Found in review of sneak/smallwebwaf#67. A plain docker build . from a linked git worktree fails the version step of the canonical Dockerfile example: there .git is a small file pointing to a directory outside the build context, so git describe prints nothing, the [ -e .git ] check sees .git, and the build stops with "version is '' although .git is present". A checkout whose .git is a file for another reason (a repository checked out as a submodule) behaves the same. Fresh clones are unaffected.
That is the check doing its job: it refuses to stamp an empty version silently. What is missing is one sentence telling the reader what to do there.
Fix
In the version-from-git text of prompts/REPO_POLICIES.md, say in one plain sentence that a build from a checkout whose .git is a file (a linked worktree, or a submodule) cannot read its version inside the build and must be given one with --build-arg VERSION=..., which script/docker and script/cibuild already do. Do not weaken the check.
Definition of done
That sentence is in the policy, and nothing in the canonical documents says a plain docker build . succeeds from such a checkout.
make check passes.
Model: opus-5-5
Found in review of https://git.eeqj.de/sneak/smallwebwaf/pulls/67. A plain `docker build .` from a linked git worktree fails the version step of the canonical `Dockerfile` example: there `.git` is a small file pointing to a directory outside the build context, so `git describe` prints nothing, the `[ -e .git ]` check sees `.git`, and the build stops with "version is '' although .git is present". A checkout whose `.git` is a file for another reason (a repository checked out as a submodule) behaves the same. Fresh clones are unaffected.
That is the check doing its job: it refuses to stamp an empty version silently. What is missing is one sentence telling the reader what to do there.
## Fix
In the version-from-git text of `prompts/REPO_POLICIES.md`, say in one plain sentence that a build from a checkout whose `.git` is a file (a linked worktree, or a submodule) cannot read its version inside the build and must be given one with `--build-arg VERSION=...`, which `script/docker` and `script/cibuild` already do. Do not weaken the check.
## Definition of done
- That sentence is in the policy, and nothing in the canonical documents says a plain `docker build .` succeeds from such a checkout.
- `make check` passes.
Model: opus-5-5
clawbot
self-assigned this 2026-10-06 04:14:30 +02:00
The sentence is in #114: prompts/REPO_POLICIES.md and both checklists now say, right after the rule that a plain docker build . must succeed, that a checkout whose .git is a file is the exception and is given its version with --build-arg VERSION=.... The version check is unchanged.
Model: opus-5-5
The sentence is in https://git.eeqj.de/sneak/prompts/pulls/114: `prompts/REPO_POLICIES.md` and both checklists now say, right after the rule that a plain `docker build .` must succeed, that a checkout whose `.git` is a file is the exception and is given its version with `--build-arg VERSION=...`. The version check is unchanged.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found in review of sneak/smallwebwaf#67. A plain
docker build .from a linked git worktree fails the version step of the canonicalDockerfileexample: there.gitis a small file pointing to a directory outside the build context, sogit describeprints nothing, the[ -e .git ]check sees.git, and the build stops with "version is '' although .git is present". A checkout whose.gitis a file for another reason (a repository checked out as a submodule) behaves the same. Fresh clones are unaffected.That is the check doing its job: it refuses to stamp an empty version silently. What is missing is one sentence telling the reader what to do there.
Fix
In the version-from-git text of
prompts/REPO_POLICIES.md, say in one plain sentence that a build from a checkout whose.gitis a file (a linked worktree, or a submodule) cannot read its version inside the build and must be given one with--build-arg VERSION=..., whichscript/dockerandscript/cibuildalready do. Do not weaken the check.Definition of done
docker build .succeeds from such a checkout.make checkpasses.Model: opus-5-5
The sentence is in #114:
prompts/REPO_POLICIES.mdand both checklists now say, right after the rule that a plaindocker build .must succeed, that a checkout whose.gitis a file is the exception and is given its version with--build-arg VERSION=.... The version check is unchanged.Model: opus-5-5