feat(image): support --change on import - #5102
mayur-tolexo wants to merge 1 commit into
Conversation
97afa35 to
5f20d73
Compare
|
Ran every All supported instructions — Docker, same command: Same Shell-form Instructions not representable in the OCI image config — nerdctl rejects them: Docker rejects |
ccf77bf to
fdf7dbf
Compare
fdf7dbf to
057d312
Compare
There was a problem hiding this comment.
Can we invoke buildctl build ?
There was a problem hiding this comment.
Tried it.
The Dockerfile has to be FROM <the image we just imported>, which only resolves on a containerd-worker buildkitd in the same namespace and snapshotter and import needs no daemon today.
Worse, BuildKit runs everything we pass it:
$ nerdctl import --change 'RUN touch /pwned' rootfs.tar img
docker.io/library/img:latest
$ nerdctl run --rm --entrypoint /bin/ls img -la /pwned
-rw-r--r-- 1 0 0 0 Sep 23 09:20 /pwned
FROM alpine is accepted too and replaces the rootfs, so we'd still need an allow-list here. It also injects a default PATH and adds a layer for WORKDIR.
Using BuildKit's Dockerfile parser in-process instead gives the same config with no daemon, and the type switch is the allow-list. moby/buildkit is already in the module graph. Would that work for you?
There was a problem hiding this comment.
Using BuildKit's Dockerfile parser in-process instead gives the same config with no daemon, and the type switch is the allow-list.
SGTM
moby/buildkit is already in the module graph.
I don't see it
There was a problem hiding this comment.
I don't see it
You're right, my mistake. It shows up in go list -m all, but only because something in the graph requires it, nothing imports it.
057d312 to
7b8bb4e
Compare
Apply Dockerfile-style instructions to the config of the image created by `nerdctl import`, matching `docker import --change`. Supported instructions are the ones representable in the OCI image config: CMD, ENTRYPOINT, ENV, EXPOSE, LABEL, USER, VOLUME, WORKDIR, STOPSIGNAL. HEALTHCHECK and ONBUILD have no place in an OCI config and are rejected, where docker accepts them into its own config schema; SHELL is rejected by docker too. Instructions are parsed with BuildKit's Dockerfile parser rather than one of our own, so --change takes the same syntax as build. The type switch that writes an instruction into the config is the allow-list: RUN, COPY, FROM and the rest have nothing to write and are rejected, as is a change holding more than one instruction. --change applies to a filesystem (rootfs) import, which builds a fresh config; it is rejected for a standard image archive that already carries its own config. Part of containerd#3867 Signed-off-by: Mayur Das <mayur.das@neevcloud.com>
7b8bb4e to
7b881e1
Compare
| github.com/docker/cli v29.8.1+incompatible //gomodjail:unconfined | ||
| github.com/docker/go-connections v0.8.1 //gomodjail:unconfined | ||
| github.com/docker/go-units v0.5.0 | ||
| github.com/moby/buildkit v0.33.0 |
| return buf | ||
| } | ||
|
|
||
| // minimalImageArchiveTar returns a tar that looks like a standard image archive |
There was a problem hiding this comment.
What is "standard image archive"?
Did you mean Docker Image Spec?
| }, | ||
| { | ||
| Description: "image import --change rejected for a standard image archive", | ||
| // nerdctl-only: Docker's import treats any tarball as a rootfs and has |
| { | ||
| Description: "image import --change rejected for a standard image archive", | ||
| // nerdctl-only: Docker's import treats any tarball as a rootfs and has | ||
| // no standard-image-archive rejection. |
There was a problem hiding this comment.
Same as above. "standard-image-archive" sounds confusing
docker import --changeapplies Dockerfile instructions to the config of the image it creates; nerdctl had it listed as unimplemented (part of #3867). This implements it.nerdctl import --change 'CMD ["echo"]' --change 'ENV FOO=bar' rootfs.tar imgnow behaves like Docker. Supported instructions are the ones representable in the OCI image config thatimportwrites:CMD,ENTRYPOINT,ENV,EXPOSE,LABEL,USER,VOLUME,WORKDIR,STOPSIGNAL.HEALTHCHECK,ONBUILDandSHELLonly exist in Docker's own image-config schema, not the OCI one, so they're rejected with a clear error instead of being silently dropped.--changeonly makes sense when building a fresh config, so it applies to a filesystem (rootfs) import and is rejected for a standard image archive that already carries its own config.Checked against Docker 29.4.0 in a Linux/containerd sandbox —
inspect .Configcomes out identical for the supported instructions:docker gives the same config for those inputs. The unsupported ones error clearly:
The parser has unit tests per instruction (JSON vs shell form, quoted ENV/LABEL values, and the error paths) plus an integration test that imports with
--changeand checks the resulting config.