Keep a submodule's own .git/config out of the build context (closes #88) #96

Merged
clawbot merged 1 commits from issue-88-submodule-git-config into next 2026-10-04 12:48:56 +02:00
Collaborator

Closes #88, left over from #85.

The canonical .dockerignore kept out .git/config and the configs under .git/modules/. But a submodule that keeps its own .git directory (one added from a repository already in the tree) still shipped sub/.git/config, credential included. Both git patterns now start with **/: **/.git/config and **/.git/modules/**/config.

A submodule whose name has a config segment (config, deploy/config, config/lib) still loses its whole git directory, because the pattern also matches that segment's directory under .git/modules/. Go's version stamping then fails the build. The file records this as a KNOWN GAP: with the fix: give the submodule a name without that segment (git submodule add --name). REPO_POLICIES.md and both checklists say the same.

Checked by enumerating images built from scratch repositories, a stand-in credential in every config. They had a submodule with its own submodule, a submodule keeping its own .git directory with its own submodule, and submodules at deploy/config, config/lib and a/config/b.

  • No stand-in credential and no git config file anywhere in the image.
  • With the default name at deploy/config, config/lib or a/config/b, git describe --tags --always works and Go's version stamping fails the build, as the gap says.
  • With a --name lacking the segment at the same paths, both work.
  • Control with the file from next: both configs of the submodule that keeps its own .git directory arrived.

Judgement call: the config case is left as a known gap. Closing it takes a re-include with wildcards plus a re-exclude, and any re-include with wildcards makes BuildKit walk every excluded directory, node_modules included, on every build.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/prompts/issues/88, left over from https://git.eeqj.de/sneak/prompts/pulls/85. The canonical `.dockerignore` kept out `.git/config` and the configs under `.git/modules/`. But a submodule that keeps its own `.git` directory (one added from a repository already in the tree) still shipped `sub/.git/config`, credential included. Both git patterns now start with `**/`: `**/.git/config` and `**/.git/modules/**/config`. A submodule whose name has a `config` segment (`config`, `deploy/config`, `config/lib`) still loses its whole git directory, because the pattern also matches that segment's directory under `.git/modules/`. Go's version stamping then fails the build. The file records this as a `KNOWN GAP:` with the fix: give the submodule a name without that segment (`git submodule add --name`). `REPO_POLICIES.md` and both checklists say the same. Checked by enumerating images built from scratch repositories, a stand-in credential in every config. They had a submodule with its own submodule, a submodule keeping its own `.git` directory with its own submodule, and submodules at `deploy/config`, `config/lib` and `a/config/b`. - No stand-in credential and no git `config` file anywhere in the image. - With the default name at `deploy/config`, `config/lib` or `a/config/b`, `git describe --tags --always` works and Go's version stamping fails the build, as the gap says. - With a `--name` lacking the segment at the same paths, both work. - Control with the file from `next`: both configs of the submodule that keeps its own `.git` directory arrived. Judgement call: the `config` case is left as a known gap. Closing it takes a re-include with wildcards plus a re-exclude, and any re-include with wildcards makes BuildKit walk every excluded directory, `node_modules` included, on every build. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 10:34:51 +02:00
clawbot self-assigned this 2026-10-04 10:34:51 +02:00
Author
Collaborator

FAIL: needs rework.

  1. Conflicts with current next in TODO.md (Completed Steps) and in prompts/REPO_POLICIES.md, where the lint-phase bullet just above the .dockerignore bullet was rewritten for #83. Acceptable: rebase onto next, keeping its apt-get bullet unchanged and every Completed Steps entry newest first.

  2. The known gap is described too narrowly. .dockerignore line 24, prompts/REPO_POLICIES.md line 256, prompts/EXISTING_REPO_CHECKLIST.md line 71, prompts/NEW_REPO_CHECKLIST.md line 79 and TODO.md line 27 say it hits a submodule named config or deploy/config. It hits any submodule whose name has a config segment anywhere, such as config/lib or a/config/b: **/.git/modules/**/config matches the config directory on the way to that submodule's git directory, so everything below it stays out and Go's version stamping fails the build. Someone with a submodule named config/lib reads that they are not affected. Acceptable: the same words in all five places, for example "a submodule whose name has a config segment (config, deploy/config, config/lib)".

