check / check (push) Waiting to run
The size tests skip a case whose secret needs more locked memory than the process can lock, found by locking a buffer of that size: memguard panics otherwise, and a plain `docker build .` runs under an 8 MiB RLIMIT_MEMLOCK. script/cibuild, or any process allowed to lock past the limit, runs every case. The build stage stamps the VERSION build argument, else `git describe --tags --always`, and fails when .git is present but yields no version. `make build` stamps `git describe` too instead of the fixed 0.1.0. .dockerignore keeps .git/config out; script/docker is now the canonical copy. Model: opus-5-5 Co-authored-by: clawbot <sneak+clawbot@sneak.cloud>
26 lines
492 B
Plaintext
26 lines
492 B
Plaintext
# .git is sent without its config. Without a VERSION build argument the
|
|
# stage that compiles runs `git describe --tags --always` on .git, which
|
|
# does not need .git/config; that file can hold a credential, such as a
|
|
# password in a remote URL or the token the CI checkout step stores there.
|
|
.git/config
|
|
|
|
# Build artifacts
|
|
secret
|
|
coverage.out
|
|
*.test
|
|
|
|
# IDE and editor files
|
|
.vscode
|
|
.idea
|
|
*.swp
|
|
*.swo
|
|
*~
|
|
|
|
# macOS
|
|
.DS_Store
|
|
|
|
# Claude files
|
|
.claude/
|
|
|
|
# Local settings
|
|
.claude/settings.local.json |