Skip to content

bake: do not leak target overrides into inherited entries - #4113

Open
breken-ai wants to merge 1 commit into
docker:masterfrom
breken-ai:fix-bake-override-shared-entries
Open

breken-ai wants to merge 1 commit into
docker:masterfrom
breken-ai:fix-bake-override-shared-entries

Conversation

@breken-ai

Copy link
Copy Markdown

Targets that inherit from the same parent share the parent's output and secret entries, because Target.Merge copies the slices and pointers as they are. Two --set overrides change those entries in place, so an override for one target also changes every other target that inherits the same entries:

  • setPushOverride writes Attrs["push"] on the shared ExportEntry, and for push=false it swaps entries inside the shared slice.
  • updateSecret (the secret.<id>= source override) writes Env and FilePath on the shared Secret.
target "_common" {
  output = ["type=image"]
  secret = ["id=token,env=COMMON_TOKEN"]
}
target "api" {
  inherits = ["_common"]
  tags = ["example.com/api"]
}
target "app" {
  inherits = ["_common"]
  tags = ["example.com/app"]
}

docker buildx bake --print --set app.push=true --set app.secret.token=env=APP_TOKEN api app on master:

api output=[{push: true, type: image}] secret=[{id: token, env: APP_TOKEN}]
app output=[{push: true, type: image}] secret=[{id: token, env: APP_TOKEN}]

So --set app.push=true also pushes api, and api gets app's secret source. With this change:

api output=[{type: image}]             secret=[{id: token, env: COMMON_TOKEN}]
app output=[{push: true, type: image}] secret=[{id: token, env: APP_TOKEN}]

Fix: copy before changing. setPushOverride now builds a new slice and clones any entry whose push attribute it sets (withExportAttr). updateSecret replaces the entry in a cloned slice. For push=false the output order is kept now instead of being swapped.

Tests

  • New TestPushOverride/inherited_outputs (app.push=true and app.push=false) and TestSecretSourceOverrideInherited. On master they fail because api gets push=true and env=APP_TOKEN, and they pass with the fix.
  • go test ./bake/... passes. golangci-lint v2.8.0 (the version in hack/dockerfiles/lint.Dockerfile) reports 0 issues on ./bake/....
  • End to end: the --print output above is from binaries built from master and from this branch.

AI disclosure: I found and fixed this with help from an AI coding assistant (Claude). I reviewed the change and ran the tests above. The commit has an Assisted-By: trailer and a DCO sign-off.

Targets that inherit from the same parent share the parent's output
and secret entries. The push override set the "push" attribute on
those shared entries, and the secret source override changed the shared
secret, so "--set app.push=true" also pushed every sibling target and
"--set app.secret.token=env=X" also changed the secret of siblings.

Copy the entries before changing them.

Assisted-By: Claude
Signed-off-by: breken-ai <312387581+breken-ai@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant