Repository navigation
fix(docker-bun): make Bun image install and SQLite startup reliable - #11470
Merged
diegosouzapw merged 2 commits intoAug 25, 2026
Merged
diegosouzapw merged 2 commits into
diegosouzapw merged 2 commits into
Conversation
5 tasks done
diegosouzapw
merged commit Aug 25, 2026
a8f9024
into
diegosouzapw:release/v3.8.51
7 of 16 checks passed
diegosouzapw
pushed a commit
that referenced
this pull request
Aug 25, 2026
Validated in a combined 4-PR batch worktree off release/v3.8.51 tip (complements #11468 and #11470, both merged first). Conflicted against #11470's Dockerfile.bun hunk in the shared worktree — resolved additively (both the ownership hardening and the addon-stripping RUN block coexist, ordered so the strip runs as root before USER bun) and pushed the same resolution to this branch. - Focused test: bun-runtime-native-addon.test.mjs — 1/1 pass, part of batch's 5/5 node:test run - typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity — all OK - Full-repo lint: 228 pre-existing dashboard react-hooks/* findings, unrelated to this diff Thanks for the isolated-probe root-causing (better-sqlite3 specifically, ruling out keytar/onnxruntime-node/sqlite-vec/tls-client-node/wreq-js/sharp) plus the production ARM64 evidence.
diegosouzapw
pushed a commit
that referenced
this pull request
Aug 26, 2026
…11428) Validated in a combined dependabot worktree off release/v3.8.51 tip alongside #11426 and #11440 — a fresh npm install of all three combined (2437 packages, 0 vulnerabilities) plus full-suite validation: - typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity, check:cycles — all OK, including through the @types/node 22→26 major jump - npm run lint — 0 errors (after also draining an unrelated stale-suppressions cascade, see #11596) - npm run test:vitest — 451/452 pass; the 1 failure (auto/glm materialization) is a pre-existing timing-flaky test, reproduced 11/11 pass ×3 in isolation, unrelated to this bump - Node runtime unaffected — v24.16.0 unchanged, only the type definitions moved 8 development-group updates. The bun 1.3.14→1.4.0 + @types/bun bump aligns with the Bun-native infrastructure work merged earlier today (#11468/#11470/#11471/#11482), which was built against Bun 1.4+ assumptions.
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…iegosouzapw#11470) Validated in a combined 4-PR batch worktree off release/v3.8.51 tip (Bun-native SQLite infrastructure cluster; complements diegosouzapw#11468 already merged). - typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity — all OK (Docker build itself not executed in this environment; reviewed the Dockerfile.bun diff for correctness) - Full-repo lint: 228 pre-existing dashboard react-hooks/* findings, unrelated to this diff Thanks for the two concrete failure modes fixed (missing postinstall.mjs during layer-cached bun install, ARM64 NAPI crash avoided by using the native bun:sqlite smoke check instead of rebuilding better-sqlite3) plus the non-root USER bun hardening.
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…1482) Validated in a combined 4-PR batch worktree off release/v3.8.51 tip (complements diegosouzapw#11468 and diegosouzapw#11470, both merged first). Conflicted against diegosouzapw#11470's Dockerfile.bun hunk in the shared worktree — resolved additively (both the ownership hardening and the addon-stripping RUN block coexist, ordered so the strip runs as root before USER bun) and pushed the same resolution to this branch. - Focused test: bun-runtime-native-addon.test.mjs — 1/1 pass, part of batch's 5/5 node:test run - typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity — all OK - Full-repo lint: 228 pre-existing dashboard react-hooks/* findings, unrelated to this diff Thanks for the isolated-probe root-causing (better-sqlite3 specifically, ruling out keytar/onnxruntime-node/sqlite-vec/tls-client-node/wreq-js/sharp) plus the production ARM64 evidence.
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…iegosouzapw#11428) Validated in a combined dependabot worktree off release/v3.8.51 tip alongside diegosouzapw#11426 and diegosouzapw#11440 — a fresh npm install of all three combined (2437 packages, 0 vulnerabilities) plus full-suite validation: - typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity, check:cycles — all OK, including through the @types/node 22→26 major jump - npm run lint — 0 errors (after also draining an unrelated stale-suppressions cascade, see diegosouzapw#11596) - npm run test:vitest — 451/452 pass; the 1 failure (auto/glm materialization) is a pre-existing timing-flaky test, reproduced 11/11 pass ×3 in isolation, unrelated to this bump - Node runtime unaffected — v24.16.0 unchanged, only the type definitions moved 8 development-group updates. The bun 1.3.14→1.4.0 + @types/bun bump aligns with the Bun-native infrastructure work merged earlier today (diegosouzapw#11468/diegosouzapw#11470/diegosouzapw#11471/diegosouzapw#11482), which was built against Bun 1.4+ assumptions.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes two failure modes in
Dockerfile.bunduring image build and startup:bun installruns root lifecycle scripts.bun:sqlitesmoke verification instead of attempting to rebuild and loadbetter-sqlite3Node-API addon (which crashes under Bun on Linux ARM64).USER bunsecurity context torunner-base(mirroringrunner-web).Motivation & Failure Modes Fixed
postinstall.mjsmissing duringbun install: When caching dependency layers,bun installinvokespostinstallfrompackage.json. Copyingscripts/build/andscripts/dev/sync-env.mjsalongside manifests preventsError: Module not found '/app/scripts/build/postinstall.mjs'.better-sqlite3and requiring it under Bun triggers a nativeSIGABRT(napi_get_last_error_info) on ARM64. Since OmniRoute already prefersbun:sqlitewhen running under Bun, replacing the rebuild and smoke check with nativebun:sqliteavoids loading the native Node addon while ensuring database readiness.runner-basestage now assigns ownership to UID/GID 1000 and drops privileges viaUSER bun.Key Changes
Dockerfile.bun:scripts/build/andscripts/dev/sync-env.mjsbeforebun install.node-gyp rebuild better-sqlite3.bun:sqlitein-memory smoke check.chown -R bun:bunandUSER buninrunner-base.Validation
bun:sqlite smoke: OK.