#!/bin/sh # script/cibuild: run the CI build. The Dockerfile runs script/check # (via make check), so a successful build implies all checks pass. # The Gitea workflow runs this on push. The memlock ulimit lets the tests # that lock large secrets in memory (memguard mlocks them) run; under the # lower limit of a plain `docker build .` they are skipped. # A cached build checks nothing: a new CHECK_EPOCH on every run makes the # Dockerfile's check steps run again on an unchanged tree, while its base # images and module downloads stay cached. set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" main() { cd "$ROOT" docker build --ulimit memlock=-1:-1 \ --build-arg CHECK_EPOCH="$(date +%s)" . } main "$@"