Files
copilotkit__copilotkit/showcase/bin/spec/test_ghcr_digest.rb
Jordan Ritter 914dbc5855 fix(showcase/bin): surface GHCR /token exchange failures instead of masking them
bearer_for ended with a blanket `rescue StandardError => nil` plus
`return nil if status >= 400`. Now that bearer_for ALWAYS performs the
/token exchange (even when a token is present), that swallow masked real
failures: a non-2xx /token response, a malformed JSON body, or a transport
error all collapsed to nil, after which manifest_exists issued the manifest
HEAD anonymously (no Authorization). That silently violated manifest_exists's
documented raise-on-transport/5xx contract and conflated "no token supplied"
with "supplied token failed to exchange".

bearer_for now:
- raises GHCR::Error on a >=400 /token response WHEN a token was supplied
  (token absent still returns nil — the legitimate anonymous-public fallback);
- raises GHCR::Error on JSON::ParserError for an unparseable 200 body;
- no longer swallows StandardError, so transport exceptions
  (Errno::ECONNREFUSED, Net::ReadTimeout, ...) propagate.

Call-site enumeration (bearer_for is called only by manifest_exists and
resolve_digest):
- manifest_exists: documents "Raises GHCR::Error on 5xx or transport failure",
  so a raised exchange error is consistent with — and strengthens — its own
  contract. Assumption holds.
- resolve_digest: already raises GHCR::Error on its own manifest HEAD >=400 and
  does not rescue bearer_for, so a raised exchange error propagates exactly as
  its other failures do. Assumption holds.
Neither caller is broken by bearer_for raising; both already propagate
GHCR::Error to their callers.

Tests: add 3 red-green cases in test_ghcr_bearer.rb (token-present 401 raises;
token-present malformed body raises; token-present exchange failure issues NO
anonymous manifest HEAD). The existing manifest_exists/digest fakes were only
green because the old swallow masked the fake's "no fake response" error — they
never modeled the mandatory /token exchange; added a successful /token fake to
each so they exercise the real path. Renumbered the snapshot-ivar-lint
allowlist (+13 lines) to track the bin/railway line drift.
2026-06-04 09:18:08 -07:00

77 lines
3.0 KiB
Ruby

# frozen_string_literal: true
require_relative "spec_helper"
class GHCRDigestTest < Minitest::Test
# Fake HTTP layer for the GHCR client.
class FakeHTTP
def initialize(responses)
@responses = responses
end
def call(method:, url:, headers: {})
key = [method, url]
r = @responses[key] || @responses[url]
raise "no fake response for #{key.inspect}" unless r
r
end
end
def test_parse_image_ref_handles_all_shapes
g = Railway::GHCR.new
p1 = g.parse_image_ref("ghcr.io/copilotkit/showcase-shell:latest")
assert_equal "ghcr.io", p1[:registry]
assert_equal "copilotkit", p1[:org]
assert_equal "showcase-shell", p1[:name]
assert_equal "latest", p1[:tag]
assert_nil p1[:digest]
p2 = g.parse_image_ref("ghcr.io/copilotkit/showcase-shell@sha256:abc")
assert_equal "sha256:abc", p2[:digest]
p3 = g.parse_image_ref("ghcr.io/copilotkit/showcase-shell:latest@sha256:def")
assert_equal "latest", p3[:tag]
assert_equal "sha256:def", p3[:digest]
end
# bearer_for ALWAYS performs the /token exchange now, so every fake that
# reaches a manifest HEAD must also model a successful exchange.
TOKEN_URL = "https://ghcr.io/token?service=ghcr.io&scope=repository:copilotkit/showcase-shell:pull"
def token_ok
{ TOKEN_URL => { status: 200, headers: {}, body: %({"token":"minted"}) } }
end
def test_resolve_digest_returns_digest_from_header
url = "https://ghcr.io/v2/copilotkit/showcase-shell/manifests/latest"
fake = FakeHTTP.new(token_ok.merge(
url => { status: 200, headers: { "docker-content-digest" => "sha256:beefcafe" }, body: "" },
))
g = Railway::GHCR.new(token: "x", http: fake)
assert_equal "sha256:beefcafe", g.resolve_digest("ghcr.io/copilotkit/showcase-shell:latest")
end
def test_resolve_digest_returns_existing_digest_immediately
# When the ref already has @sha256:..., we don't hit the network at all.
g = Railway::GHCR.new(token: "x", http: nil)
assert_equal "sha256:abc",
g.resolve_digest("ghcr.io/copilotkit/showcase-shell@sha256:abc")
end
def test_resolve_digest_returns_nil_on_404
url = "https://ghcr.io/v2/copilotkit/showcase-shell/manifests/nope"
fake = FakeHTTP.new(token_ok.merge(url => { status: 404, headers: {}, body: "" }))
g = Railway::GHCR.new(token: "x", http: fake)
assert_nil g.resolve_digest("ghcr.io/copilotkit/showcase-shell:nope")
end
def test_resolve_digest_raises_on_5xx
url = "https://ghcr.io/v2/copilotkit/showcase-shell/manifests/latest"
fake = FakeHTTP.new(token_ok.merge(url => { status: 500, headers: {}, body: "boom" }))
g = Railway::GHCR.new(token: "x", http: fake)
assert_raises(Railway::GHCR::Error) do
g.resolve_digest("ghcr.io/copilotkit/showcase-shell:latest")
end
end
end