check / check (push) Waiting to run
upaas uploads its clone as a tar context, which .dockerignore does not filter, so its builds already carried .git; the binary said "unknown" because the VERSION build arg defaulted to "unknown". The old .git/ exclusion kept .git out of a directory-context build only. .dockerignore now lets .git through without its config, which can carry a credential, and leaves out no tracked file (an excluded one would read as deleted and mark the version -dirty). The VERSION build arg loses its "unknown" default, so script/version derives the version inside the build; a given VERSION still takes precedence. The builder stage installs git, trusts the copied checkout whoever owns its files, and fails when its context carries .git and the version still comes out "unknown". The CI fingerprint is now the commit being checked. Model: opus-5-5
64 lines
2.2 KiB
Bash
Executable File
64 lines
2.2 KiB
Bash
Executable File
#!/bin/sh
|
|
# script/version: output the version string the binary is stamped with.
|
|
# Our own extension to scripts-to-rule-them-all. The Makefile's build
|
|
# target and script/docker both take the value from here, so a `make
|
|
# build` binary and a `make docker` image built from the same checkout
|
|
# report the same thing.
|
|
#
|
|
# Order of precedence:
|
|
#
|
|
# 1. $VERSION, if set and non-empty: an explicit value, such as the
|
|
# Dockerfile's VERSION build arg.
|
|
# 2. `git describe --tags --always --dirty` against this checkout. At
|
|
# a clean tagged commit that is exactly the tag; otherwise it
|
|
# carries the short SHA, the commit distance when a tag is
|
|
# reachable, and a -dirty suffix for uncommitted changes.
|
|
# 3. "unknown", for a tree with no git metadata and no $VERSION -- a
|
|
# source tarball, or a `docker build` with no .git in its context
|
|
# and no VERSION build arg. That case must not fail the build and
|
|
# must not name a tag the tree may not be at, so it names nothing.
|
|
#
|
|
# The git step insists the enclosing repository is this checkout, not
|
|
# merely some repository above it: an unpacked tarball sitting inside an
|
|
# unrelated working copy would otherwise be stamped with that copy's
|
|
# version.
|
|
#
|
|
# Nothing here may vary between two builds of the same commit: the
|
|
# release gate asserts the binary is byte-identical across builds. That
|
|
# rules out a build timestamp, a hostname, and a builder identity.
|
|
set -eu
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
|
|
|
# in_this_checkout succeeds when git can read metadata for a repository
|
|
# whose work tree root is $ROOT.
|
|
in_this_checkout() {
|
|
command -v git >/dev/null 2>&1 || return 1
|
|
|
|
top="$(git rev-parse --show-toplevel 2>/dev/null)" || return 1
|
|
[ -n "$top" ] || return 1
|
|
|
|
top="$(cd "$top" 2>/dev/null && pwd -P)" || return 1
|
|
[ "$top" = "$ROOT" ]
|
|
}
|
|
|
|
main() {
|
|
if [ -n "${VERSION:-}" ]; then
|
|
echo "$VERSION"
|
|
|
|
return 0
|
|
fi
|
|
|
|
cd "$ROOT"
|
|
|
|
if in_this_checkout; then
|
|
# --always keeps an untagged history from failing the build: it
|
|
# falls back to the bare short SHA.
|
|
git describe --tags --always --dirty 2>/dev/null && return 0
|
|
fi
|
|
|
|
echo "unknown"
|
|
}
|
|
|
|
main "$@"
|