Skip to content

resolve digest-only tags in ResolvePullSpec for PreserveOriginal imports - #5172

Merged
openshift-merge-bot[bot] merged 1 commit into
openshift:mainfrom
deepsm007:release-import-stable-local-reference-policy
May 12, 2026
Merged

openshift-merge-bot[bot] merged 1 commit into
openshift:mainfrom
deepsm007:release-import-stable-local-reference-policy

Conversation

@deepsm007

@deepsm007 deepsm007 commented May 11, 2026 •

Copy link
Copy Markdown
Contributor

/cc @openshift/test-platform
/hold

Release Import Digest Resolution for PreserveOriginal Tags

This PR enhances the release import process to properly handle digest-only image references when using the PreserveOriginal import mode in the CI system's image streaming.

Changes

Image Resolution Enhancement (pkg/util/imagestream.go)
The ResolvePullSpec function now includes a fallback mechanism for resolving tags that contain only a digest. When an exact pull spec is required (requireExact=true) and the tag's image reference is empty, the function will return the digest-qualified reference directly from the DockerImageReference field (e.g., image@sha256:abc123...). This ensures that digest-only references can be properly resolved without requiring a repository image field.

Consistent Tag Reference Policy (pkg/steps/release/import_release.go)
When updating the stable ImageStream to include tags from the extracted release payload, the code now explicitly sets Reference = false for all imported tags. This applies consistently to both newly imported tags from the release payload and tags preserved from the existing stable ImageStream. Combined with the ImportModePreserveOriginal setting, this ensures that original image references (including digest-only references) are preserved without being converted to local repository references.

Impact

These changes improve the reliability of release imports when using PreserveOriginal import mode, allowing the CI system to properly handle and resolve digest-only image references that may not have traditional tag-based image identifiers. This is particularly important for release pipelines where images are referenced by their SHA256 digests rather than mutable tags.

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Pipeline controller notification
This repo is configured to use the pipeline controller. Second-stage tests will be triggered either automatically or after lgtm label is added, depending on the repository configuration. The pipeline controller will automatically detect which contexts are required and will utilize /test Prow commands to trigger the second stage.

For optional jobs, comment /test ? to see a list of all defined jobs. To trigger manually all jobs from second stage use /pipeline required command.

This repository is configured in: automatic mode

@openshift-ci
openshift-ci Bot requested a review from droslean May 11, 2026 16:41
@openshift-ci openshift-ci Bot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label May 11, 2026
@coderabbitai

coderabbitai Bot commented May 11, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: d73d91b0-f1f4-4a99-ba20-6b326ce3cb3e

📥 Commits

Reviewing files that changed from the base of the PR and between ebf83c9 and 74d595c.

📒 Files selected for processing (2)
  • pkg/steps/release/import_release.go
  • pkg/util/imagestream.go
🚧 Files skipped from review as they are similar to previous changes (1)
  • pkg/util/imagestream.go

📝 Walkthrough

Walkthrough

Two changes to image stream handling: ResolvePullSpec now returns a digest-qualified DockerImageReference when requireExact=true and the first tag item has an @sha256: digest; import_release now clears tag.Reference (sets it to false) for tags copied from the release payload and for tags preserved/added from the existing stable ImageStream.

