Repository navigation
fix(docker): rebuild better-sqlite3 after hardened install - #2772
diegosouzapw merged 2 commits into
Conversation
|
Kilo Code Review could not run — your account is out of credits. Add credits or switch to a free model to enable reviews on this change. |
There was a problem hiding this comment.
Code Review
This pull request updates the Dockerfile to rebuild and smoke-test the better-sqlite3 native dependency during the builder stage. However, there is a potential runtime issue: because the runner stage only copies selected files from node_modules, the rebuilt native binary may not be present in the final runner image. It is recommended to explicitly copy better-sqlite3 to the runner stage and run the smoke test there to guarantee the final image is functional.
|
Additional local validation on macOS ARM64 / Docker linux ARM64:
Temporary test container was stopped after validation. |
a80bb55
into
diegosouzapw:release/v3.8.5
|
Thanks @thanet-s for this crucial fix! Hardening with ignore-scripts is a great security default, but rebuilding the native sqlite bindings ensures the container is functional on startup. This has been integrated and will be included in the v3.8.5 release. |
* chore(release): bump version to v3.8.5 * fix(docker): rebuild better-sqlite3 after hardened install (#2772) Integrated into release/v3.8.5 * ci: build Docker platforms on native runners (#2774) Integrated into release/v3.8.5 * docs(release): sync v3.8.5 documentation and metadata Update changelog entries, API reference version, package metadata, and localized LLM documentation for the 3.8.5 release. Refresh generated docs source mappings and architecture counts for current executors and OAuth providers. * chore(release): bump to v3.8.5 — changelog, docs, version sync * chore(release): translate Hall of Contributors to English in workflows and changelog * fix(combos): make target timeout configurable (#2775) Merge PR #2775 — fix(combos): make target timeout configurable * feat: fix so restart of server restarts batch jobs instead of failing them (#2755) Merge PR #2755 — feat: fix so restart of server restarts batch jobs instead of failing them * chore(release): update changelog with merged PRs notes and credits * feat(api): add endpoint restrictions for client API keys (#2777) Merge PR #2777 — feat(api): add endpoint restrictions for client API keys * chore(release): update changelog with PR #2777 entry and contributor credit --------- Co-authored-by: Thanet S. <cho.112543@gmail.com> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com> Co-authored-by: Markus Hartung <mail@hartmark.se> Co-authored-by: Jack <5443152+hijak@users.noreply.github.com>
* chore(release): bump version to v3.8.5 * fix(docker): rebuild better-sqlite3 after hardened install (diegosouzapw#2772) Integrated into release/v3.8.5 * ci: build Docker platforms on native runners (diegosouzapw#2774) Integrated into release/v3.8.5 * docs(release): sync v3.8.5 documentation and metadata Update changelog entries, API reference version, package metadata, and localized LLM documentation for the 3.8.5 release. Refresh generated docs source mappings and architecture counts for current executors and OAuth providers. * chore(release): bump to v3.8.5 — changelog, docs, version sync * chore(release): translate Hall of Contributors to English in workflows and changelog * fix(combos): make target timeout configurable (diegosouzapw#2775) Merge PR diegosouzapw#2775 — fix(combos): make target timeout configurable * feat: fix so restart of server restarts batch jobs instead of failing them (diegosouzapw#2755) Merge PR diegosouzapw#2755 — feat: fix so restart of server restarts batch jobs instead of failing them * chore(release): update changelog with merged PRs notes and credits * feat(api): add endpoint restrictions for client API keys (diegosouzapw#2777) Merge PR diegosouzapw#2777 — feat(api): add endpoint restrictions for client API keys * chore(release): update changelog with PR diegosouzapw#2777 entry and contributor credit --------- Co-authored-by: Thanet S. <cho.112543@gmail.com> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com> Co-authored-by: Markus Hartung <mail@hartmark.se> Co-authored-by: Jack <5443152+hijak@users.noreply.github.com>
…apw#2772) Integrated into release/v3.8.5
