Fixes items 1 and 4 of #72 in the canonical Go Dockerfile example in prompts/REPO_POLICIES.md.
Test phase on the Debian Go image.go test -race needs cgo, and the alpine Go image has no C compiler, so the test phase failed with -race requires cgo before running any test. The comment above the FROM says why, and the sentence introducing the example names the Debian Go image.
safe.directory in the stage that compiles. A build context sent as a tar stream keeps the sender's file owners; git then refuses the checkout, git describe prints nothing, and the version check fails the build. A docker build . of a directory is unaffected, since its files arrive owned by root. The policy text and both checklists now say this in the same words.
Not changed: the builder's RUN apk add --no-cache git line, whose pinning is the open owner question on #72. The builder stays on the alpine image; only the test phase moved.
Checked on a throwaway Go module with the example as written and real digests: (a) a tar-stream context owned by uid 1000 still gets the git describe version; (b) a planted data race fails the test phase and passes once removed.
Disclosures:
Judgement call: the checklists gained the safe.directory sentence because they restate the version-from-git rule; they name no test-phase image, so the Debian change needed nothing there.
Partly verified: make check has not run on this commit. The worker's account hit its weekly limit while waiting for the shared build lock, and the manager pushed the branch and opened this PR from the worker's draft.
Model: opus-5-5
Fixes items 1 and 4 of https://git.eeqj.de/sneak/prompts/issues/72 in the canonical Go `Dockerfile` example in `prompts/REPO_POLICIES.md`.
- **Test phase on the Debian Go image.** `go test -race` needs cgo, and the alpine Go image has no C compiler, so the test phase failed with `-race requires cgo` before running any test. The comment above the `FROM` says why, and the sentence introducing the example names the Debian Go image.
- **`safe.directory` in the stage that compiles.** A build context sent as a tar stream keeps the sender's file owners; git then refuses the checkout, `git describe` prints nothing, and the version check fails the build. A `docker build .` of a directory is unaffected, since its files arrive owned by root. The policy text and both checklists now say this in the same words.
Not changed: the builder's `RUN apk add --no-cache git` line, whose pinning is the open owner question on https://git.eeqj.de/sneak/prompts/issues/72. The builder stays on the alpine image; only the test phase moved.
Checked on a throwaway Go module with the example as written and real digests: (a) a tar-stream context owned by uid 1000 still gets the `git describe` version; (b) a planted data race fails the test phase and passes once removed.
Disclosures:
- Judgement call: the checklists gained the `safe.directory` sentence because they restate the version-from-git rule; they name no test-phase image, so the Debian change needed nothing there.
- Partly verified: `make check` has not run on this commit. The worker's account hit its weekly limit while waiting for the shared build lock, and the manager pushed the branch and opened this PR from the worker's draft.
Model: opus-5-5
The test phase ran go test -race on the alpine Go image, which has no C
compiler, so cgo was off and the phase failed with "-race requires cgo"
before running a test. It now uses the Debian Go image.
A build context sent as a tar stream keeps the sender's file owners, so
git in the stage that compiles refused the checkout and the version came
out empty. That stage now runs
git config --system --add safe.directory /src, and the policy text and
both checklists say why. The apk add --no-cache git line is unchanged:
its pinning waits on #72.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Fixes items 1 and 4 of #72 in the canonical Go
Dockerfileexample inprompts/REPO_POLICIES.md.go test -raceneeds cgo, and the alpine Go image has no C compiler, so the test phase failed with-race requires cgobefore running any test. The comment above theFROMsays why, and the sentence introducing the example names the Debian Go image.safe.directoryin the stage that compiles. A build context sent as a tar stream keeps the sender's file owners; git then refuses the checkout,git describeprints nothing, and the version check fails the build. Adocker build .of a directory is unaffected, since its files arrive owned by root. The policy text and both checklists now say this in the same words.Not changed: the builder's
RUN apk add --no-cache gitline, whose pinning is the open owner question on #72. The builder stays on the alpine image; only the test phase moved.Checked on a throwaway Go module with the example as written and real digests: (a) a tar-stream context owned by uid 1000 still gets the
git describeversion; (b) a planted data race fails the test phase and passes once removed.Disclosures:
safe.directorysentence because they restate the version-from-git rule; they name no test-phase image, so the Debian change needed nothing there.make checkhas not run on this commit. The worker's account hit its weekly limit while waiting for the shared build lock, and the manager pushed the branch and opened this PR from the worker's draft.Model: opus-5-5
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.