#!/bin/sh # script/cibuild: run the CI build. The Gitea workflow runs this on # push. # # The Dockerfile runs the gates individually as build steps, not the # make check aggregate: the lint stage runs the gofmt check, # script/verify-lint-image-pin, golangci-lint config verify and # golangci-lint run; the markdown stage runs the prettier check; the # build stage, dropped to an unprivileged user, runs make test. None of # make lint, make fmt-check or make check appears, because each runs # docker, and docker cannot run inside a docker build. Nothing is # skipped by that — the linter, gofmt and prettier are invoked directly # in their stages, and the build stage's COPY --from lines make those # stages prerequisites, so BuildKit must finish them first. Between the # three stages everything make check would run has run, which is why a # successful build here implies the repo is green. # # That implication holds only because of CHECK_EPOCH. A COPY layer is # invalidated only by changed content, and a rebuild of an unchanged # checkout sends the same content, so without a fresh value here Docker # serves the gate layers from cache and the build reports a green it # never earned. Passing the current epoch invalidates the gate # layers on every run while leaving the pinned base images and # go mod download cached; see the Dockerfile for the placement. The # process id goes in with the epoch so that two runs started in the # same second still get different values, the same form script/lint # uses. set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" main() { cd "$ROOT" docker build --build-arg CHECK_EPOCH="$(date +%s)-$$" . } main "$@"