Conversation
The compose spec allows a ulimit to be a single number that sets both the soft and the hard limit (for example "nofile: 4096"). compose-go stores that form in UlimitsConfig.Single and leaves Soft and Hard at 0, but the conversion only read Soft and Hard, so the target got "nofile=0:0" and every RUN step failed with "too many open files". Use Single for both limits when it is set, like docker compose does. Assisted-By: Claude Signed-off-by: breken-ai <312387581+breken-ai@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The compose spec lets a ulimit be a single number that sets both the soft and the hard limit:
compose-go stores that short form in
UlimitsConfig.Singleand leavesSoftandHardat 0.ParseComposeonly readsSoftandHard, so the target getsnofile=0:0:The
soft/hardmap form works, so only the short form is affected. It has been this way since build ulimits were added to the compose conversion (64e2b25).Fix: when
Singleis set, use it for both limits, the same way docker compose handles it for containers.Tests
TestComposeUlimitsSingleValue(nproc: 65535next to asoft/hardentry). On master it fails withnproc=0:0, and it passes with the fix.go test ./bake/...passes. golangci-lint v2.8.0 (the version inhack/dockerfiles/lint.Dockerfile) reports 0 issues on./bake/....ulimit -Sn; ulimit -Hn: the master binary fails as shown, and the patched binary printsnofile soft=4096 hard=4096.AI disclosure: I found and fixed this with help from an AI coding assistant (Claude). I reviewed the change and ran the tests above. The commit has an
Assisted-By:trailer and a DCO sign-off.