Skip to content

build rejects valid tag@digest image references during registry inspection #1307

Description

@lusoris

Summary

@devcontainers/cli 0.89.0 rejects valid OCI/Docker name:tag@sha256:digest references during registry inspection. This reproduces for both a direct devcontainer.json.image and a Dockerfile FROM. The equivalent digest-only reference works.

This is related to #825, but that report is limited to Feature identifiers and explicitly says ordinary image references accept tag plus digest.

Environment

  • @devcontainers/cli: 0.89.0
  • Node.js: 26.9.0
  • OS: Linux 7.2.6-1-cachyos x64
  • CLI 0.89.0 and current main: 5dc7533314b5ba7ec3875c30143dfe1aec644870

Minimal reproduction

.devcontainer/devcontainer.json:

{
  "image": "mcr.microsoft.com/devcontainers/go:2.3.1-1.27-bookworm@sha256:adc326255c019241228f9da4a1cb5d6a89abaaa0eb8d926a355b00af7daafd00"
}

Run:

npx -y @devcontainers/cli@0.89.0 build --workspace-folder . --log-level info

The same failure occurs when a Dockerfile contains a FROM reference in name:tag@digest form.

Actual result

Path 'devcontainers/go:2.3.1-1.27-bookworm' for input 'mcr.microsoft.com/devcontainers/go:2.3.1-1.27-bookworm@sha256:adc326255c019241228f9da4a1cb5d6a89abaaa0eb8d926a355b00af7daafd00' failed validation. Expected path to match regex ...\nError fetching image details: Could not parse image name ...\n```\n\nChanging only the reference to the equivalent digest-only form succeeds:\n\n```text\nmcr.microsoft.com/devcontainers/go@sha256:adc326255c019241228f9da4a1cb5d6a89abaaa0eb8d926a355b00af7daafd00\n```\n\nDocker itself accepts the original tag-plus-digest reference.\n\nIn my two original runs, the CLI also remained alive after printing the parser diagnostic until interrupted with SIGINT. I have not isolated whether that is the fallback `docker pull` path or process cleanup, so the deterministic defect in this report is the parser rejection.\n\n## Expected result\n\n`build` should accept the distribution reference grammar `name [":" tag] ["@" digest]` for direct images and Dockerfile base images.\n\n## Source-level observation\n\n`getRef` removes the digest suffix but leaves `:tag` in `resource` before validating the repository path. The colon then fails the path regex. `inspectImageInRegistry` reports `Could not parse image name`, and both direct-image and Dockerfile inspection reach that path.\n\nReference grammar: https://github.com/distribution/reference/blob/0965666a6ade2e06035fe352e38344be1e68951a/reference.go#L5-L20\n\nRelevant 0.89.0 code: https://github.com/devcontainers/cli/blob/5dc7533314b5ba7ec3875c30143dfe1aec644870/src/spec-configuration/containerCollectionsOCI.ts#L152-L230

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions