import { test } from "node:test"; import assert from "node:assert/strict"; import { pinnedInto, repositoryOf, stillUnpinned } from "../src/pinning.ts"; const SERVED = [ "192.0.2.250:5000/postgres@sha256:" + "a".repeat(64), "192.0.2.250:5000/mesh-provision-postgres@sha256:" + "b".repeat(64), "192.0.2.250:5000/gitea/gitea@sha256:" + "c".repeat(64), "192.0.2.250:5000/ghcr.io/mailu/admin@sha256:" + "d".repeat(64), ]; test("the repository is what survives being served somewhere else", () => { assert.equal(repositoryOf(SERVED[0]!), "postgres"); assert.equal(repositoryOf(SERVED[2]!), "gitea/gitea"); assert.equal(repositoryOf(SERVED[3]!), "ghcr.io/mailu/admin"); assert.equal(repositoryOf("alpine"), "alpine"); }); // The case this exists for: an image the mesh builds has no digest until it is built, so a // manifest ships sixty-four zeros and would stop on the machine (novox/hq 04-ISSUES/025). test("a placeholder for one of our own images becomes the one this scenario serves", () => { const before = `"image": "mesh-provision-postgres@sha256:${"0".repeat(64)}"`; const after = pinnedInto(before, SERVED); assert.match(after, /192\.0\.2\.250:5000\/mesh-provision-postgres@sha256:b{64}/); assert.deepEqual(stillUnpinned(after), []); }); // And a real third-party digest is replaced too — the text says which image, the scenario says // which copy of it. test("a real digest is redirected to this scenario's copy", () => { const before = `"image": "gitea/gitea@sha256:${"f".repeat(64)}"`; assert.match(pinnedInto(before, SERVED), /192\.0\.2\.250:5000\/gitea\/gitea@sha256:c{64}/); }); test("a reference that already carries a registry is still redirected", () => { const before = `"image": "docker.io/postgres@sha256:${"e".repeat(64)}"`; assert.match(pinnedInto(before, SERVED), /192\.0\.2\.250:5000\/postgres@sha256:a{64}/); }); // **Left alone, not blanked.** A repository this scenario did not stock may be reachable some // other way, and emptying the reference would produce the exact failure this prevents. test("something the scenario does not serve is untouched", () => { const before = `"image": "redis@sha256:${"9".repeat(64)}"`; assert.equal(pinnedInto(before, SERVED), before); }); // A longer repository ending in a shorter one must not be half-replaced. test("a repository that ends in another one is not partly rewritten", () => { const before = `"image": "my-postgres@sha256:${"7".repeat(64)}"`; assert.equal(pinnedInto(before, SERVED), before, "'my-postgres' was rewritten because it ends in 'postgres'"); }); test("every image in a whole manifest is redirected at once", () => { const manifest = JSON.stringify({ resources: [ { id: "db", image: `postgres@sha256:${"1".repeat(64)}` }, { id: "prov", image: `mesh-provision-postgres@sha256:${"0".repeat(64)}` }, { id: "app", image: `gitea/gitea@sha256:${"2".repeat(64)}` }, ], }); const after = pinnedInto(manifest, SERVED); assert.deepEqual(stillUnpinned(after), []); for (const want of ["a".repeat(64), "b".repeat(64), "c".repeat(64)]) { assert.ok(after.includes(want), `missing ${want.slice(0, 6)}… in ${after}`); } }); test("what is still a placeholder can be named", () => { const text = `"image": "something-of-ours@sha256:${"0".repeat(64)}"`; assert.deepEqual(stillUnpinned(text), ["something-of-ours"]); });