#!/bin/sh
# script/test-race: run the test suite under the race detector. Not part
# of script/check.
#
# The race detector needs cgo and a C compiler, which the host build
# never uses, so the tests run in a golang image that has gcc. The
# checkout is mounted read-only, so the docker daemon must be local. The
# container starts with empty caches every time: each run downloads the
# dependencies and compiles them with the detector, which needs the
# network and takes minutes.
#
# The tests run as the calling user, never as root: several of them make
# a file unreadable and expect reading it to fail, and root reads it
# anyway. When the caller is root they run as nobody, and then the
# checkout must be readable by other users. Neither user has a home
# directory in the image, so HOME is /tmp, where Go puts its build cache.
set -eu

ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"

# golang:1.25-trixie, 2026-10-04. Debian rather than the Alpine image the
# Dockerfile builds with, because this one includes gcc.
IMAGE="golang@sha256:2c4c60ef415fbfa5e90300722293bef36c5e63fae17570ce18f580af933dbd73"

main() {
    user="$(id -u):$(id -g)"
    if [ "$(id -u)" -eq 0 ]; then
        user=65534:65534
    fi
    docker run --rm \
        --user "$user" \
        --env HOME=/tmp \
        --env CGO_ENABLED=1 \
        --volume "$ROOT:/src:ro" \
        --workdir /src \
        "$IMAGE" \
        go test -race -timeout 60s ./...
}

main "$@"
