From 49d661945f4d61f7b021c6a004bf6b3fe00ab3b8 Mon Sep 17 00:00:00 2001 From: Terry Howe Date: Mon, 13 Jul 2026 12:13:04 -0600 Subject: [PATCH] refactor: drop unused registry config path overrides Only registries.conf was ever set (by tests); PolicyConfigPath, CertsDirPaths, and ContainersAuthPath were always empty and fell through to the container ecosystem default search locations. Remove the exported ConfigOptions struct and ClientOptConfigOptions option, and replace them with an unexported withRegistriesConfigPath test hook. No production behavior changes; avoids committing public API to the still-experimental oras-go v3 config surface. Signed-off-by: Terry Howe --- pkg/registry/client.go | 27 +++++++++++---------------- pkg/registry/client_test.go | 8 +++----- 2 files changed, 14 insertions(+), 21 deletions(-) diff --git a/pkg/registry/client.go b/pkg/registry/client.go index 66a778e47..871209e9d 100644 --- a/pkg/registry/client.go +++ b/pkg/registry/client.go @@ -57,14 +57,6 @@ storing semantic versions, Helm adopts the convention of changing plus (+) to an underscore (_) in chart version tags when pushing to a registry and back to a plus (+) when pulling from a registry.` -// ConfigOptions specifies override paths for container ecosystem config files. -type ConfigOptions struct { - RegistriesConfigPath string - PolicyConfigPath string - CertsDirPaths []string - ContainersAuthPath string -} - type ( // RemoteClient shadows the ORAS remote.Client interface // (hiding the ORAS type from Helm client visibility) @@ -92,7 +84,9 @@ type ( builder *remote.ClientBuilder policyEvaluator *policy.Evaluator signatureVerification bool - configOptions ConfigOptions + // registriesConfigPath overrides the registries.conf path; empty means + // the container ecosystem default search locations are used. Test-only. + registriesConfigPath string insecure bool certFile string keyFile string @@ -137,11 +131,10 @@ func NewClient(options ...ClientOption) (*Client, error) { // Load the full container ecosystem config stack: Docker config.json, // containers auth.json, registries.conf, policy.json, certs.d, registries.d. // Missing files are silently skipped. + // Only registries.conf is overridable (empty means default search); all + // other config files always resolve to their default locations. loaderOpts := remoteconfig.LoadConfigsOptions{ - RegistriesConfigPath: client.configOptions.RegistriesConfigPath, - PolicyConfigPath: client.configOptions.PolicyConfigPath, - CertsDirPaths: client.configOptions.CertsDirPaths, - ContainersAuthPath: client.configOptions.ContainersAuthPath, + RegistriesConfigPath: client.registriesConfigPath, } configs, err := remoteconfig.LoadConfigsWithOptions(loaderOpts) if err != nil { @@ -415,10 +408,12 @@ func ClientOptSignatureVerification(enabled bool) ClientOption { } } -// ClientOptConfigOptions returns a function that overrides default config file paths. -func ClientOptConfigOptions(o ConfigOptions) ClientOption { +// withRegistriesConfigPath overrides the registries.conf path. It is unexported +// because the only consumer is hermetic tests; production always uses the +// container ecosystem default search locations. +func withRegistriesConfigPath(path string) ClientOption { return func(c *Client) { - c.configOptions = o + c.registriesConfigPath = path } } diff --git a/pkg/registry/client_test.go b/pkg/registry/client_test.go index 9029ba906..4babf7132 100644 --- a/pkg/registry/client_test.go +++ b/pkg/registry/client_test.go @@ -230,16 +230,14 @@ func TestNewClient_WithDenyAllPolicy(t *testing.T) { require.Same(t, evaluator, c.policyEvaluator) } -func TestNewClient_WithConfigOptions(t *testing.T) { +func TestNewClient_WithRegistriesConfigPath(t *testing.T) { t.Parallel() credFile := filepath.Join(t.TempDir(), "config.json") c, err := NewClient( ClientOptWriter(io.Discard), ClientOptCredentialsFile(credFile), - ClientOptConfigOptions(ConfigOptions{ - RegistriesConfigPath: "/nonexistent/registries.conf", - }), + withRegistriesConfigPath("/nonexistent/registries.conf"), ) require.NoError(t, err) // nonexistent paths are silently skipped require.NotNil(t, c) @@ -271,7 +269,7 @@ func TestLogin_LocationRewrite(t *testing.T) { c, err := NewClient( ClientOptWriter(io.Discard), ClientOptCredentialsFile(credFile), - ClientOptConfigOptions(ConfigOptions{RegistriesConfigPath: registriesConf}), + withRegistriesConfigPath(registriesConf), ) require.NoError(t, err)