Keep a submodule's own .git/config out of the build context (closes #88)
check / check (push) Failing after 1s
check / check (push) Failing after 1s
The canonical .dockerignore kept out .git/config and the configs under .git/modules/, but not the config of a submodule that keeps its own .git directory, so its credential reached the image. Both git patterns now carry the **/ prefix. A submodule named config or deploy/config still loses its whole git directory, and Go's version stamping fails the build. Closing that needs a wildcard re-include, which makes BuildKit walk every excluded directory on every build, so the file records it as a KNOWN GAP with the remedy, git submodule add --name. REPO_POLICIES.md and both checklists say the same. Model: opus-5-5
This commit is contained in:
+8
-3
@@ -18,9 +18,14 @@
|
||||
# does not need .git/config; that file can hold a credential, such as a
|
||||
# password in a remote URL or the token the CI checkout step stores there.
|
||||
# Each submodule keeps a config with the same exposure in its git directory
|
||||
# under .git/modules/, nested again for a submodule's own submodules.
|
||||
.git/config
|
||||
.git/modules/**/config
|
||||
# under .git/modules/, nested again for a submodule's own submodules, or in
|
||||
# its own .git directory when it keeps one.
|
||||
# KNOWN GAP: `**/.git/modules/**/config` also matches the git directory
|
||||
# of a submodule named `config` or `deploy/config`, so all of it stays
|
||||
# out and Go's version stamping fails the build; nothing leaks. Name
|
||||
# such a submodule without that segment: `git submodule add --name`.
|
||||
**/.git/config
|
||||
**/.git/modules/**/config
|
||||
|
||||
# Agent scratch: one full checkout of the repo per in-flight agent.
|
||||
# Anchored because it occurs once where agents run at the repo root.
|
||||
|
||||
@@ -21,6 +21,15 @@ fmt-check, and commit.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: The canonical `.dockerignore` now also keeps out the git `config`
|
||||
of a submodule that keeps its own `.git` directory, which still reached the
|
||||
image (issue 88): both git patterns now carry the `**/` prefix. A submodule
|
||||
named `config` or `deploy/config` still loses its whole git directory, so Go's
|
||||
version stamping fails the build; the file records this as a `KNOWN GAP:` with
|
||||
the remedy, `git submodule add --name`. Closing it would take a wildcard
|
||||
re-include, which makes BuildKit walk every excluded directory, such as
|
||||
`node_modules`, on every build. `REPO_POLICIES.md` and both checklists say so
|
||||
in the same words.
|
||||
- 2026-10-04: `REPO_POLICIES.md` now says how a Go tool a repo needs on the host
|
||||
is pinned (issue 37): installed with `go install` pinned to a commit hash,
|
||||
never tracked as a `go.mod` tool dependency or through a `tools.go` file.
|
||||
|
||||
@@ -63,22 +63,26 @@ with your task.
|
||||
here run anywhere other than the repo root, the anchored entry misses
|
||||
`services/api/.claude/`: add anchored entries for those directories.
|
||||
- [ ] If the repo embeds a version in a binary: `.dockerignore` lets `.git` into
|
||||
the build context. It keeps out `.git/config` and each submodule's
|
||||
`config` under `.git/modules/` at any depth (`.git/modules/**/config`),
|
||||
which `git describe` does not need and which can hold a credential: a
|
||||
password in a remote URL, or the token the CI checkout step stores there.
