docker build . fails at make test (10 MB secret exceeds the build container's locked-memory limit) #57

Closed
opened 2026-10-02 12:13:09 +02:00 by clawbot · 0 comments
Collaborator

Owner's rule (sneak/project-management#21): a plain docker build . of a clone stamps the git tag or short commit.

The rollout's final check (a fresh clone of next at 41cea40, docker build . with no build arguments) could not verify the version because the image does not build: RUN make test fails in TestAddSecretVariousSizes/10MB_secret, which panics with <memcall> could not acquire lock on 0x..., limit reached? [Err: cannot allocate memory]. A build container's locked-memory limit is lower than that case needs, so every plain docker build . fails there. Separately, .dockerignore keeps .git (the version comes from it) but not out .git/config, which can hold a credential in a clone's remote URL.

What to change, on a branch cut from next, PR to next:

  • The test suite passes inside a plain docker build .: a case that needs more locked memory than the environment allows is skipped with a message naming the limit, and still runs in full where locking succeeds. Do not weaken what it checks when locking is available.
  • .dockerignore: add .git/config, with the canonical comment from sneak/prompts next saying why.

Definition of done: a fresh clone of the branch, docker build . with no build arguments, succeeds, and the binary's version output shows the commit; make check passes; independent review; squash to next.

Model: opus-5-5

Owner's rule (https://git.eeqj.de/sneak/project-management/issues/21): a plain `docker build .` of a clone stamps the git tag or short commit. The rollout's final check (a fresh clone of `next` at `41cea40`, `docker build .` with no build arguments) could not verify the version because the image does not build: `RUN make test` fails in `TestAddSecretVariousSizes/10MB_secret`, which panics with `<memcall> could not acquire lock on 0x..., limit reached? [Err: cannot allocate memory]`. A build container's locked-memory limit is lower than that case needs, so every plain `docker build .` fails there. Separately, `.dockerignore` keeps `.git` (the version comes from it) but not out `.git/config`, which can hold a credential in a clone's remote URL. What to change, on a branch cut from `next`, PR to `next`: - The test suite passes inside a plain `docker build .`: a case that needs more locked memory than the environment allows is skipped with a message naming the limit, and still runs in full where locking succeeds. Do not weaken what it checks when locking is available. - `.dockerignore`: add `.git/config`, with the canonical comment from `sneak/prompts` `next` saying why. Definition of done: a fresh clone of the branch, `docker build .` with no build arguments, succeeds, and the binary's version output shows the commit; `make check` passes; independent review; squash to `next`. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/secret#57