Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
41ad87b3b9 |
+5
-10
@@ -50,14 +50,10 @@ ARG CHECK_EPOCH
|
||||
|
||||
COPY . .
|
||||
|
||||
# Go's build cache is kept between builds in this cache mount, which make test
|
||||
# and make build both use, so each compiles only what changed since the last
|
||||
# build, not the standard library and every dependency from nothing.
|
||||
# script/test passes -count=1, so test results are never taken from it.
|
||||
# The mount has its own id because the default id, its path, is shared with
|
||||
# other repositories' builds, and Go's cache does not notice changes to C
|
||||
# libraries: an entry compiled there against other C headers could be reused
|
||||
# here. It does not notice a change of this image's own C headers either.
|
||||
# This cache mount keeps Go's build cache between builds for make test and
|
||||
# make build; -count=1 in script/test keeps test results out of it. Go's cache
|
||||
# does not notice C header changes, so the mount has its own id: change the id
|
||||
# when the C packages installed above change.
|
||||
RUN --mount=type=cache,id=sneak/secret/go-build,target=/root/.cache/go-build \
|
||||
make test
|
||||
|
||||
@@ -65,8 +61,7 @@ RUN --mount=type=cache,id=sneak/secret/go-build,target=/root/.cache/go-build \
|
||||
# is given, otherwise `git describe --tags --always` of the .git the build
|
||||
# context carries: the tag on a tagged commit, tag-N-gHASH on a commit after
|
||||
# one, the short commit when no tag is reachable. A context that carries .git
|
||||
# and still yields no version fails the build. make build uses the same Go
|
||||
# build cache mount as make test.
|
||||
# and still yields no version fails the build.
|
||||
ARG VERSION
|
||||
RUN --mount=type=cache,id=sneak/secret/go-build,target=/root/.cache/go-build \
|
||||
version="${VERSION:-$(git describe --tags --always)}"; \
|
||||
|
||||
@@ -22,12 +22,12 @@ https://git.eeqj.de/sneak/secret/milestone/12
|
||||
library and every dependency from nothing on every build
|
||||
(https://git.eeqj.de/sneak/secret/issues/124). The `Dockerfile` runs it and
|
||||
`make build` with Go's build cache in a BuildKit cache mount, which docker
|
||||
keeps between builds, locally and on the Gitea runner alike, so each compiles
|
||||
only what changed since the last build. The mount has an id of its own, so
|
||||
other repositories' builds do not share it. `script/test` passes `-count=1`,
|
||||
so every test runs on every build and no result comes from Go's test cache. A
|
||||
build with an empty cache, such as the first after docker's build cache is
|
||||
cleared, compiles everything in `make test` as before.
|
||||
keeps between builds, so each compiles only what changed since the last build.
|
||||
The mount has an id of its own, so other repositories' builds do not share it.
|
||||
`script/test` passes `-count=1`, so every test runs on every build and no
|
||||
result comes from Go's test cache. A build with an empty cache, such as the
|
||||
first after docker's build cache is cleared, compiles everything in
|
||||
`make test` as before.
|
||||
- 2026-10-06: The tests run quickly with the race detector on
|
||||
(https://git.eeqj.de/sneak/secret/issues/120). Most of their time went to
|
||||
deriving keys from passphrases with scrypt, which is slow on purpose. The new
|
||||
|
||||
Reference in New Issue
Block a user