Stop the firewall and ACL suites building or pulling the test image when the harness supplies it

Both compose files carry a build: key beside image:, so compose treats the
named image as a build target. Under --skip-build the suites ran a plain
`docker compose up -d`, and when the per-run image the harness named was
missing, compose silently built it from whatever the build context held
and the suite passed against binaries it was never given.

With --skip-build the suites now start with `--no-build --pull never`, so
a missing image is an error instead of a rebuild or a registry pull. Hand
runs without the flag still build as before. The firewall README says
that --skip-build now requires the image to exist.
This commit is contained in:
Johnathan Corgan
2026-09-19 00:42:35 +00:00
parent 1c709a87e8
commit af65b72f5b
3 changed files with 11 additions and 4 deletions
+3 -1
View File
@@ -189,10 +189,12 @@ docker compose -f "$COMPOSE_FILE" down >/dev/null 2>&1 || true
# has already built the image this compose file names, and rebuilding it here # has already built the image this compose file names, and rebuilding it here
# would overwrite that image from whatever the shared build context happens to # would overwrite that image from whatever the shared build context happens to
# hold — which is how a suite ends up certifying binaries it was never given. # hold — which is how a suite ends up certifying binaries it was never given.
# With --skip-build a missing image is an error: compose may neither build it
# from the build: context nor pull a same-named image from a registry.
if [ "$SKIP_BUILD" = false ]; then if [ "$SKIP_BUILD" = false ]; then
docker compose -f "$COMPOSE_FILE" up -d --build docker compose -f "$COMPOSE_FILE" up -d --build
else else
docker compose -f "$COMPOSE_FILE" up -d docker compose -f "$COMPOSE_FILE" up -d --no-build --pull never
fi fi
log "Waiting for expected peer convergence" log "Waiting for expected peer convergence"
+5 -2
View File
@@ -74,8 +74,11 @@ Run the suite:
``` ```
`test.sh` regenerates fixtures automatically before starting Docker. `test.sh` regenerates fixtures automatically before starting Docker.
Use `--skip-build` to reuse the existing release binaries. Use Use `--skip-build` to reuse the existing release binaries and the
`--keep-up` to leave the containers running for inspection. existing test image: the suite then neither builds nor pulls the image
named by `FIPS_TEST_IMAGE` (default `fips-test:latest`), so that image
must already exist. Use `--keep-up` to leave the containers running for
inspection.
## Expected output shape ## Expected output shape
+3 -1
View File
@@ -195,10 +195,12 @@ docker compose -f "$COMPOSE_FILE" down >/dev/null 2>&1 || true
# has already built the image this compose file names, and rebuilding it here # has already built the image this compose file names, and rebuilding it here
# would overwrite that image from whatever the shared build context happens to # would overwrite that image from whatever the shared build context happens to
# hold — which is how a suite ends up certifying binaries it was never given. # hold — which is how a suite ends up certifying binaries it was never given.
# With --skip-build a missing image is an error: compose may neither build it
# from the build: context nor pull a same-named image from a registry.
if [ "$SKIP_BUILD" = false ]; then if [ "$SKIP_BUILD" = false ]; then
docker compose -f "$COMPOSE_FILE" up -d --build docker compose -f "$COMPOSE_FILE" up -d --build
else else
docker compose -f "$COMPOSE_FILE" up -d docker compose -f "$COMPOSE_FILE" up -d --no-build --pull never
fi fi
log "Waiting for fips0 on both nodes" log "Waiting for fips0 on both nodes"