-
Notifications
You must be signed in to change notification settings - Fork 832
feat(image): support --change on import #5102
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -23,6 +23,7 @@ import ( | |
| "net/http" | ||
| "os" | ||
| "path/filepath" | ||
| "slices" | ||
| "strings" | ||
| "testing" | ||
|
|
||
|
|
@@ -45,6 +46,20 @@ func minimalRootfsTar(t *testing.T) *bytes.Buffer { | |
| return buf | ||
| } | ||
|
|
||
| // minimalImageArchiveTar returns a tar that looks like a standard image archive | ||
| // (it carries a manifest.json), used to exercise the --change rejection path. | ||
| func minimalImageArchiveTar(t *testing.T) *bytes.Buffer { | ||
| t.Helper() | ||
| buf := new(bytes.Buffer) | ||
| tw := tar.NewWriter(buf) | ||
| content := []byte("[]") | ||
| assert.NilError(t, tw.WriteHeader(&tar.Header{Name: "manifest.json", Size: int64(len(content)), Mode: 0644})) | ||
| _, err := tw.Write(content) | ||
| assert.NilError(t, err) | ||
| assert.NilError(t, tw.Close()) | ||
| return buf | ||
| } | ||
|
|
||
| func TestImageImportErrors(t *testing.T) { | ||
| nerdtest.Setup() | ||
|
|
||
|
|
@@ -143,6 +158,55 @@ func TestImageImport(t *testing.T) { | |
| } | ||
| }, | ||
| }, | ||
| { | ||
| Description: "image import with change", | ||
| Cleanup: func(data test.Data, helpers test.Helpers) { | ||
| helpers.Anyhow("rmi", "-f", data.Identifier()) | ||
| }, | ||
| Command: func(data test.Data, helpers test.Helpers) test.TestableCommand { | ||
| cmd := helpers.Command("import", | ||
| "--change", `CMD ["echo","hi"]`, | ||
| "--change", "ENV FOO=bar", | ||
| "--change", "WORKDIR /srv", | ||
| "--change", "EXPOSE 8080", | ||
| "-", data.Identifier()) | ||
| cmd.Feed(bytes.NewReader(minimalRootfsTar(t).Bytes())) | ||
| return cmd | ||
| }, | ||
| Expected: func(data test.Data, helpers test.Helpers) *test.Expected { | ||
| identifier := data.Identifier() + ":latest" | ||
| return &test.Expected{ | ||
| Output: expect.All( | ||
| func(stdout string, t tig.T) { | ||
| img := nerdtest.InspectImage(helpers, identifier) | ||
| assert.Assert(t, img.Config != nil) | ||
| assert.DeepEqual(t, img.Config.Cmd, []string{"echo", "hi"}) | ||
| assert.Assert(t, slices.Contains(img.Config.Env, "FOO=bar")) | ||
| assert.Equal(t, img.Config.WorkingDir, "/srv") | ||
| _, ok := img.Config.ExposedPorts["8080/tcp"] | ||
| assert.Assert(t, ok) | ||
| }, | ||
| ), | ||
| } | ||
| }, | ||
| }, | ||
| { | ||
| Description: "image import --change rejected for a standard image archive", | ||
| // nerdctl-only: Docker's import treats any tarball as a rootfs and has | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Is this a bug of Docker? |
||
| // no standard-image-archive rejection. | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Same as above. "standard-image-archive" sounds confusing |
||
| Require: require.Not(nerdtest.Docker), | ||
| Command: func(data test.Data, helpers test.Helpers) test.TestableCommand { | ||
| cmd := helpers.Command("import", "--change", `CMD ["echo"]`, "-", data.Identifier()) | ||
| cmd.Feed(bytes.NewReader(minimalImageArchiveTar(t).Bytes())) | ||
| return cmd | ||
| }, | ||
| Expected: func(data test.Data, helpers test.Helpers) *test.Expected { | ||
| return &test.Expected{ | ||
| ExitCode: expect.ExitCodeGenericFail, | ||
| Errors: []error{errors.New("filesystem archive")}, | ||
| } | ||
| }, | ||
| }, | ||
| { | ||
| Description: "image import with platform", | ||
| Cleanup: func(data test.Data, helpers test.Helpers) { | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -27,6 +27,7 @@ require ( | |
| github.com/docker/cli v29.8.1+incompatible //gomodjail:unconfined | ||
| github.com/docker/go-connections v0.8.1 //gomodjail:unconfined | ||
| github.com/docker/go-units v0.5.0 | ||
| github.com/moby/buildkit v0.33.0 | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Now v0.33.1 |
||
| github.com/moby/moby/client v0.6.0 //gomodjail:unconfined | ||
| github.com/moby/moby/v2 v2.0.0-beta.24 //gomodjail:unconfined | ||
| github.com/moby/sys/mount v0.3.5 //gomodjail:unconfined | ||
|
|
@@ -90,20 +91,21 @@ require ( | |
| //gomodjail:unconfined | ||
| github.com/containerd/ttrpc v1.2.9 // indirect | ||
| //gomodjail:unconfined | ||
| github.com/docker/docker-credential-helpers v0.9.3 // indirect | ||
| github.com/docker/docker-credential-helpers v0.9.8 // indirect | ||
| github.com/moby/docker-image-spec v1.3.1 // indirect | ||
| github.com/moby/locker v1.0.1 // indirect | ||
| github.com/moby/moby/api v1.56.0 // indirect | ||
| //gomodjail:unconfined | ||
| github.com/moby/sys/mountinfo v0.7.2 // indirect | ||
| github.com/moby/sys/symlink v0.3.0 // indirect | ||
| golang.org/x/exp v0.0.0-20250711185948-6ae5c78190dc // indirect | ||
| golang.org/x/exp v0.0.0-20260603202125-055de637280b // indirect | ||
| ) | ||
|
|
||
| require ( | ||
| cyphar.com/go-pathrs v0.2.5 // indirect | ||
| github.com/Azure/go-ansiterm v0.0.0-20250102033503-faa5f7b0171c // indirect | ||
| github.com/ProtonMail/go-crypto v1.4.1 // indirect | ||
| github.com/agext/levenshtein v1.2.3 // indirect | ||
| github.com/cespare/xxhash/v2 v2.3.0 // indirect | ||
| //gomodjail:unconfined | ||
| github.com/cilium/ebpf v0.22.0 // indirect | ||
|
|
@@ -146,6 +148,7 @@ require ( | |
| github.com/petermattis/goid v0.0.0-20240813172612-4fcff4a6cae7 // indirect | ||
| github.com/philhofer/fwd v1.2.0 // indirect | ||
| github.com/pkg/errors v0.9.1 // indirect | ||
| github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 // indirect | ||
| //gomodjail:unconfined | ||
| github.com/santhosh-tekuri/jsonschema/v6 v6.0.1 // indirect | ||
| github.com/sasha-s/go-deadlock v0.3.5 // indirect | ||
|
|
@@ -157,6 +160,7 @@ require ( | |
| github.com/stefanberger/go-pkcs11uri v0.0.0-20230803200340-78284954bff6 // indirect | ||
| //gomodjail:unconfined | ||
| github.com/tinylib/msgp v1.3.0 // indirect | ||
| github.com/tonistiigi/go-csvvalue v0.0.0-20240814133006-030d3b2625d0 // indirect | ||
| //gomodjail:unconfined | ||
| github.com/vbatts/tar-split v0.12.3 // indirect | ||
| github.com/xhit/go-str2duration/v2 v2.1.0 // indirect | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
What is "standard image archive"?
Did you mean Docker Image Spec?