Re-vendor the canonical files from sneak/prompts at dd4027b (closes #95)
check / check (push) Waiting to run
check / check (push) Waiting to run
The shared files are the copies at sneak/prompts commit dd4027b, with this repository's own entries kept after them. script/lint, script/test and REPO_POLICIES.md come from its next at c55a0cb, so the lint and test builds write no image. golangci-lint is v2.14.0 and raises no findings. Lint and test are phases of the Dockerfile; the tests run under the race detector as nobody, so Dockerfile.lint, script/verify-lint-image-pin and make test-race are gone. Every docker build in script/ passes --no-cache. Formatting runs on the host: script/bootstrap installs the pinned node and yarn, and the prettier and markdown stages are gone. .claude/settings.json is deleted. Deviation: the workflow keeps fetch-depth: 0. Deviation: .gitignore keeps the scan database patterns. Over the cap: make test takes 82 to 100 seconds on this host. Model: opus-5-5
This commit is contained in:
@@ -29,6 +29,17 @@
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- re-vendor the canonical files from `sneak/prompts` commit `dd4027b`, with
|
||||
`script/lint`, `script/test` and `REPO_POLICIES.md` from its `next` at
|
||||
`c55a0cb`: golangci-lint v2.14.0; lint and test are phases of the `Dockerfile`
|
||||
that write no image, and `make test` runs the suite under the race detector,
|
||||
so `Dockerfile.lint`, `script/verify-lint-image-pin` and `make test-race` are
|
||||
gone; every `docker build` in `script/` passes `--no-cache`; prettier runs on
|
||||
the host, from the node and yarn `script/bootstrap` installs, so the
|
||||
`prettier` and `markdown` stages are gone and the build stage installs `git`
|
||||
and `make` itself; `.claude/settings.json` is deleted (2026-10-08,
|
||||
https://git.eeqj.de/sneak/sfdupes/issues/95)
|
||||
|
||||
- cut the narration from `TODO.md` Completed Steps and from the comments in
|
||||
`script/` and both Dockerfiles; §Workflow now branches from and merges to
|
||||
`next` (2026-10-04, https://git.eeqj.de/sneak/sfdupes/issues/49)
|
||||
@@ -37,12 +48,15 @@
|
||||
container, outside `make check` (2026-10-04,
|
||||
https://git.eeqj.de/sneak/sfdupes/issues/18)
|
||||
|
||||
- a bare `docker build .` fails with a message naming `script/cibuild` and
|
||||
`script/docker` instead of serving the gates from cache (2026-10-04,
|
||||
https://git.eeqj.de/sneak/sfdupes/issues/39)
|
||||
- a bare `docker build .` failed, naming `script/cibuild` and `script/docker`,
|
||||
rather than serve the gates from cache (2026-10-04,
|
||||
https://git.eeqj.de/sneak/sfdupes/issues/39). Since
|
||||
https://git.eeqj.de/sneak/sfdupes/issues/95 a bare build succeeds, as
|
||||
`REPO_POLICIES.md` requires, and may serve the gates from cache; the builds in
|
||||
`script/` pass `--no-cache`, so theirs always run
|
||||
|
||||
- `make fmt` and `make fmt-check` run prettier over all Markdown, in Docker, and
|
||||
CI checks it; all Markdown reformatted (2026-10-04,
|
||||
- `make fmt` and `make fmt-check` run prettier over all Markdown, and CI checks
|
||||
it; all Markdown reformatted (2026-10-04,
|
||||
https://git.eeqj.de/sneak/sfdupes/issues/19)
|
||||
|
||||
- `script/lint` writes no image, so a run no longer leaves an untagged one
|
||||
@@ -167,32 +181,28 @@
|
||||
`ENV PATH=/home/builder/go/bin:$PATH` went with its `go install`.
|
||||
`script/verify-linter-pin` is retired; `script/verify-lint-image-pin`, a gate
|
||||
in both files, compares their two `FROM` lines and restates neither pin.
|
||||
Traps: an unchanged tree lets a lint build pass in under a second having run
|
||||
no linter, so every gate `RUN` references `ARG CHECK_EPOCH` (BuildKit hashes
|
||||
the expanded command) and `script/lint` passes `"$(date +%s)-$$"`, the PID
|
||||
because two runs land in the same second easily. Nothing inside an image build
|
||||
may shell out to docker, so the `Dockerfile` lint stage calls `golangci-lint`
|
||||
directly and the build stage runs `make test` and `make fmt-check` instead of
|
||||
`make check`, through `make` because the Makefile's `export CGO_ENABLED = 0`
|
||||
only reaches what it invokes. `COPY --from=lint /src/go.sum /dev/null`
|
||||
replaces the copied linter binary as the only edge making the build stage wait
|
||||
for lint; dropping it would end fail-fast linting under a still-green build.
