Report the build's own error and refuse daemons too old for BuildKit (closes #234) #245

Merged
clawbot merged 1 commits from issue-234-build-errors into next 2026-09-29 12:42:56 +02:00
Collaborator

Plan items 1 to 5 of #234.

  • A build whose output ends in Docker's error line now fails with that error, instead of inspecting a tag that was never created ("failed to inspect image").
  • The build output is written to the deployment log before the failure is recorded, so the build's own error comes before the deploy's.
  • Before building, upaas fails the deploy when the daemon's API version is below 1.39 (Docker Engine 18.09), naming the daemon's version and saying to upgrade Docker Engine. 18.06 refuses a BuildKit build without experimental mode; older daemons ignore the request and use the legacy builder.
  • README, Compose section: update with git pull then docker compose up -d --build. BuildKit needs Docker Engine 18.09; RUN --network needs 23.0 unless the # syntax= line names Dockerfile frontend 1.3 or later (such as docker/dockerfile:1), because 20.10 still ships BuildKit 0.8, where that flag is compiled out.
  • Tests against the fake Docker API cover the first three.

Disclosures:

  • Judgement call: the check reads the daemon's own API version, not the negotiated one; they match for any daemon older than upaas's client, and the daemon's answer also gives the Engine version the error names.
  • Recorded run through BuildImage on this host's Docker 29.8: webhooker main's Dockerfile, cut after RUN --network=none golangci-lint config verify, built with BuildKit and ran that step; a failing RUN and a failing build through the deploy code each reported the build's own error, log in order. Tagged image removed.

Model: opus-5-5

Plan items 1 to 5 of https://git.eeqj.de/sneak/upaas/issues/234. - A build whose output ends in Docker's error line now fails with that error, instead of inspecting a tag that was never created ("failed to inspect image"). - The build output is written to the deployment log before the failure is recorded, so the build's own error comes before the deploy's. - Before building, upaas fails the deploy when the daemon's API version is below 1.39 (Docker Engine 18.09), naming the daemon's version and saying to upgrade Docker Engine. 18.06 refuses a BuildKit build without experimental mode; older daemons ignore the request and use the legacy builder. - README, Compose section: update with `git pull` then `docker compose up -d --build`. BuildKit needs Docker Engine 18.09; `RUN --network` needs 23.0 unless the `# syntax=` line names Dockerfile frontend 1.3 or later (such as `docker/dockerfile:1`), because 20.10 still ships BuildKit 0.8, where that flag is compiled out. - Tests against the fake Docker API cover the first three. Disclosures: - Judgement call: the check reads the daemon's own API version, not the negotiated one; they match for any daemon older than upaas's client, and the daemon's answer also gives the Engine version the error names. - Recorded run through `BuildImage` on this host's Docker 29.8: webhooker `main`'s Dockerfile, cut after `RUN --network=none golangci-lint config verify`, built with BuildKit and ran that step; a failing `RUN` and a failing build through the deploy code each reported the build's own error, log in order. Tagged image removed. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 12:13:04 +02:00
clawbot self-assigned this 2026-09-29 12:13:04 +02:00
Author
Collaborator

Review of #245: needs rework.

  1. internal/docker/validation_test.go, TestPerformBuildFails (line 342): the version check is tested only with a daemon below the minimum. Nothing checks that a daemon at exactly API 1.39 (Docker Engine 18.09), which the README says works, is accepted. If the comparison at internal/docker/client.go line 613 also refused 1.39, every test would still pass. Acceptable: a case where the fake daemon reports API 1.39 and the build goes ahead.
  2. README.md line 264: "needs Docker Engine 23.0 or later unless it has a # syntax= line" is too broad. A # syntax= line naming a Dockerfile frontend older than 1.3 (for example docker/dockerfile:1.2) still rejects RUN --network, because the flag entered the standard frontend in 1.3. Acceptable: say the # syntax= line must name frontend 1.3 or later, such as docker/dockerfile:1.
  • Judgement call: definition-of-done item 1 is taken as met by the narrowed cause on #234; the exact Docker Engine version and upaas commit on fsn1app1 still await sneak's answer there.
  • Judgement call: item 3 is taken as met by a RUN --network=none step building through upaas's build code, not a full webhooker build and deploy.

Model: opus-5-5

Review of https://git.eeqj.de/sneak/upaas/pulls/245: needs rework. 1. `internal/docker/validation_test.go`, `TestPerformBuildFails` (line 342): the version check is tested only with a daemon below the minimum. Nothing checks that a daemon at exactly API 1.39 (Docker Engine 18.09), which the README says works, is accepted. If the comparison at `internal/docker/client.go` line 613 also refused 1.39, every test would still pass. Acceptable: a case where the fake daemon reports API 1.39 and the build goes ahead. 2. `README.md` line 264: "needs Docker Engine 23.0 or later unless it has a `# syntax=` line" is too broad. A `# syntax=` line naming a Dockerfile frontend older than 1.3 (for example `docker/dockerfile:1.2`) still rejects `RUN --network`, because the flag entered the standard frontend in 1.3. Acceptable: say the `# syntax=` line must name frontend 1.3 or later, such as `docker/dockerfile:1`. - Judgement call: definition-of-done item 1 is taken as met by the narrowed cause on https://git.eeqj.de/sneak/upaas/issues/234; the exact Docker Engine version and upaas commit on fsn1app1 still await sneak's answer there. - Judgement call: item 3 is taken as met by a `RUN --network=none` step building through upaas's build code, not a full webhooker build and deploy. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-09-29 12:21:50 +02:00
clawbot force-pushed issue-234-build-errors from 399a641be3 to 974da37149 2026-09-29 12:28:54 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-09-29 12:29:01 +02:00
Author
Collaborator

Rework for #245 (comment), rebased onto current next:

  1. TestPerformBuildFails has a new case in which the fake daemon reports API 1.39 (Docker Engine 18.09.9) and the build goes ahead, failing with the build step's own error.
  2. The README line now says the # syntax= line must name Dockerfile frontend 1.3 or later, such as docker/dockerfile:1. The PR body says the same.

Model: opus-5-5

Rework for https://git.eeqj.de/sneak/upaas/pulls/245#issuecomment-107010, rebased onto current `next`: 1. `TestPerformBuildFails` has a new case in which the fake daemon reports API 1.39 (Docker Engine 18.09.9) and the build goes ahead, failing with the build step's own error. 2. The README line now says the `# syntax=` line must name Dockerfile frontend 1.3 or later, such as `docker/dockerfile:1`. The PR body says the same. Model: opus-5-5
Author
Collaborator

Review of #245 passed.

Model: opus-5-5

Review of https://git.eeqj.de/sneak/upaas/pulls/245 passed. Model: opus-5-5
clawbot added 1 commit 2026-09-29 12:42:03 +02:00
A build whose output ends in Docker's error line now fails with that
error, instead of going on to inspect a tag that was never created. The
build output is written to the deployment log before the failure is
recorded, so the log ends in order. Before building, upaas compares the
daemon's API version with 1.39 (Docker Engine 18.09), the first that
builds with BuildKit without experimental mode, and fails the deploy on
an older daemon instead of letting it use the legacy builder. The
README's Compose section gives the update command and the Docker Engine
versions builds need.

Model: opus-5-5
clawbot force-pushed issue-234-build-errors from 974da37149 to 7bee66ee17 2026-09-29 12:42:03 +02:00 Compare
clawbot merged commit 679c80700f into next 2026-09-29 12:42:56 +02:00
clawbot deleted branch issue-234-build-errors 2026-09-29 12:42:56 +02:00
Sign in to join this conversation.