Compare commits

..
1 Commits
Author SHA1 Message Date
clawbot 51a5d71b8a Stamp the tag or short commit in a plain docker build (closes #211)
check / check (pull_request) Successful in 3m45s
A plain `docker build .` stamped `dev`: `.dockerignore` left out `.git`
and the Dockerfile defaulted VERSION to `dev`. `.dockerignore` now
sends `.git` without `.git/config`. Given no build arguments, the
builder stamps `git describe --tags --always` and the commit and date
from git, and fails if `.git` is present but yields no version. The
empty CHECK_EPOCH refusal is gone so the plain build succeeds.
`script/version` now prints `git describe --tags --always --dirty`, so
make, the scripts and a plain build agree. `vaultik version` treats
the short commit and tag-N-gHASH forms as development builds, so they
keep the development-build notice.

Model: opus-5-5
2026-10-02 06:44:32 +00:00
4 changed files with 32 additions and 15 deletions
+7 -5
View File
@@ -906,11 +906,13 @@ git metadata reports `dev`.
`v`, so the tag `v1.0.0` produces `vaultik 1.0.0`, matching the archive
name `vaultik_1.0.0_linux_amd64.tar.gz`. `goreleaser --snapshot` stamps
`dev-<12 chars of the commit sha>` rather than inventing the next patch
number. `vaultik version` calls `dev` and `dev-<sha>` development
builds. If `script/version` cannot be run at all, `make` stops with an
error instead of building an unversioned binary, and a binary that
somehow carries an empty version string still reports itself as a
development build.
number. `vaultik version` calls a build a development build when its
version is `dev`, `dev-<sha>`, the short commit sha or
`<tag>-<N>-g<short sha>`, with or without `-dirty`; only a plain tag,
such as `v1.0.0` or `1.0.0`, is a release. If `script/version` cannot
be run at all, `make` stops with an error instead of building an
unversioned binary, and a binary that somehow carries an empty version
string still reports itself as a development build.
### cutting a release
+11 -5
View File
@@ -3,6 +3,7 @@
package globals
import (
"regexp"
"strings"
"time"
)
@@ -59,10 +60,11 @@ func New() (*Globals, error) {
}
// IsDevVersion reports whether v names a development build rather than
// a release. Both "dev" and goreleaser's snapshot "dev-<sha>" count. A
// make or docker build of an untagged commit reports `git describe`
// output instead (the short commit, or tag-N-gHASH), which this does
// not recognise.
// a release. "dev" and goreleaser's snapshot "dev-<sha>" count, and so
// does what `git describe --tags --always --dirty` gives a make or
// docker build of an untagged commit: the bare short commit, or
// tag-N-gHASH on a commit after a tag, either with or without "-dirty".
// A plain tag such as "v1.0.0" or "1.0.0" is a release.
//
// The empty string counts too. Nothing that knows its version reports
// no version, so an empty Version means the stamping failed, and the
@@ -71,7 +73,11 @@ func New() (*Globals, error) {
// case; this is the second line of defence, for a binary linked by
// something other than the Makefile.
func IsDevVersion(v string) bool {
return v == "" || v == DevVersion || strings.HasPrefix(v, DevVersion+"-")
if v == "" || v == DevVersion || strings.HasPrefix(v, DevVersion+"-") {
return true
}
return regexp.MustCompile(`^(.+-[0-9]+-g)?[0-9a-f]+(-dirty)?$`).MatchString(v)
}
// shortCommitLen is the number of commit-hash characters ShortCommit keeps.
+12 -4
View File
@@ -34,10 +34,11 @@ func TestGlobalsNew(t *testing.T) {
}
// TestIsDevVersion covers the boundary that matters: everything
// goreleaser's snapshot template, and script/version outside a git
// checkout, can emit must be recognised as a development build, and a
// real tag must not be. A plain equality check against "dev" used to decide
// this, which classified every commit-stamped dev build as a release.
// script/version, a plain docker build and goreleaser's snapshot
// template can emit for an untagged build must be recognised as a
// development build, and a real tag must not be. A plain equality check
// against "dev" used to decide this, which classified every
// commit-stamped dev build as a release.
func TestIsDevVersion(t *testing.T) {
t.Parallel()
@@ -49,6 +50,13 @@ func TestIsDevVersion(t *testing.T) {
{"dev", true},
{"dev-b6e4a218a39e", true},
{"dev-b6e4a218a39e-dirty", true},
// What `git describe --tags --always --dirty` produces with no
// tag reachable, and on a commit after a tag.
{"877eb2f", true},
{"877eb2f-dirty", true},
{"v1.0.0-3-g877eb2f", true},
{"v1.0.0-3-g877eb2f-dirty", true},
{"1.0.0-rc.1-12-g877eb2f", true},
// What a tagged build produces (goreleaser's .Version strips
// the leading "v"; script/version keeps it).
{"1.0.0", false},
+2 -1
View File
@@ -4,7 +4,8 @@
# call this rather than carrying a hardcoded constant, which is what used
# to make every local build claim to be 1.0.0-rc.1 regardless of git
# state. script/docker and script/cibuild pass its output to the image
# build, which otherwise runs the same `git describe` itself.
# build; given no version, the image build runs `git describe --tags
# --always` itself, without `--dirty`.
#
# The version is `git describe --tags --always --dirty`: the tag on a
# tagged commit, tag-N-gHASH on a commit after one, the short commit