Stop script/lint writing an image it never uses (closes #48) #91

Merged
clawbot merged 1 commits from issue-48-lint-no-image into next 2026-10-04 18:01:30 +02:00
Collaborator

script/lint now builds Dockerfile.lint with --output=type=cacheonly. The lint result is the build's exit status and nothing ever used the image, yet every run exported one and left it behind untagged. Now nothing is exported, and the only thing a run leaves behind is build cache.

Why cacheonly rather than a tag: a fixed tag would stop the untagged images piling up, but every run would still pay for the export, and there would be one more image name to look after. cacheonly removes both costs.

What a reader might trip over:

  • CHECK_EPOCH is unchanged and still makes the gate steps run on every invocation. The build cache is still written, so go mod download and the copy of the tree stay cached as before.
  • --output needs BuildKit, which docker build uses by default. With the legacy builder (DOCKER_BUILDKIT=0), script/lint fails at once with unknown flag: --output, so it can never report a lint pass it did not run.
  • script/docker and script/cibuild are untouched: script/docker needs its tagged image, and script/cibuild is outside this issue.

Deviation: the issue asks for before/after timings and the run-by-run proof to be reported. They went to the manager rather than here, under the rule against posting test results on the tracker.

Model: opus-5-5

`script/lint` now builds `Dockerfile.lint` with `--output=type=cacheonly`. The lint result is the build's exit status and nothing ever used the image, yet every run exported one and left it behind untagged. Now nothing is exported, and the only thing a run leaves behind is build cache. Why `cacheonly` rather than a tag: a fixed tag would stop the untagged images piling up, but every run would still pay for the export, and there would be one more image name to look after. `cacheonly` removes both costs. What a reader might trip over: - `CHECK_EPOCH` is unchanged and still makes the gate steps run on every invocation. The build cache is still written, so `go mod download` and the copy of the tree stay cached as before. - `--output` needs BuildKit, which `docker build` uses by default. With the legacy builder (`DOCKER_BUILDKIT=0`), `script/lint` fails at once with `unknown flag: --output`, so it can never report a lint pass it did not run. - `script/docker` and `script/cibuild` are untouched: `script/docker` needs its tagged image, and `script/cibuild` is outside this issue. Deviation: the issue asks for before/after timings and the run-by-run proof to be reported. They went to the manager rather than here, under the rule against posting test results on the tracker. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 17:08:31 +02:00
clawbot self-assigned this 2026-10-04 17:08:31 +02:00
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot added needs-rebase and removed needs-review labels 2026-10-04 17:47:36 +02:00
clawbot added 1 commit 2026-10-04 17:54:21 +02:00
script/lint builds Dockerfile.lint only for the exit status, but every
run exported the result as an image: seconds spent exporting, and one
untagged image left behind each time. It now builds with
--output=type=cacheonly, so nothing is exported. CHECK_EPOCH still
changes on every run, so the gate steps still run each time; the build
cache is kept as before.

Model: opus-5-5
clawbot force-pushed issue-48-lint-no-image from 7266f89551 to 60d7b97a8d 2026-10-04 17:54:21 +02:00 Compare
Author
Collaborator

Rebased onto next; only the TODO.md entry conflicted.

Model: opus-5-5

Rebased onto `next`; only the `TODO.md` entry conflicted. Model: opus-5-5
clawbot added needs-review and removed needs-rebase labels 2026-10-04 17:54:24 +02:00
clawbot merged commit 1317d66589 into next 2026-10-04 18:01:30 +02:00
clawbot deleted branch issue-48-lint-no-image 2026-10-04 18:01:30 +02:00
Sign in to join this conversation.