Skip to content

fix(docker): switch to glibc to fix libSQL segfault on restart - #1930

Merged
Evrard-Nil merged 1 commit into
stagingfrom
fix/dockerfile-glibc
Apr 2, 2026
Merged

Evrard-Nil merged 1 commit into
stagingfrom
fix/dockerfile-glibc

Conversation

@Evrard-Nil

Copy link
Copy Markdown
Contributor

Summary

  • Switch Dockerfile from Alpine/musl to Debian/glibc (both build and runtime stages)
  • The musl-linked binary segfaults when reopening an existing libSQL database after container restart
  • Root cause: bundled SQLite C code in libsql-ffi has threading/mmap issues when statically linked against musl

Test plan

  • Built on crabshack0 (144-core sysbox host)
  • First boot — OK
  • Restart with existing DB — no segfault (previously segfaulted 100% of the time)
  • Second restart — OK
  • Verified ironclaw --version, gateway, Docker daemon, all functional
  • CI Docker Image workflow builds successfully

The musl-linked binary segfaults when reopening an existing libSQL
database after container restart. The bundled SQLite C code in
libsql-ffi has threading/mmap issues when statically linked against
musl. Switching build and runtime to Debian/glibc resolves this.

Tested on sysbox with multiple restart cycles — no segfault.

[skip-regression-check]
Copilot AI review requested due to automatic review settings April 2, 2026 19:33
@github-actions github-actions Bot added scope: sandbox Docker sandbox size: S 10-49 changed lines risk: low Changes to docs, tests, or low-risk modules contributor: regular 2-5 merged PRs labels Apr 2, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request migrates the Dockerfile from Alpine to Debian (bookworm) to resolve threading issues with libSQL/SQLite when statically linked against musl. The review identifies two potential failures: the removal of cmake from the build stage which is likely required for dependencies like wasm-tools, and the use of the adduser command in the debian:bookworm-slim runtime image which may not be available. Both issues would likely result in build or runtime errors.

Comment thread Dockerfile
Comment thread Dockerfile

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Switches the production Docker image from Alpine/musl to Debian/glibc to avoid libSQL-related segfaults after container restarts (reopening an existing DB), aligning the container runtime with a glibc-linked build.

Changes:

  • Updated build stages to use rust:1.92-bookworm instead of Alpine/musl.
  • Updated runtime stage to debian:bookworm-slim and installed ca-certificates via apt.
  • Adjusted user creation to Debian-compatible tooling.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread Dockerfile
Comment thread Dockerfile
Comment thread Dockerfile
@Evrard-Nil
Evrard-Nil merged commit 2b6f22f into staging Apr 2, 2026
18 checks passed
@Evrard-Nil
Evrard-Nil deleted the fix/dockerfile-glibc branch April 2, 2026 20:44
serrrfirat pushed a commit that referenced this pull request Apr 5, 2026
The musl-linked binary segfaults when reopening an existing libSQL
database after container restart. The bundled SQLite C code in
libsql-ffi has threading/mmap issues when statically linked against
musl. Switching build and runtime to Debian/glibc resolves this.

Tested on sysbox with multiple restart cycles — no segfault.

[skip-regression-check]
drchirag1991 pushed a commit to drchirag1991/ironclaw that referenced this pull request Apr 8, 2026
…rai#1930)

The musl-linked binary segfaults when reopening an existing libSQL
database after container restart. The bundled SQLite C code in
libsql-ffi has threading/mmap issues when statically linked against
musl. Switching build and runtime to Debian/glibc resolves this.

Tested on sysbox with multiple restart cycles — no segfault.

[skip-regression-check]
@ironclaw-ci ironclaw-ci Bot mentioned this pull request Apr 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: regular 2-5 merged PRs risk: low Changes to docs, tests, or low-risk modules scope: sandbox Docker sandbox size: S 10-49 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants