fix: use sha256 descriptor digest and keep operator errors fully sanitized
This commit is contained in:
@@ -129,8 +129,7 @@ export class WorkspacePreprocessingService {
|
||||
{ kind: "runtime_config", digest: runtime.configLease.configDigest },
|
||||
],
|
||||
});
|
||||
} catch (error) {
|
||||
const detail = error instanceof Error ? error.message : String(error);
|
||||
} catch {
|
||||
return {
|
||||
schemaVersion: 1,
|
||||
status: "failed",
|
||||
@@ -140,7 +139,6 @@ export class WorkspacePreprocessingService {
|
||||
descriptorBlob: "",
|
||||
operation: "inspect",
|
||||
completedStages: [],
|
||||
warnings: detail.length > 0 ? [detail.slice(0, 512)] : undefined,
|
||||
};
|
||||
}
|
||||
}
|
||||
|
||||
@@ -352,7 +352,8 @@ export async function renderActiveWorkspaceRuntime(options: {
|
||||
const repository = new GitWorkspaceRepository(options.registryConfig);
|
||||
await repository.ensureLayout();
|
||||
const snapshotPath = options.registry.snapshotPath(revision.commit, revision.id);
|
||||
const workspace = parseWorkspaceYaml(await readFileAsync(snapshotPath, "utf8"));
|
||||
const descriptorSource = await readFileAsync(snapshotPath, "utf8");
|
||||
const workspace = parseWorkspaceYaml(descriptorSource);
|
||||
const rendered = renderWorkspaceRuntimeFromWorkspace({
|
||||
workspace,
|
||||
workspaceId: revision.id,
|
||||
@@ -367,7 +368,7 @@ export async function renderActiveWorkspaceRuntime(options: {
|
||||
return {
|
||||
...rendered,
|
||||
snapshotPath,
|
||||
descriptorBlob: revision.blob,
|
||||
descriptorBlob: `sha256:${createHash("sha256").update(descriptorSource).digest("hex")}`,
|
||||
catalogBlob: (await repository.catalogBlob(revision.commit)).trim(),
|
||||
};
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user