Skip to content

mkctr: build the files layer in a deterministic order - #37

Closed
RaphaelFakhri wants to merge 1 commit into
tailscale:mainfrom
RaphaelFakhri:fix-layer-deterministic
Closed

RaphaelFakhri wants to merge 1 commit into
tailscale:mainfrom
RaphaelFakhri:fix-layer-deterministic

Conversation

@RaphaelFakhri

Copy link
Copy Markdown

Write the files layer in a deterministic order so identical inputs produce the same layer digest.

layerFromFiles ranged over a map, so tar entries and their parent directory headers were written in random order. Two builds from the same inputs produced layers with different digests, even though the code sets zero modification times to make images reproducible.

This change visits the sources in sorted order.

The new test builds a layer 30 times from five files and checks that every DiffID is identical.

This branch and the missing-source fix both add mkctr_test.go. The second one merged needs a trivial rebase to combine the test files.

Test command: go test . -run Reproducible -v

Fixes #35

layerFromFiles ranged over a map, so entries and their parent directory
headers were written to the tar in a random order. Two builds from
identical inputs produced layers with different digests, although the
code sets zero modification times to make images reproducible.

Visit the sources in sorted order.

Fixes #35

Signed-off-by: Raphael Fakhri <153192858+RaphaelFakhri@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

mkctr produces a different files layer on every build

1 participant