Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a64614f5ce |
+7
-14
@@ -50,26 +50,19 @@ ARG CHECK_EPOCH
|
|||||||
|
|
||||||
COPY . .
|
COPY . .
|
||||||
|
|
||||||
# Go's build cache is kept between builds in this cache mount, which make test
|
# Go's build cache is kept between builds in this cache mount, so make test
|
||||||
# and make build both use, so each compiles only what changed since the last
|
# compiles only what changed since the last build, not the standard library
|
||||||
# build, not the standard library and every dependency from nothing.
|
# and every dependency from nothing. script/test passes -count=1, so test
|
||||||
# script/test passes -count=1, so test results are never taken from it.
|
# results are never taken from it.
|
||||||
# The mount has its own id because the default id, its path, is shared with
|
RUN --mount=type=cache,target=/root/.cache/go-build make test
|
||||||
# other repositories' builds, and Go's cache does not notice changes to C
|
|
||||||
# libraries: an entry compiled there against other C headers could be reused
|
|
||||||
# here. It does not notice a change of this image's own C headers either.
|
|
||||||
RUN --mount=type=cache,id=sneak/secret/go-build,target=/root/.cache/go-build \
|
|
||||||
make test
|
|
||||||
|
|
||||||
# The version stamped into the binary: the VERSION build argument when one
|
# The version stamped into the binary: the VERSION build argument when one
|
||||||
# is given, otherwise `git describe --tags --always` of the .git the build
|
# is given, otherwise `git describe --tags --always` of the .git the build
|
||||||
# context carries: the tag on a tagged commit, tag-N-gHASH on a commit after
|
# context carries: the tag on a tagged commit, tag-N-gHASH on a commit after
|
||||||
# one, the short commit when no tag is reachable. A context that carries .git
|
# one, the short commit when no tag is reachable. A context that carries .git
|
||||||
# and still yields no version fails the build. make build uses the same Go
|
# and still yields no version fails the build.
|
||||||
# build cache mount as make test.
|
|
||||||
ARG VERSION
|
ARG VERSION
|
||||||
RUN --mount=type=cache,id=sneak/secret/go-build,target=/root/.cache/go-build \
|
RUN version="${VERSION:-$(git describe --tags --always)}"; \
|
||||||
version="${VERSION:-$(git describe --tags --always)}"; \
|
|
||||||
if [ -e .git ] && { [ -z "$version" ] || [ "$version" = dev ] || \
|
if [ -e .git ] && { [ -z "$version" ] || [ "$version" = dev ] || \
|
||||||
[ "$version" = unknown ]; }; then \
|
[ "$version" = unknown ]; }; then \
|
||||||
echo "no version could be derived although the build context carries .git" >&2; \
|
echo "no version could be derived although the build context carries .git" >&2; \
|
||||||
|
|||||||
@@ -626,7 +626,7 @@ provide:
|
|||||||
(memguard needs mlock; the Dockerfile runs the checks), with a new
|
(memguard needs mlock; the Dockerfile runs the checks), with a new
|
||||||
`CHECK_EPOCH` build argument on every run so the checks run again on an
|
`CHECK_EPOCH` build argument on every run so the checks run again on an
|
||||||
unchanged tree; the `Dockerfile` keeps Go's build cache between builds, so
|
unchanged tree; the `Dockerfile` keeps Go's build cache between builds, so
|
||||||
`make test` and `make build` compile only what changed
|
`make test` compiles only what changed
|
||||||
- `script/precommit` — pre-commit checks: `go mod tidy` verification, then
|
- `script/precommit` — pre-commit checks: `go mod tidy` verification, then
|
||||||
`script/check`
|
`script/check`
|
||||||
- `script/install-precommit` — install the git pre-commit hook that runs
|
- `script/install-precommit` — install the git pre-commit hook that runs
|
||||||
|
|||||||
@@ -20,14 +20,13 @@ https://git.eeqj.de/sneak/secret/milestone/12
|
|||||||
|
|
||||||
- 2026-10-06: `make test` in `script/cibuild` no longer compiles the standard
|
- 2026-10-06: `make test` in `script/cibuild` no longer compiles the standard
|
||||||
library and every dependency from nothing on every build
|
library and every dependency from nothing on every build
|
||||||
(https://git.eeqj.de/sneak/secret/issues/124). The `Dockerfile` runs it and
|
(https://git.eeqj.de/sneak/secret/issues/124). The `Dockerfile` runs it with
|
||||||
`make build` with Go's build cache in a BuildKit cache mount, which docker
|
Go's build cache in a BuildKit cache mount, which docker keeps between builds,
|
||||||
keeps between builds, locally and on the Gitea runner alike, so each compiles
|
locally and on the Gitea runner alike, so it compiles only what changed since
|
||||||
only what changed since the last build. The mount has an id of its own, so
|
the last build. `script/test` passes `-count=1`, so every test runs on every
|
||||||
other repositories' builds do not share it. `script/test` passes `-count=1`,
|
build and no result comes from Go's test cache. A build with an empty cache,
|
||||||
so every test runs on every build and no result comes from Go's test cache. A
|
such as the first after docker's build cache is cleared, compiles everything
|
||||||
build with an empty cache, such as the first after docker's build cache is
|
in `make test` as before.
|
||||||
cleared, compiles everything in `make test` as before.
|
|
||||||
- 2026-10-06: The tests run quickly with the race detector on
|
- 2026-10-06: The tests run quickly with the race detector on
|
||||||
(https://git.eeqj.de/sneak/secret/issues/120). Most of their time went to
|
(https://git.eeqj.de/sneak/secret/issues/120). Most of their time went to
|
||||||
deriving keys from passphrases with scrypt, which is slow on purpose. The new
|
deriving keys from passphrases with scrypt, which is slow on purpose. The new
|
||||||
|
|||||||
+2
-2
@@ -6,8 +6,8 @@
|
|||||||
# the lower limit of a plain `docker build .`.
|
# the lower limit of a plain `docker build .`.
|
||||||
# A cached build checks nothing: a new CHECK_EPOCH on every run makes the
|
# A cached build checks nothing: a new CHECK_EPOCH on every run makes the
|
||||||
# Dockerfile's check steps run again on an unchanged tree, while its base
|
# Dockerfile's check steps run again on an unchanged tree, while its base
|
||||||
# images, module downloads and the Go build cache that make test and make
|
# images, module downloads and the Go build cache that make test uses stay
|
||||||
# build use stay cached.
|
# cached.
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|||||||
Reference in New Issue
Block a user