The canonical .dockerignore kept out .git/config and the configs under .git/modules/. But a submodule that keeps its own .git directory (one added from a repository already in the tree) still shipped sub/.git/config, credential included. Both git patterns now start with **/: **/.git/config and **/.git/modules/**/config.
A submodule whose name has a config segment (config, deploy/config, config/lib) still loses its whole git directory, because the pattern also matches that segment's directory under .git/modules/. Go's version stamping then fails the build. The file records this as a KNOWN GAP: with the fix: give the submodule a name without that segment (git submodule add --name). REPO_POLICIES.md and both checklists say the same.
Checked by enumerating images built from scratch repositories, a stand-in credential in every config. They had a submodule with its own submodule, a submodule keeping its own .git directory with its own submodule, and submodules at deploy/config, config/lib and a/config/b.
No stand-in credential and no git config file anywhere in the image.
With the default name at deploy/config, config/lib or a/config/b, git describe --tags --always works and Go's version stamping fails the build, as the gap says.
With a --name lacking the segment at the same paths, both work.
Control with the file from next: both configs of the submodule that keeps its own .git directory arrived.
Judgement call: the config case is left as a known gap. Closing it takes a re-include with wildcards plus a re-exclude, and any re-include with wildcards makes BuildKit walk every excluded directory, node_modules included, on every build.
Model: opus-5-5
Closes https://git.eeqj.de/sneak/prompts/issues/88, left over from https://git.eeqj.de/sneak/prompts/pulls/85.
The canonical `.dockerignore` kept out `.git/config` and the configs under `.git/modules/`. But a submodule that keeps its own `.git` directory (one added from a repository already in the tree) still shipped `sub/.git/config`, credential included. Both git patterns now start with `**/`: `**/.git/config` and `**/.git/modules/**/config`.
A submodule whose name has a `config` segment (`config`, `deploy/config`, `config/lib`) still loses its whole git directory, because the pattern also matches that segment's directory under `.git/modules/`. Go's version stamping then fails the build. The file records this as a `KNOWN GAP:` with the fix: give the submodule a name without that segment (`git submodule add --name`). `REPO_POLICIES.md` and both checklists say the same.
Checked by enumerating images built from scratch repositories, a stand-in credential in every config. They had a submodule with its own submodule, a submodule keeping its own `.git` directory with its own submodule, and submodules at `deploy/config`, `config/lib` and `a/config/b`.
- No stand-in credential and no git `config` file anywhere in the image.
- With the default name at `deploy/config`, `config/lib` or `a/config/b`, `git describe --tags --always` works and Go's version stamping fails the build, as the gap says.
- With a `--name` lacking the segment at the same paths, both work.
- Control with the file from `next`: both configs of the submodule that keeps its own `.git` directory arrived.
Judgement call: the `config` case is left as a known gap. Closing it takes a re-include with wildcards plus a re-exclude, and any re-include with wildcards makes BuildKit walk every excluded directory, `node_modules` included, on every build.
Model: opus-5-5
Conflicts with current next in TODO.md (Completed Steps) and in prompts/REPO_POLICIES.md, where the lint-phase bullet just above the .dockerignore bullet was rewritten for #83. Acceptable: rebase onto next, keeping its apt-get bullet unchanged and every Completed Steps entry newest first.
The known gap is described too narrowly. .dockerignore line 24, prompts/REPO_POLICIES.md line 256, prompts/EXISTING_REPO_CHECKLIST.md line 71, prompts/NEW_REPO_CHECKLIST.md line 79 and TODO.md line 27 say it hits a submodule named config or deploy/config. It hits any submodule whose name has a config segment anywhere, such as config/lib or a/config/b: **/.git/modules/**/config matches the config directory on the way to that submodule's git directory, so everything below it stays out and Go's version stamping fails the build. Someone with a submodule named config/lib reads that they are not affected. Acceptable: the same words in all five places, for example "a submodule whose name has a config segment (config, deploy/config, config/lib)".
The fix for a submodule that keeps its own .git directory, and the decision to leave the config case as a known gap, both hold up.
Judgement call: gated a local rebase onto next with both conflicts resolved by hand.
Model: opus-5-5
FAIL: needs rework.
1. Conflicts with current `next` in `TODO.md` (Completed Steps) and in `prompts/REPO_POLICIES.md`, where the lint-phase bullet just above the `.dockerignore` bullet was rewritten for https://git.eeqj.de/sneak/prompts/issues/83. Acceptable: rebase onto `next`, keeping its `apt-get` bullet unchanged and every Completed Steps entry newest first.
2. The known gap is described too narrowly. `.dockerignore` line 24, `prompts/REPO_POLICIES.md` line 256, `prompts/EXISTING_REPO_CHECKLIST.md` line 71, `prompts/NEW_REPO_CHECKLIST.md` line 79 and `TODO.md` line 27 say it hits a submodule named `config` or `deploy/config`. It hits any submodule whose name has a `config` segment anywhere, such as `config/lib` or `a/config/b`: `**/.git/modules/**/config` matches the `config` directory on the way to that submodule's git directory, so everything below it stays out and Go's version stamping fails the build. Someone with a submodule named `config/lib` reads that they are not affected. Acceptable: the same words in all five places, for example "a submodule whose name has a `config` segment (`config`, `deploy/config`, `config/lib`)".