The fix for a submodule that keeps its own .git directory, and the decision to leave the config case as a known gap, both hold up.

Judgement call: gated a local rebase onto next with both conflicts resolved by hand.

Model: opus-5-5

FAIL: needs rework. 1. Conflicts with current `next` in `TODO.md` (Completed Steps) and in `prompts/REPO_POLICIES.md`, where the lint-phase bullet just above the `.dockerignore` bullet was rewritten for https://git.eeqj.de/sneak/prompts/issues/83. Acceptable: rebase onto `next`, keeping its `apt-get` bullet unchanged and every Completed Steps entry newest first. 2. The known gap is described too narrowly. `.dockerignore` line 24, `prompts/REPO_POLICIES.md` line 256, `prompts/EXISTING_REPO_CHECKLIST.md` line 71, `prompts/NEW_REPO_CHECKLIST.md` line 79 and `TODO.md` line 27 say it hits a submodule named `config` or `deploy/config`. It hits any submodule whose name has a `config` segment anywhere, such as `config/lib` or `a/config/b`: `**/.git/modules/**/config` matches the `config` directory on the way to that submodule's git directory, so everything below it stays out and Go's version stamping fails the build. Someone with a submodule named `config/lib` reads that they are not affected. Acceptable: the same words in all five places, for example "a submodule whose name has a `config` segment (`config`, `deploy/config`, `config/lib`)". The fix for a submodule that keeps its own `.git` directory, and the decision to leave the `config` case as a known gap, both hold up. Judgement call: gated a local rebase onto `next` with both conflicts resolved by hand. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-04 12:01:21 +02:00
clawbot added 1 commit 2026-10-04 12:08:31 +02:00
The canonical .dockerignore kept out .git/config and the configs under
.git/modules/, but not the config of a submodule that keeps its own .git
directory, so its credential reached the image. Both git patterns now
carry the **/ prefix.

A submodule whose name has a config segment (config, deploy/config,
config/lib) still loses its whole git directory, and Go's version
stamping fails the build. Closing that needs a wildcard re-include,
which makes BuildKit walk every excluded directory on every build, so
the file records it as a KNOWN GAP with the remedy, git submodule add
--name. REPO_POLICIES.md and both checklists say the same.

Model: opus-5-5
clawbot force-pushed issue-88-submodule-git-config from 73bbe8f736 to 44ef6d4158 2026-10-04 12:08:31 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-04 12:08:53 +02:00
Author
Collaborator
  1. Rebased onto next; its apt-get bullet is unchanged and this branch's Completed Steps entry is on top.
  2. All five places now say "a submodule whose name has a config segment (config, deploy/config, config/lib)"; scratch builds confirm the gap for config/lib and a/config/b and that git submodule add --name without the segment fixes both. PR body updated to match.

Model: opus-5-5

1. Rebased onto `next`; its `apt-get` bullet is unchanged and this branch's Completed Steps entry is on top. 2. All five places now say "a submodule whose name has a `config` segment (`config`, `deploy/config`, `config/lib`)"; scratch builds confirm the gap for `config/lib` and `a/config/b` and that `git submodule add --name` without the segment fixes both. PR body updated to match. Model: opus-5-5
Author
Collaborator

PASS: both findings of the previous review are fixed, and the change meets the definition of done of #88.

Judgement call: the PR body runs slightly over about 250 words; taken as within the limit.

Model: opus-5-5

PASS: both findings of the previous review are fixed, and the change meets the definition of done of https://git.eeqj.de/sneak/prompts/issues/88. Judgement call: the PR body runs slightly over about 250 words; taken as within the limit. Model: opus-5-5
clawbot merged commit 61a9afbb4f into next 2026-10-04 12:48:56 +02:00
clawbot deleted branch issue-88-submodule-git-config 2026-10-04 12:48:56 +02:00
Sign in to join this conversation.