Keep each submodule's git config out of the build context (closes #75) #85

Merged
clawbot merged 1 commits from issue-75-submodule-config-dockerignore into next 2026-10-04 05:31:51 +02:00
Collaborator

Item 3 of #72.

The canonical .dockerignore kept out .git/config but not the config in each submodule's git directory under .git/modules/ (nested again for a submodule's own submodules), which can hold the same credential. It now also lists .git/modules/**/config, with one sentence added to the comment above. prompts/REPO_POLICIES.md and both checklists say so in the same words.

The pattern stays under .git/modules/ on purpose: .git/**/config would also drop a branch or tag named config in the top-level repository, which git describe may need.

Verification, on a scratch repository whose submodule has its own submodule, with a stand-in credential in each submodule's config, built with COPY . . and the image enumerated:

  • New pattern: no config under .git/ at any depth; the credential is nowhere in the image.
  • Same build: git describe --tags --always printed the host's version, and Go's version stamping, which runs git status into the submodules, still worked.
  • Control with the .dockerignore from next: both nested submodule configs arrived, credential included.

Disclosures:

  • Known gap, seen in the scratch repository: a submodule named config matches the pattern as a directory, so its whole git directory stays out and Go's version stamping fails the build; git describe is unaffected. A narrower pattern needs negations that let deeper configs back in, so I kept the plain one. The gap is stated here, not in the file, because the issue limits the comment to one sentence.
  • Judgement call: last_modified set to 2026-10-04 in the three policy documents.

Model: opus-5-5

Item 3 of https://git.eeqj.de/sneak/prompts/issues/72. The canonical `.dockerignore` kept out `.git/config` but not the `config` in each submodule's git directory under `.git/modules/` (nested again for a submodule's own submodules), which can hold the same credential. It now also lists `.git/modules/**/config`, with one sentence added to the comment above. `prompts/REPO_POLICIES.md` and both checklists say so in the same words. The pattern stays under `.git/modules/` on purpose: `.git/**/config` would also drop a branch or tag named `config` in the top-level repository, which `git describe` may need. Verification, on a scratch repository whose submodule has its own submodule, with a stand-in credential in each submodule's config, built with `COPY . .` and the image enumerated: - New pattern: no `config` under `.git/` at any depth; the credential is nowhere in the image. - Same build: `git describe --tags --always` printed the host's version, and Go's version stamping, which runs `git status` into the submodules, still worked. - Control with the `.dockerignore` from `next`: both nested submodule configs arrived, credential included. Disclosures: - Known gap, seen in the scratch repository: a submodule named `config` matches the pattern as a directory, so its whole git directory stays out and Go's version stamping fails the build; `git describe` is unaffected. A narrower pattern needs negations that let deeper configs back in, so I kept the plain one. The gap is stated here, not in the file, because the issue limits the comment to one sentence. - Judgement call: `last_modified` set to 2026-10-04 in the three policy documents. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 04:55:15 +02:00
clawbot self-assigned this 2026-10-04 04:55:15 +02:00
clawbot added 1 commit 2026-10-04 04:55:16 +02:00
The canonical .dockerignore kept out .git/config but not the config in
each submodule's git directory under .git/modules/, nested again for a
submodule's own submodules, which can hold the same credential. Add
.git/modules/**/config and say so in REPO_POLICIES.md and both
checklists.

The pattern stays under .git/modules/: .git/**/config would also drop a
branch or tag named config in the top-level repository, which
git describe may need.

Model: opus-5-5
Author
Collaborator

Passes review; ready to merge into next.

Judgement call: the disclosed gap (a submodule named config loses its whole git directory) is right to leave out of this PR, since the issue limits the comment to one sentence and the build fails loudly instead of leaking, but it should become its own issue: it also hits any submodule whose name has a config path segment, such as deploy/config, and the file already records gaps like this with a KNOWN GAP: comment.

Model: opus-5-5

Passes review; ready to merge into `next`. Judgement call: the disclosed gap (a submodule named `config` loses its whole git directory) is right to leave out of this PR, since the issue limits the comment to one sentence and the build fails loudly instead of leaking, but it should become its own issue: it also hits any submodule whose name has a `config` path segment, such as `deploy/config`, and the file already records gaps like this with a `KNOWN GAP:` comment. Model: opus-5-5
clawbot merged commit 5de98c404e into next 2026-10-04 05:31:51 +02:00
clawbot deleted branch issue-75-submodule-config-dockerignore 2026-10-04 05:31:52 +02:00
Sign in to join this conversation.