Skip to content

tracked build artifact: http-honeypot binary is committed and not gitignored #3463

Description

@Xore

Problem

A compiled Go binary is committed and tracked in git:

arcane/home/honeypot-http/http-honeypot/http-honeypot

Verified on main:

$ git ls-tree origin/main -- arcane/home/honeypot-http/http-honeypot/ | grep -v '\.go$'
100755 blob c0b9924b3ca168b429bd56750b108ab5dc7d552a  arcane/home/honeypot-http/http-honeypot/http-honeypot

$ git check-ignore -v arcane/home/honeypot-http/http-honeypot/http-honeypot
(no match — not ignored, therefore committable)

Impact

Any go build run in-tree — by a human, a delegated agent, or a local verification step —
silently rewrites the tracked blob. Consequences:

  1. Phantom diffs. A git status after a local build shows a modified binary that has
    nothing to do with the change under review. During the feat(http-honeypot): measure #3394's Ollure coverage and add the model-target class #3442 conflict resolution this
    produced exactly that: a dirty worktree that had to be restored by hand.
  2. Risk of committing it. An agent doing git add -A after a build can sweep the
    rebuilt binary into an unrelated PR, replacing the committed artifact with one built on
    the agent's machine. That is a supply-chain-relevant change, not a cosmetic one.
  3. Noise in review and blame. Binary diffs are unreviewable and the file is dead weight
    in the history.

Proposal

  1. git rm --cached the binary from the tree.
  2. Add the exact path to .gitignore.
  3. No coordination needed — verified already: nothing copies the committed artifact. The
    Dockerfile builds the binary inside the image and copies it across from the builder stage.

Verified on main:

$ git grep -n 'http-honeypot/http-honeypot' origin/main -- '*.yml' '*.yaml' 'Dockerfile*' '*.sh'
(no matches)

$ git show origin/main:arcane/home/honeypot-http/http-honeypot/Dockerfile
5:  COPY *.go .
9:  COPY --from=build /honeypot /honeypot
20: ENTRYPOINT ["/honeypot"]

The committed blob is unreferenced. Removing it from the tree is safe and reversible.

Notes

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions