#!/bin/sh
# script/test-race: run the test suite under the race detector. Not part
# of script/check.
#
# The race detector needs cgo and a C compiler, which the host build
# never uses, so the tests run in a golang image that has gcc. The
# checkout is mounted read-only, so the docker daemon must be local. The
# container starts with empty caches every time: each run downloads the
# dependencies and compiles them with the detector, which needs the
# network and takes minutes.
#
# The tests run as nobody, not root: several of them make a file
# unreadable and expect reading it to fail, and root reads it anyway.
# nobody has no home directory, so HOME is /tmp, where Go puts its build
# cache.
set -eu

ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"

# golang:1.25-trixie, 2026-10-04. Debian rather than the Alpine image the
# Dockerfile builds with, because this one includes gcc.
IMAGE="golang@sha256:2c4c60ef415fbfa5e90300722293bef36c5e63fae17570ce18f580af933dbd73"

main() {
    docker run --rm \
        --user 65534:65534 \
        --env HOME=/tmp \
        --env CGO_ENABLED=1 \
        --volume "$ROOT:/src:ro" \
        --workdir /src \
        "$IMAGE" \
        go test -race -timeout 60s ./...
}

main "$@"
