Since #128, script/test builds the test phase of the Dockerfile with --no-cache, as REPO_POLICIES.md requires. On this host --no-cache also starts Go's build cache mount empty, so every make test compiles the standard library and every dependency with -race before any test runs; that is about 40 s of a run. make test takes 51 to 60 s here, and about 90 s when the host is loaded: over the policy's 20-second target, and over its 60-second cap under load.
Definition of done
make test with -race takes under 20 seconds in script/cibuild on this host, measured twice, within what sneak rules may be cached (question on #128).
Model: opus-5-5
Since https://git.eeqj.de/sneak/secret/pulls/128, `script/test` builds the test phase of the `Dockerfile` with `--no-cache`, as `REPO_POLICIES.md` requires. On this host `--no-cache` also starts Go's build cache mount empty, so every `make test` compiles the standard library and every dependency with `-race` before any test runs; that is about 40 s of a run. `make test` takes 51 to 60 s here, and about 90 s when the host is loaded: over the policy's 20-second target, and over its 60-second cap under load.
## Definition of done
- `make test` with `-race` takes under 20 seconds in `script/cibuild` on this host, measured twice, within what sneak rules may be cached (question on https://git.eeqj.de/sneak/secret/pulls/128).
Model: opus-5-5
Question for sneak: the policy at sneak/promptsdd4027b, now vendored here (#128), requires --no-cache on every build in script/ and caps make test at 60 s. On this host --no-cache also empties Go's build cache mount, so each make test compiles the standard library and every dependency with -race first: 51 to 60 s quiet, about 90 s loaded, against the 20-second target. Before this, with the cache mount kept, it was about 20 s. This will hit every Go repository that runs -race.
Options:
Let check builds keep Go's build cache mount (recommended): script/test and script/lint rebuild every layer without --no-cache emptying the mount, for example by busting the layer cache with a build argument as CHECK_EPOCH did. -count=1 keeps test results from being reused. Needs a change to REPO_POLICIES.md in sneak/prompts, then a re-vendor here.
Rebuild only the test stage (--no-cache-filter=test) on top of a cached stage that compiles the dependencies; a departure from the policy's --no-cache for this repository only. Unverified whether that keeps the mount.
Keep the policy as written and accept make test over the target, and over the cap under load.
Model: opus-5-5
**Question for sneak:** the policy at `sneak/prompts` `dd4027b`, now vendored here (https://git.eeqj.de/sneak/secret/pulls/128), requires `--no-cache` on every build in `script/` and caps `make test` at 60 s. On this host `--no-cache` also empties Go's build cache mount, so each `make test` compiles the standard library and every dependency with `-race` first: 51 to 60 s quiet, about 90 s loaded, against the 20-second target. Before this, with the cache mount kept, it was about 20 s. This will hit every Go repository that runs `-race`.
Options:
1. Let check builds keep Go's build cache mount (recommended): `script/test` and `script/lint` rebuild every layer without `--no-cache` emptying the mount, for example by busting the layer cache with a build argument as `CHECK_EPOCH` did. `-count=1` keeps test results from being reused. Needs a change to `REPO_POLICIES.md` in `sneak/prompts`, then a re-vendor here.
2. Rebuild only the test stage (`--no-cache-filter=test`) on top of a cached stage that compiles the dependencies; a departure from the policy's `--no-cache` for this repository only. Unverified whether that keeps the mount.
3. Keep the policy as written and accept `make test` over the target, and over the cap under load.
Model: opus-5-5
sneak
was assigned by clawbot2026-10-07 05:43:13 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Since #128,
script/testbuilds the test phase of theDockerfilewith--no-cache, asREPO_POLICIES.mdrequires. On this host--no-cachealso starts Go's build cache mount empty, so everymake testcompiles the standard library and every dependency with-racebefore any test runs; that is about 40 s of a run.make testtakes 51 to 60 s here, and about 90 s when the host is loaded: over the policy's 20-second target, and over its 60-second cap under load.Definition of done
make testwith-racetakes under 20 seconds inscript/cibuildon this host, measured twice, within what sneak rules may be cached (question on #128).Model: opus-5-5
Question for sneak: the policy at
sneak/promptsdd4027b, now vendored here (#128), requires--no-cacheon every build inscript/and capsmake testat 60 s. On this host--no-cachealso empties Go's build cache mount, so eachmake testcompiles the standard library and every dependency with-racefirst: 51 to 60 s quiet, about 90 s loaded, against the 20-second target. Before this, with the cache mount kept, it was about 20 s. This will hit every Go repository that runs-race.Options:
script/testandscript/lintrebuild every layer without--no-cacheemptying the mount, for example by busting the layer cache with a build argument asCHECK_EPOCHdid.-count=1keeps test results from being reused. Needs a change toREPO_POLICIES.mdinsneak/prompts, then a re-vendor here.--no-cache-filter=test) on top of a cached stage that compiles the dependencies; a departure from the policy's--no-cachefor this repository only. Unverified whether that keeps the mount.make testover the target, and over the cap under load.Model: opus-5-5