Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
e9544679d0 |
@@ -6,6 +6,11 @@ WORKDIR /src
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
# script/cibuild sets CHECK_EPOCH to the current time, so the RUN steps
|
||||
# below run again on each build, an unchanged tree included, while the
|
||||
# steps above stay cached. ARG is per stage: the build stage declares it too.
|
||||
ARG CHECK_EPOCH
|
||||
|
||||
COPY . .
|
||||
|
||||
RUN make fmt-check
|
||||
@@ -25,6 +30,9 @@ WORKDIR /build
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
# As in the lint stage: the RUN steps below run again on each script/cibuild.
|
||||
ARG CHECK_EPOCH
|
||||
|
||||
COPY . .
|
||||
|
||||
RUN make test
|
||||
|
||||
@@ -523,7 +523,8 @@ them. We provide:
|
||||
- `script/docker` — build the Docker image tagged with the project name
|
||||
- `script/cibuild` — CI entrypoint: `docker build --ulimit
|
||||
memlock=-1:-1 .` (memguard needs mlock; the Dockerfile runs the
|
||||
checks)
|
||||
checks), with a new `CHECK_EPOCH` build argument on every run so the
|
||||
checks run again on an unchanged tree
|
||||
- `script/precommit` — pre-commit checks: `go mod tidy` verification,
|
||||
then `script/check`
|
||||
- `script/install-precommit` — install the git pre-commit hook that
|
||||
|
||||
@@ -25,6 +25,14 @@ Bring the repo into policy compliance in one commit:
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: `script/cibuild` runs the checks again on an unchanged
|
||||
tree (https://git.eeqj.de/sneak/secret/issues/54). It passes the
|
||||
current time as the `CHECK_EPOCH` build argument, which both the lint
|
||||
and the build stage of the `Dockerfile` declare after their module
|
||||
download, so the `RUN` steps below the argument run again on each
|
||||
build while the base images and module downloads stay cached. Before,
|
||||
a second run on the same tree took every check from the build cache
|
||||
and reported success having run nothing.
|
||||
- 2026-10-04: A failed unlocker add no longer leaves a partial unlocker
|
||||
directory (https://git.eeqj.de/sneak/secret/issues/48).
|
||||
`secret unlocker add pgp` resolves the GPG key's fingerprint once, for
|
||||
|
||||
+5
-1
@@ -4,13 +4,17 @@
|
||||
# The Gitea workflow runs this on push. The memlock ulimit lets the tests
|
||||
# that lock large secrets in memory (memguard mlocks them) run; under the
|
||||
# lower limit of a plain `docker build .` they are skipped.
|
||||
# A cached build checks nothing: a new CHECK_EPOCH on every run makes the
|
||||
# Dockerfile's check steps run again on an unchanged tree, while its base
|
||||
# images and module downloads stay cached.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
docker build --ulimit memlock=-1:-1 .
|
||||
docker build --ulimit memlock=-1:-1 \
|
||||
--build-arg CHECK_EPOCH="$(date +%s)" .
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
Reference in New Issue
Block a user