compiles only what changed `make test` and `make build` compile only what changed
- `script/precommit` — pre-commit checks: `go mod tidy` verification, then - `script/precommit` — pre-commit checks: `go mod tidy` verification, then
`script/check` `script/check`
- `script/install-precommit` — install the git pre-commit hook that runs - `script/install-precommit` — install the git pre-commit hook that runs
+8 -7
View File
@@ -20,13 +20,14 @@ https://git.eeqj.de/sneak/secret/milestone/12
- 2026-10-06: `make test` in `script/cibuild` no longer compiles the standard - 2026-10-06: `make test` in `script/cibuild` no longer compiles the standard
library and every dependency from nothing on every build library and every dependency from nothing on every build
(https://git.eeqj.de/sneak/secret/issues/124). The `Dockerfile` runs it with (https://git.eeqj.de/sneak/secret/issues/124). The `Dockerfile` runs it and
Go's build cache in a BuildKit cache mount, which docker keeps between builds, `make build` with Go's build cache in a BuildKit cache mount, which docker
locally and on the Gitea runner alike, so it compiles only what changed since keeps between builds, locally and on the Gitea runner alike, so each compiles
the last build. `script/test` passes `-count=1`, so every test runs on every only what changed since the last build. The mount has an id of its own, so
build and no result comes from Go's test cache. A build with an empty cache, other repositories' builds do not share it. `script/test` passes `-count=1`,
such as the first after docker's build cache is cleared, compiles everything so every test runs on every build and no result comes from Go's test cache. A
in `make test` as before. build with an empty cache, such as the first after docker's build cache is
cleared, compiles everything in `make test` as before.
- 2026-10-06: The tests run quickly with the race detector on - 2026-10-06: The tests run quickly with the race detector on
(https://git.eeqj.de/sneak/secret/issues/120). Most of their time went to (https://git.eeqj.de/sneak/secret/issues/120). Most of their time went to
deriving keys from passphrases with scrypt, which is slow on purpose. The new deriving keys from passphrases with scrypt, which is slow on purpose. The new
+2 -2
View File
@@ -6,8 +6,8 @@
# the lower limit of a plain `docker build .`. # the lower limit of a plain `docker build .`.
# A cached build checks nothing: a new CHECK_EPOCH on every run makes the # A cached build checks nothing: a new CHECK_EPOCH on every run makes the
# Dockerfile's check steps run again on an unchanged tree, while its base # Dockerfile's check steps run again on an unchanged tree, while its base
# images, module downloads and the Go build cache that make test uses stay # images, module downloads and the Go build cache that make test and make
# cached. # build use stay cached.
set -eu set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"