The controller imports mesh-host/validate through a replace onto the forge that holds it, and every build — the build agent's go build in a fresh toolchain container, the Dockerfile's go mod download — would have fetched it through the public proxy and checksum database at build time: a merge breaking main on the network, the class Phase 1 removes. vendor/ is committed; go builds from it with nothing fetched, and refuses to build when it and go.mod disagree, so a pin moved without go mod vendor fails at once. The Dockerfile copies vendor/ and builds with GOPROXY=off.
17 lines
490 B
Go
17 lines
490 B
Go
package puddle
|
|
|
|
import "time"
|
|
|
|
// nanotime returns the time in nanoseconds since process start.
|
|
//
|
|
// This approach, described at
|
|
// https://github.com/golang/go/issues/61765#issuecomment-1672090302,
|
|
// is fast, monotonic, and portable, and avoids the previous
|
|
// dependence on runtime.nanotime using the (unsafe) linkname hack.
|
|
// In particular, time.Since does less work than time.Now.
|
|
func nanotime() int64 {
|
|
return time.Since(globalStart).Nanoseconds()
|
|
}
|
|
|
|
var globalStart = time.Now()
|