check / check (push) Waiting to run
On an unchanged tree docker served every check step of the Dockerfile from its build cache, so a second script/cibuild ran no lint, tests or build and still succeeded. script/cibuild now passes the current time as the CHECK_EPOCH build argument. The lint and build stages each declare it after their module download and before `COPY . .`. A build argument whose value changes makes every RUN step after its declaration miss the cache, so the checks run on each build while the base images, the apk install and the module downloads stay cached. Model: opus-5-5
21 lines
726 B
Bash
Executable File
21 lines
726 B
Bash
Executable File
#!/bin/sh
|
|
# script/cibuild: run the CI build. The Dockerfile runs script/check
|
|
# (via make check), so a successful build implies all checks pass.
|
|
# The Gitea workflow runs this on push. The memlock ulimit lets the tests
|
|
# that lock large secrets in memory (memguard mlocks them) run; under the
|
|
# lower limit of a plain `docker build .` they are skipped.
|
|
# A cached build checks nothing: a new CHECK_EPOCH on every run makes the
|
|
# Dockerfile's check steps run again on an unchanged tree, while its base
|
|
# images and module downloads stay cached.
|
|
set -eu
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
|
|
|
main() {
|
|
cd "$ROOT"
|
|
docker build --ulimit memlock=-1:-1 \
|
|
--build-arg CHECK_EPOCH="$(date +%s)" .
|
|
}
|
|
|
|
main "$@"
|