The Dockerfile builds mfer in the golang image with cgo on (the default there) and copies it into a scratch final stage. The binary is dynamically linked against the C library, which scratch does not have, so the image cannot run at all: docker run --rm mfer version fails with exec /mfer: no such file or directory. The build passes because nothing runs the final image.
Definition of done
The binary in the final stage is statically linked (for example CGO_ENABLED=0 on its go build), and docker run --rm <image> version prints the version.
The build fails if the final binary is not statically linked, so this cannot come back silently (a plain check in the builder stage is enough).
make check passes.
Commit title ends with (closes #N) for this issue's number.
Model: opus-5-5
## Problem
The `Dockerfile` builds `mfer` in the `golang` image with cgo on (the default there) and copies it into a `scratch` final stage. The binary is dynamically linked against the C library, which `scratch` does not have, so the image cannot run at all: `docker run --rm mfer version` fails with `exec /mfer: no such file or directory`. The build passes because nothing runs the final image.
## Definition of done
- The binary in the final stage is statically linked (for example `CGO_ENABLED=0` on its `go build`), and `docker run --rm <image> version` prints the version.
- The build fails if the final binary is not statically linked, so this cannot come back silently (a plain check in the builder stage is enough).
- `make check` passes.
- Commit title ends with ` (closes #N)` for this issue's number.
Model: opus-5-5
Fixed in #130. The binary that ships in the image is now built with cgo off, so it is statically linked. The build also fails if that binary is ever dynamically linked again.
Model: opus-5-5
Fixed in https://git.eeqj.de/sneak/mfer/pulls/130. The binary that ships in the image is now built with cgo off, so it is statically linked. The build also fails if that binary is ever dynamically linked again.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Problem
The
Dockerfilebuildsmferin thegolangimage with cgo on (the default there) and copies it into ascratchfinal stage. The binary is dynamically linked against the C library, whichscratchdoes not have, so the image cannot run at all:docker run --rm mfer versionfails withexec /mfer: no such file or directory. The build passes because nothing runs the final image.Definition of done
CGO_ENABLED=0on itsgo build), anddocker run --rm <image> versionprints the version.make checkpasses.(closes #N)for this issue's number.Model: opus-5-5
Fixed in #130. The binary that ships in the image is now built with cgo off, so it is statically linked. The build also fails if that binary is ever dynamically linked again.
Model: opus-5-5