|
||||
The stage that compiles has `git` (the Debian Go image has it; an alpine
|
||||
one needs `apk add --no-cache git`) and takes the version from the
|
||||
`VERSION` build argument when one is given, otherwise from
|
||||
`git describe --tags --always`. That gives the tag on a tagged commit; on
|
||||
a later commit, the tag, the number of commits since it and the short
|
||||
commit (`v1.2.3-4-gabc1234`); and the short commit when no tag is
|
||||
reachable. The stage that compiles also marks its working directory safe
|
||||
for git (`git config --system --add safe.directory /src`): a context sent
|
||||
as a tar stream keeps the sender's file owners, and git refuses a checkout
|
||||
owned by another user, so the version would come out empty. `ARG VERSION`
|
||||
has no default, and the build fails if the context carries `.git` and the
|
||||
version still comes out empty, `dev` or `unknown`. A plain
|
||||
the build context. It keeps out every git `config` at any depth
|
||||
(`**/.git/config`, `**/.git/modules/**/config`): the repository's own,
|
||||
each submodule's under `.git/modules/`, and that of a submodule keeping
|
||||
its own `.git` directory. `git describe` does not need them, and each can
|
||||
hold a credential: a password in a remote URL, or the token the CI
|
||||
checkout step stores there. A submodule named `config` or `deploy/config`
|
||||
loses its whole git directory to `**/.git/modules/**/config`, and Go's
|
||||
version stamping then fails the build: give it a name without that segment
|
||||
(`git submodule add --name`). The stage that compiles has `git` (the
|
||||
Debian Go image has it; an alpine one needs `apk add --no-cache git`) and
|
||||
takes the version from the `VERSION` build argument when one is given,
|
||||
otherwise from `git describe --tags --always`. That gives the tag on a
|
||||
tagged commit; on a later commit, the tag, the number of commits since it
|
||||
and the short commit (`v1.2.3-4-gabc1234`); and the short commit when no
|
||||
tag is reachable. The stage that compiles also marks its working directory
|
||||
safe for git (`git config --system --add safe.directory /src`): a context
|
||||
sent as a tar stream keeps the sender's file owners, and git refuses a
|
||||
checkout owned by another user, so the version would come out empty.
|
||||
`ARG VERSION` has no default, and the build fails if the context carries
|
||||
`.git` and the version still comes out empty, `dev` or `unknown`. A plain
|
||||
`docker build .` with no build arguments must succeed; a Dockerfile that
|
||||
refuses an empty build argument drops that refusal and keeps the argument.
|
||||
`script/docker` and `script/cibuild` pass the version they compute on the
|
||||
|
||||
@@ -71,22 +71,26 @@ Template files can be fetched from:
|
||||
will run them in subdirectories, `services/api/.claude/` needs its own
|
||||
anchored entry.
|
||||
- If the image embeds a version in a binary: `.dockerignore` lets `.git`
|
||||
into the build context. It keeps out `.git/config` and each submodule's
|
||||
`config` under `.git/modules/` at any depth (`.git/modules/**/config`),
|
||||
which `git describe` does not need and which can hold a credential: a
|
||||
password in a remote URL, or the token the CI checkout step stores there.
|
||||
The stage that compiles has `git` (the Debian Go image has it; an alpine
|
||||
one needs `apk add --no-cache git`) and takes the version from the
|
||||
`VERSION` build argument when one is given, otherwise from
|
||||
`git describe --tags --always`. That gives the tag on a tagged commit; on
|
||||
a later commit, the tag, the number of commits since it and the short
|
||||
commit (`v1.2.3-4-gabc1234`); and the short commit when no tag is
|
||||
reachable. The stage that compiles also marks its working directory safe
|
||||
for git (`git config --system --add safe.directory /src`): a context sent
|
||||
as a tar stream keeps the sender's file owners, and git refuses a checkout
|
||||
owned by another user, so the version would come out empty. `ARG VERSION`
|
||||
has no default, and the build fails if the context carries `.git` and the
|
||||
version still comes out empty, `dev` or `unknown`. A plain
|
||||
into the build context. It keeps out every git `config` at any depth
|
||||
(`**/.git/config`, `**/.git/modules/**/config`): the repository's own,
|
||||
each submodule's under `.git/modules/`, and that of a submodule keeping
|
||||
its own `.git` directory. `git describe` does not need them, and each can
|
||||
hold a credential: a password in a remote URL, or the token the CI
|
||||
checkout step stores there. A submodule named `config` or `deploy/config`
|
||||
loses its whole git directory to `**/.git/modules/**/config`, and Go's
|
||||
version stamping then fails the build: give it a name without that segment
|
||||
(`git submodule add --name`). The stage that compiles has `git` (the
|
||||
Debian Go image has it; an alpine one needs `apk add --no-cache git`) and
|
||||
takes the version from the `VERSION` build argument when one is given,
|
||||
otherwise from `git describe --tags --always`. That gives the tag on a
|
||||
tagged commit; on a later commit, the tag, the number of commits since it
|
||||
and the short commit (`v1.2.3-4-gabc1234`); and the short commit when no
|
||||
tag is reachable. The stage that compiles also marks its working directory
|
||||
safe for git (`git config --system --add safe.directory /src`): a context
|
||||
sent as a tar stream keeps the sender's file owners, and git refuses a
|
||||
checkout owned by another user, so the version would come out empty.
