Skip to content

Check that the build version reaches the binary - #93

Merged
beetlebugorg merged 1 commit into
mainfrom
ci/verify-version-stamp
Aug 28, 2026
Merged

beetlebugorg merged 1 commit into
mainfrom
ci/verify-version-stamp

Conversation

@beetlebugorg

Copy link
Copy Markdown
Owner

What changes

The version probe in the test job runs make on the host. The image builds are where a VERSION build arg was dropped, and nothing looked there. Three checks close that, each catching a different failure.

The Makefile reads the linker flags back. all, static, and lambda now run go version -m against what they just built and fail when VERSION is not in it. The lambda binary calls lambda.Start in main, so it cannot be asked for its version; the recorded build settings answer instead.

pr.yml refuses an image build that takes VERSION without declaring it. This is the exact invariant that was violated. Dockerfile.lambda and Dockerfile.binaries were handed the arg and never declared ARG VERSION, so Docker discarded it.

pr.yml and release.yml ask the artifact. The container build now loads and runs dims version. The release workflow unzips the standalone binary and does the same. Both runners are native for their architecture, so the artifact answers for itself.

VERSION also falls back to unknown rather than an empty string when git rev-parse fails, so a build from a source tarball still stamps something.

Verify

The Makefile guard, in the builder image:

make all VERSION=probe-1234           -> dims version prints probe-1234
make all VERSION=probe-1234 \
  LD_FLAGS=...Version=wrong...        -> VERSION=probe-1234 did not reach build/dims
                                         make: *** [Makefile:27: all] Error 1

The declaration guard:

as committed                          -> pass
ARG VERSION removed from lambda       -> Dockerfile.lambda takes a VERSION build arg
                                         but never declares it

The artifact check, against the real failure. Removing ARG VERSION from Dockerfile and building with --build-arg VERSION=pr-999:

build succeeds, the arg is discarded
docker run go-dims version            -> ""      (want pr-999)
assertion fails

With the declaration in place the same build reports pr-999.

make VERSION=version-probe still satisfies the existing probe, and go test -race -count=1 ./... passes on the builder image. make lambda reaches its zip step, which the plain builder image cannot run because zip is installed by Dockerfile.lambda rather than the base image. The guard runs before that and passes.

- Read the linker flags back out of each binary the Makefile builds.
- Refuse an image build that takes a VERSION arg without declaring it.
- Run the built container and the released binary to confirm the version.
@beetlebugorg
beetlebugorg merged commit 455f1e0 into main Aug 28, 2026
3 checks passed
@beetlebugorg
beetlebugorg deleted the ci/verify-version-stamp branch August 28, 2026 00:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant