Skip to content

tests: Add test for OCI install from auth-protected registry - #6683

Closed
1pav wants to merge 4 commits into
flatpak:mainfrom
1pav:wip/oci-deploy-no-fetch-remote-with-tests
Closed

1pav wants to merge 4 commits into
flatpak:mainfrom
1pav:wip/oci-deploy-no-fetch-remote-with-tests

Conversation

@1pav

@1pav 1pav commented Jun 11, 2026 •

Copy link
Copy Markdown
Contributor

Adds a regression test for the fix introduced in #6682.

This adds test-oci-auth.sh, which starts the mock OCI registry with bearer token auth enabled, configures the test authenticator so the client can mirror the image, then runs an install. With the fix the system helper does not access the online registry during deploy at all, so the install succeeds. Without the fix the system helper's unauthenticated manifest fetch returns 401 and the install fails.

Depends on: #6682

Assisted-by: Cursor

Comment thread tests/test-oci-deploy-auth.sh Fixed
Comment thread tests/test-oci-deploy-auth.sh Fixed
Comment thread tests/test-oci-deploy-auth.sh Fixed
Comment thread tests/test-oci-deploy-auth.sh Fixed
@1pav
1pav force-pushed the wip/oci-deploy-no-fetch-remote-with-tests branch from 01c718f to 80cf57f Compare June 11, 2026 13:18
Comment thread tests/meson.build Outdated
Comment thread tests/meson.build Outdated
Comment thread tests/meson.build
'system,nodeltas',
'system,deltas',
'system-norevokefs,nodeltas',
'system-norevokefs,deltas',

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe a bit more general question: shouldn't we just add the test to test-auth.sh instead?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I opted for a separate file because it looks like adapting test-auth.sh to also accomodate the OCI case would make the whole script a bit messy. That module is largely ostree-specific in how remote and token are setup. Adding OCI auth tests there would mean spawning a second mock web server (i.e. the OCI registry) and setting up a second (OCI) remote.

swick and others added 3 commits June 11, 2026 17:24
In flatpak_pull_from_oci we can be in in the system helper where we pull
the mirrored OCI image into the system repo. However, to fetch the
signatures in GPG signed repos, we used a remote OciImageSource created
through `flatpak_remote_state_fetch_image_source`. This caused fetching
some data from the registry which we don't want in the deploy method,
and also fails if a token is required to access the repo.

This change fetches the signatures from the mirrored OCI repo instead of
pulling them from the remote OciImageSource. The signatures can come from
anywhere because we verify them against the GPG key in the system repo.

The important bit is the change in `flatpak_pull_from_oci` where we now
pass in the local image_source to fetch the signatures from, and in the
system helper, where we get the right metadata to check the signatures
against (eventually ends up in `flatpak_oci_signatures_verify`).
…istry

Add infrastructure for testing OCI installations from auth-protected
registries. The mock server now supports requiring a bearer token on all
/v2/ requests, configurable via a new POST /testing-auth/configure admin
endpoint. The client gains a corresponding 'configure-auth' subcommand.

Assisted-by: Cursor
@1pav
1pav force-pushed the wip/oci-deploy-no-fetch-remote-with-tests branch from 963fb1a to 449e7d5 Compare June 11, 2026 17:05
@1pav 1pav changed the title tests: Add test for system OCI deploy from auth-protected registry tests: Add test for OCI install from auth-protected registry Jun 11, 2026
Add a regression test that installs from an auth-protected OCI registry.
The registry requires a bearer token for all /v2/ requests; the client
authenticates via the mock test authenticator and the installation
completes successfully. The test runs for both user and system install
paths.

Assisted-by: Cursor
@1pav

1pav commented Jun 12, 2026

Copy link
Copy Markdown
Contributor Author

Closing as testing code in this PR was included in #6682 and merged.

@1pav 1pav closed this Jun 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants