fix: expose catalog identity as a sha256 content digest
This commit is contained in:
@@ -354,6 +354,7 @@ export async function renderActiveWorkspaceRuntime(options: {
|
|||||||
const snapshotPath = options.registry.snapshotPath(revision.commit, revision.id);
|
const snapshotPath = options.registry.snapshotPath(revision.commit, revision.id);
|
||||||
const descriptorSource = await readFileAsync(snapshotPath, "utf8");
|
const descriptorSource = await readFileAsync(snapshotPath, "utf8");
|
||||||
const workspace = parseWorkspaceYaml(descriptorSource);
|
const workspace = parseWorkspaceYaml(descriptorSource);
|
||||||
|
const catalogSource = await repository.readCatalog(revision.commit);
|
||||||
const rendered = renderWorkspaceRuntimeFromWorkspace({
|
const rendered = renderWorkspaceRuntimeFromWorkspace({
|
||||||
workspace,
|
workspace,
|
||||||
workspaceId: revision.id,
|
workspaceId: revision.id,
|
||||||
@@ -369,7 +370,7 @@ export async function renderActiveWorkspaceRuntime(options: {
|
|||||||
...rendered,
|
...rendered,
|
||||||
snapshotPath,
|
snapshotPath,
|
||||||
descriptorBlob: `sha256:${createHash("sha256").update(descriptorSource).digest("hex")}`,
|
descriptorBlob: `sha256:${createHash("sha256").update(descriptorSource).digest("hex")}`,
|
||||||
catalogBlob: (await repository.catalogBlob(revision.commit)).trim(),
|
catalogBlob: `sha256:${createHash("sha256").update(catalogSource).digest("hex")}`,
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -160,7 +160,7 @@ test("active workspace rendering is byte-identical to direct snapshot rendering"
|
|||||||
expect(active.renderedConfig).toBe(direct.renderedConfig);
|
expect(active.renderedConfig).toBe(direct.renderedConfig);
|
||||||
expect(active.workspaceRevision).toBe(f.revision.commit);
|
expect(active.workspaceRevision).toBe(f.revision.commit);
|
||||||
expect(active.descriptorBlob).toMatch(/^sha256:[0-9a-f]{64}$/);
|
expect(active.descriptorBlob).toMatch(/^sha256:[0-9a-f]{64}$/);
|
||||||
expect(active.catalogBlob).toMatch(/^[0-9a-f]{40}$/);
|
expect(active.catalogBlob).toMatch(/^sha256:[0-9a-f]{64}$/);
|
||||||
});
|
});
|
||||||
|
|
||||||
test("deterministic operator leases publish one revision-bound protected config and refuse changed same-revision bytes", async () => {
|
test("deterministic operator leases publish one revision-bound protected config and refuse changed same-revision bytes", async () => {
|
||||||
|
|||||||
Reference in New Issue
Block a user