The fix for a submodule that keeps its own `.git` directory, and the decision to leave the `config` case as a known gap, both hold up.
Judgement call: gated a local rebase onto `next` with both conflicts resolved by hand.
Model: opus-5-5
The canonical .dockerignore kept out .git/config and the configs under
.git/modules/, but not the config of a submodule that keeps its own .git
directory, so its credential reached the image. Both git patterns now
carry the **/ prefix.
A submodule whose name has a config segment (config, deploy/config,
config/lib) still loses its whole git directory, and Go's version
stamping fails the build. Closing that needs a wildcard re-include,
which makes BuildKit walk every excluded directory on every build, so
the file records it as a KNOWN GAP with the remedy, git submodule add
--name. REPO_POLICIES.md and both checklists say the same.
Model: opus-5-5
Rebased onto next; its apt-get bullet is unchanged and this branch's Completed Steps entry is on top.
All five places now say "a submodule whose name has a config segment (config, deploy/config, config/lib)"; scratch builds confirm the gap for config/lib and a/config/b and that git submodule add --name without the segment fixes both. PR body updated to match.
Model: opus-5-5
1. Rebased onto `next`; its `apt-get` bullet is unchanged and this branch's Completed Steps entry is on top.
2. All five places now say "a submodule whose name has a `config` segment (`config`, `deploy/config`, `config/lib`)"; scratch builds confirm the gap for `config/lib` and `a/config/b` and that `git submodule add --name` without the segment fixes both. PR body updated to match.
Model: opus-5-5
PASS: both findings of the previous review are fixed, and the change meets the definition of done of #88.
Judgement call: the PR body runs slightly over about 250 words; taken as within the limit.
Model: opus-5-5
PASS: both findings of the previous review are fixed, and the change meets the definition of done of https://git.eeqj.de/sneak/prompts/issues/88.
Judgement call: the PR body runs slightly over about 250 words; taken as within the limit.
Model: opus-5-5
clawbot
merged commit 61a9afbb4f into next2026-10-04 12:48:56 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #88, left over from #85.
The canonical
.dockerignorekept out.git/configand the configs under.git/modules/. But a submodule that keeps its own.gitdirectory (one added from a repository already in the tree) still shippedsub/.git/config, credential included. Both git patterns now start with**/:**/.git/configand**/.git/modules/**/config.A submodule whose name has a
configsegment (config,deploy/config,config/lib) still loses its whole git directory, because the pattern also matches that segment's directory under.git/modules/. Go's version stamping then fails the build. The file records this as aKNOWN GAP:with the fix: give the submodule a name without that segment (git submodule add --name).REPO_POLICIES.mdand both checklists say the same.Checked by enumerating images built from scratch repositories, a stand-in credential in every config. They had a submodule with its own submodule, a submodule keeping its own
.gitdirectory with its own submodule, and submodules atdeploy/config,config/libanda/config/b.configfile anywhere in the image.deploy/config,config/libora/config/b,git describe --tags --alwaysworks and Go's version stamping fails the build, as the gap says.--namelacking the segment at the same paths, both work.next: both configs of the submodule that keeps its own.gitdirectory arrived.Judgement call: the
configcase is left as a known gap. Closing it takes a re-include with wildcards plus a re-exclude, and any re-include with wildcards makes BuildKit walk every excluded directory,node_modulesincluded, on every build.Model: opus-5-5
FAIL: needs rework.
Conflicts with current
nextinTODO.md(Completed Steps) and inprompts/REPO_POLICIES.md, where the lint-phase bullet just above the.dockerignorebullet was rewritten for #83. Acceptable: rebase ontonext, keeping itsapt-getbullet unchanged and every Completed Steps entry newest first.The known gap is described too narrowly.
.dockerignoreline 24,prompts/REPO_POLICIES.mdline 256,prompts/EXISTING_REPO_CHECKLIST.mdline 71,prompts/NEW_REPO_CHECKLIST.mdline 79 andTODO.mdline 27 say it hits a submodule namedconfigordeploy/config. It hits any submodule whose name has aconfigsegment anywhere, such asconfig/libora/config/b:**/.git/modules/**/configmatches theconfigdirectory on the way to that submodule's git directory, so everything below it stays out and Go's version stamping fails the build. Someone with a submodule namedconfig/libreads that they are not affected. Acceptable: the same words in all five places, for example "a submodule whose name has aconfigsegment (config,deploy/config,config/lib)".The fix for a submodule that keeps its own
.gitdirectory, and the decision to leave theconfigcase as a known gap, both hold up.Judgement call: gated a local rebase onto
nextwith both conflicts resolved by hand.Model: opus-5-5
73bbe8f736to44ef6d4158next; itsapt-getbullet is unchanged and this branch's Completed Steps entry is on top.configsegment (config,deploy/config,config/lib)"; scratch builds confirm the gap forconfig/libanda/config/band thatgit submodule add --namewithout the segment fixes both. PR body updated to match.Model: opus-5-5
PASS: both findings of the previous review are fixed, and the change meets the definition of done of #88.
Judgement call: the PR body runs slightly over about 250 words; taken as within the limit.
Model: opus-5-5