|
||||
`golangci-lint config verify`, included per the ruling, validates from an
|
||||
embedded schema with no network call, but `go mod download` above the gates
|
||||
still needs the network on a cold cache. Verified: `make lint` green with no
|
||||
`golangci-lint` on `PATH`; two back-to-back `script/lint` runs on an untouched
|
||||
tree both ran the linter (27.7s and 28.7s in the lint step, `COPY . .`
|
||||
`CACHED` above); a planted unused variable failed `script/lint`, and failed
|
||||
`make docker` at `[lint 9/9]` with the build stage stopped at
|
||||
`[builder 3/12]`; the drift guard fails on a tag-only, a digest-only and an
|
||||
unreadable reference, naming both sides; under `--network none` config verify
|
||||
passes a valid config and rejects an invalid one; `make docker` green in 5m35s
|
||||
with all six gates run under one epoch (lint 37.6s, test 25.2s reporting
|
||||
`ok sneak.berlin/go/sfdupes 1.938s coverage: 88.5%`, not `(cached)`); in the
|
||||
builder image with the Go test cache off, `--user 0:0` still fails
|
||||
`TestScanHardlinkRunFailsTogether` where the unprivileged user passes. Noted
|
||||
for follow-up, not fixed here: `golangci-lint` warns that `gomodguard` is
|
||||
deprecated since v2.12.0 in favour of `gomodguard_v2`.
|
||||
Traps: nothing inside an image build may shell out to docker, so the
|
||||
`Dockerfile` lint stage calls `golangci-lint` directly and the build stage
|
||||
runs `make test` and `make fmt-check` instead of `make check`, through `make`
|
||||
because the Makefile's `export CGO_ENABLED = 0` only reaches what it invokes.
|
||||
`COPY --from=lint /src/go.sum /dev/null` replaces the copied linter binary as
|
||||
the only edge making the build stage wait for lint; dropping it would end
|
||||
fail-fast linting under a still-green build. `golangci-lint config verify`,
|
||||
included per the ruling, validates from an embedded schema with no network
|
||||
call, but `go mod download` above the gates still needs the network on a cold
|
||||
cache. Verified: `make lint` green with no `golangci-lint` on `PATH`; two
|
||||
back-to-back `script/lint` runs on an untouched tree both ran the linter
|
||||
(27.7s and 28.7s in the lint step, `COPY . .` `CACHED` above); a planted
|
||||
unused variable failed `script/lint`, and failed `make docker` at `[lint 9/9]`
|
||||
with the build stage stopped at `[builder 3/12]`; the drift guard fails on a
|
||||
tag-only, a digest-only and an unreadable reference, naming both sides; under
|
||||
`--network none` config verify passes a valid config and rejects an invalid
|
||||
one; `make docker` green in 5m35s with all six gates run (lint 37.6s, test
|
||||
25.2s reporting `ok sneak.berlin/go/sfdupes 1.938s coverage: 88.5%`, not
|
||||
`(cached)`); in the builder image with the Go test cache off, `--user 0:0`
|
||||
still fails `TestScanHardlinkRunFailsTogether` where the unprivileged user
|
||||
passes. Noted for follow-up, not fixed here: `golangci-lint` warns that
|
||||
`gomodguard` is deprecated since v2.12.0 in favour of `gomodguard_v2`.
|
||||
|
||||
- install the Docker build stage's prerequisites by running `script/bootstrap`
|
||||
instead of `apk add --no-cache make` inline (2026-08-09, branch
|
||||
@@ -205,43 +215,32 @@
|
||||
`script/verify-linter-pin`, run in the build stage before bootstrap, fails the
|
||||
build naming both versions unless that copied binary is the version
|
||||
`script/bootstrap` pins; a pin it cannot read is a hard failure, not a skip.
