Adds script/test-race and its make test-race shim, following the plan on #18. It runs go test -race -timeout 60s ./... with cgo on, in a digest-pinned golang:1.25-trixie image, with the checkout mounted read-only and the container removed on exit. It is not part of make check; the Makefile, the Dockerfile and the shipped binary keep CGO_ENABLED=0. README.md documents both entrypoints, and the accepted-divergence note in TODO.md now points at the new target.
What the diff does not show:
The image is Debian, not the Alpine one the Dockerfile builds with, because the Debian image ships gcc.
The tests run as the calling user, or as nobody (uid 65534) when that is root, because root reads the files the tests make unreadable. Only in that root case must the checkout be readable by other users.
Each run starts with empty module and build caches, so it downloads the dependencies and compiles them with the detector every time. It needs the network and takes a few minutes.
The detector found no races, so there are no code changes and no new issues.
Disclosures:
Judgement call: script/lint builds an image from a copy of the tree, but this script mounts the checkout as the plan says, so it needs a local docker daemon.
Judgement call: unlike script/test, there is no verbose rerun on failure; a race report names the failing test on its own.
Unverified: the root case was not re-run after the rework; it keeps the earlier behaviour unchanged.
Model: opus-5-5
Adds `script/test-race` and its `make test-race` shim, following the plan on https://git.eeqj.de/sneak/sfdupes/issues/18. It runs `go test -race -timeout 60s ./...` with cgo on, in a digest-pinned `golang:1.25-trixie` image, with the checkout mounted read-only and the container removed on exit. It is not part of `make check`; the `Makefile`, the `Dockerfile` and the shipped binary keep `CGO_ENABLED=0`. `README.md` documents both entrypoints, and the accepted-divergence note in `TODO.md` now points at the new target.
What the diff does not show:
- The image is Debian, not the Alpine one the `Dockerfile` builds with, because the Debian image ships `gcc`.
- The tests run as the calling user, or as `nobody` (uid 65534) when that is root, because root reads the files the tests make unreadable. Only in that root case must the checkout be readable by other users.
- Each run starts with empty module and build caches, so it downloads the dependencies and compiles them with the detector every time. It needs the network and takes a few minutes.
- The detector found no races, so there are no code changes and no new issues.
Disclosures:
- Judgement call: `script/lint` builds an image from a copy of the tree, but this script mounts the checkout as the plan says, so it needs a local docker daemon.
- Judgement call: unlike `script/test`, there is no verbose rerun on failure; a race report names the failing test on its own.
- Unverified: the root case was not re-run after the rework; it keeps the earlier behaviour unchanged.
Model: opus-5-5
README.md (the script/test-race entry) and the header comment of script/test-race: the tests run as nobody, so the target only works on a checkout that other users can read, and nothing in the tree says so (only the PR body does). On a checkout made under umask 077 it fails with a Go error saying /src contains no module, which points nowhere near the cause. Acceptable: state the requirement in both places, or remove it, for example by running as the invoking user when that user is not root.
The branch does not rebase cleanly onto next: its TODO.md Completed Steps entry conflicts with the one for #48. Acceptable: rebase with this entry at the top of the list.
Model: opus-5-5
1. `README.md` (the `script/test-race` entry) and the header comment of `script/test-race`: the tests run as `nobody`, so the target only works on a checkout that other users can read, and nothing in the tree says so (only the PR body does). On a checkout made under umask 077 it fails with a Go error saying `/src` contains no module, which points nowhere near the cause. Acceptable: state the requirement in both places, or remove it, for example by running as the invoking user when that user is not root.
2. The branch does not rebase cleanly onto `next`: its `TODO.md` Completed Steps entry conflicts with the one for https://git.eeqj.de/sneak/sfdupes/issues/48. Acceptable: rebase with this entry at the top of the list.
Model: opus-5-5
Requirement removed: script/test-race now runs the tests as the calling user, falling back to nobody only when the caller is root; the README.md entry and the script's header comment say so. Run on a fresh checkout made under umask 077, where the previous version fails as described.
Rebased onto current next with this entry at the top of Completed Steps; make fmt applied.
Model: opus-5-5
1. Requirement removed: `script/test-race` now runs the tests as the calling user, falling back to `nobody` only when the caller is root; the `README.md` entry and the script's header comment say so. Run on a fresh checkout made under umask 077, where the previous version fails as described.
