check / check (push) Successful in 1m2s
The size tests skip a case whose secret needs more locked memory than the process can lock, found by locking a buffer of that size: memguard panics otherwise, and a plain `docker build .` runs under an 8 MiB RLIMIT_MEMLOCK. script/cibuild, or any process allowed to lock past the limit, runs every case. The build stage stamps the VERSION build argument, else `git describe --tags --always`, and fails when .git is present but yields no version. `make build` stamps `git describe` too instead of the fixed 0.1.0. .dockerignore keeps .git/config out; script/docker is now the canonical copy. Model: opus-5-5
17 lines
487 B
Bash
Executable File
17 lines
487 B
Bash
Executable File
#!/bin/sh
|
|
# script/cibuild: run the CI build. The Dockerfile runs script/check
|
|
# (via make check), so a successful build implies all checks pass.
|
|
# The Gitea workflow runs this on push. The memlock ulimit lets the tests
|
|
# that lock large secrets in memory (memguard mlocks them) run; under the
|
|
# lower limit of a plain `docker build .` they are skipped.
|
|
set -eu
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
|
|
|
main() {
|
|
cd "$ROOT"
|
|
docker build --ulimit memlock=-1:-1 .
|
|
}
|
|
|
|
main "$@"
|