next → main: a plain docker build passes and stamps the version #59

Open
clawbot wants to merge 1 commits from next into main
Collaborator

On next: a plain docker build . of a clone builds again and stamps the git tag or short commit. The size tests skip a case only when the process cannot actually lock the memory it needs (a plain build runs under an 8 MiB locked-memory limit); script/cibuild, or any process allowed to lock past the limit, runs every case. .git goes into the build context without its config, and secret info reports the git tag or short commit instead of the fixed 0.1.0 (#58, for sneak/project-management#21).

To know before merging: this repo's CI runner has run nothing since 2026-08-10, so these commits carry no CI status; the change was reviewed and built locally.

Model: opus-5-5

On `next`: a plain `docker build .` of a clone builds again and stamps the git tag or short commit. The size tests skip a case only when the process cannot actually lock the memory it needs (a plain build runs under an 8 MiB locked-memory limit); `script/cibuild`, or any process allowed to lock past the limit, runs every case. `.git` goes into the build context without its `config`, and `secret info` reports the git tag or short commit instead of the fixed `0.1.0` (https://git.eeqj.de/sneak/secret/pulls/58, for https://git.eeqj.de/sneak/project-management/issues/21). To know before merging: this repo's CI runner has run nothing since 2026-08-10, so these commits carry no CI status; the change was reviewed and built locally. Model: opus-5-5
clawbot added the merge-ready label 2026-10-02 14:16:11 +02:00
sneak was assigned by clawbot 2026-10-02 14:16:11 +02:00
clawbot added 1 commit 2026-10-02 14:16:11 +02:00
The size tests skip a case whose secret needs more locked memory than
the process can lock, found by locking a buffer of that size: memguard
panics otherwise, and a plain `docker build .` runs under an 8 MiB
RLIMIT_MEMLOCK. script/cibuild, or any process allowed to lock past the
limit, runs every case.

The build stage stamps the VERSION build argument, else
`git describe --tags --always`, and fails when .git is present but
yields no version. `make build` stamps `git describe` too instead of
the fixed 0.1.0. .dockerignore keeps .git/config out; script/docker is
now the canonical copy.

Model: opus-5-5
Co-authored-by: clawbot <sneak+clawbot@sneak.cloud>
Some checks are pending
check / check (push) Waiting to run
Required
Details
Some required checks are missing.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin next:next
git checkout next
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/secret#59