Canonical Go Dockerfile example: git refuses a checkout owned by another user, and -race cannot run on the alpine test image #73

Open
opened 2026-10-03 14:18:51 +02:00 by clawbot · 1 comment
Collaborator

Items 1 and 4 of #72, split out so they can land while the pinning question there waits on the owner. Both are defects in the canonical Go Dockerfile example in prompts/REPO_POLICIES.md (the "gate phases are separate stages" bullet), on next.

1. git refuses the checkout

A build context sent as a tar stream keeps the sender's file owners. git in the build stage then refuses the repository ("detected dubious ownership"), git describe prints nothing, and the version step fails the build. upaas clones as root and is unaffected; other build hosts are not. webhooker, mfer and currentstat.us already work around it.

Fix: in the builder stage, right after git is installed, RUN git config --system --add safe.directory /src, with a one-line comment saying why. Do not change the apk add --no-cache git line itself: whether that install must be pinned is the open owner question on #72.

4. -race cannot work in the test phase

The test phase runs go test -race on golang:1.x-alpine. The race detector needs cgo, and the alpine image has no C compiler, so the flag cannot do what it says. Fix it without adding any new package install: base the test phase on the Debian-based Go image (golang:1.x, pinned by digest like every other base image), which ships a C compiler. Update the image comment above the FROM and any sentence that says the test phase uses alpine.

Definition of done

  • Both fixes are in the example, and every other canonical document that restates the example or its image choice agrees (git grep for alpine, -race and safe.directory under prompts/).
  • Verified by building a throwaway Go module in a scratch directory with the example as written: (a) a context whose files are owned by a different user than the one running git still gets a version; (b) a test with a planted data race fails the test phase, and passes once the race is removed. Record what you ran in the PR only as one line per check, no logs.
  • make check passes.

Model: opus-5-5

Items 1 and 4 of https://git.eeqj.de/sneak/prompts/issues/72, split out so they can land while the pinning question there waits on the owner. Both are defects in the canonical Go `Dockerfile` example in `prompts/REPO_POLICIES.md` (the "gate phases are separate stages" bullet), on `next`. ## 1. git refuses the checkout A build context sent as a tar stream keeps the sender's file owners. git in the build stage then refuses the repository ("detected dubious ownership"), `git describe` prints nothing, and the version step fails the build. upaas clones as root and is unaffected; other build hosts are not. webhooker, mfer and currentstat.us already work around it. Fix: in the builder stage, right after git is installed, `RUN git config --system --add safe.directory /src`, with a one-line comment saying why. Do not change the `apk add --no-cache git` line itself: whether that install must be pinned is the open owner question on https://git.eeqj.de/sneak/prompts/issues/72. ## 4. -race cannot work in the test phase The test phase runs `go test -race` on `golang:1.x-alpine`. The race detector needs cgo, and the alpine image has no C compiler, so the flag cannot do what it says. Fix it without adding any new package install: base the test phase on the Debian-based Go image (`golang:1.x`, pinned by digest like every other base image), which ships a C compiler. Update the image comment above the `FROM` and any sentence that says the test phase uses alpine. ## Definition of done - Both fixes are in the example, and every other canonical document that restates the example or its image choice agrees (`git grep` for `alpine`, `-race` and `safe.directory` under `prompts/`). - Verified by building a throwaway Go module in a scratch directory with the example as written: (a) a context whose files are owned by a different user than the one running git still gets a version; (b) a test with a planted data race fails the test phase, and passes once the race is removed. Record what you ran in the PR only as one line per check, no logs. - `make check` passes. Model: opus-5-5
Author
Collaborator

State for whoever picks this up: a worker started 15:47 UTC on the worker account claude2 (session "issue-to-pr: prompts #73"); nothing pushed yet. Left: its PR against next, then an independent review and a squash-merge. If no PR appears, start a fresh worker from the plan in the issue body.

Model: opus-5-5

State for whoever picks this up: a worker started 15:47 UTC on the worker account `claude2` (session "issue-to-pr: prompts #73"); nothing pushed yet. Left: its PR against `next`, then an independent review and a squash-merge. If no PR appears, start a fresh worker from the plan in the issue body. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/prompts#73