Repository navigation
fix: reject unresolved image references and verify native settings - #73
TheRealBecks wants to merge 7 commits into
Conversation
cb58aee to
f2e16ac
Compare
|
Fresh trusted native run 37218370132 failed for exact candidate Independent log review found tests 1–8 passed in every lane, the container-settings test failed, and the tenth label test never ran. Rootful memory-only START controls returned HTTP500 with bounded cgroup/controller diagnostics. Rootless renamed-device controls returned Debian500/upstream400 with bounded ENOENT/device diagnostics; same-path controls started. These controls do not establish causality or resolve Containers #344. Debian rootless subsequently timed out in repeated-dynamic IPv4 START and explicitly reported unverified inner ports cleanup. The other three reported successful final inner cleanup. Outer teardown had no logged error, but there is no explicit positive outer-inventory record, so blanket cleanup success is not claimed. No native artifacts were uploaded. Offline gate/source review remains recorded, but cannot substitute for native acceptance. No unchanged retry, host repair, lane substitution or gate weakening is authorized. Logs preserved at |
|
Diagnostic-only follow-up at current head Independent four-file source review cleared the final SHA-256 freeze. Primary canonical format/lint and complete offline gate passed, including 235 Python tests and both new pure Rust regressions. Logs: The PR remains draft and merge-blocked. Run37218370132 belongs to predecessor |
|
Diagnostic checkpoint for #39 (not capability admission or release readiness).
Earlier run Independently reviewed failure evidenceThe new diagnostic contract was exercised: all four original resource START failures remained their groups' first checkpoints (500 for both Debian modes and upstream rootful; 400 for upstream rootless). Later controls never replaced those failed positives. Rootful memory-only START remains rejected; rootless renamed-device START remains rejected despite same-path success. Resource enforcement and underlying causes remain unknown. Debian rootless separately retains its later port timeout and unverified inner cleanup. The other three lanes report final successful inner readback; generic outer warnings are not independently authenticated outer-absence proof. Private run/job/log evidence is retained at |
|
Diagnostic-only continuation at exact head The previous Independent source and post-format reviews passed. Canonical format/lint and complete gate passed: Rust/MSRV/unit/doc checks and all265 Python contracts. Private gate log The old failed native run is not validation of this new candidate. One new exact-head validation-only acquisition may exercise the corrected original-response diagnostics under the unchanged four-lane contract; it is not an unchanged retry, fixture repair or release run. Preserve every failed result and do not repeat the same failed head, weaken assertions, substitute control success, infer unsupported modes or request publication. Actual resource failure causes/enforcement and later volume/PID1 checks remain unestablished pending genuine evidence. |
Closes #39 only after fresh exact-candidate native gates and independent evidence
review pass. Parents #3/#30/#31 and BoxFerry #343/#366 remain open. Draft status
is intentional: offline success is not native compatibility or release readiness.
Integrated scope
Preserve the original PR #50 and #73 checkpoints/dirty checkout while integrating
current main's PID1 identity (#74/#75) and strict cleanup presence (#76/#77).
The separate final checkout is
/tmp/dockerlens-issue39-final-integration;reviewed head
ee16951c775b73ab8cecc7ed7b95c104586c40aais a fast-forward of theprevious published candidate, not an overwrite.
Retain all eleven mandatory native tests: original checks, container settings,
volume labels and PID1 identity. Preserve both independent proof groups and
exact candidate/run/image/mode/API bindings in the reconciled evidence emitter.
Private captured-output handling, fail-closed presence, cleanup and budgets stay.
Resource effect reads now authenticate full owned identity/private PID namespace,
PID1/helper placement, active cgroup mount-parent topology and stable before/after
placement. Reject shadowed, ambiguous, cyclic, missing-parent or unowned evidence.
Both finite assertions and unlimited baselines resolve the actual leaf rather than
assuming a fixed cgroup root. Strict memory/PID values, START failures, unknown
enforcement and the genuine failed no-swap result remain unchanged.
The narrow product correction rejects unresolved image references before planning;
registry-port/digest/image-ID forms and the existing Unreleased note are retained.
No catalogue capability or historical observation is admitted or rewritten.
Verification
final integration reviews cleared the frozen source with stated limits.
public/doc/Rustdoc and 257 Python tests, wrapper exit 0. Log
/tmp/dl39-integrated-final-gate-20261005.log.startup diagnostics 18. Post-format review proved the sole formatting change
was test-module ordering. Exact owned runner lifecycle and silent ID/name absence
were authenticated; original dirty checkpoint remains untouched.
Debian11/upstream rootful/rootless lanes, all eleven required checks each.
Historical failed native run
37233669686remains immutable; this mappingcorrection does not establish its startup cause or turn failed cleanup into proof.
No unchanged native retry, host repair or stress-threshold relaxation occurred.
Shared consumers / Renovate
No operational pin, dependency, manifest/lockfile, workflow/action or canonical
extraction location changed. Existing native image/Engine/package/BusyBox managers,
grouping and approvals remain authoritative; no Renovate edit is needed. Other
Lens products/website do not consume this Docker-specific harness. BoxFerry has
its own application consumer gate; Lens products never depend on BoxFerry.
No release, release-PR merge, publication, deployment, Windows support or macOS
runner work is authorized or claimed.