Fail a bare docker build instead of serving cached gates (closes #39) #93

Merged
clawbot merged 1 commits from issue-39-require-check-epoch into next 2026-10-04 19:30:21 +02:00
Collaborator

Each Dockerfile stage that runs gates (lint, markdown, build) now fails straight after its ARG CHECK_EPOCH when the value is empty, printing CHECK_EPOCH is unset; build via script/cibuild or script/docker. A plain docker build . therefore stops instead of serving the gates from cache.

script/cibuild and script/docker now pass "$(date +%s)-$$", the form script/lint already uses.

The README paragraph on CHECK_EPOCH describes both. In TODO.md, the entry for #32 now says thirteen steps stayed cached and names the lint stage's WORKDIR /src as the extra one. Prettier rewrapped that paragraph, so the diff there looks bigger than the change.

Things the diff does not show:

  • The prettier stage gets no check. script/fmt and script/fmt-check build it on its own with no epoch, and it runs no gates.
  • In a bare build the build stage's check is never reached, because that stage waits on lint and markdown, which fail first. Only those two were seen failing. The build stage keeps its own copy in case that wait is ever removed.

Disclosures:

  • Judgement call, epoch form: tightened to "$(date +%s)-$$" so all three scripts use the same form. %N was avoided because it is GNU-only.
  • Not done, outside this issue: Dockerfile.lint has the same gap for a bare docker build -f Dockerfile.lint ..

Model: opus-5-5

Each `Dockerfile` stage that runs gates (lint, markdown, build) now fails straight after its `ARG CHECK_EPOCH` when the value is empty, printing `CHECK_EPOCH is unset; build via script/cibuild or script/docker`. A plain `docker build .` therefore stops instead of serving the gates from cache. `script/cibuild` and `script/docker` now pass `"$(date +%s)-$$"`, the form `script/lint` already uses. The README paragraph on `CHECK_EPOCH` describes both. In `TODO.md`, the entry for https://git.eeqj.de/sneak/sfdupes/issues/32 now says thirteen steps stayed cached and names the lint stage's `WORKDIR /src` as the extra one. Prettier rewrapped that paragraph, so the diff there looks bigger than the change. Things the diff does not show: - The prettier stage gets no check. `script/fmt` and `script/fmt-check` build it on its own with no epoch, and it runs no gates. - In a bare build the build stage's check is never reached, because that stage waits on lint and markdown, which fail first. Only those two were seen failing. The build stage keeps its own copy in case that wait is ever removed. Disclosures: - Judgement call, epoch form: tightened to `"$(date +%s)-$$"` so all three scripts use the same form. `%N` was avoided because it is GNU-only. - Not done, outside this issue: `Dockerfile.lint` has the same gap for a bare `docker build -f Dockerfile.lint .`. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 18:59:38 +02:00
clawbot self-assigned this 2026-10-04 18:59:38 +02:00
clawbot added 1 commit 2026-10-04 18:59:38 +02:00
Each Dockerfile stage that runs gates now checks, right after its
ARG CHECK_EPOCH, that the value is not empty, and stops with a message
naming script/cibuild and script/docker. A plain `docker build .` can
no longer report a green from cached gate layers.

script/cibuild and script/docker now append the process id to the
epoch, the form script/lint already uses, so two runs started in the
same second still get different values.

README says both. TODO.md corrects the steady-state CACHED count
recorded for issue 32 from twelve to thirteen.

Model: opus-5-5
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot merged commit bebfac1dcb into next 2026-10-04 19:30:21 +02:00
clawbot deleted branch issue-39-require-check-epoch 2026-10-04 19:30:21 +02:00
Sign in to join this conversation.