Fix git ownership and -race in the canonical Go Dockerfile (closes #73) #82

Merged
clawbot merged 1 commits from issue-73-dockerfile-safe-directory-race into next 2026-10-04 04:31:51 +02:00
Collaborator

Fixes items 1 and 4 of #72 in the canonical Go Dockerfile example in prompts/REPO_POLICIES.md.

  • Test phase on the Debian Go image. go test -race needs cgo, and the alpine Go image has no C compiler, so the test phase failed with -race requires cgo before running any test. The comment above the FROM says why, and the sentence introducing the example names the Debian Go image.
  • safe.directory in the stage that compiles. A build context sent as a tar stream keeps the sender's file owners; git then refuses the checkout, git describe prints nothing, and the version check fails the build. A docker build . of a directory is unaffected, since its files arrive owned by root. The policy text and both checklists now say this in the same words.

Not changed: the builder's RUN apk add --no-cache git line, whose pinning is the open owner question on #72. The builder stays on the alpine image; only the test phase moved.

Checked on a throwaway Go module with the example as written and real digests: (a) a tar-stream context owned by uid 1000 still gets the git describe version; (b) a planted data race fails the test phase and passes once removed.

Disclosures:

  • Judgement call: the checklists gained the safe.directory sentence because they restate the version-from-git rule; they name no test-phase image, so the Debian change needed nothing there.

Model: opus-5-5

Fixes items 1 and 4 of https://git.eeqj.de/sneak/prompts/issues/72 in the canonical Go `Dockerfile` example in `prompts/REPO_POLICIES.md`. - **Test phase on the Debian Go image.** `go test -race` needs cgo, and the alpine Go image has no C compiler, so the test phase failed with `-race requires cgo` before running any test. The comment above the `FROM` says why, and the sentence introducing the example names the Debian Go image. - **`safe.directory` in the stage that compiles.** A build context sent as a tar stream keeps the sender's file owners; git then refuses the checkout, `git describe` prints nothing, and the version check fails the build. A `docker build .` of a directory is unaffected, since its files arrive owned by root. The policy text and both checklists now say this in the same words. Not changed: the builder's `RUN apk add --no-cache git` line, whose pinning is the open owner question on https://git.eeqj.de/sneak/prompts/issues/72. The builder stays on the alpine image; only the test phase moved. Checked on a throwaway Go module with the example as written and real digests: (a) a tar-stream context owned by uid 1000 still gets the `git describe` version; (b) a planted data race fails the test phase and passes once removed. Disclosures: - Judgement call: the checklists gained the `safe.directory` sentence because they restate the version-from-git rule; they name no test-phase image, so the Debian change needed nothing there. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 01:31:10 +02:00
clawbot self-assigned this 2026-10-04 01:31:10 +02:00
Author
Collaborator

needs-rebase

  • TODO.md, Completed Steps: the branch conflicts with current next, which added its own 2026-10-03 entry at the top of that list (for #65), so the PR cannot be merged as it stands. Acceptable: rebase onto current next, keep both entries with this one on top, and change nothing else.

Model: opus-5-5

`needs-rebase` - `TODO.md`, Completed Steps: the branch conflicts with current `next`, which added its own 2026-10-03 entry at the top of that list (for https://git.eeqj.de/sneak/prompts/issues/65), so the PR cannot be merged as it stands. Acceptable: rebase onto current `next`, keep both entries with this one on top, and change nothing else. Model: opus-5-5
clawbot added needs-rebase and removed needs-review labels 2026-10-04 03:43:35 +02:00
clawbot added 1 commit 2026-10-04 03:52:31 +02:00
The test phase ran go test -race on the alpine Go image, which has no C
compiler, so cgo was off and the phase failed with "-race requires cgo"
before running a test. It now uses the Debian Go image.

A build context sent as a tar stream keeps the sender's file owners, so
git in the stage that compiles refused the checkout and the version came
out empty. That stage now runs
git config --system --add safe.directory /src, and the policy text and
both checklists say why. The apk add --no-cache git line is unchanged:
its pinning waits on #72.

Model: opus-5-5
clawbot force-pushed issue-73-dockerfile-safe-directory-race from 581dfa3b15 to 562de69ab6 2026-10-04 03:52:31 +02:00 Compare
clawbot added needs-review and removed needs-rebase labels 2026-10-04 03:52:34 +02:00
Author
Collaborator

Rebased onto current next; resolved the TODO.md Completed Steps conflict by keeping both entries, this one above the entry for #65; nothing else changed.

Model: opus-5-5

Rebased onto current `next`; resolved the `TODO.md` Completed Steps conflict by keeping both entries, this one above the entry for https://git.eeqj.de/sneak/prompts/issues/65; nothing else changed. Model: opus-5-5
Author
Collaborator

PASS: the rebased change fixes both defects named in #73 as its definition of done asks, and resolves the TODO.md conflict by keeping both entries with this one on top.

Model: opus-5-5

PASS: the rebased change fixes both defects named in https://git.eeqj.de/sneak/prompts/issues/73 as its definition of done asks, and resolves the `TODO.md` conflict by keeping both entries with this one on top. Model: opus-5-5
clawbot merged commit dcc0ba0b66 into next 2026-10-04 04:31:51 +02:00
clawbot deleted branch issue-73-dockerfile-safe-directory-race 2026-10-04 04:31:52 +02:00
Sign in to join this conversation.