fix(docker): pull only :latest for a tagless --from, not every tag - #4124
Conversation
The Docker driver passed a bare reference as CreateImageOptions.from_image with no tag. The daemon interprets a tagless fromImage as a request for every tag in the repository and pulls them all (issue NVIDIA#4029). Normalize a pull reference by appending ':latest' when it has neither an explicit tag nor a digest, matching 'docker pull' and the Podman driver. Parsing inspects only the final path component so a registry port (e.g. 'registry:5000/team/app') is not mistaken for a tag and a digest-pinned reference ('...@sha256:...') is left untouched. Applied at both pull sites (pull_image and pull_runtime_image). Signed-off-by: Udaya Tejas <udayatejas2004@gmail.com>
|
All contributors have signed the DCO ✍️ ✅ |
|
I have read the DCO document and I hereby sign the DCO. |
|
recheck |
|
/ok to test e930bbd |
|
Label |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
The independent code review found no blocking issues in the Docker pull fix. Both pull sites select :latest for bare references while preserving explicit tags, digests, and registry ports.
@udsy19, I checked your DCO sign-off and recheck request; the DCO and vouch checks now pass.
Action required: A maintainer must follow the E2E helper's Re-run all jobs instruction for the current-head E2E run when GitHub permits the rerun, and approve the waiting Trivy Changes run. Alternatively, the operator can enable the narrowly scoped workflow actions in sandbox policy. The authorized E2E rerun was rejected by sandbox policy.
Blocking findings: None.
Carried findings: None.
Gator metadata
- Validation: Focused Docker-driver bug fix for #4029; the earlier #4045 is closed and unmerged.
- Docs: Intentionally unnecessary for this corrective fix: it restores ordinary single-image pull semantics without adding a command, flag, or configuration surface. Existing published examples use explicit tags and remain correct.
- Checks: DCO and vouch passed. Current-head Branch Checks and Helm Lint have started. Trivy Changes still requires workflow approval.
- E2E:
test:e2eapplied;/ok to testposted for the freshly verified head; mirror matches the head. Branch E2E Checks started, but the label helper's requested rerun could not be dispatched under current sandbox policy. - Head SHA:
e930bbd1dc3c8cb1d3e0e38251985d3b8b3a8e56 - Base SHA:
36819f476d14e59f29fa6e50ef6c829976ac41d0 - Merge base SHA:
36819f476d14e59f29fa6e50ef6c829976ac41d0 - Patch ID:
dd06fc330ecd8763e64d0a823f4875bd4a6b148e - Gator payload:
10 - Review mode:
initial - Previous reviewed SHA:
none - Review budget exhausted:
no - Maintainer decision required:
no - Next state:
gator:blocked - Blocked reason:
test_dispatch_required
Monitoring CompleteMonitoring is complete because this PR has merged. Final status: The last gator state was I removed the active |
Summary
Creating a sandbox from an image reference without a tag (e.g.
--from nicolaka/netshoot) makes the Docker driver pull the repository's entire tag history, likedocker pull --all-tags— the reporter saw ~9.5 GB across 37 tags from one command.Fixes #4029.
Root cause
pull_image(andpull_runtime_image) incrates/openshell-driver-docker/src/lib.rsbuildCreateImageOptions { from_image: Some(image.to_string()), .. }with notag. The Engine API treats a taglessfromImageas "pull every tag." ThedockerCLI and the Podman driver append:latestto a bare reference first.Fix
Add
normalize_pull_reference, which appends:latestonly when the reference has neither a tag nor a digest, and apply it at both pull sites. Reference parsing matches the existingopenshell_core::driver_utils::supervisor_image_tagrule: a digest (@sha256:…) is left untouched, and a:is treated as a tag only in the final path component so a registry host-port (registry:5000/team/app) is not mistaken for a tag. (A separate small helper is used rather thansupervisor_image_tagbecause that one resolves a bare ref to an impliedlatestand so can't distinguish "already tagged" from "needs a tag" — the exact distinction this fix turns on.)Tests
normalize_pull_reference_appends_latest_only_when_untaggedcovers: bare →:latest, already-tagged unchanged, digest unchanged,registry:5000/team/app→:latest, andregistry:5000/team/app:v1unchanged.cargo test -p openshell-driver-docker normalize_pull_referencepasses.