Re-vendor the shared files from sneak/prompts at dd4027b (closes #504)
check / check (push) Failing after 6s
check / check (push) Failing after 6s
Fetches the shared files unchanged from sneak/prompts commit dd4027b and adds .prettierignore; .dockerignore keeps this repository's anchored host artifacts at its end. Linting moves into the Dockerfile's lint phase on the golangci-lint v2.14.0 image, which also runs the js-lint stage, and Dockerfile.lint is gone. Tests move into a test phase on the golang bookworm image. script/lint, test, docker and cibuild are the model scripts, every docker build in script/ passes --no-cache, and the .ci-fingerprint barrier is gone. The workflow no longer calls script/ci-mark-superseded, so it and its tests are removed. make build passes -trimpath and -s -w. Model: opus-5-5
This commit is contained in:
+106
-58
@@ -1,34 +1,3 @@
|
||||
# Lint stage
|
||||
# golangci/golangci-lint:v2.12.2 (Debian-based), 2026-08-07
|
||||
# Using Debian-based image because mattn/go-sqlite3 (CGO) does not
|
||||
# compile on Alpine musl (off64_t is a glibc type).
|
||||
FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS lint
|
||||
|
||||
WORKDIR /src
|
||||
|
||||
# Copy go mod files first for better layer caching
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
# Copy source code. In CI the context also carries .ci-fingerprint, which
|
||||
# holds the hash of the commit being checked (see
|
||||
# .gitea/workflows/check.yml). That invalidates this layer, so the checks
|
||||
# below cannot report success by replaying a cached pass. Do not add it to
|
||||
# .dockerignore.
|
||||
COPY . .
|
||||
|
||||
# Run the Go formatting check and the linter. gofmt and golangci-lint are
|
||||
# invoked directly rather than through `make fmt-check` and `make lint`: this
|
||||
# stage is already the pinned linter image, and both scripts build docker
|
||||
# stages, so calling them here would need a docker daemon inside the build.
|
||||
# The Markdown half of `make fmt-check` is the markdown-check stage below.
|
||||
# Keep the golangci-lint steps in step with Dockerfile.lint, including
|
||||
# --network=none (see its header for why).
|
||||
RUN if [ -n "$(gofmt -s -l .)" ]; then echo "gofmt needed on:"; gofmt -s -l .; exit 1; fi
|
||||
RUN script/assets
|
||||
RUN --network=none golangci-lint config verify --config .golangci.yml
|
||||
RUN --network=none golangci-lint run --config .golangci.yml --build-tags browser ./...
|
||||
|
||||
# Stylesheet stages. static/css/tailwind.css is generated, by this pinned
|
||||
# tailwindcss, from static/css/input.css and the files its @source lines
|
||||
# name. `make css` (script/css) writes it out from the css-output stage.
|
||||
@@ -67,10 +36,7 @@ RUN sed 's/}/}\n/g' static/css/tailwind.css > /tmp/committed.css \
|
||||
|
||||
# JavaScript lint stages: ESLint, at the version package.json and yarn.lock
|
||||
# pin, checks static/js/ against eslint.config.mjs. js-deps installs it, and
|
||||
# prettier for the Markdown stages below, and stays cached until package.json,
|
||||
# yarn.lock or .yarnrc.yml changes. script/lint forces only js-lint to re-run,
|
||||
# and the build stage below runs it too. COPY . . brings in the CI cache
|
||||
# barrier described in the lint stage above.
|
||||
# prettier for the Markdown stages below. The lint phase below runs js-lint.
|
||||
#
|
||||
# The image's own corepack runs the yarn that package.json's packageManager
|
||||
# field names, yarn 4.18.1 (released 2026-09-24), and checks it against the
|
||||
@@ -104,23 +70,109 @@ FROM js-deps AS markdown-check
|
||||
COPY . .
|
||||
RUN --network=none node_modules/.bin/prettier --check '**/*.md'
|
||||
|
||||
# Lint phase: the Go formatting check and golangci-lint over the Go code,
|
||||
# and ESLint over static/js/ through the copy from js-lint at the end.
|
||||
# `make lint` (script/lint) builds this stage alone; the build stage below
|
||||
# depends on it.
|
||||
#
|
||||
# golangci/golangci-lint:v2.14.0 (Debian-based), 2026-09-24
|
||||
# Using Debian-based image because mattn/go-sqlite3 (CGO) does not
|
||||
# compile on Alpine musl (off64_t is a glibc type).
|
||||
FROM golangci/golangci-lint:v2.14.0@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f AS lint
|
||||
|
||||
WORKDIR /src
|
||||
|
||||
# Copy go mod files first for better layer caching
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
COPY . .
