An undeclared COPY --from is refused; an undeclared FROM is said, not yet refused

The mesh's own images start FROM a public base — the control plane's, the builder's,
the tool runtime's — and refusing those refuses genesis. They declare their bases
next; until then the base is named every build, with the remedy.
This commit is contained in:
2026-09-21 20:48:00 +02:00
parent 6f6e1244d4
commit e81f352979
2 changed files with 32 additions and 16 deletions
+10 -6
View File
@@ -120,12 +120,16 @@ FROM scratch
COPY --from=vendor/tool:latest /tool /tool
FROM golang:1.25-alpine AS go
`
got := undeclaredFetches(recipe, map[string]bool{"RUNTIME_BASE": true})
want := []string{"${MC_BASE} (a build argument the manifest does not declare)", "vendor/tool:latest", "golang:1.25-alpine"}
if strings.Join(got, "|") != strings.Join(want, "|") {
t.Fatalf("got %v, want %v", got, want)
bases, copies := undeclaredFetches(recipe, map[string]bool{"RUNTIME_BASE": true})
if strings.Join(copies, "|") != "${MC_BASE} (a build argument the manifest does not declare)|vendor/tool:latest" {
t.Fatalf("copies out of undeclared images: %v", copies)
}
if got := undeclaredFetches(recipe, map[string]bool{"RUNTIME_BASE": true, "MC_BASE": true}); len(got) != 2 {
t.Fatalf("declared arguments are not fetches: %v", got)
// A base fetched on its own is named apart: the mesh's own images still start FROM one, so
// it is said rather than refused until they declare theirs.
if strings.Join(bases, "|") != "golang:1.25-alpine" {
t.Fatalf("undeclared bases: %v", bases)
}
if _, copies := undeclaredFetches(recipe, map[string]bool{"RUNTIME_BASE": true, "MC_BASE": true}); len(copies) != 1 {
t.Fatalf("declared arguments are not fetches: %v", copies)
}
}