image_digest.resolve honours a @digest: asks the registry for THAT manifest (R-746)
gates / gates (push) Successful in 2s
gates / gates (push) Successful in 2s
The digest was dropped and the tag's current digest returned, so 'is this digest still served' got a false yes (measured: redis:7-alpine@sha256:000…0 resolved to the tag's digest; now HTTP 404). A malformed digest is refused without a request. test_image_digest.py (no network); red-proof: the pre-fix resolver fails 3 of 4 cases. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
+12
-4
@@ -34,8 +34,8 @@ UA = "felhom-catalog-digest/1.0 (read-only)"
|
|||||||
|
|
||||||
|
|
||||||
def split_ref(ref):
|
def split_ref(ref):
|
||||||
"""'ghcr.io/a/b:1.2' -> ('ghcr.io', 'a/b', '1.2'). A digest suffix is dropped; Docker Hub
|
"""'ghcr.io/a/b:1.2' -> ('ghcr.io', 'a/b', '1.2'). A digest suffix is dropped here (resolve() asks for it by
|
||||||
short names get `library/`."""
|
itself); Docker Hub short names get `library/`."""
|
||||||
ref = ref.split("@", 1)[0]
|
ref = ref.split("@", 1)[0]
|
||||||
first = ref.split("/", 1)[0]
|
first = ref.split("/", 1)[0]
|
||||||
if "/" in ref and ("." in first or ":" in first or first == "localhost"):
|
if "/" in ref and ("." in first or ":" in first or first == "localhost"):
|
||||||
@@ -69,15 +69,23 @@ def _bearer(www_auth):
|
|||||||
|
|
||||||
|
|
||||||
def resolve(ref, timeout=30):
|
def resolve(ref, timeout=30):
|
||||||
"""(digest, None) or (None, why). Read-only: one HEAD, one token fetch at most."""
|
"""(digest, None) or (None, why). Read-only: one HEAD, one token fetch at most.
|
||||||
|
|
||||||
|
A ref carrying `@sha256:…` asks for THAT manifest (R-746): the answer is the digest only when the registry still
|
||||||
|
serves it, never the tag's current digest — a caller asking "is this digest still served" got a false yes."""
|
||||||
host, repo, tag = split_ref(ref)
|
host, repo, tag = split_ref(ref)
|
||||||
url = "https://%s/v2/%s/manifests/%s" % (host, repo, tag)
|
want = ref.split("@", 1)[1] if "@" in ref else ""
|
||||||
|
if want and not (want.startswith("sha256:") and len(want) == 71):
|
||||||
|
return None, "not a sha256 digest: %s" % want
|
||||||
|
url = "https://%s/v2/%s/manifests/%s" % (host, repo, want or tag)
|
||||||
headers = {"Accept": ACCEPT, "User-Agent": UA}
|
headers = {"Accept": ACCEPT, "User-Agent": UA}
|
||||||
for attempt in (1, 2):
|
for attempt in (1, 2):
|
||||||
req = urllib.request.Request(url, headers=headers, method="HEAD")
|
req = urllib.request.Request(url, headers=headers, method="HEAD")
|
||||||
try:
|
try:
|
||||||
with urllib.request.urlopen(req, timeout=timeout) as r:
|
with urllib.request.urlopen(req, timeout=timeout) as r:
|
||||||
d = r.headers.get("Docker-Content-Digest")
|
d = r.headers.get("Docker-Content-Digest")
|
||||||
|
if want and d != want:
|
||||||
|
return None, "the registry answered %s for %s" % (d, want)
|
||||||
if d and d.startswith("sha256:") and len(d) == 71:
|
if d and d.startswith("sha256:") and len(d) == 71:
|
||||||
return d, None
|
return d, None
|
||||||
return None, "no Docker-Content-Digest header (HTTP %s)" % r.status
|
return None, "no Docker-Content-Digest header (HTTP %s)" % r.status
|
||||||
|
|||||||
@@ -0,0 +1,75 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""R-746: image_digest.resolve honours a `@digest` — it asks the registry for THAT manifest and never answers the tag's
|
||||||
|
current digest. No network: urlopen is replaced by a fake registry that serves one tag and one digest.
|
||||||
|
|
||||||
|
COMPANION RED-PROOF: with the pre-fix resolve (it dropped the digest and asked for the tag), the absent-digest case
|
||||||
|
answers the tag's digest and this test fails ("a digest the registry does not serve was resolved")."""
|
||||||
|
import io
|
||||||
|
import os
|
||||||
|
import sys
|
||||||
|
import unittest
|
||||||
|
import urllib.error
|
||||||
|
|
||||||
|
sys.path.insert(0, os.path.dirname(os.path.abspath(__file__)))
|
||||||
|
import image_digest # noqa: E402
|
||||||
|
|
||||||
|
SERVED = "sha256:" + "a" * 64
|
||||||
|
GONE = "sha256:" + "0" * 64
|
||||||
|
|
||||||
|
|
||||||
|
class _Resp:
|
||||||
|
def __init__(self, digest):
|
||||||
|
self.headers = {"Docker-Content-Digest": digest}
|
||||||
|
self.status = 200
|
||||||
|
|
||||||
|
def __enter__(self):
|
||||||
|
return self
|
||||||
|
|
||||||
|
def __exit__(self, *a):
|
||||||
|
return False
|
||||||
|
|
||||||
|
|
||||||
|
class FakeRegistry:
|
||||||
|
def __init__(self):
|
||||||
|
self.urls = []
|
||||||
|
|
||||||
|
def __call__(self, req, timeout=30):
|
||||||
|
url = req.full_url
|
||||||
|
self.urls.append(url)
|
||||||
|
last = url.rsplit("/", 1)[-1]
|
||||||
|
if last in ("7-alpine", SERVED): # the tag and the digest it serves
|
||||||
|
return _Resp(SERVED)
|
||||||
|
raise urllib.error.HTTPError(url, 404, "not found", {}, io.BytesIO(b""))
|
||||||
|
|
||||||
|
|
||||||
|
class ResolveDigest(unittest.TestCase):
|
||||||
|
def setUp(self):
|
||||||
|
self.fake = FakeRegistry()
|
||||||
|
self.orig = image_digest.urllib.request.urlopen
|
||||||
|
image_digest.urllib.request.urlopen = self.fake
|
||||||
|
|
||||||
|
def tearDown(self):
|
||||||
|
image_digest.urllib.request.urlopen = self.orig
|
||||||
|
|
||||||
|
def test_plain_tag_unchanged(self):
|
||||||
|
self.assertEqual(image_digest.resolve("redis:7-alpine"), (SERVED, None))
|
||||||
|
self.assertTrue(self.fake.urls[-1].endswith("/manifests/7-alpine"))
|
||||||
|
|
||||||
|
def test_served_digest_is_asked_by_digest(self):
|
||||||
|
d, why = image_digest.resolve("redis:7-alpine@" + SERVED)
|
||||||
|
self.assertEqual(d, SERVED, why)
|
||||||
|
self.assertTrue(self.fake.urls[-1].endswith("/manifests/" + SERVED), self.fake.urls)
|
||||||
|
|
||||||
|
def test_absent_digest_is_refused(self):
|
||||||
|
d, why = image_digest.resolve("redis:7-alpine@" + GONE)
|
||||||
|
self.assertIsNone(d, "a digest the registry does not serve was resolved (to %s)" % d)
|
||||||
|
self.assertIn("404", why)
|
||||||
|
|
||||||
|
def test_malformed_digest_is_refused(self):
|
||||||
|
d, why = image_digest.resolve("redis:7-alpine@sha256:abc")
|
||||||
|
self.assertIsNone(d)
|
||||||
|
self.assertEqual(self.fake.urls, [], "a malformed digest must not reach the registry")
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
unittest.main()
|
||||||
Reference in New Issue
Block a user