From 5fa8b7412e7d12b49a9ba19148ee51ca082a8b65 Mon Sep 17 00:00:00 2001 From: Lemon-miaow Date: Wed, 23 Sep 2026 19:19:04 +0800 Subject: [PATCH] fix(build): keep macOS ._*/.DS_Store junk out of the image MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit A Mac-staged tree (BSD tar materializes extended attributes as ._ sidecars) went through the docker build and one landed in internal/store/migrations/ — //go:embed-ed into the binary, where every `felis migrate` then died with 'migration "._0004..." has a non-numeric version'. Observed live wiring up the auditfix42 image: the installer's own run_migrations failed on it. Exclude the sidecars and .DS_Store from the build context; deploy/*.yaml and plugins/ have the same exposure. --- .dockerignore | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/.dockerignore b/.dockerignore index 7b63d15..53a1dd4 100644 --- a/.dockerignore +++ b/.dockerignore @@ -31,3 +31,14 @@ Dockerfile *.key felis felis.exe + +# macOS materializes extended attributes as ._ sidecars (BSD tar uploads, +# Finder copies, network volumes) and leaves .DS_Store behind. Neither is +# source, and one is actively harmful: a ._*.sql beside the migrations is +# //go:embed-ed into the binary and makes every `felis migrate` fail +# ("non-numeric version") — observed live on a Mac-staged tree. Same exposure +# for any tree the other //go:embed patterns walk (deploy/, plugins/). +._* +**/._* +.DS_Store +**/.DS_Store