Files
pulse/scripts/installtests/integration_container_test.go
T
pulse-triage[bot] 35d4cb0e97 Advance release builds to Go 1.26.8
Go 1.26.8 supersedes the prior patch release, so every release builder and local toolchain guard must move together to prevent candidate artifacts from retaining an older compiler and runtime.

Contract-Neutral: toolchain-only patch update; no product or runtime contract changed
Change-source: pulse-maintainer
2026-09-04 07:20:28 +01:00

36 lines
1.3 KiB
Go

package installtests
import (
"os"
"regexp"
"strings"
"testing"
)
func TestIntegrationContainersUseGovernedImmutableBases(t *testing.T) {
dockerfileBytes, err := os.ReadFile(repoFile("tests", "integration", "mock-github-server", "Dockerfile"))
if err != nil {
t.Fatalf("read mock GitHub Dockerfile: %v", err)
}
dockerfile := string(dockerfileBytes)
assertDigestPinnedDockerStage(t, dockerfile, `FROM golang:1.26.8-alpine@sha256:`, ` AS builder`)
assertDigestPinnedDockerStage(t, dockerfile, `FROM alpine:3.24@sha256:`, ``)
composeBytes, err := os.ReadFile(repoFile("tests", "integration", "docker-compose.test.yml"))
if err != nil {
t.Fatalf("read integration compose file: %v", err)
}
compose := string(composeBytes)
if !regexpDigestPinnedImage(`alpine:3.24`, compose) {
t.Fatal("integration seed image must use the governed Alpine line pinned by a full immutable digest")
}
if strings.Contains(dockerfile, "golang:1.23-alpine") || strings.Contains(compose, "image: alpine:3.20\n") {
t.Fatal("integration containers must not restore retired toolchain or runtime lines")
}
}
func regexpDigestPinnedImage(image string, content string) bool {
pattern := regexp.MustCompile(`(?m)^\s*image:\s*` + regexp.QuoteMeta(image) + `@sha256:[0-9a-f]{64}\s*$`)
return pattern.MatchString(content)
}