2. Rebased onto current `next` with this entry at the top of Completed Steps; `make fmt` applied.
Model: opus-5-5
README.md line 745 (the script/bootstrap entry) and script/bootstrap (header comment at line 10, the comment at line 78, and the warning printed at lines 82-84) still say that everything except linting and formatting works without docker, and the warning lists make lint, make fmt, make fmt-check, make check and make docker as the targets that need it. make test-race now needs docker too, so the README sentence is no longer true and a user without docker is told the wrong set of targets. Acceptable: add make test-race to that list in the warning and both comments, and make the README sentence name it as well.
Model: opus-5-5
1. `README.md` line 745 (the `script/bootstrap` entry) and `script/bootstrap` (header comment at line 10, the comment at line 78, and the warning printed at lines 82-84) still say that everything except linting and formatting works without docker, and the warning lists `make lint`, `make fmt`, `make fmt-check`, `make check` and `make docker` as the targets that need it. `make test-race` now needs docker too, so the README sentence is no longer true and a user without docker is told the wrong set of targets. Acceptable: add `make test-race` to that list in the warning and both comments, and make the README sentence name it as well.
Model: opus-5-5
script/test-race runs go test -race in a digest-pinned Debian golang
image that has gcc, since the detector needs cgo and the build keeps it
off. The checkout is mounted read-only and the container is removed
afterwards. The tests run as the calling user, or as nobody when that is
root, so the tests that make a file unreadable still see the read fail.
It is not part of make check. The detector found no races.
Model: opus-5-5
make test-race is now named in the script/bootstrap warning, in both of its comments, and in the README.md sentence about what works without docker.
Rebased onto current next, with this entry still at the top of Completed Steps.
Model: opus-5-5
1. `make test-race` is now named in the `script/bootstrap` warning, in both of its comments, and in the `README.md` sentence about what works without docker.
Rebased onto current `next`, with this entry still at the top of Completed Steps.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Adds
script/test-raceand itsmake test-raceshim, following the plan on #18. It runsgo test -race -timeout 60s ./...with cgo on, in a digest-pinnedgolang:1.25-trixieimage, with the checkout mounted read-only and the container removed on exit. It is not part ofmake check; theMakefile, theDockerfileand the shipped binary keepCGO_ENABLED=0.README.mddocuments both entrypoints, and the accepted-divergence note inTODO.mdnow points at the new target.What the diff does not show:
Dockerfilebuilds with, because the Debian image shipsgcc.nobody(uid 65534) when that is root, because root reads the files the tests make unreadable. Only in that root case must the checkout be readable by other users.Disclosures:
script/lintbuilds an image from a copy of the tree, but this script mounts the checkout as the plan says, so it needs a local docker daemon.script/test, there is no verbose rerun on failure; a race report names the failing test on its own.Model: opus-5-5
README.md(thescript/test-raceentry) and the header comment ofscript/test-race: the tests run asnobody, so the target only works on a checkout that other users can read, and nothing in the tree says so (only the PR body does). On a checkout made under umask 077 it fails with a Go error saying/srccontains no module, which points nowhere near the cause. Acceptable: state the requirement in both places, or remove it, for example by running as the invoking user when that user is not root.The branch does not rebase cleanly onto
next: itsTODO.mdCompleted Steps entry conflicts with the one for #48. Acceptable: rebase with this entry at the top of the list.Model: opus-5-5
2439b00f44toa67a83fb42script/test-racenow runs the tests as the calling user, falling back tonobodyonly when the caller is root; theREADME.mdentry and the script's header comment say so. Run on a fresh checkout made under umask 077, where the previous version fails as described.nextwith this entry at the top of Completed Steps;make fmtapplied.Model: opus-5-5
README.mdline 745 (thescript/bootstrapentry) andscript/bootstrap(header comment at line 10, the comment at line 78, and the warning printed at lines 82-84) still say that everything except linting and formatting works without docker, and the warning listsmake lint,make fmt,make fmt-check,make checkandmake dockeras the targets that need it.make test-racenow needs docker too, so the README sentence is no longer true and a user without docker is told the wrong set of targets. Acceptable: addmake test-raceto that list in the warning and both comments, and make the README sentence name it as well.Model: opus-5-5
a67a83fb42toe4e297aa60make test-raceis now named in thescript/bootstrapwarning, in both of its comments, and in theREADME.mdsentence about what works without docker.Rebased onto current
next, with this entry still at the top of Completed Steps.Model: opus-5-5
Review passed.
Model: opus-5-5