Repository navigation
The guest suite pulls its Debian image from ECR Public's copy of Docker Hub's, by the same digest - #823
Conversation
|
Review of #823 at Measured during this review (registry
BLOCKER
NOTE
SEND BACK |
…er Hub's, by the same digest Docker Hub's anonymous pull limit refused `guest / suite`'s container pull in the merge queue. Amazon ECR Public mirrors Docker Official Images under `public.ecr.aws/docker/library/` and serves this exact digest anonymously: a manifest HEAD with an anonymous token answered 200 and `docker-content-digest: sha256:a2aa4626…`. The digest is the provenance wherever the bytes come from, since a registry serving other bytes fails the pull, so the fix is the registry prefix and nothing else: no mirror workflow, no package of our own, no credentials and no permissions. nightly's `portability-linux` keeps testing `sid` as it stands, unpinned, from the same mirror. The host-tools issue gains the image's row, admitted because the runner's Ubuntu 24.04 publishes QEMU 8.2.2 and the instrument declares 11.1.1, and a row for Docker, which runs every `container:`: refused, Go, a standing failure that goes with the container. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
8b47bad to
3fb782c
Compare
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Round 2 of #823 at Round 1 BLOCKERs
BLOCKER
NOTE
SEND BACK |
|
CI at |
…ge (#823), ToyOS's own network stack (#801), the signed package repository (#808) and the HTTPS client (#810), into the stop's hold of the console wire No conflict. The merge's diff against 0d448b2 under kernel/ and tests/ is main's own change from 198a9d3 line for line, differing only in tests/toyos.rs's hunk offsets, so the T14 reading at 0d448b2 carries. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
…st-side hash is toyos-sha2's #810's https_fetch hashed the body it serves with the sha2 crate, which this branch removes from the build crate's dependencies; it now hashes with toyos-sha2, still a different SHA-256 from the guest's ring. Cargo.lock is main's, regenerated by cargo over this branch's manifests. #817's toyos-ssh hashes with ring and takes no sha2. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
guest / suitepulleddebian:sid-20260918@sha256:a2aa4626…from Docker Hub with no credentials. Docker Hub's anonymous pull limit refused that pull three times in each of two merge-queue runs, withtoomanyrequests: You have reached your unauthenticated pull rate limit. #811 and #813 were dropped for a cause neither diff carried.What changed and why
guest.yml's container now pullspublic.ecr.aws/docker/library/debian@sha256:a2aa46262453eba3f464d8b1c7a8c31db85eb15af180ae34dd400615d7208547anonymously. That registry is Amazon ECR Public's mirror of Docker Official Images. The digest is the provenance: a registry that served other bytes would fail the pull. The tag is dropped from the reference. A pin by digest ignores the tag, and ECR Public'ssid-20260918resolves to the same digest (measured below).portability-linuxstill testssidas it stands, image and archive both. It pullspublic.ecr.aws/docker/library/debian:sid, unpinned on purpose, as it did from Docker Hub.credentials:, nopermissions:and nopackages: write.src/ci.rs's workflow count is unchanged..github/qemu-versiondeclares, 11.1.1, from the snapshot archive the dated image names. The runner's Ubuntu 24.04 publishes QEMU 8.2.2 in every noble pocket (LaunchpadgetPublishedSources,qemu, noble: Release, Security and Updates).issues/the-build-runs-host-tools-outside-rust-and-qemu.mdgains two rows:container:with Docker, and Docker is Go. Go is not C or C++ ToyOS can one day build and run, and Actions runs acontainer:with Docker alone. Both jobs usedcontainer:before this change, so this is a standing failure that was already there and is now declared. It goes when the container goes.Which mirror, and why its anonymous quota holds (an estimate from documentation, not a measurement)
ECR Public. Its service-quotas page (docs.aws.amazon.com/AmazonECR/latest/public/public-service-quotas.html) states two limits for unauthenticated pulls:
The page does not name the unit either limit is counted per. The review reads it as per source IP. GitHub's runners share addresses, so this is the same shape as Docker Hub's failure. The difference is the size of the budget.
The budget is large. The pinned index's
linux/amd64manifest has one layer of 49,649,461 bytes, measured below. One pull is therefore about 50 MB, and 500 GB is about 10,000 pulls of this image per counted unit per month. The 1-per-second limit is a throttle on a burst, not a running total. Docker Hub refused us on a running total of pulls.This is an estimate. I cannot see how many other tenants share a runner's address, or what they pull from ECR Public. If the quota is reached, the pull fails loudly, as Docker Hub's did, and nothing degrades silently.
mirror.gcr.io/library/debian@sha256:a2aa4626…also serves this digest anonymously (the review measured200). It is the next prefix to try if ECR refuses.Measured
Anonymous registry requests with the project
User-Agent:public.ecr.aws/token/?scope=repository:docker/library/debian:pull, thenHEAD /v2/docker/library/debian/manifests/sha256:a2aa4626…:HTTP/2 200,docker-content-digest: sha256:a2aa46262453eba3f464d8b1c7a8c31db85eb15af180ae34dd400615d7208547.…/manifests/sid:200, digestsha256:c53e0503….sidhas moved on from the pinned snapshot, as expected.linux/amd64entry issha256:e6650c18…. Its manifest lists one layer of 49,649,461 bytes.Gates
cargo run -- --ci hostat3fb782c93, macOS arm64: exit 0,Host: 78 step(s), all green. The full log is posted to this pull request in eight comments, scrubbed of home-directory paths and user names. The loomFAILEDandSIGABRTlines in it are the negative controls' expected reds ([ci] control …: 1 verdict(s) reached).guest / suite's Initialize containers step,docker pull public.ecr.aws/docker/library/debian@sha256:a2aa4626…succeeds with no login.instrumentline ofcargo run -- --ci guestreads QEMU 11.1.1.hostis green.Unsure
ghcr.io/toyosorg/debian, and nothing reads it now.gh api -X DELETE /orgs/ToyOSOrg/packages/container/debianwas refused:You need at least delete:packages and read:packages scopes to delete a package. (HTTP 403). The orchestrator deletes it.🤖 Generated with Claude Code
https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C