|
||||
`ARG VERSION` has no default, and the build fails if the context carries
|
||||
`.git` and the version still comes out empty, `dev` or `unknown`. A plain
|
||||
`docker build .` with no build arguments must succeed; a Dockerfile that
|
||||
refuses an empty build argument drops that refusal and keeps the argument.
|
||||
- The Dockerfile carries a `lint` phase and a `test` phase, each invoking
|
||||
|
||||
+21
-16
@@ -238,22 +238,27 @@ style conventions are in separate documents:
|
||||
`RUN mkdir -p web/dist && touch web/dist/index.html web/dist/style.css`.
|
||||
- If the project requires CGO or system libraries for linting (e.g.
|
||||
`vips-dev`), install them in the lint phase with `apk add`.
|
||||
- `.dockerignore` lets `.git` into the build context. It keeps out
|
||||
`.git/config` and each submodule's `config` under `.git/modules/` at any
|
||||
depth (`.git/modules/**/config`), which `git describe` does not need and
|
||||
which can hold a credential: a password in a remote URL, or the token the
|
||||
CI checkout step stores there. The stage that compiles has `git` (the
|
||||
Debian Go image has it; an alpine one needs `apk add --no-cache git`) and
|
||||
takes the version from the `VERSION` build argument when one is given,
|
||||
otherwise from `git describe --tags --always`. That gives the tag on a
|
||||
tagged commit; on a later commit, the tag, the number of commits since it
|
||||
and the short commit (`v1.2.3-4-gabc1234`); and the short commit when no
|
||||
tag is reachable. The stage that compiles also marks its working directory
|
||||
safe for git (`git config --system --add safe.directory /src`): a context
|
||||
sent as a tar stream keeps the sender's file owners, and git refuses a
|
||||
checkout owned by another user, so the version would come out empty.
|
||||
`ARG VERSION` has no default, and the build fails if the context carries
|
||||
`.git` and the version still comes out empty, `dev` or `unknown`. A plain
|
||||
- `.dockerignore` lets `.git` into the build context. It keeps out every git
|
||||
`config` at any depth (`**/.git/config`, `**/.git/modules/**/config`): the
|
||||
repository's own, each submodule's under `.git/modules/`, and that of a
|
||||
submodule keeping its own `.git` directory. `git describe` does not need
|
||||
them, and each can hold a credential: a password in a remote URL, or the
|
||||
token the CI checkout step stores there. A submodule named `config` or
|
||||
`deploy/config` loses its whole git directory to
|
||||
`**/.git/modules/**/config`, and Go's version stamping then fails the
|
||||
build: give it a name without that segment (`git submodule add --name`).
|
||||
The stage that compiles has `git` (the Debian Go image has it; an alpine
|
||||
one needs `apk add --no-cache git`) and takes the version from the
|
||||
`VERSION` build argument when one is given, otherwise from
|
||||
`git describe --tags --always`. That gives the tag on a tagged commit; on
|
||||
a later commit, the tag, the number of commits since it and the short
|
||||
commit (`v1.2.3-4-gabc1234`); and the short commit when no tag is
|
||||
reachable. The stage that compiles also marks its working directory safe
|
||||
for git (`git config --system --add safe.directory /src`): a context sent
|
||||
as a tar stream keeps the sender's file owners, and git refuses a checkout
|
||||
owned by another user, so the version would come out empty. `ARG VERSION`
|
||||
has no default, and the build fails if the context carries `.git` and the
|
||||
version still comes out empty, `dev` or `unknown`. A plain
|
||||
`docker build .` with no build arguments must succeed; a Dockerfile that
|
||||
refuses an empty build argument drops that refusal and keeps the argument.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user