Skip to content

fix(docker): pull only :latest for a tagless --from, not every tag - #4124

Merged
johntmyers merged 1 commit into
NVIDIA:mainfrom
udsy19:fix/docker-pull-bare-ref-latest
Oct 3, 2026
Merged

johntmyers merged 1 commit into
NVIDIA:mainfrom
udsy19:fix/docker-pull-bare-ref-latest

Conversation

@udsy19

@udsy19 udsy19 commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Summary

Creating a sandbox from an image reference without a tag (e.g. --from nicolaka/netshoot) makes the Docker driver pull the repository's entire tag history, like docker pull --all-tags — the reporter saw ~9.5 GB across 37 tags from one command.

Fixes #4029.

Root cause

pull_image (and pull_runtime_image) in crates/openshell-driver-docker/src/lib.rs build CreateImageOptions { from_image: Some(image.to_string()), .. } with no tag. The Engine API treats a tagless fromImage as "pull every tag." The docker CLI and the Podman driver append :latest to a bare reference first.

Fix

Add normalize_pull_reference, which appends :latest only when the reference has neither a tag nor a digest, and apply it at both pull sites. Reference parsing matches the existing openshell_core::driver_utils::supervisor_image_tag rule: a digest (@sha256:…) is left untouched, and a : is treated as a tag only in the final path component so a registry host-port (registry:5000/team/app) is not mistaken for a tag. (A separate small helper is used rather than supervisor_image_tag because that one resolves a bare ref to an implied latest and so can't distinguish "already tagged" from "needs a tag" — the exact distinction this fix turns on.)

Tests

normalize_pull_reference_appends_latest_only_when_untagged covers: bare → :latest, already-tagged unchanged, digest unchanged, registry:5000/team/app → :latest, and registry:5000/team/app:v1 unchanged. cargo test -p openshell-driver-docker normalize_pull_reference passes.

The Docker driver passed a bare reference as CreateImageOptions.from_image
with no tag. The daemon interprets a tagless fromImage as a request for
every tag in the repository and pulls them all (issue NVIDIA#4029).

Normalize a pull reference by appending ':latest' when it has neither an
explicit tag nor a digest, matching 'docker pull' and the Podman driver.
Parsing inspects only the final path component so a registry port (e.g.
'registry:5000/team/app') is not mistaken for a tag and a digest-pinned
reference ('...@sha256:...') is left untouched. Applied at both pull
sites (pull_image and pull_runtime_image).

Signed-off-by: Udaya Tejas <udayatejas2004@gmail.com>
@udsy19
udsy19 requested review from a team, derekwaynecarr, mrunalp and sjenning as code owners October 2, 2026 15:14
@copy-pr-bot

copy-pr-bot Bot commented Oct 2, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

All contributors have signed the DCO ✍️ ✅
Posted by the DCO Assistant Lite bot.

@udsy19

udsy19 commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

I have read the DCO document and I hereby sign the DCO.

@udsy19

udsy19 commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

recheck

@johntmyers johntmyers added the test:e2e Requires end-to-end coverage label Oct 2, 2026
@johntmyers

Copy link
Copy Markdown
Collaborator

/ok to test e930bbd

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Label test:e2e applied for e930bbd. Open the existing run and click Re-run all jobs to execute with the label set. The run will execute the standard E2E suite after building the required gateway, sandbox, and supervisor images once. The matching required CI gate status on this PR will flip green automatically once the run finishes.

@johntmyers johntmyers left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

The independent code review found no blocking issues in the Docker pull fix. Both pull sites select :latest for bare references while preserving explicit tags, digests, and registry ports.

@udsy19, I checked your DCO sign-off and recheck request; the DCO and vouch checks now pass.

Action required: A maintainer must follow the E2E helper's Re-run all jobs instruction for the current-head E2E run when GitHub permits the rerun, and approve the waiting Trivy Changes run. Alternatively, the operator can enable the narrowly scoped workflow actions in sandbox policy. The authorized E2E rerun was rejected by sandbox policy.

Blocking findings: None.

Carried findings: None.

Gator metadata
  • Validation: Focused Docker-driver bug fix for #4029; the earlier #4045 is closed and unmerged.
  • Docs: Intentionally unnecessary for this corrective fix: it restores ordinary single-image pull semantics without adding a command, flag, or configuration surface. Existing published examples use explicit tags and remain correct.
  • Checks: DCO and vouch passed. Current-head Branch Checks and Helm Lint have started. Trivy Changes still requires workflow approval.
  • E2E: test:e2e applied; /ok to test posted for the freshly verified head; mirror matches the head. Branch E2E Checks started, but the label helper's requested rerun could not be dispatched under current sandbox policy.
  • Head SHA: e930bbd1dc3c8cb1d3e0e38251985d3b8b3a8e56
  • Base SHA: 36819f476d14e59f29fa6e50ef6c829976ac41d0
  • Merge base SHA: 36819f476d14e59f29fa6e50ef6c829976ac41d0
  • Patch ID: dd06fc330ecd8763e64d0a823f4875bd4a6b148e
  • Gator payload: 10
  • Review mode: initial
  • Previous reviewed SHA: none
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:blocked
  • Blocked reason: test_dispatch_required

@johntmyers johntmyers added gator:blocked Gator is blocked by process or repository gates gator:approval-needed Gator completed review; maintainer approval needed gator:watch-pipeline Gator is monitoring PR CI/CD status and removed gator:blocked Gator is blocked by process or repository gates gator:approval-needed Gator completed review; maintainer approval needed gator:watch-pipeline Gator is monitoring PR CI/CD status labels Oct 2, 2026
@johntmyers
johntmyers added this pull request to the merge queue Oct 3, 2026
@johntmyers johntmyers added gator:merge-ready and removed gator:approval-needed Gator completed review; maintainer approval needed labels Oct 3, 2026
Merged via the queue into NVIDIA:main with commit fcd8fe5 Oct 3, 2026
192 of 197 checks passed
@johntmyers

Copy link
Copy Markdown
Collaborator

gator-agent

Monitoring Complete

Monitoring is complete because this PR has merged.

Final status: The last gator state was gator:merge-ready; the current head had no blocking Gator review findings and received maintainer approval.

I removed the active gator:* label because there is nothing left for gator to monitor on this PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

test:e2e Requires end-to-end coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug: Docker driver pulls every tag of a repository when --from has no tag

2 participants