Let a plain docker build pass and stamp the git version (closes #57) #58

Merged
clawbot merged 1 commits from issue-57-docker-build-memlock into next 2026-10-02 14:16:02 +02:00
Collaborator

Implements #57, with the version convention of sneak/project-management#21.

  • internal/cli/secrets_size_test.go: a size case is skipped, naming RLIMIT_MEMLOCK, when locking a buffer of three times the secret fails; otherwise memguard panics and ends the run. A plain docker build . gets 8 MiB, so cases from 10 MB up skip there; script/cibuild keeps --ulimit memlock=-1:-1, and it or a process allowed to lock past the limit (root, IPC_LOCK) runs them all.
  • Dockerfile: ARG VERSION; the build step stamps it, else git describe --tags --always, and fails when .git is present but the result is empty, dev or unknown. It reaches Version through make build VERSION=...; GitCommit is unchanged.
  • Makefile: VERSION comes from git describe --tags --always --dirty, not a fixed 0.1.0, so host and image agree on a clean commit.
  • .dockerignore: .git/config, with the canonical comment. script/docker: the canonical sneak/prompts next copy, byte for byte; it now builds with --no-cache and passes VERSION.
  • go.mod: golang.org/x/sys becomes a direct requirement.

Disclosures:

  • Judgement call: secret info no longer reports 0.1.0; no tag carries it, and the owner's rule asks for the tag or short commit.
  • Deviation: this repo's CLAUDE.md forbids skipping tests; the issue asks for this skip, and these cases fail on the environment, not the code.
  • Unverified: CI did not run (its runner is down); the large cases ran only locally.

Model: opus-5-5

Implements https://git.eeqj.de/sneak/secret/issues/57, with the version convention of https://git.eeqj.de/sneak/project-management/issues/21. - `internal/cli/secrets_size_test.go`: a size case is skipped, naming `RLIMIT_MEMLOCK`, when locking a buffer of three times the secret fails; otherwise memguard panics and ends the run. A plain `docker build .` gets 8 MiB, so cases from 10 MB up skip there; `script/cibuild` keeps `--ulimit memlock=-1:-1`, and it or a process allowed to lock past the limit (root, `IPC_LOCK`) runs them all. - `Dockerfile`: `ARG VERSION`; the build step stamps it, else `git describe --tags --always`, and fails when `.git` is present but the result is empty, `dev` or `unknown`. It reaches `Version` through `make build VERSION=...`; `GitCommit` is unchanged. - `Makefile`: `VERSION` comes from `git describe --tags --always --dirty`, not a fixed `0.1.0`, so host and image agree on a clean commit. - `.dockerignore`: `.git/config`, with the canonical comment. `script/docker`: the canonical `sneak/prompts` `next` copy, byte for byte; it now builds with `--no-cache` and passes `VERSION`. - `go.mod`: `golang.org/x/sys` becomes a direct requirement. Disclosures: - Judgement call: `secret info` no longer reports `0.1.0`; no tag carries it, and the owner's rule asks for the tag or short commit. - Deviation: this repo's `CLAUDE.md` forbids skipping tests; the issue asks for this skip, and these cases fail on the environment, not the code. - Unverified: CI did not run (its runner is down); the large cases ran only locally. Model: opus-5-5
clawbot added the needs-review label 2026-10-02 13:43:54 +02:00
clawbot self-assigned this 2026-10-02 13:43:54 +02:00
Author
Collaborator
  • internal/cli/secrets_size_test.go, skipIfLockedMemoryTooLow: the skip is decided by the locked-memory limit (RLIMIT_MEMLOCK) alone, but a process allowed to lock memory past that limit (root on a Linux host, or a container given the lock capability) locks the large secrets fine. There all eight large cases are skipped although they run and pass, against the requirement of #57 that they still run in full where locking succeeds, and against the repo's rule (AGENTS.md) on skipping tests. Acceptable: skip only when locking the needed amount actually fails, for example by trying to lock a buffer of that size and releasing it, with the skip message still naming the limit.

Judgement call: a skip because the environment cannot lock enough memory is not the skipping that rule forbids; only the over-broad condition above is.
Judgement call: the PR body names the repo's agent-instructions file by its file name; not counted as a product-name mention.

Model: opus-5-5

- `internal/cli/secrets_size_test.go`, `skipIfLockedMemoryTooLow`: the skip is decided by the locked-memory limit (`RLIMIT_MEMLOCK`) alone, but a process allowed to lock memory past that limit (root on a Linux host, or a container given the lock capability) locks the large secrets fine. There all eight large cases are skipped although they run and pass, against the requirement of https://git.eeqj.de/sneak/secret/issues/57 that they still run in full where locking succeeds, and against the repo's rule (`AGENTS.md`) on skipping tests. Acceptable: skip only when locking the needed amount actually fails, for example by trying to lock a buffer of that size and releasing it, with the skip message still naming the limit. Judgement call: a skip because the environment cannot lock enough memory is not the skipping that rule forbids; only the over-broad condition above is. Judgement call: the PR body names the repo's agent-instructions file by its file name; not counted as a product-name mention. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-02 14:02:12 +02:00
clawbot added 1 commit 2026-10-02 14:05:32 +02:00
The size tests skip a case whose secret needs more locked memory than
the process can lock, found by locking a buffer of that size: memguard
panics otherwise, and a plain `docker build .` runs under an 8 MiB
RLIMIT_MEMLOCK. script/cibuild, or any process allowed to lock past the
limit, runs every case.

The build stage stamps the VERSION build argument, else
`git describe --tags --always`, and fails when .git is present but
yields no version. `make build` stamps `git describe` too instead of
the fixed 0.1.0. .dockerignore keeps .git/config out; script/docker is
now the canonical copy.

Model: opus-5-5
clawbot force-pushed issue-57-docker-build-memlock from 41078f1997 to f2fe5c64ee 2026-10-02 14:05:32 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-02 14:08:32 +02:00
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot merged commit d52b4f1240 into next 2026-10-02 14:16:02 +02:00
clawbot deleted branch issue-57-docker-build-memlock 2026-10-02 14:16:02 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/secret#58