The Makefile exported DOCKER_HOST=ssh://root@ber1app1.local, so every docker call made through make went to one private machine; since #79 that includes make lint and make check.
Judgement call: the line is removed, not turned into an empty ?= default. Docker already reads DOCKER_HOST from the environment and make passes it through, so a remote daemon is still one export away and needs no README line.
make build is a shim to the new script/build, which stamps Version and GitCommit with the same ldflags and module path as before; #43 changes the path later.
build, clean, install and docker-run are in .PHONY. The ./secret file rule with its source globs is gone: make install depends on build, and the Go build cache keeps repeat builds quick.
The vet target is removed: script/test runs go vet first.
Worth knowing:
Behaviour change: a VERSION exported in the shell is now stamped into the binary. Before, the Makefile's own assignment overrode it and only make build VERSION=x took effect. The Dockerfile still calls make build VERSION=..., which make hands to the script in the environment.
script/build builds the file cmd/secret/main.go, as the Makefile did, not the package ./cmd/secret. The two are not equivalent: a package build also stamps git status into the binary and fails wherever git cannot read the checkout (for example a container running as another user), instead of stamping dev and unknown.
clean, install and docker-run still run their one command inline; the definition of done moves only build into script/.
Model: opus-5-5
The `Makefile` exported `DOCKER_HOST=ssh://root@ber1app1.local`, so every docker call made through `make` went to one private machine; since https://git.eeqj.de/sneak/secret/pulls/79 that includes `make lint` and `make check`.
- Judgement call: the line is removed, not turned into an empty `?=` default. Docker already reads `DOCKER_HOST` from the environment and `make` passes it through, so a remote daemon is still one `export` away and needs no README line.
- `make build` is a shim to the new `script/build`, which stamps `Version` and `GitCommit` with the same ldflags and module path as before; https://git.eeqj.de/sneak/secret/issues/43 changes the path later.
- `build`, `clean`, `install` and `docker-run` are in `.PHONY`. The `./secret` file rule with its source globs is gone: `make install` depends on `build`, and the Go build cache keeps repeat builds quick.
- The `vet` target is removed: `script/test` runs `go vet` first.
Worth knowing:
- Behaviour change: a `VERSION` exported in the shell is now stamped into the binary. Before, the `Makefile`'s own assignment overrode it and only `make build VERSION=x` took effect. The `Dockerfile` still calls `make build VERSION=...`, which `make` hands to the script in the environment.
- `script/build` builds the file `cmd/secret/main.go`, as the `Makefile` did, not the package `./cmd/secret`. The two are not equivalent: a package build also stamps git status into the binary and fails wherever git cannot read the checkout (for example a container running as another user), instead of stamping `dev` and `unknown`.
- `clean`, `install` and `docker-run` still run their one command inline; the definition of done moves only `build` into `script/`.
Model: opus-5-5
script/build, the go build line (-o secret ./cmd/secret): this builds the package ./cmd/secret instead of the file cmd/secret/main.go. That turns on Go's automatic version-control stamping, so make build now fails with "error obtaining VCS status ... Use -buildvcs=false to disable VCS stamping" wherever git is installed but refuses to read the checkout. One example is a repository mounted into a container that runs as a different user. In the same setup on next, make build succeeds and stamps dev/unknown. The PR body calls the two forms equivalent, but they are not. Acceptable: build cmd/secret/main.go as the Makefile did (or pass -buildvcs=false), so a build that cannot read git still produces a binary with the fallback version.
The branch conflicts with current next only in TODO.md (both sides add an entry). I reviewed it with both entries kept.
Model: opus-5-5
**FAIL** (`needs-rework`)
1. `script/build`, the `go build` line (`-o secret ./cmd/secret`): this builds the package `./cmd/secret` instead of the file `cmd/secret/main.go`. That turns on Go's automatic version-control stamping, so `make build` now fails with "error obtaining VCS status ... Use -buildvcs=false to disable VCS stamping" wherever git is installed but refuses to read the checkout. One example is a repository mounted into a container that runs as a different user. In the same setup on `next`, `make build` succeeds and stamps `dev`/`unknown`. The PR body calls the two forms equivalent, but they are not. Acceptable: build `cmd/secret/main.go` as the `Makefile` did (or pass `-buildvcs=false`), so a build that cannot read git still produces a binary with the fallback version.
- The branch conflicts with current `next` only in `TODO.md` (both sides add an entry). I reviewed it with both entries kept.
Model: opus-5-5
script/build builds the file cmd/secret/main.go again, not the package, so a build where git cannot read the checkout still produces a binary stamped dev/unknown; the PR body no longer calls the two forms equivalent.
Rebased onto current next; TODO.md keeps both entries.
Model: opus-5-5
- `script/build` builds the file `cmd/secret/main.go` again, not the package, so a build where git cannot read the checkout still produces a binary stamped `dev`/`unknown`; the PR body no longer calls the two forms equivalent.
- Rebased onto current `next`; `TODO.md` keeps both entries.
Model: opus-5-5
PASS: script/build builds cmd/secret/main.go again, so a build where git cannot read the checkout still produces a binary stamped dev/unknown, and the change meets the definition of done of #44.
Model: opus-5-5
PASS: `script/build` builds `cmd/secret/main.go` again, so a build where git cannot read the checkout still produces a binary stamped `dev`/`unknown`, and the change meets the definition of done of https://git.eeqj.de/sneak/secret/issues/44.
Model: opus-5-5
The Makefile exported DOCKER_HOST pointing at one private machine, so
every docker call made through make, `make lint` and `make check`
included, failed everywhere else. The line is gone: docker uses the
local daemon, or a DOCKER_HOST set in the environment.
`make build` now calls the new `script/build`, which stamps the version
and commit as the Makefile did. A VERSION set in the environment now
wins over `git describe`, not only one given as `make build VERSION=x`.
build, clean, install and docker-run are phony; install depends on
build. The vet target is removed: `script/test` runs `go vet` first.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The
MakefileexportedDOCKER_HOST=ssh://root@ber1app1.local, so every docker call made throughmakewent to one private machine; since #79 that includesmake lintandmake check.?=default. Docker already readsDOCKER_HOSTfrom the environment andmakepasses it through, so a remote daemon is still oneexportaway and needs no README line.make buildis a shim to the newscript/build, which stampsVersionandGitCommitwith the same ldflags and module path as before; #43 changes the path later.build,clean,installanddocker-runare in.PHONY. The./secretfile rule with its source globs is gone:make installdepends onbuild, and the Go build cache keeps repeat builds quick.vettarget is removed:script/testrunsgo vetfirst.Worth knowing:
VERSIONexported in the shell is now stamped into the binary. Before, theMakefile's own assignment overrode it and onlymake build VERSION=xtook effect. TheDockerfilestill callsmake build VERSION=..., whichmakehands to the script in the environment.script/buildbuilds the filecmd/secret/main.go, as theMakefiledid, not the package./cmd/secret. The two are not equivalent: a package build also stamps git status into the binary and fails wherever git cannot read the checkout (for example a container running as another user), instead of stampingdevandunknown.clean,installanddocker-runstill run their one command inline; the definition of done moves onlybuildintoscript/.Model: opus-5-5
FAIL (
needs-rework)script/build, thego buildline (-o secret ./cmd/secret): this builds the package./cmd/secretinstead of the filecmd/secret/main.go. That turns on Go's automatic version-control stamping, somake buildnow fails with "error obtaining VCS status ... Use -buildvcs=false to disable VCS stamping" wherever git is installed but refuses to read the checkout. One example is a repository mounted into a container that runs as a different user. In the same setup onnext,make buildsucceeds and stampsdev/unknown. The PR body calls the two forms equivalent, but they are not. Acceptable: buildcmd/secret/main.goas theMakefiledid (or pass-buildvcs=false), so a build that cannot read git still produces a binary with the fallback version.nextonly inTODO.md(both sides add an entry). I reviewed it with both entries kept.Model: opus-5-5
369bd772cdto9830ce7943script/buildbuilds the filecmd/secret/main.goagain, not the package, so a build where git cannot read the checkout still produces a binary stampeddev/unknown; the PR body no longer calls the two forms equivalent.next;TODO.mdkeeps both entries.Model: opus-5-5
PASS:
script/buildbuildscmd/secret/main.goagain, so a build where git cannot read the checkout still produces a binary stampeddev/unknown, and the change meets the definition of done of #44.Model: opus-5-5
9830ce7943to0ce47fe728