From af65b72f5bbc78234533a5ba205b04be39bdb21f Mon Sep 17 00:00:00 2001 From: Johnathan Corgan Date: Sat, 19 Sep 2026 00:42:35 +0000 Subject: [PATCH] Stop the firewall and ACL suites building or pulling the test image when the harness supplies it Both compose files carry a build: key beside image:, so compose treats the named image as a build target. Under --skip-build the suites ran a plain `docker compose up -d`, and when the per-run image the harness named was missing, compose silently built it from whatever the build context held and the suite passed against binaries it was never given. With --skip-build the suites now start with `--no-build --pull never`, so a missing image is an error instead of a rebuild or a registry pull. Hand runs without the flag still build as before. The firewall README says that --skip-build now requires the image to exist. --- testing/acl-allowlist/test.sh | 4 +++- testing/firewall/README.md | 7 +++++-- testing/firewall/test.sh | 4 +++- 3 files changed, 11 insertions(+), 4 deletions(-) diff --git a/testing/acl-allowlist/test.sh b/testing/acl-allowlist/test.sh index 79f3fc30..85a490e7 100755 --- a/testing/acl-allowlist/test.sh +++ b/testing/acl-allowlist/test.sh @@ -189,10 +189,12 @@ docker compose -f "$COMPOSE_FILE" down >/dev/null 2>&1 || true # has already built the image this compose file names, and rebuilding it here # would overwrite that image from whatever the shared build context happens to # hold — which is how a suite ends up certifying binaries it was never given. +# With --skip-build a missing image is an error: compose may neither build it +# from the build: context nor pull a same-named image from a registry. if [ "$SKIP_BUILD" = false ]; then docker compose -f "$COMPOSE_FILE" up -d --build else - docker compose -f "$COMPOSE_FILE" up -d + docker compose -f "$COMPOSE_FILE" up -d --no-build --pull never fi log "Waiting for expected peer convergence" diff --git a/testing/firewall/README.md b/testing/firewall/README.md index 3a6bd999..e6db25f3 100644 --- a/testing/firewall/README.md +++ b/testing/firewall/README.md @@ -74,8 +74,11 @@ Run the suite: ``` `test.sh` regenerates fixtures automatically before starting Docker. -Use `--skip-build` to reuse the existing release binaries. Use -`--keep-up` to leave the containers running for inspection. +Use `--skip-build` to reuse the existing release binaries and the +existing test image: the suite then neither builds nor pulls the image +named by `FIPS_TEST_IMAGE` (default `fips-test:latest`), so that image +must already exist. Use `--keep-up` to leave the containers running for +inspection. ## Expected output shape diff --git a/testing/firewall/test.sh b/testing/firewall/test.sh index 418af19c..8a3cb0d5 100755 --- a/testing/firewall/test.sh +++ b/testing/firewall/test.sh @@ -195,10 +195,12 @@ docker compose -f "$COMPOSE_FILE" down >/dev/null 2>&1 || true # has already built the image this compose file names, and rebuilding it here # would overwrite that image from whatever the shared build context happens to # hold — which is how a suite ends up certifying binaries it was never given. +# With --skip-build a missing image is an error: compose may neither build it +# from the build: context nor pull a same-named image from a registry. if [ "$SKIP_BUILD" = false ]; then docker compose -f "$COMPOSE_FILE" up -d --build else - docker compose -f "$COMPOSE_FILE" up -d + docker compose -f "$COMPOSE_FILE" up -d --no-build --pull never fi log "Waiting for fips0 on both nodes"