Changes

Image stream resolution & stable ImageStream tag merge

Layer / File(s) Summary
Exact Digest Resolution
pkg/util/imagestream.go
When requireExact=true and tags.Items[0].Image is empty but tags.Items[0].DockerImageReference contains @sha256:, return that digest-qualified DockerImageReference and set exists=true (short-circuits repository-based pull spec construction).
Stable ImageStream Tag Merge — release-sourced tags
pkg/steps/release/import_release.go (lines ~244)
When copying tags from releaseIS.Spec.Tags into the stable ImageStream update list, set tag.Reference = false.
Stable ImageStream Tag Merge — existing stable tags
pkg/steps/release/import_release.go (lines ~254)
When preserving/adding tags from stable.Spec.Tags into the updated stable tag list, set tag.Reference = false to ensure the Reference field is explicitly cleared.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 12 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Test Coverage For New Features ⚠️ Warning New files lack test coverage. pkg/util/imagestream.go and pkg/steps/release/import_release.go added with no corresponding *_test.go files. Add unit tests for both new files, using table-driven tests for ResolvePullSpec to cover all code paths.
✅ Passed checks (12 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the main change: resolving digest-only tags in ResolvePullSpec specifically for PreserveOriginal imports, which aligns with both file modifications.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Go Error Handling ✅ Passed New code properly handles errors. imagestream.go safely dereferences with guards. import_release.go assigns fields without errors. All error wrapping uses %w format.
Stable And Deterministic Test Names ✅ Passed PR modifies only production code files (pkg/util/imagestream.go and pkg/steps/release/import_release.go), neither of which contain Ginkgo tests. The custom check is not applicable.
Test Structure And Quality ✅ Passed The custom check requires reviewing Ginkgo test code quality. This PR adds only production code with no Ginkgo tests. The check is not applicable.
Microshift Test Compatibility ✅ Passed PR does not add any new Ginkgo e2e tests. Both modified files (imagestream.go and import_release.go) are source code, not test files. The check is not applicable.
Single Node Openshift (Sno) Test Compatibility ✅ Passed No Ginkgo e2e tests added. PR modifies only internal utility packages for image stream and release handling. SNO test compatibility check not applicable.
Topology-Aware Scheduling Compatibility ✅ Passed PR modifies image stream utility and release import logic. No scheduling constraints, pod affinity, topology assumptions, or controller code introduced. Changes limited to image resolution logic.
Ote Binary Stdout Contract ✅ Passed Changes are in regular utility and step methods only. No process-level code modifications. No stdout writes detected that would violate the OTE Binary Stdout Contract.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed This PR does not add any Ginkgo e2e tests. Changes are limited to utility and implementation files (pkg/util/imagestream.go, pkg/steps/release/import_release.go). The custom check is not applicable.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands and usage tips.

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label May 11, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
pkg/steps/release/import_release.go (1)

237-253: ⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Restrict forced Local policy to payload-derived tags only.

This now applies Local to carried-over stable.Spec.Tags as well, not just payload tags. That broadens behavior and can flip existing non-payload tag policy unexpectedly. Keep forced Local in the releaseIS.Spec.Tags path, and preserve policy for the stable.Spec.Tags merge path.

Suggested patch
 		referencePolicy := imagev1.LocalTagReferencePolicy
 		existing := sets.New[string]()
 		tags := make([]imagev1.TagReference, 0, len(releaseIS.Spec.Tags)+len(stable.Spec.Tags))
 		for _, tag := range releaseIS.Spec.Tags {
 			existing.Insert(tag.Name)
 			tag.ReferencePolicy.Type = referencePolicy
 			tag.ImportPolicy.ImportMode = imagev1.ImportModePreserveOriginal
 			tags = append(tags, tag)
 		}
 		for _, tag := range stable.Spec.Tags {
 			if existing.Has(tag.Name) {
 				continue
 			}
 			existing.Insert(tag.Name)
-			tag.ReferencePolicy.Type = referencePolicy
 			tag.ImportPolicy.ImportMode = imagev1.ImportModePreserveOriginal
 			tags = append(tags, tag)
 		}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@pkg/steps/release/import_release.go` around lines 237 - 253, The code
currently forces referencePolicy := imagev1.LocalTagReferencePolicy for both
releaseIS.Spec.Tags and stable.Spec.Tags; change it so the Local override is
applied only when iterating releaseIS.Spec.Tags (where you set
tag.ReferencePolicy.Type = referencePolicy), and do NOT modify
tag.ReferencePolicy.Type when merging stable.Spec.Tags (leave stable tags'
existing ReferencePolicy intact); keep the existing ImportPolicy.ImportMode
assignment if desired but remove or skip the line setting
tag.ReferencePolicy.Type in the stable.Spec.Tags loop so carried-over stable
tags retain their original policy.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@pkg/steps/release/import_release.go`:
- Around line 237-253: The code currently forces referencePolicy :=
imagev1.LocalTagReferencePolicy for both releaseIS.Spec.Tags and
stable.Spec.Tags; change it so the Local override is applied only when iterating
releaseIS.Spec.Tags (where you set tag.ReferencePolicy.Type = referencePolicy),
and do NOT modify tag.ReferencePolicy.Type when merging stable.Spec.Tags (leave
stable tags' existing ReferencePolicy intact); keep the existing
ImportPolicy.ImportMode assignment if desired but remove or skip the line
setting tag.ReferencePolicy.Type in the stable.Spec.Tags loop so carried-over
stable tags retain their original policy.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: e9a0025b-c128-4bf6-8fa4-c284d2ae3ae8

📥 Commits

Reviewing files that changed from the base of the PR and between 1afea1e and 7f8e76e.

