Fix git ownership and -race in the canonical Go Dockerfile (closes #73) #82

Open
clawbot wants to merge 1 commits from issue-73-dockerfile-safe-directory-race into next
Collaborator

Fixes items 1 and 4 of #72 in the canonical Go Dockerfile example in prompts/REPO_POLICIES.md.

  • Test phase on the Debian Go image. go test -race needs cgo, and the alpine Go image has no C compiler, so the test phase failed with -race requires cgo before running any test. The comment above the FROM says why, and the sentence introducing the example names the Debian Go image.
  • safe.directory in the stage that compiles. A build context sent as a tar stream keeps the sender's file owners; git then refuses the checkout, git describe prints nothing, and the version check fails the build. A docker build . of a directory is unaffected, since its files arrive owned by root. The policy text and both checklists now say this in the same words.

Not changed: the builder's RUN apk add --no-cache git line, whose pinning is the open owner question on #72. The builder stays on the alpine image; only the test phase moved.

Checked on a throwaway Go module with the example as written and real digests: (a) a tar-stream context owned by uid 1000 still gets the git describe version; (b) a planted data race fails the test phase and passes once removed.

Disclosures:

  • Judgement call: the checklists gained the safe.directory sentence because they restate the version-from-git rule; they name no test-phase image, so the Debian change needed nothing there.
  • Partly verified: make check has not run on this commit. The worker's account hit its weekly limit while waiting for the shared build lock, and the manager pushed the branch and opened this PR from the worker's draft.

Model: opus-5-5

Fixes items 1 and 4 of https://git.eeqj.de/sneak/prompts/issues/72 in the canonical Go `Dockerfile` example in `prompts/REPO_POLICIES.md`. - **Test phase on the Debian Go image.** `go test -race` needs cgo, and the alpine Go image has no C compiler, so the test phase failed with `-race requires cgo` before running any test. The comment above the `FROM` says why, and the sentence introducing the example names the Debian Go image. - **`safe.directory` in the stage that compiles.** A build context sent as a tar stream keeps the sender's file owners; git then refuses the checkout, `git describe` prints nothing, and the version check fails the build. A `docker build .` of a directory is unaffected, since its files arrive owned by root. The policy text and both checklists now say this in the same words. Not changed: the builder's `RUN apk add --no-cache git` line, whose pinning is the open owner question on https://git.eeqj.de/sneak/prompts/issues/72. The builder stays on the alpine image; only the test phase moved. Checked on a throwaway Go module with the example as written and real digests: (a) a tar-stream context owned by uid 1000 still gets the `git describe` version; (b) a planted data race fails the test phase and passes once removed. Disclosures: - Judgement call: the checklists gained the `safe.directory` sentence because they restate the version-from-git rule; they name no test-phase image, so the Debian change needed nothing there. - Partly verified: `make check` has not run on this commit. The worker's account hit its weekly limit while waiting for the shared build lock, and the manager pushed the branch and opened this PR from the worker's draft. Model: opus-5-5
clawbot added 1 commit 2026-10-03 18:25:50 +02:00
The test phase ran go test -race on the alpine Go image, which has no C
compiler, so cgo was off and the phase failed with "-race requires cgo"
before running a test. It now uses the Debian Go image.

A build context sent as a tar stream keeps the sender's file owners, so
git in the stage that compiles refused the checkout and the version came
out empty. That stage now runs
git config --system --add safe.directory /src, and the policy text and
both checklists say why. The apk add --no-cache git line is unchanged:
its pinning waits on #72.

Model: opus-5-5
clawbot added the needs-review label 2026-10-04 01:31:10 +02:00
clawbot self-assigned this 2026-10-04 01:31:10 +02:00
All checks were successful
check / check (push) Successful in 26s
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin issue-73-dockerfile-safe-directory-race:issue-73-dockerfile-safe-directory-race
git checkout issue-73-dockerfile-safe-directory-race
Sign in to join this conversation.