From ad3c3125a8f6e1727e3c41592edc492cd06b8191 Mon Sep 17 00:00:00 2001 From: mptyl Date: Tue, 11 Aug 2026 19:25:04 +0200 Subject: [PATCH] fix: expose catalog identity as a sha256 content digest --- backend/src/workspaces/runtime-config-lease.ts | 3 ++- backend/test/workspace-runtime-config-lease.test.ts | 2 +- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/backend/src/workspaces/runtime-config-lease.ts b/backend/src/workspaces/runtime-config-lease.ts index f437fff7..af126c9c 100644 --- a/backend/src/workspaces/runtime-config-lease.ts +++ b/backend/src/workspaces/runtime-config-lease.ts @@ -354,6 +354,7 @@ export async function renderActiveWorkspaceRuntime(options: { const snapshotPath = options.registry.snapshotPath(revision.commit, revision.id); const descriptorSource = await readFileAsync(snapshotPath, "utf8"); const workspace = parseWorkspaceYaml(descriptorSource); + const catalogSource = await repository.readCatalog(revision.commit); const rendered = renderWorkspaceRuntimeFromWorkspace({ workspace, workspaceId: revision.id, @@ -369,7 +370,7 @@ export async function renderActiveWorkspaceRuntime(options: { ...rendered, snapshotPath, descriptorBlob: `sha256:${createHash("sha256").update(descriptorSource).digest("hex")}`, - catalogBlob: (await repository.catalogBlob(revision.commit)).trim(), + catalogBlob: `sha256:${createHash("sha256").update(catalogSource).digest("hex")}`, }; } diff --git a/backend/test/workspace-runtime-config-lease.test.ts b/backend/test/workspace-runtime-config-lease.test.ts index 8ab5ee87..ab491cac 100644 --- a/backend/test/workspace-runtime-config-lease.test.ts +++ b/backend/test/workspace-runtime-config-lease.test.ts @@ -160,7 +160,7 @@ test("active workspace rendering is byte-identical to direct snapshot rendering" expect(active.renderedConfig).toBe(direct.renderedConfig); expect(active.workspaceRevision).toBe(f.revision.commit); expect(active.descriptorBlob).toMatch(/^sha256:[0-9a-f]{64}$/); - expect(active.catalogBlob).toMatch(/^[0-9a-f]{40}$/); + expect(active.catalogBlob).toMatch(/^sha256:[0-9a-f]{64}$/); }); test("deterministic operator leases publish one revision-bound protected config and refuse changed same-revision bytes", async () => {