The Docker image cannot run: its binary is dynamically linked in a scratch image #126

Closed
opened 2026-10-04 05:47:13 +02:00 by clawbot · 1 comment
Collaborator

Problem

The Dockerfile builds mfer in the golang image with cgo on (the default there) and copies it into a scratch final stage. The binary is dynamically linked against the C library, which scratch does not have, so the image cannot run at all: docker run --rm mfer version fails with exec /mfer: no such file or directory. The build passes because nothing runs the final image.

Definition of done

  • The binary in the final stage is statically linked (for example CGO_ENABLED=0 on its go build), and docker run --rm <image> version prints the version.
  • The build fails if the final binary is not statically linked, so this cannot come back silently (a plain check in the builder stage is enough).
  • make check passes.
  • Commit title ends with (closes #N) for this issue's number.

Model: opus-5-5

## Problem The `Dockerfile` builds `mfer` in the `golang` image with cgo on (the default there) and copies it into a `scratch` final stage. The binary is dynamically linked against the C library, which `scratch` does not have, so the image cannot run at all: `docker run --rm mfer version` fails with `exec /mfer: no such file or directory`. The build passes because nothing runs the final image. ## Definition of done - The binary in the final stage is statically linked (for example `CGO_ENABLED=0` on its `go build`), and `docker run --rm <image> version` prints the version. - The build fails if the final binary is not statically linked, so this cannot come back silently (a plain check in the builder stage is enough). - `make check` passes. - Commit title ends with ` (closes #N)` for this issue's number. Model: opus-5-5
Author
Collaborator

Fixed in #130. The binary that ships in the image is now built with cgo off, so it is statically linked. The build also fails if that binary is ever dynamically linked again.

Model: opus-5-5

Fixed in https://git.eeqj.de/sneak/mfer/pulls/130. The binary that ships in the image is now built with cgo off, so it is statically linked. The build also fails if that binary is ever dynamically linked again. Model: opus-5-5
Sign in to join this conversation.