|
||||
|
||||
# gofmt and golangci-lint are invoked directly rather than through `make
|
||||
# fmt-check` and `make lint`, which are themselves docker builds and would
|
||||
# need a docker daemon inside this one. The Markdown half of `make
|
||||
# fmt-check` is the markdown-check stage above.
|
||||
RUN if [ -n "$(gofmt -s -l .)" ]; then echo "gofmt needed on:"; gofmt -s -l .; exit 1; fi
|
||||
|
||||
# static/static.go embeds the Alpine.js file this extracts from 3p/; without
|
||||
# it the static package does not compile and cannot be linted.
|
||||
RUN script/assets
|
||||
|
||||
# The golangci-lint steps run with --network=none. `golangci-lint config
|
||||
# verify` is documented as fetching its JSON schema over HTTPS; this pinned
|
||||
# image resolves the schema without any network, and --network=none enforces
|
||||
# that. It also proves no linter reaches out at analysis time.
|
||||
#
|
||||
# `run` silently ignores config keys it does not recognize, so a typo would
|
||||
# disable a setting without a word. `config verify` is what catches that.
|
||||
RUN --network=none golangci-lint config verify --config .golangci.yml
|
||||
# --build-tags browser also lints the browser test, which is built only with
|
||||
# that tag (make test-browser).
|
||||
RUN --network=none golangci-lint run --config .golangci.yml --build-tags browser ./...
|
||||
|
||||
# Nothing is wanted from js-lint; the copy is what makes this phase run it.
|
||||
COPY --from=js-lint /src/yarn.lock /dev/null
|
||||
|
||||
# Test phase. -race needs cgo and so a C compiler, which the Debian Go image
|
||||
# ships and the alpine one does not. `make test` (script/test) builds this
|
||||
# stage alone; the build stage below depends on it.
|
||||
#
|
||||
# golang:1.26.1-bookworm (Debian-based), 2026-03-17
|
||||
FROM golang:1.26.1-bookworm@sha256:4465644228bc2857a954b092167e12aa59c006a3492282a6c820bf4755fd64a4 AS test
|
||||
|
||||
WORKDIR /src
|
||||
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
COPY . .
