Fix git ownership and -race in the canonical Go Dockerfile (closes #73)
check / check (push) Successful in 26s

The test phase ran go test -race on the alpine Go image, which has no C
compiler, so cgo was off and the phase failed with "-race requires cgo"
before running a test. It now uses the Debian Go image.

A build context sent as a tar stream keeps the sender's file owners, so
git in the stage that compiles refused the checkout and the version came
out empty. That stage now runs
git config --system --add safe.directory /src, and the policy text and
both checklists say why. The apk add --no-cache git line is unchanged:
its pinning waits on #72.

Model: opus-5-5
This commit is contained in:
2026-10-03 15:54:45 +00:00
parent 7ea5cdcdcd
commit 581dfa3b15
4 changed files with 40 additions and 19 deletions
+7
View File
@@ -21,6 +21,13 @@ fmt-check, and commit.
# Completed Steps
- 2026-10-03: Fixed two defects in the canonical Go `Dockerfile` example (issue
73). The test phase now uses the Debian Go image, since `-race` needs cgo and
the alpine image has no C compiler, so the phase failed before running a test.
The stage that compiles runs `git config --system --add safe.directory /src`,
because a context sent as a tar stream keeps the sender's file owners and git
refuses that checkout, leaving the version empty. Both checklists state that
step in the same words.
- 2026-10-03: Brought the canonical `.gitignore` level with `.dockerignore` on
secrets (issue 38): it now also ignores `prod.env`-style `*.env` files,
`.envrc`, `*.p12`, `*.pfx` and the extensionless SSH private keys, written to