Skip to content

fix(docker-bun): make Bun image install and SQLite startup reliable - #11470

Merged
diegosouzapw merged 2 commits into
diegosouzapw:release/v3.8.51from
TheDemonTuan:fix/docker-bun-install-sqlite
Aug 25, 2026
Merged

diegosouzapw merged 2 commits into
diegosouzapw:release/v3.8.51from
TheDemonTuan:fix/docker-bun-install-sqlite

Conversation

@TheDemonTuan

Copy link
Copy Markdown
Contributor

Summary

Fixes two failure modes in Dockerfile.bun during image build and startup:

  1. Ensures root postinstall script helpers are available before bun install runs root lifecycle scripts.
  2. Uses native bun:sqlite smoke verification instead of attempting to rebuild and load better-sqlite3 Node-API addon (which crashes under Bun on Linux ARM64).
  3. Adds non-root USER bun security context to runner-base (mirroring runner-web).

Motivation & Failure Modes Fixed

  1. postinstall.mjs missing during bun install: When caching dependency layers, bun install invokes postinstall from package.json. Copying scripts/build/ and scripts/dev/sync-env.mjs alongside manifests prevents Error: Module not found '/app/scripts/build/postinstall.mjs'.
  2. ARM64 N-API crash: Rebuilding better-sqlite3 and requiring it under Bun triggers a native SIGABRT (napi_get_last_error_info) on ARM64. Since OmniRoute already prefers bun:sqlite when running under Bun, replacing the rebuild and smoke check with native bun:sqlite avoids loading the native Node addon while ensuring database readiness.
  3. Container Security: runner-base stage now assigns ownership to UID/GID 1000 and drops privileges via USER bun.

Key Changes

  • Dockerfile.bun:
    • Copies scripts/build/ and scripts/dev/sync-env.mjs before bun install.
    • Removes node-gyp rebuild better-sqlite3.
    • Adds bun:sqlite in-memory smoke check.
    • Adds chown -R bun:bun and USER bun in runner-base.

Validation

  • Verified Dockerfile layers build and smoke check passes with bun:sqlite smoke: OK.

@diegosouzapw
diegosouzapw merged commit a8f9024 into diegosouzapw:release/v3.8.51 Aug 25, 2026
7 of 16 checks passed
diegosouzapw pushed a commit that referenced this pull request Aug 25, 2026
Validated in a combined 4-PR batch worktree off release/v3.8.51 tip (complements #11468 and #11470, both merged first). Conflicted against #11470's Dockerfile.bun hunk in the shared worktree — resolved additively (both the ownership hardening and the addon-stripping RUN block coexist, ordered so the strip runs as root before USER bun) and pushed the same resolution to this branch.
- Focused test: bun-runtime-native-addon.test.mjs — 1/1 pass, part of batch's 5/5 node:test run
- typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity — all OK
- Full-repo lint: 228 pre-existing dashboard react-hooks/* findings, unrelated to this diff

Thanks for the isolated-probe root-causing (better-sqlite3 specifically, ruling out keytar/onnxruntime-node/sqlite-vec/tls-client-node/wreq-js/sharp) plus the production ARM64 evidence.
diegosouzapw pushed a commit that referenced this pull request Aug 26, 2026
…11428)

Validated in a combined dependabot worktree off release/v3.8.51 tip alongside #11426 and #11440 — a fresh npm install of all three combined (2437 packages, 0 vulnerabilities) plus full-suite validation:
- typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity, check:cycles — all OK, including through the @types/node 22→26 major jump
- npm run lint — 0 errors (after also draining an unrelated stale-suppressions cascade, see #11596)
- npm run test:vitest — 451/452 pass; the 1 failure (auto/glm materialization) is a pre-existing timing-flaky test, reproduced 11/11 pass ×3 in isolation, unrelated to this bump
- Node runtime unaffected — v24.16.0 unchanged, only the type definitions moved

8 development-group updates. The bun 1.3.14→1.4.0 + @types/bun bump aligns with the Bun-native infrastructure work merged earlier today (#11468/#11470/#11471/#11482), which was built against Bun 1.4+ assumptions.
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…iegosouzapw#11470)

Validated in a combined 4-PR batch worktree off release/v3.8.51 tip (Bun-native SQLite infrastructure cluster; complements diegosouzapw#11468 already merged).
- typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity — all OK (Docker build itself not executed in this environment; reviewed the Dockerfile.bun diff for correctness)
- Full-repo lint: 228 pre-existing dashboard react-hooks/* findings, unrelated to this diff

Thanks for the two concrete failure modes fixed (missing postinstall.mjs during layer-cached bun install, ARM64 NAPI crash avoided by using the native bun:sqlite smoke check instead of rebuilding better-sqlite3) plus the non-root USER bun hardening.
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…1482)

Validated in a combined 4-PR batch worktree off release/v3.8.51 tip (complements diegosouzapw#11468 and diegosouzapw#11470, both merged first). Conflicted against diegosouzapw#11470's Dockerfile.bun hunk in the shared worktree — resolved additively (both the ownership hardening and the addon-stripping RUN block coexist, ordered so the strip runs as root before USER bun) and pushed the same resolution to this branch.
- Focused test: bun-runtime-native-addon.test.mjs — 1/1 pass, part of batch's 5/5 node:test run
- typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity — all OK
- Full-repo lint: 228 pre-existing dashboard react-hooks/* findings, unrelated to this diff

Thanks for the isolated-probe root-causing (better-sqlite3 specifically, ruling out keytar/onnxruntime-node/sqlite-vec/tls-client-node/wreq-js/sharp) plus the production ARM64 evidence.
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…iegosouzapw#11428)

Validated in a combined dependabot worktree off release/v3.8.51 tip alongside diegosouzapw#11426 and diegosouzapw#11440 — a fresh npm install of all three combined (2437 packages, 0 vulnerabilities) plus full-suite validation:
- typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity, check:cycles — all OK, including through the @types/node 22→26 major jump
- npm run lint — 0 errors (after also draining an unrelated stale-suppressions cascade, see diegosouzapw#11596)
- npm run test:vitest — 451/452 pass; the 1 failure (auto/glm materialization) is a pre-existing timing-flaky test, reproduced 11/11 pass ×3 in isolation, unrelated to this bump
- Node runtime unaffected — v24.16.0 unchanged, only the type definitions moved

8 development-group updates. The bun 1.3.14→1.4.0 + @types/bun bump aligns with the Bun-native infrastructure work merged earlier today (diegosouzapw#11468/diegosouzapw#11470/diegosouzapw#11471/diegosouzapw#11482), which was built against Bun 1.4+ assumptions.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants