Files
webhooker/script/version
T
clawbot 74004178ce
check / check (push) Failing after 3s
Re-vendor the shared files from sneak/prompts at dd4027b (closes #504)
Fetches the shared files unchanged from sneak/prompts commit dd4027b and
adds .prettierignore; .dockerignore keeps this repository's anchored host
artifacts at its end.

Linting moves into the Dockerfile's lint phase on the golangci-lint
v2.14.0 image, which also runs the js-lint stage, and Dockerfile.lint is
gone. Tests move into a test phase on the golang bookworm image.
script/lint, test, docker and cibuild are the model scripts, every docker
build in script/ passes --no-cache, and the .ci-fingerprint barrier is
gone. The workflow no longer calls script/ci-mark-superseded, so it and
its tests are removed. make build passes -trimpath and -s -w.

Model: opus-5-5
2026-10-06 00:30:35 +00:00

66 lines
2.3 KiB
Bash
Executable File

#!/bin/sh
# script/version: output the version string the binary is stamped with.
# Our own extension to scripts-to-rule-them-all. The Makefile's build
# and version targets take the value from here, and the Dockerfile's
# build stage calls them. script/docker and script/cibuild run the same
# `git describe` on the host and pass the result in as $VERSION, so a
# `make build` binary and a `make docker` image built from the same
# checkout report the same thing.
#
# Order of precedence:
#
# 1. $VERSION, if set and non-empty: an explicit value, such as the
# Dockerfile's VERSION build arg.
# 2. `git describe --tags --always --dirty` against this checkout. At
# a clean tagged commit that is exactly the tag; otherwise it
# carries the short SHA, the commit distance when a tag is
# reachable, and a -dirty suffix for uncommitted changes.
# 3. "unknown", for a tree with no git metadata and no $VERSION -- a
# source tarball, or a `docker build` with no .git in its context
# and no VERSION build arg. That case must not fail the build and
# must not name a tag the tree may not be at, so it names nothing.
#
# The git step insists the enclosing repository is this checkout, not
# merely some repository above it: an unpacked tarball sitting inside an
# unrelated working copy would otherwise be stamped with that copy's
# version.
#
# Nothing here may vary between two builds of the same commit: the
# release gate asserts the binary is byte-identical across builds. That
# rules out a build timestamp, a hostname, and a builder identity.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
# in_this_checkout succeeds when git can read metadata for a repository
# whose work tree root is $ROOT.
in_this_checkout() {
command -v git >/dev/null 2>&1 || return 1
top="$(git rev-parse --show-toplevel 2>/dev/null)" || return 1
[ -n "$top" ] || return 1
top="$(cd "$top" 2>/dev/null && pwd -P)" || return 1
[ "$top" = "$ROOT" ]
}
main() {
if [ -n "${VERSION:-}" ]; then
echo "$VERSION"
return 0
fi
cd "$ROOT"
if in_this_checkout; then
# --always keeps an untagged history from failing the build: it
# falls back to the bare short SHA.
git describe --tags --always --dirty 2>/dev/null && return 0
fi
echo "unknown"
}
main "$@"