Skip to content

fix(docker): rebuild better-sqlite3 after hardened install - #2772

Merged
diegosouzapw merged 2 commits into
diegosouzapw:release/v3.8.5from
thanet-s:fix/docker-better-sqlite3-native-rebuild
May 27, 2026
Merged

diegosouzapw merged 2 commits into
diegosouzapw:release/v3.8.5from
thanet-s:fix/docker-better-sqlite3-native-rebuild

Conversation

@thanet-s

Copy link
Copy Markdown
Contributor

Summary

  • keep the Docker builder install hardened with --ignore-scripts
  • explicitly rebuild better-sqlite3 after install so the native better_sqlite3.node binding exists for the target platform
  • smoke-test better-sqlite3 during the image build so missing bindings fail at build time instead of container startup

Fixes #2771

Root Cause

The current ARM64 latest image installs better-sqlite3 without its native binding because broad install scripts are disabled. Startup then fails in bootstrap-env.mjs when it tries to inspect an existing SQLite database.

Validation

  • git diff --check
  • node -e "require('better-sqlite3')(':memory:').close(); console.log('better-sqlite3 OK')"
  • Confirmed the published ARM64 image sha256:3286f8a645d3262427d19b2b806ccd95313f0b3e8716c0d73a6b681e3cf91fd8 lacks /app/node_modules/better-sqlite3/build/Release/better_sqlite3.node and fails the same require smoke test

Full Docker image rebuild was not rerun locally because the current Next.js production build path takes around 30 minutes in this environment; the Dockerfile now includes the exact smoke test in the build layer so CI/image build will catch the native binding failure directly.

@thanet-s
thanet-s requested a review from diegosouzapw as a code owner May 27, 2026 06:07
@kilo-code-bot

kilo-code-bot Bot commented May 27, 2026

Copy link
Copy Markdown

Kilo Code Review could not run — your account is out of credits.

Add credits or switch to a free model to enable reviews on this change.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the Dockerfile to rebuild and smoke-test the better-sqlite3 native dependency during the builder stage. However, there is a potential runtime issue: because the runner stage only copies selected files from node_modules, the rebuilt native binary may not be present in the final runner image. It is recommended to explicitly copy better-sqlite3 to the runner stage and run the smoke test there to guarantee the final image is functional.

Comment thread Dockerfile
@thanet-s

Copy link
Copy Markdown
Contributor Author

Additional local validation on macOS ARM64 / Docker linux ARM64:

  • Host: darwin arm64, Node v24.15.0, ABI 137
  • Host smoke test passed: node -e "require("better-sqlite3")(:memory:).close(); console.log("mac better-sqlite3 OK")"
  • Docker daemon: linux/arm64 29.4.0
  • Built ARM64 image from this branch: docker build --platform linux/arm64 --target runner-base -t omniroute:bs3-arm-test .
  • Build passed the new Dockerfile layer: npm ci --ignore-scripts, npm rebuild better-sqlite3, and node -e "require("better-sqlite3")(:memory:).close()"
  • Runtime image verification passed: /app/node_modules/better-sqlite3/build/Release/better_sqlite3.node exists, better-sqlite3 loads inside the image, and bootstrap-env.mjs inspected an existing storage.sqlite successfully.
  • Standalone startup passed: the container reached normal Next.js startup and DB migrations, docker ps reported healthy, and docker exec omniroute-bs3-arm-test-run node healthcheck.mjs exited 0.

Temporary test container was stopped after validation.

@diegosouzapw
diegosouzapw changed the base branch from main to release/v3.8.5 May 27, 2026 07:13
@diegosouzapw
diegosouzapw merged commit a80bb55 into diegosouzapw:release/v3.8.5 May 27, 2026
84 of 85 checks passed
@diegosouzapw

Copy link
Copy Markdown
Owner

Thanks @thanet-s for this crucial fix! Hardening with ignore-scripts is a great security default, but rebuilding the native sqlite bindings ensures the container is functional on startup. This has been integrated and will be included in the v3.8.5 release.

@diegosouzapw diegosouzapw mentioned this pull request May 27, 2026
diegosouzapw added a commit that referenced this pull request May 27, 2026
* chore(release): bump version to v3.8.5

* fix(docker): rebuild better-sqlite3 after hardened install (#2772)

Integrated into release/v3.8.5

* ci: build Docker platforms on native runners (#2774)

Integrated into release/v3.8.5

* docs(release): sync v3.8.5 documentation and metadata

Update changelog entries, API reference version, package metadata, and
localized LLM documentation for the 3.8.5 release. Refresh generated
docs source mappings and architecture counts for current executors and
OAuth providers.

* chore(release): bump to v3.8.5 — changelog, docs, version sync

* chore(release): translate Hall of Contributors to English in workflows and changelog

* fix(combos): make target timeout configurable (#2775)

Merge PR #2775 — fix(combos): make target timeout configurable

* feat: fix so restart of server restarts batch jobs instead of failing them (#2755)

Merge PR #2755 — feat: fix so restart of server restarts batch jobs instead of failing them

* chore(release): update changelog with merged PRs notes and credits

* feat(api): add endpoint restrictions for client API keys (#2777)

Merge PR #2777 — feat(api): add endpoint restrictions for client API keys

* chore(release): update changelog with PR #2777 entry and contributor credit

---------

Co-authored-by: Thanet S. <cho.112543@gmail.com>
Co-authored-by: Randi <55005611+rdself@users.noreply.github.com>
Co-authored-by: Markus Hartung <mail@hartmark.se>
Co-authored-by: Jack <5443152+hijak@users.noreply.github.com>
HouMinXi pushed a commit to HouMinXi/OmniRoute that referenced this pull request Aug 2, 2026
* chore(release): bump version to v3.8.5

* fix(docker): rebuild better-sqlite3 after hardened install (diegosouzapw#2772)

Integrated into release/v3.8.5

* ci: build Docker platforms on native runners (diegosouzapw#2774)

Integrated into release/v3.8.5

* docs(release): sync v3.8.5 documentation and metadata

Update changelog entries, API reference version, package metadata, and
localized LLM documentation for the 3.8.5 release. Refresh generated
docs source mappings and architecture counts for current executors and
OAuth providers.

* chore(release): bump to v3.8.5 — changelog, docs, version sync

* chore(release): translate Hall of Contributors to English in workflows and changelog

* fix(combos): make target timeout configurable (diegosouzapw#2775)

Merge PR diegosouzapw#2775 — fix(combos): make target timeout configurable

* feat: fix so restart of server restarts batch jobs instead of failing them (diegosouzapw#2755)

Merge PR diegosouzapw#2755 — feat: fix so restart of server restarts batch jobs instead of failing them

* chore(release): update changelog with merged PRs notes and credits

* feat(api): add endpoint restrictions for client API keys (diegosouzapw#2777)

Merge PR diegosouzapw#2777 — feat(api): add endpoint restrictions for client API keys

* chore(release): update changelog with PR diegosouzapw#2777 entry and contributor credit

---------

Co-authored-by: Thanet S. <cho.112543@gmail.com>
Co-authored-by: Randi <55005611+rdself@users.noreply.github.com>
Co-authored-by: Markus Hartung <mail@hartmark.se>
Co-authored-by: Jack <5443152+hijak@users.noreply.github.com>
HouMinXi pushed a commit to HouMinXi/OmniRoute that referenced this pull request Aug 2, 2026
Poid-ZA pushed a commit to Poid-ZA/OmniRoute that referenced this pull request Aug 5, 2026
* chore(release): bump version to v3.8.5

* fix(docker): rebuild better-sqlite3 after hardened install (diegosouzapw#2772)

Integrated into release/v3.8.5

* ci: build Docker platforms on native runners (diegosouzapw#2774)

Integrated into release/v3.8.5

* docs(release): sync v3.8.5 documentation and metadata

Update changelog entries, API reference version, package metadata, and
localized LLM documentation for the 3.8.5 release. Refresh generated
docs source mappings and architecture counts for current executors and
OAuth providers.

* chore(release): bump to v3.8.5 — changelog, docs, version sync

* chore(release): translate Hall of Contributors to English in workflows and changelog

* fix(combos): make target timeout configurable (diegosouzapw#2775)

Merge PR diegosouzapw#2775 — fix(combos): make target timeout configurable

* feat: fix so restart of server restarts batch jobs instead of failing them (diegosouzapw#2755)

Merge PR diegosouzapw#2755 — feat: fix so restart of server restarts batch jobs instead of failing them

* chore(release): update changelog with merged PRs notes and credits

* feat(api): add endpoint restrictions for client API keys (diegosouzapw#2777)

Merge PR diegosouzapw#2777 — feat(api): add endpoint restrictions for client API keys

* chore(release): update changelog with PR diegosouzapw#2777 entry and contributor credit

---------

Co-authored-by: Thanet S. <cho.112543@gmail.com>
Co-authored-by: Randi <55005611+rdself@users.noreply.github.com>
Co-authored-by: Markus Hartung <mail@hartmark.se>
Co-authored-by: Jack <5443152+hijak@users.noreply.github.com>
Poid-ZA pushed a commit to Poid-ZA/OmniRoute that referenced this pull request Aug 5, 2026
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
* chore(release): bump version to v3.8.5

* fix(docker): rebuild better-sqlite3 after hardened install (diegosouzapw#2772)

Integrated into release/v3.8.5

* ci: build Docker platforms on native runners (diegosouzapw#2774)

Integrated into release/v3.8.5

* docs(release): sync v3.8.5 documentation and metadata

Update changelog entries, API reference version, package metadata, and
localized LLM documentation for the 3.8.5 release. Refresh generated
docs source mappings and architecture counts for current executors and
OAuth providers.

* chore(release): bump to v3.8.5 — changelog, docs, version sync

* chore(release): translate Hall of Contributors to English in workflows and changelog

* fix(combos): make target timeout configurable (diegosouzapw#2775)

Merge PR diegosouzapw#2775 — fix(combos): make target timeout configurable

* feat: fix so restart of server restarts batch jobs instead of failing them (diegosouzapw#2755)

Merge PR diegosouzapw#2755 — feat: fix so restart of server restarts batch jobs instead of failing them

* chore(release): update changelog with merged PRs notes and credits

* feat(api): add endpoint restrictions for client API keys (diegosouzapw#2777)

Merge PR diegosouzapw#2777 — feat(api): add endpoint restrictions for client API keys

* chore(release): update changelog with PR diegosouzapw#2777 entry and contributor credit

---------

Co-authored-by: Thanet S. <cho.112543@gmail.com>
Co-authored-by: Randi <55005611+rdself@users.noreply.github.com>
Co-authored-by: Markus Hartung <mail@hartmark.se>
Co-authored-by: Jack <5443152+hijak@users.noreply.github.com>
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] Docker ARM64 v3.8.4 fails to start because better-sqlite3 native binding is missing

2 participants