Compare commits

..
1 Commits
Author SHA1 Message Date
clawbot 877eb2f755 Stamp the tag or short commit in a plain docker build (closes #211)
check / check (pull_request) Successful in 3m54s
A plain `docker build .` stamped `dev`: `.dockerignore` left out `.git`
and the Dockerfile defaulted VERSION to `dev`. `.dockerignore` is now
the canonical one plus this repo's entries, sending `.git` without
`.git/config`. Given no build arguments, the builder stamps `git
describe --tags --always` and the commit and date from git, and fails
if `.git` is present but yields no version. The empty CHECK_EPOCH
refusal is gone so the plain build succeeds; the scripts still pass an
epoch. `script/version` now prints `git describe --tags --always
--dirty`, so make, the scripts and a plain build agree.

Model: opus-5-5
2026-10-02 05:21:11 +00:00
4 changed files with 15 additions and 32 deletions
+5 -7
View File
@@ -906,13 +906,11 @@ git metadata reports `dev`.
`v`, so the tag `v1.0.0` produces `vaultik 1.0.0`, matching the archive `v`, so the tag `v1.0.0` produces `vaultik 1.0.0`, matching the archive
name `vaultik_1.0.0_linux_amd64.tar.gz`. `goreleaser --snapshot` stamps name `vaultik_1.0.0_linux_amd64.tar.gz`. `goreleaser --snapshot` stamps
`dev-<12 chars of the commit sha>` rather than inventing the next patch `dev-<12 chars of the commit sha>` rather than inventing the next patch
number. `vaultik version` calls a build a development build when its number. `vaultik version` calls `dev` and `dev-<sha>` development
version is `dev`, `dev-<sha>`, the short commit sha or builds. If `script/version` cannot be run at all, `make` stops with an
`<tag>-<N>-g<short sha>`, with or without `-dirty`; only a plain tag, error instead of building an unversioned binary, and a binary that
such as `v1.0.0` or `1.0.0`, is a release. If `script/version` cannot somehow carries an empty version string still reports itself as a
be run at all, `make` stops with an error instead of building an development build.
unversioned binary, and a binary that somehow carries an empty version
string still reports itself as a development build.
### cutting a release ### cutting a release
+5 -11
View File
@@ -3,7 +3,6 @@
package globals package globals
import ( import (
"regexp"
"strings" "strings"
"time" "time"
) )
@@ -60,11 +59,10 @@ func New() (*Globals, error) {
} }
// IsDevVersion reports whether v names a development build rather than // IsDevVersion reports whether v names a development build rather than
// a release. "dev" and goreleaser's snapshot "dev-<sha>" count, and so // a release. Both "dev" and goreleaser's snapshot "dev-<sha>" count. A
// does what `git describe --tags --always --dirty` gives a make or // make or docker build of an untagged commit reports `git describe`
// docker build of an untagged commit: the bare short commit, or // output instead (the short commit, or tag-N-gHASH), which this does
// tag-N-gHASH on a commit after a tag, either with or without "-dirty". // not recognise.
// A plain tag such as "v1.0.0" or "1.0.0" is a release.
// //
// The empty string counts too. Nothing that knows its version reports // The empty string counts too. Nothing that knows its version reports
// no version, so an empty Version means the stamping failed, and the // no version, so an empty Version means the stamping failed, and the
@@ -73,11 +71,7 @@ func New() (*Globals, error) {
// case; this is the second line of defence, for a binary linked by // case; this is the second line of defence, for a binary linked by
// something other than the Makefile. // something other than the Makefile.
func IsDevVersion(v string) bool { func IsDevVersion(v string) bool {
if v == "" || v == DevVersion || strings.HasPrefix(v, DevVersion+"-") { return v == "" || v == DevVersion || strings.HasPrefix(v, DevVersion+"-")
return true
}
return regexp.MustCompile(`^(.+-[0-9]+-g)?[0-9a-f]+(-dirty)?$`).MatchString(v)
} }
// shortCommitLen is the number of commit-hash characters ShortCommit keeps. // shortCommitLen is the number of commit-hash characters ShortCommit keeps.
+4 -12
View File
@@ -34,11 +34,10 @@ func TestGlobalsNew(t *testing.T) {
} }
// TestIsDevVersion covers the boundary that matters: everything // TestIsDevVersion covers the boundary that matters: everything
// script/version, a plain docker build and goreleaser's snapshot // goreleaser's snapshot template, and script/version outside a git
// template can emit for an untagged build must be recognised as a // checkout, can emit must be recognised as a development build, and a
// development build, and a real tag must not be. A plain equality check // real tag must not be. A plain equality check against "dev" used to decide
// against "dev" used to decide this, which classified every // this, which classified every commit-stamped dev build as a release.
// commit-stamped dev build as a release.
func TestIsDevVersion(t *testing.T) { func TestIsDevVersion(t *testing.T) {
t.Parallel() t.Parallel()
@@ -50,13 +49,6 @@ func TestIsDevVersion(t *testing.T) {
{"dev", true}, {"dev", true},
{"dev-b6e4a218a39e", true}, {"dev-b6e4a218a39e", true},
{"dev-b6e4a218a39e-dirty", true}, {"dev-b6e4a218a39e-dirty", true},
// What `git describe --tags --always --dirty` produces with no
// tag reachable, and on a commit after a tag.
{"877eb2f", true},
{"877eb2f-dirty", true},
{"v1.0.0-3-g877eb2f", true},
{"v1.0.0-3-g877eb2f-dirty", true},
{"1.0.0-rc.1-12-g877eb2f", true},
// What a tagged build produces (goreleaser's .Version strips // What a tagged build produces (goreleaser's .Version strips
// the leading "v"; script/version keeps it). // the leading "v"; script/version keeps it).
{"1.0.0", false}, {"1.0.0", false},
+1 -2
View File
@@ -4,8 +4,7 @@
# call this rather than carrying a hardcoded constant, which is what used # call this rather than carrying a hardcoded constant, which is what used
# to make every local build claim to be 1.0.0-rc.1 regardless of git # to make every local build claim to be 1.0.0-rc.1 regardless of git
# state. script/docker and script/cibuild pass its output to the image # state. script/docker and script/cibuild pass its output to the image
# build; given no version, the image build runs `git describe --tags # build, which otherwise runs the same `git describe` itself.
# --always` itself, without `--dirty`.
# #
# The version is `git describe --tags --always --dirty`: the tag on a # The version is `git describe --tags --always --dirty`: the tag on a
# tagged commit, tag-N-gHASH on a commit after one, the short commit # tagged commit, tag-N-gHASH on a commit after one, the short commit