* chore(release): bump version to v3.8.5 * fix(docker): rebuild better-sqlite3 after hardened install (diegosouzapw#2772) Integrated into release/v3.8.5 * ci: build Docker platforms on native runners (diegosouzapw#2774) Integrated into release/v3.8.5 * docs(release): sync v3.8.5 documentation and metadata Update changelog entries, API reference version, package metadata, and localized LLM documentation for the 3.8.5 release. Refresh generated docs source mappings and architecture counts for current executors and OAuth providers. * chore(release): bump to v3.8.5 — changelog, docs, version sync * chore(release): translate Hall of Contributors to English in workflows and changelog * fix(combos): make target timeout configurable (diegosouzapw#2775) Merge PR diegosouzapw#2775 — fix(combos): make target timeout configurable * feat: fix so restart of server restarts batch jobs instead of failing them (diegosouzapw#2755) Merge PR diegosouzapw#2755 — feat: fix so restart of server restarts batch jobs instead of failing them * chore(release): update changelog with merged PRs notes and credits * feat(api): add endpoint restrictions for client API keys (diegosouzapw#2777) Merge PR diegosouzapw#2777 — feat(api): add endpoint restrictions for client API keys * chore(release): update changelog with PR diegosouzapw#2777 entry and contributor credit --------- Co-authored-by: Thanet S. <cho.112543@gmail.com> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com> Co-authored-by: Markus Hartung <mail@hartmark.se> Co-authored-by: Jack <5443152+hijak@users.noreply.github.com>
…apw#2772) Integrated into release/v3.8.5
* chore(release): bump version to v3.8.5 * fix(docker): rebuild better-sqlite3 after hardened install (diegosouzapw#2772) Integrated into release/v3.8.5 * ci: build Docker platforms on native runners (diegosouzapw#2774) Integrated into release/v3.8.5 * docs(release): sync v3.8.5 documentation and metadata Update changelog entries, API reference version, package metadata, and localized LLM documentation for the 3.8.5 release. Refresh generated docs source mappings and architecture counts for current executors and OAuth providers. * chore(release): bump to v3.8.5 — changelog, docs, version sync * chore(release): translate Hall of Contributors to English in workflows and changelog * fix(combos): make target timeout configurable (diegosouzapw#2775) Merge PR diegosouzapw#2775 — fix(combos): make target timeout configurable * feat: fix so restart of server restarts batch jobs instead of failing them (diegosouzapw#2755) Merge PR diegosouzapw#2755 — feat: fix so restart of server restarts batch jobs instead of failing them * chore(release): update changelog with merged PRs notes and credits * feat(api): add endpoint restrictions for client API keys (diegosouzapw#2777) Merge PR diegosouzapw#2777 — feat(api): add endpoint restrictions for client API keys * chore(release): update changelog with PR diegosouzapw#2777 entry and contributor credit --------- Co-authored-by: Thanet S. <cho.112543@gmail.com> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com> Co-authored-by: Markus Hartung <mail@hartmark.se> Co-authored-by: Jack <5443152+hijak@users.noreply.github.com>
…apw#2772) Integrated into release/v3.8.5
Summary
--ignore-scriptsbetter-sqlite3after install so the nativebetter_sqlite3.nodebinding exists for the target platformbetter-sqlite3during the image build so missing bindings fail at build time instead of container startupFixes #2771
Root Cause
The current ARM64
latestimage installsbetter-sqlite3without its native binding because broad install scripts are disabled. Startup then fails inbootstrap-env.mjswhen it tries to inspect an existing SQLite database.Validation
git diff --checknode -e "require('better-sqlite3')(':memory:').close(); console.log('better-sqlite3 OK')"sha256:3286f8a645d3262427d19b2b806ccd95313f0b3e8716c0d73a6b681e3cf91fd8lacks/app/node_modules/better-sqlite3/build/Release/better_sqlite3.nodeand fails the same require smoke testFull Docker image rebuild was not rerun locally because the current Next.js production build path takes around 30 minutes in this environment; the Dockerfile now includes the exact smoke test in the build layer so CI/image build will catch the native binding failure directly.