Conversation
Targets that inherit from the same parent share the parent's output and secret entries. The push override set the "push" attribute on those shared entries, and the secret source override changed the shared secret, so "--set app.push=true" also pushed every sibling target and "--set app.secret.token=env=X" also changed the secret of siblings. Copy the entries before changing them. Assisted-By: Claude Signed-off-by: breken-ai <312387581+breken-ai@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Targets that inherit from the same parent share the parent's
outputandsecretentries, becauseTarget.Mergecopies the slices and pointers as they are. Two--setoverrides change those entries in place, so an override for one target also changes every other target that inherits the same entries:setPushOverridewritesAttrs["push"]on the sharedExportEntry, and forpush=falseit swaps entries inside the shared slice.updateSecret(thesecret.<id>=source override) writesEnvandFilePathon the sharedSecret.docker buildx bake --print --set app.push=true --set app.secret.token=env=APP_TOKEN api appon master:So
--set app.push=truealso pushesapi, andapigetsapp's secret source. With this change:Fix: copy before changing.
setPushOverridenow builds a new slice and clones any entry whosepushattribute it sets (withExportAttr).updateSecretreplaces the entry in a cloned slice. Forpush=falsethe output order is kept now instead of being swapped.Tests
TestPushOverride/inherited_outputs(app.push=trueandapp.push=false) andTestSecretSourceOverrideInherited. On master they fail becauseapigetspush=trueandenv=APP_TOKEN, and they pass with the fix.go test ./bake/...passes. golangci-lint v2.8.0 (the version inhack/dockerfiles/lint.Dockerfile) reports 0 issues on./bake/....--printoutput above is from binaries built from master and from this branch.AI disclosure: I found and fixed this with help from an AI coding assistant (Claude). I reviewed the change and ran the tests above. The commit has an
Assisted-By:trailer and a DCO sign-off.