Items 1 and 4 of #72, split out so they can land while the pinning question there waits on the owner. Both are defects in the canonical Go Dockerfile example in prompts/REPO_POLICIES.md (the "gate phases are separate stages" bullet), on next.
1. git refuses the checkout
A build context sent as a tar stream keeps the sender's file owners. git in the build stage then refuses the repository ("detected dubious ownership"), git describe prints nothing, and the version step fails the build. upaas clones as root and is unaffected; other build hosts are not. webhooker, mfer and currentstat.us already work around it.
Fix: in the builder stage, right after git is installed, RUN git config --system --add safe.directory /src, with a one-line comment saying why. Do not change the apk add --no-cache git line itself: whether that install must be pinned is the open owner question on #72.
4. -race cannot work in the test phase
The test phase runs go test -race on golang:1.x-alpine. The race detector needs cgo, and the alpine image has no C compiler, so the flag cannot do what it says. Fix it without adding any new package install: base the test phase on the Debian-based Go image (golang:1.x, pinned by digest like every other base image), which ships a C compiler. Update the image comment above the FROM and any sentence that says the test phase uses alpine.
Definition of done
Both fixes are in the example, and every other canonical document that restates the example or its image choice agrees (git grep for alpine, -race and safe.directory under prompts/).
Verified by building a throwaway Go module in a scratch directory with the example as written: (a) a context whose files are owned by a different user than the one running git still gets a version; (b) a test with a planted data race fails the test phase, and passes once the race is removed. Record what you ran in the PR only as one line per check, no logs.
make check passes.
Model: opus-5-5
Items 1 and 4 of https://git.eeqj.de/sneak/prompts/issues/72, split out so they can land while the pinning question there waits on the owner. Both are defects in the canonical Go `Dockerfile` example in `prompts/REPO_POLICIES.md` (the "gate phases are separate stages" bullet), on `next`.
## 1. git refuses the checkout
A build context sent as a tar stream keeps the sender's file owners. git in the build stage then refuses the repository ("detected dubious ownership"), `git describe` prints nothing, and the version step fails the build. upaas clones as root and is unaffected; other build hosts are not. webhooker, mfer and currentstat.us already work around it.
Fix: in the builder stage, right after git is installed, `RUN git config --system --add safe.directory /src`, with a one-line comment saying why. Do not change the `apk add --no-cache git` line itself: whether that install must be pinned is the open owner question on https://git.eeqj.de/sneak/prompts/issues/72.
## 4. -race cannot work in the test phase
The test phase runs `go test -race` on `golang:1.x-alpine`. The race detector needs cgo, and the alpine image has no C compiler, so the flag cannot do what it says. Fix it without adding any new package install: base the test phase on the Debian-based Go image (`golang:1.x`, pinned by digest like every other base image), which ships a C compiler. Update the image comment above the `FROM` and any sentence that says the test phase uses alpine.
## Definition of done
- Both fixes are in the example, and every other canonical document that restates the example or its image choice agrees (`git grep` for `alpine`, `-race` and `safe.directory` under `prompts/`).
- Verified by building a throwaway Go module in a scratch directory with the example as written: (a) a context whose files are owned by a different user than the one running git still gets a version; (b) a test with a planted data race fails the test phase, and passes once the race is removed. Record what you ran in the PR only as one line per check, no logs.
- `make check` passes.
Model: opus-5-5
State for whoever picks this up: a worker started 15:47 UTC on the worker account claude2 (session "issue-to-pr: prompts #73"); nothing pushed yet. Left: its PR against next, then an independent review and a squash-merge. If no PR appears, start a fresh worker from the plan in the issue body.
Model: opus-5-5
State for whoever picks this up: a worker started 15:47 UTC on the worker account `claude2` (session "issue-to-pr: prompts #73"); nothing pushed yet. Left: its PR against `next`, then an independent review and a squash-merge. If no PR appears, start a fresh worker from the plan in the issue body.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Items 1 and 4 of #72, split out so they can land while the pinning question there waits on the owner. Both are defects in the canonical Go
Dockerfileexample inprompts/REPO_POLICIES.md(the "gate phases are separate stages" bullet), onnext.1. git refuses the checkout
A build context sent as a tar stream keeps the sender's file owners. git in the build stage then refuses the repository ("detected dubious ownership"),
git describeprints nothing, and the version step fails the build. upaas clones as root and is unaffected; other build hosts are not. webhooker, mfer and currentstat.us already work around it.Fix: in the builder stage, right after git is installed,
RUN git config --system --add safe.directory /src, with a one-line comment saying why. Do not change theapk add --no-cache gitline itself: whether that install must be pinned is the open owner question on #72.4. -race cannot work in the test phase
The test phase runs
go test -raceongolang:1.x-alpine. The race detector needs cgo, and the alpine image has no C compiler, so the flag cannot do what it says. Fix it without adding any new package install: base the test phase on the Debian-based Go image (golang:1.x, pinned by digest like every other base image), which ships a C compiler. Update the image comment above theFROMand any sentence that says the test phase uses alpine.Definition of done
git grepforalpine,-raceandsafe.directoryunderprompts/).make checkpasses.Model: opus-5-5
State for whoever picks this up: a worker started 15:47 UTC on the worker account
claude2(session "issue-to-pr: prompts #73"); nothing pushed yet. Left: its PR againstnext, then an independent review and a squash-merge. If no PR appears, start a fresh worker from the plan in the issue body.Model: opus-5-5