fix(ci): verify registry upload against exported OCI config
CI / check (push) Successful in 51s
CI / deploy (push) Successful in 1m9s
CI / publish-container (push) Successful in 54s

This commit is contained in:
Simo committed 2026-09-09 20:33:14 +02:00
1 parent e617ed176a
commit 8dc187483c
4 files changed
+19 -18

No files matched your search

+8 -11
View File
@@ -57,7 +57,7 @@ describe("verified application image reuse", () => {
expect(calls).not.toContain("docker build --network=host --build-arg");
expect(
calls.indexOf("verify scripts/verify-portable-image.mjs"),
).toBeLessThan(calls.indexOf("regctl image import"));
).toBeLessThan(calls.indexOf("regctl image copy"));
});
it.each(["missing", "mismatch"])(
"builds committed source when verification marker is %s",
@@ -71,16 +71,12 @@ describe("verified application image reuse", () => {
it("uses the token account namespace instead of the repository owner", () => {
const calls = simulate("verified");
expect(calls).toContain(
`regctl image import registry.invalid/simo/cms:${sha}`,
);
expect(calls).toContain(`registry.invalid/simo/cms:${sha}\n`);
expect(calls).not.toContain("registry.invalid/owner/cms");
});
it("supports an explicit organization namespace", () => {
const calls = simulate("verified", "My-Org");
expect(calls).toContain(
`regctl image import registry.invalid/my-org/cms:${sha}`,
);
expect(calls).toContain(`registry.invalid/my-org/cms:${sha}\n`);
});
it("bounds uploads and verifies both published image configs", () => {
@@ -88,15 +84,16 @@ it("bounds uploads and verifies both published image configs", () => {
expect(calls).toContain("--blob-chunk 8388608 --blob-max 8388608");
expect(calls).not.toContain("docker push");
expect(calls.match(/regctl image import/g)).toHaveLength(2);
expect(calls.match(/regctl manifest get/g)).toHaveLength(2);
expect(calls.match(/--platform linux\/amd64/g)).toHaveLength(2);
expect(calls.match(/regctl image copy/g)).toHaveLength(2);
expect(calls.match(/regctl manifest get/g)).toHaveLength(4);
expect(calls.match(/--platform linux\/amd64/g)).toHaveLength(4);
});
it.each(["upload-fails", "wrong-config", "bad-checksum"])(
"stops publication on %s",
(scenario) => {
const calls = simulate(scenario, "", 1);
expect(calls).not.toContain(
`regctl image import registry.invalid/simo/cms:${sha} `,
expect(calls.match(/regctl image copy/g)?.length ?? 0).toBeLessThanOrEqual(
1,
);
},
);
+2 -2
View File
@@ -18,9 +18,9 @@ curl() {
cat > "$output" <<'MOCK'
#!/usr/bin/env bash
echo "regctl $*" >> "$TEST_DIR/calls"
if [[ "$1 $2" = "image import" && "$SCENARIO" = upload-fails ]]; then exit 1; fi
if [[ "$1 $2" = "image copy" && "$SCENARIO" = upload-fails ]]; then exit 1; fi
if [[ "$1 $2" = "manifest get" ]]; then
if [[ "$SCENARIO" = wrong-config ]]; then echo sha256:wrong; else echo sha256:candidate; fi
if [[ "$SCENARIO" = wrong-config && "$3" != ocidir:* ]]; then echo sha256:wrong; else printf "sha256:%064d\n" 0; fi
fi
MOCK
}