📒 Files selected for processing (1)
  • pkg/steps/release/import_release.go

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Scheduling tests matching the pipeline_run_if_changed or not excluded by pipeline_skip_if_only_changed parameters:
/test e2e

@deepsm007
deepsm007 force-pushed the release-import-stable-local-reference-policy branch from 7f8e76e to 4318481 Compare May 11, 2026 19:45

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@pkg/util/imagestream.go`:
- Around line 32-36: The isLocalReferenceTag function currently requires both
st.Reference and st.ReferencePolicy.Type == imageapi.LocalTagReferencePolicy,
which incorrectly excludes tags that have the LocalTagReferencePolicy but no
Reference set; update isLocalReferenceTag to remove the st.Reference check and
return true solely when st.ReferencePolicy.Type ==
imageapi.LocalTagReferencePolicy (keeping the loop over is.Spec.Tags and tag
name match), so Local-policy tags created in import_release.go are recognized
and allow the ResolvePullSpec exact-resolution fallback to run.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: e15637b2-f82e-4672-8d55-efaaba273a52

📥 Commits

Reviewing files that changed from the base of the PR and between 7f8e76e and 4318481.

📒 Files selected for processing (2)
  • pkg/steps/release/import_release.go
  • pkg/util/imagestream.go
🚧 Files skipped from review as they are similar to previous changes (1)
  • pkg/steps/release/import_release.go

Comment thread pkg/util/imagestream.go Outdated
@deepsm007
deepsm007 force-pushed the release-import-stable-local-reference-policy branch from 4318481 to ebf83c9 Compare May 11, 2026 20:10
@deepsm007 deepsm007 changed the title release import always Local referencePolicy on stable payload tags resolve digest-only tags in ResolvePullSpec for PreserveOriginal imports May 11, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@pkg/util/imagestream.go`:
- Around line 59-61: The current branch only applies the digest-qualified
fallback when tags.Items[0].Image is empty, causing exact-resolution to miss
using tags.Items[0].DockerImageReference even when Image is present; update the
logic in the function handling tag resolution (the block using
tags.Items[0].Image and tags.Items[0].DockerImageReference) so that when
requireExact is true and tags.Items[0].DockerImageReference contains "@sha256:"
you set pullSpec = tags.Items[0].DockerImageReference and exists = true
regardless of whether tags.Items[0].Image is non-empty (i.e., check the
DockerImageReference digest condition outside or in addition to the else branch
that tests Image).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 2a2ee24d-e59c-4a22-9b52-f82f9afd202b

📥 Commits

Reviewing files that changed from the base of the PR and between 4318481 and ebf83c9.

📒 Files selected for processing (1)
  • pkg/util/imagestream.go

Comment thread pkg/util/imagestream.go
@deepsm007
deepsm007 force-pushed the release-import-stable-local-reference-policy branch from ebf83c9 to 74d595c Compare May 11, 2026 20:34
@deepsm007

Copy link
Copy Markdown
Contributor Author

/unhold

@openshift-ci openshift-ci Bot removed the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label May 11, 2026
@deepsm007

Copy link
Copy Markdown
Contributor Author

/test e2e

@deepsm007

Copy link
Copy Markdown
Contributor Author

/test breaking-changes

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Tests from second stage were triggered manually. Pipeline can be controlled only manually, until HEAD changes. Use command to trigger second stage.

@openshift-ci

openshift-ci Bot commented May 12, 2026

Copy link
Copy Markdown
Contributor

@deepsm007: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/breaking-changes 74d595c link unknown /test breaking-changes

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@jupierce

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label May 12, 2026
@openshift-ci

openshift-ci Bot commented May 12, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: deepsm007, jupierce

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit 6ebae95 into openshift:main May 12, 2026
16 of 17 checks passed
@deepsm007
deepsm007 deleted the release-import-stable-local-reference-policy branch September 21, 2026 15:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants