Skip to content

bake: honor single-value ulimits from compose - #4112

Open
breken-ai wants to merge 1 commit into
docker:masterfrom
breken-ai:fix-compose-ulimit-single
Open

breken-ai wants to merge 1 commit into
docker:masterfrom
breken-ai:fix-compose-ulimit-single

Conversation

@breken-ai

Copy link
Copy Markdown

The compose spec lets a ulimit be a single number that sets both the soft and the hard limit:

services:
  app:
    build:
      context: .
      ulimits:
        nofile: 4096

compose-go stores that short form in UlimitsConfig.Single and leaves Soft and Hard at 0. ParseCompose only reads Soft and Hard, so the target gets nofile=0:0:

$ docker buildx bake -f compose.yaml --print
      "ulimits": [
        "nofile=0:0"
      ]
$ docker buildx bake -f compose.yaml
#6 0.116 runc run failed: unable to start container process: error loading seccomp filter into kernel: error patching filter: error disassembling original filter: error creating scratch pipe: pipe2: too many open files
ERROR: failed to solve: process "/bin/sh -c ..." did not complete successfully: exit code: 1

The soft/hard map form works, so only the short form is affected. It has been this way since build ulimits were added to the compose conversion (64e2b25).

Fix: when Single is set, use it for both limits, the same way docker compose handles it for containers.

Tests

  • New TestComposeUlimitsSingleValue (nproc: 65535 next to a soft/hard entry). On master it fails with nproc=0:0, and it passes with the fix.
  • go test ./bake/... passes. golangci-lint v2.8.0 (the version in hack/dockerfiles/lint.Dockerfile) reports 0 issues on ./bake/....
  • End to end with the docker driver and the compose file above, where the Dockerfile runs ulimit -Sn; ulimit -Hn: the master binary fails as shown, and the patched binary prints nofile soft=4096 hard=4096.

AI disclosure: I found and fixed this with help from an AI coding assistant (Claude). I reviewed the change and ran the tests above. The commit has an Assisted-By: trailer and a DCO sign-off.

The compose spec allows a ulimit to be a single number that sets both
the soft and the hard limit (for example "nofile: 4096"). compose-go
stores that form in UlimitsConfig.Single and leaves Soft and Hard at 0,
but the conversion only read Soft and Hard, so the target got
"nofile=0:0" and every RUN step failed with "too many open files".

Use Single for both limits when it is set, like docker compose does.

Assisted-By: Claude
Signed-off-by: breken-ai <312387581+breken-ai@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant