diff --git a/test/integration/harness.ts b/test/integration/harness.ts index 2f6d281..b3f259d 100644 --- a/test/integration/harness.ts +++ b/test/integration/harness.ts @@ -89,15 +89,22 @@ const UPSTREAM = new Map([ /** * What a manifest's image reference becomes on the machine. * - * Three cases, and the middle one is the whole change: + * Four cases, and the second one is the whole change: * * - **Ours** becomes the ID the machine holds it under. Nothing serves it, and nothing needs to. * - **Anything already pinned by digest** is returned exactly as written. The machine pulls it * from the internet, over its uplink, which is what a real machine does and what the lab spent * a long time serving from a registry of its own instead. - * - **A bare repository or tag** is one of ours in spirit — a bed naming an image by hand — and - * is given the digest the catalogue pins. A tag would be refused by mesh-host anyway, and - * refusing here says why rather than failing on the machine. + * - **A bare repository a bed names by hand** is given the digest mesh-catalog pins for it, so a + * bed runs the image the mesh ships. A tag would be refused by mesh-host anyway. + * - **A tag this harness has never heard of** is passed through untouched, and said out loud. + * + * That last case is not politeness, it is a finding the lab's registry was hiding. Seven catalogue + * modules name `registry-api.…/novox/…:latest` — a TAG, which ADR 0006 forbids and mesh-host + * refuses. It never showed, because the rewrite replaced every reference with a digest the lab's + * registry had assigned, tag or not. There is nothing to replace it with now, and the honest + * outcome is that those modules fail to apply, saying exactly why, on the node that carries them — + * rather than an assertion here taking the whole bed down before it starts. */ export function onTheMachine(reference: string, held: HeldImage[]): string { if (isMeshBuilt(reference)) { @@ -112,13 +119,15 @@ export function onTheMachine(reference: string, held: HeldImage[]): string { if (reference.includes("@sha256:")) return reference; const upstream = UPSTREAM.get(repositoryOf(reference)); - assert.ok( - upstream, - `${reference} is not pinned and this harness does not know an upstream digest for it. ` + - `Add the one mesh-catalog pins, or write the reference out in full — a tag moves, and the ` + - `host refuses one.`, + if (upstream) return upstream; + + console.log( + `UNPINNED: ${reference} names a tag, not a digest. The host will refuse it (novox/hq ` + + `ADR 0006). The lab's own registry used to paper over this by assigning a digest to ` + + `whatever was pushed; nothing does now. Fix the manifest, or add its digest to the ` + + `harness's UPSTREAM table.`, ); - return upstream; + return reference; } export interface Capability {