|
||||
|
||||
# static/static.go embeds the Alpine.js file this extracts from 3p/.
|
||||
RUN script/assets
|
||||
|
||||
# -timeout applies to each package on its own, so 90s has only to clear the
|
||||
# slowest one. -p 4 -parallel 8 keep the run under 2 GB of memory: at most
|
||||
# four test binaries build or run at once, each with at most eight parallel
|
||||
# tests. Under -race every test binary and every link costs a few hundred MB,
|
||||
# so the defaults (one per core) add up to several GB on a many-core host.
|
||||
#
|
||||
# The first run has no -v: go test then prints one result line per package,
|
||||
# with its coverage, and for a package that fails, everything its tests
|
||||
# wrote. Verbose output from the whole suite passes the 2 MiB at which the
|
||||
# Docker build cuts off a step's log, so on a failure only the tests that
|
||||
# failed run again, with -v. go test reports a failed test as a line starting
|
||||
# "--- FAIL: TestName" (a failed subtest's line is indented, and reruns with
|
||||
# its parent) and a failed package as "FAIL<tab>package/path<tab>...". A
|
||||
# failure that names no test, such as a build error or a timeout, is already
|
||||
# shown in full, so there is nothing to rerun. The step fails after the rerun
|
||||
# whatever its result: the first run already showed the suite is broken.
|
||||
#
|
||||
# bash with pipefail, so that the first run's status is go test's, not tee's.
|
||||
SHELL ["/bin/bash", "-o", "pipefail", "-c"]
|
||||
RUN go test -race -cover -p 4 -parallel 8 -timeout 90s ./... 2>&1 | tee /tmp/go-test.log && exit 0; \
|
||||
tests="$(awk '/^--- FAIL: / { print $3 }' /tmp/go-test.log | paste -s -d '|' -)"; \
|
||||
packages="$(awk '/^FAIL\t/ { print $2 }' /tmp/go-test.log)"; \
|
||||
if [ -n "$tests" ]; then \
|
||||
echo "--- Rerunning the failed tests with -v for details ---"; \
|
||||
go test -race -v -p 4 -parallel 8 -timeout 90s -run "^($tests)\$" $packages; \
|
||||
fi; \
|
||||
exit 1
|
||||
|
||||
# Build stage
|
||||
# golang:1.26.1-bookworm (Debian-based), 2026-03-17
|
||||
# Using Debian-based image because gorm.io/driver/sqlite pulls in
|
||||
# mattn/go-sqlite3 (CGO), which does not compile on Alpine musl.
|
||||
# mattn/go-sqlite3 (CGO), which does not compile on Alpine musl. The image
|
||||
# ships git and make, which the version step below uses.
|
||||
FROM golang:1.26.1-bookworm@sha256:4465644228bc2857a954b092167e12aa59c006a3492282a6c820bf4755fd64a4 AS builder
|
||||
|
||||
# Depend on the lint, stylesheet check, JavaScript lint and Markdown check
|
||||
# stages passing
|
||||
# Nothing is wanted from the lint and test phases or from the stylesheet and
|
||||
# Markdown checks; the copies are what make BuildKit build them first, so
|
||||
# this stage cannot run unless they all passed.
|
||||
COPY --from=lint /src/go.sum /dev/null
|
||||
COPY --from=test /src/go.sum /dev/null
|
||||
COPY --from=css-check /out/tailwind.css /dev/null
|
||||
COPY --from=js-lint /src/yarn.lock /dev/null
|
||||
COPY --from=markdown-check /src/yarn.lock /dev/null
|
||||
|
||||
# jq is a runtime dependency of script/ci-mark-superseded, which the test
|
||||
# suite executes. git is what script/version derives the version with.
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends make curl ca-certificates jq git && rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# A build context sent as a tar archive keeps its files' owners, and git
|
||||
# refuses to read a checkout owned by another user. Trust this one
|
||||
# whoever owns it.
|
||||
@@ -132,31 +184,27 @@ WORKDIR /build
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
# Copy source code, including the .ci-fingerprint cache barrier described in
|
||||
# the lint stage above.
|
||||
COPY . .
|
||||
|
||||
# Run tests and build. Both first run script/assets, which extracts Alpine.js
|
||||
# from its tarball in 3p/.
|
||||
RUN make test
|
||||
|
||||
# Version stamped into the binary: the VERSION build arg when one is
|
||||
# given, otherwise what script/version derives from the .git the build
|
||||
# context carries, so any `docker build .` of a clone stamps its commit.
|
||||
# With neither, as from a source tarball, it is "unknown".
|
||||
#
|
||||
# Declared here, below the test step, so a changed version does not
|
||||
# invalidate its cached layer.
|
||||
ARG VERSION
|
||||
|
||||
# A context that carries .git must not stamp "unknown": that means git is
|
||||
# missing here or could not read the checkout, and the image could not be
|
||||
# traced back to its commit.
|
||||
RUN if [ -d .git ] && [ "$(make version VERSION="$VERSION")" = unknown ]; then \
|
||||
echo "version is unknown although the build context carries .git" >&2; \
|
||||
exit 1; \
|
||||
# A context that carries .git must not stamp an empty version, "dev" or
|
||||
# "unknown": that means git is missing here or could not read the
|
||||
# checkout, and the image could not be traced back to its commit.
|
||||
RUN version="$(make version VERSION="$VERSION")"; \
|
||||
if [ -e .git ]; then \
|
||||
case "$version" in ""|dev|unknown) \
|
||||
echo "version is '$version' although .git is present" >&2; \
|
||||
exit 1 ;; \
|
||||
esac; \
|
||||
fi
|
||||
|
||||
# Builds through the Makefile's build target, which runs script/assets
|
||||
# (Alpine.js, extracted from its tarball in 3p/) first.
|
||||
RUN make build VERSION="$VERSION"
|
||||
|
||||
# Rebuild with static linking for Alpine runtime.
|
||||
|
||||
Reference in New Issue
Block a user