|
||||
`$GOPATH/bin` joins `PATH`, where bootstrap's `go install` lands. Everything
|
||||
added sits above `ARG CHECK_EPOCH`, and the `chown` and `USER builder` still
|
||||
precede `make check`. Verified: the guard fails the build with both versions
|
||||
named when the lint stage's linter is faked to another version, and passes an
|
||||
unmodified build; bootstrap runs clean under Alpine's `sh` and `apk`, finding
|
||||
the copied linter already at the pin; a second build served the bootstrap and
|
||||
dependency layers `CACHED` while both gates ran with a fresh epoch; a planted
|
||||
`unused` finding failed the build at the lint gate in 48.9s with the build
|
||||
stage's `make check` never starting; and the suite run in the image as
|
||||
`--user 0:0` fails `TestScanHardlinkRunFailsTogether`, so the drop to the
|
||||
unprivileged user is still needed. That last check needs the Go test cache
|
||||
off: as root it first reported `ok ... (cached)`, reusing the build-time
|
||||
result. Build times on a noisy shared host: 2m13s on an unchanged tree, 2m17s
|
||||
and 4m29s after a source change, 5m14s cold, which breaches the policy
|
||||
ceiling; `chown -R builder:builder /src /home/builder` walks the module cache
|
||||
and alone varied from 77s to 210s across those builds, and `main` measured
|
||||
5m03s cold with a 209s `chown`. Filed as
|
||||
`$GOPATH/bin` joins `PATH`, where bootstrap's `go install` lands. The `chown`
|
||||
and `USER builder` still precede `make check`. Verified: the guard fails the
|
||||
build with both versions named when the lint stage's linter is faked to
|
||||
another version, and passes an unmodified build; bootstrap runs clean under
|
||||
Alpine's `sh` and `apk`, finding the copied linter already at the pin; a
|
||||
second build served the bootstrap and dependency layers `CACHED` while both
|
||||
gates ran; a planted `unused` finding failed the build at the lint gate in
|
||||
48.9s with the build stage's `make check` never starting; and the suite run in
|
||||
the image as `--user 0:0` fails `TestScanHardlinkRunFailsTogether`, so the
|
||||
drop to the unprivileged user is still needed. That last check needs the Go
|
||||
test cache off: as root it first reported `ok ... (cached)`, reusing the
|
||||
build-time result. Build times on a noisy shared host: 2m13s on an unchanged
|
||||
tree, 2m17s and 4m29s after a source change, 5m14s cold, which breaches the
|
||||
policy ceiling; `chown -R builder:builder /src /home/builder` walks the module
|
||||
cache and alone varied from 77s to 210s across those builds, and `main`
|
||||
measured 5m03s cold with a 209s `chown`. Filed as
|
||||
https://git.eeqj.de/sneak/sfdupes/issues/43
|
||||
- bust the Docker layer cache for the gate steps, so `script/cibuild` and
|
||||
`script/docker` cannot report a green they did not earn (2026-08-09, branch
|
||||
`cibuild-cache-bust`, closes https://git.eeqj.de/sneak/sfdupes/issues/32): the
|
||||
`Dockerfile` copies the tree before its gates, so on an unchanged tree Docker
|
||||
served them from cache and the build exited 0 having run nothing. Both scripts
|
||||
now pass `--build-arg CHECK_EPOCH="$(date +%s)"`. `ARG` is per stage and the
|
||||
gates span two stages, so it is declared in both; BuildKit hashes the expanded
|
||||
command, so each gate `RUN` echoes the epoch, which also logs it as evidence
|
||||
the layer ran. It sits below the dependency layers so they stay cached.
|
||||
Verified under `BUILDKIT_PROGRESS=plain`, each script run twice back to back
|
||||
on an unchanged tree: all three gates ran on all four runs with a fresh epoch
|
||||
(`script/cibuild` 78.8s then 61.1s; `script/docker` 61.1s then 53.4s), and
|
||||
thirteen steps were still served `CACHED`. With a planted `unused` finding the
|
||||
build failed at `make lint` in 36.1s and the build-stage `make check` never
|
||||
started. Run as root, the same image fails `TestScanHardlinkRunFailsTogether`,
|
||||
because root reads through the `chmod(0)` the test relies on, so the build
|
||||
stage must drop to the unprivileged `builder` user. Local fix only;
|
||||
propagating it to the canonical templates is
|
||||
https://git.eeqj.de/sneak/prompts/issues/26
|
||||
served them from cache and the build exited 0 having run nothing. Every
|
||||
`docker build` in `script/` now passes `--no-cache` instead
|
||||
(https://git.eeqj.de/sneak/sfdupes/issues/95). Run as root, the tests fail
|
||||
`TestScanHardlinkRunFailsTogether`, because root reads through the `chmod(0)`
|
||||
the test relies on, so they run as an unprivileged user
|
||||
- check the installed golangci-lint version in `script/bootstrap` instead of
|
||||
only its presence (2026-08-09, branch `bootstrap-version-check`, closes
|
||||
https://git.eeqj.de/sneak/sfdupes/issues/24): the version lives only in
|
||||
@@ -397,6 +396,3 @@ Accepted divergences (no action):
|
||||
|
||||
- flat single-package layout with `.go` files in the repo root — fine for a
|
||||
small single-binary tool per the Go styleguide; the tracker audit agrees
|
||||
- `make test` runs without `-race` — the repo mandates `CGO_ENABLED=0` (pure-Go
|
||||
builds) and the race detector requires cgo, so the detector runs in a separate
|
||||
cgo-enabled container, `make test-race`, which is not part of `make check`
|
||||
|
||||
Reference in New Issue
Block a user