remove oras - #166
Open
bcumming wants to merge 44 commits into
Open
Conversation
…y file for downloads
…silently dropping attached metadata
…ncaught type_error
…ring them in memory pull_meta fetched the meta tar.gz with the in-memory get_blob, which checks only the HTTP status and performs no sha256 verification, then wrote the buffer back out to a temp file for tar. The meta payload (env.json, views) is later sourced into user environments, and it was the only downloaded artifact that skipped verification. Stream the layer straight to the staging path with get_blob_to_file, which hashes during download and rejects a digest mismatch. This also removes a redundant RAM+disk round trip of the whole blob. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… when pushing/adding
review.md is a local working note that was accidentally committed with 605deb3. Remove it from the index (keeping the file on disk) and ignore it, alongside the existing 'todo' entry, so it is not merged into main. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Remove uenv's runtime dependency on the external oras binary and replaces it with a self-contained, native OCI registry client written in C++ (src/oci/). After this change uenv is a fully static binary with no runtime shell-outs to oras, tar, gzip, or curl — all registry, archive, and hashing operations happen in-process. Images pushed by the new client are byte-for-byte compatible with oras, so artifacts remain interoperable in both directions.
oras was an external process uenv shelled out to for push/pull/copy/inspect. That made deployments depend on a separate binary, complicated error handling, and left the tool unable to be fully static. This PR brings all of that functionality in-house.
New features:
src/oci/ — native OCI registry client. A deliberately self-contained module (depends only on src/util/ + external libs; enforced by a grep in CI/docs) that talks the OCI distribution API over HTTP:
New src/util/ building blocks, kept in util so oci never reaches up into uenv:
Dependencies now vendored as static meson subprojects: zlib, openssl (curl's TLS backend), libarchive. Dropped the wrapdb fallback and the old curl runtime deps.
Bug fixes:
Tests: