Run the checks again on every script/cibuild (closes #54) #92
@@ -6,6 +6,11 @@ WORKDIR /src
|
|||||||
COPY go.mod go.sum ./
|
COPY go.mod go.sum ./
|
||||||
RUN go mod download
|
RUN go mod download
|
||||||
|
|
||||||
|
# script/cibuild sets CHECK_EPOCH to the current time, so the RUN steps
|
||||||
|
# below run again on each build, an unchanged tree included, while the
|
||||||
|
# steps above stay cached. ARG is per stage: the build stage declares it too.
|
||||||
|
ARG CHECK_EPOCH
|
||||||
|
|
||||||
COPY . .
|
COPY . .
|
||||||
|
|
||||||
RUN make fmt-check
|
RUN make fmt-check
|
||||||
@@ -25,6 +30,9 @@ WORKDIR /build
|
|||||||
COPY go.mod go.sum ./
|
COPY go.mod go.sum ./
|
||||||
RUN go mod download
|
RUN go mod download
|
||||||
|
|
||||||
|
# As in the lint stage: the RUN steps below run again on each script/cibuild.
|
||||||
|
ARG CHECK_EPOCH
|
||||||
|
|
||||||
COPY . .
|
COPY . .
|
||||||
|
|
||||||
RUN make test
|
RUN make test
|
||||||
|
|||||||
@@ -523,7 +523,8 @@ them. We provide:
|
|||||||
- `script/docker` — build the Docker image tagged with the project name
|
- `script/docker` — build the Docker image tagged with the project name
|
||||||
- `script/cibuild` — CI entrypoint: `docker build --ulimit
|
- `script/cibuild` — CI entrypoint: `docker build --ulimit
|
||||||
memlock=-1:-1 .` (memguard needs mlock; the Dockerfile runs the
|
memlock=-1:-1 .` (memguard needs mlock; the Dockerfile runs the
|
||||||
checks)
|
checks), with a new `CHECK_EPOCH` build argument on every run so the
|
||||||
|
checks run again on an unchanged tree
|
||||||
- `script/precommit` — pre-commit checks: `go mod tidy` verification,
|
- `script/precommit` — pre-commit checks: `go mod tidy` verification,
|
||||||
then `script/check`
|
then `script/check`
|
||||||
- `script/install-precommit` — install the git pre-commit hook that
|
- `script/install-precommit` — install the git pre-commit hook that
|
||||||
|
|||||||
@@ -25,6 +25,14 @@ Bring the repo into policy compliance in one commit:
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-10-04: `script/cibuild` runs the checks again on an unchanged
|
||||||
|
tree (https://git.eeqj.de/sneak/secret/issues/54). It passes the
|
||||||
|
current time as the `CHECK_EPOCH` build argument, which both the lint
|
||||||
|
and the build stage of the `Dockerfile` declare after their module
|
||||||
|
download, so the `RUN` steps below the argument run again on each
|
||||||
|
build while the base images and module downloads stay cached. Before,
|
||||||
|
a second run on the same tree took every check from the build cache
|
||||||
|
and reported success having run nothing.
|
||||||
- 2026-10-04: A failed unlocker add no longer leaves a partial unlocker
|
- 2026-10-04: A failed unlocker add no longer leaves a partial unlocker
|
||||||
directory (https://git.eeqj.de/sneak/secret/issues/48).
|
directory (https://git.eeqj.de/sneak/secret/issues/48).
|
||||||
`secret unlocker add pgp` resolves the GPG key's fingerprint once, for
|
`secret unlocker add pgp` resolves the GPG key's fingerprint once, for
|
||||||
|
|||||||
+5
-1
@@ -4,13 +4,17 @@
|
|||||||
# The Gitea workflow runs this on push. The memlock ulimit lets the tests
|
# The Gitea workflow runs this on push. The memlock ulimit lets the tests
|
||||||
# that lock large secrets in memory (memguard mlocks them) run; under the
|
# that lock large secrets in memory (memguard mlocks them) run; under the
|
||||||
# lower limit of a plain `docker build .` they are skipped.
|
# lower limit of a plain `docker build .` they are skipped.
|
||||||
|
# A cached build checks nothing: a new CHECK_EPOCH on every run makes the
|
||||||
|
# Dockerfile's check steps run again on an unchanged tree, while its base
|
||||||
|
# images and module downloads stay cached.
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|
||||||
main() {
|
main() {
|
||||||
cd "$ROOT"
|
cd "$ROOT"
|
||||||
docker build --ulimit memlock=-1:-1 .
|
docker build --ulimit memlock=-1:-1 \
|
||||||
|
--build-arg CHECK_EPOCH="$(date +%s)" .
|
||||||
}
|
}
|
||||||
|
|
||||||
main "$@"
|
main "$@"
|
||||||
|
|||||||
Reference in New Issue
Block a user