Skip to content

Fall back to config media type for old-style artifact types - #2114

Merged
TerryHowe merged 4 commits into
oras-project:mainfrom
Kunalbehbud:fix/enrich-artifacttype-config-fallback
Oct 9, 2026
Merged

TerryHowe merged 4 commits into
oras-project:mainfrom
Kunalbehbud:fix/enrich-artifacttype-config-fallback

Conversation

@Kunalbehbud

Copy link
Copy Markdown
Contributor

What this PR does / why we need it:

Addresses Issue 1 of #2015 (the config.mediaType fallback for descriptor artifactType), following @TerryHowe's assessment on the issue.

When oras manifest index create/update enriches a child image manifest descriptor, enrichDescriptor set desc.ArtifactType = manifest.ArtifactType and left it empty for old-style artifacts — those created before the manifest artifactType field existed, which convey their type through config.mediaType instead (e.g. historically-created artifacts like OpenTofu providers).

The image-spec descriptor guidance says artifactType "is the value of the config descriptor mediaType when the descriptor references an image manifest", and the manifest guidelines explicitly call for tooling to "fallback to the config.mediaType value". This change does that: when artifactType is empty and the config is not a standard OCI image config, the enriched descriptor falls back to config.mediaType.

enrichDescriptor is shared by both the index create and update paths, so a single change fixes both (the issue assessment expected two edits).

This PR intentionally scopes to Issue 1 only. Issue 2 (a mechanism/flag to attach platform to artifact descriptors) is a larger, separate change and is left for a follow-up.

Which issue(s) this PR fixes:
Fixes #2015

Please check the following list:

  • Does the affected code have corresponding tests, e.g. unit test, E2E test? — Added two Test_enrichDescriptor cases: the fallback path (empty artifactType + custom config.mediaType), and the guard that keeps artifactType empty when the config is the standard OCI image config type. This closes the "no test for the old-style fallback path" gap noted in the issue.
  • Does this change require a documentation update? — No; behavior now matches the documented spec expectation.
  • Does this introduce breaking changes that would require an announcement or bumping the major version? — No; it only populates a descriptor field that was previously left empty for these artifacts.
  • Do all new files have an appropriate license header? — No new files.

enrichDescriptor left the index descriptor's artifactType empty for
old-style artifacts that predate the manifest artifactType field and
convey their type through config.mediaType instead. The image-spec
descriptor guidance says tooling should fall back to config.mediaType
in that case, so do that when artifactType is empty and the config is
not a standard OCI image config.

enrichDescriptor is shared by index create and update, so both paths
are fixed.

Signed-off-by: Kunalbehbud <b.kunal2002@gmail.com>
Comment thread cmd/oras/root/manifest/index/create.go Outdated
Broaden the guard so the config media type is only used as the
artifact type when it is not a standard image config: OCI image
config, the empty JSON config, and the Docker image config are all
left out. Adds the Docker image config media type constant.

Signed-off-by: Kunalbehbud <b.kunal2002@gmail.com>
@Kunalbehbud

Copy link
Copy Markdown
Contributor Author

Good catch — applied. Switched to the switch-based guard so the config media type is only used when it isn't a standard image config: ocispec.MediaTypeImageConfig, ocispec.MediaTypeEmptyJSON, and the Docker image config are all excluded.

docker.MediaTypeConfig didn't exist yet, so I added it to internal/docker alongside the existing manifest media types (application/vnd.docker.container.image.v1+json).

Also extended Test_enrichDescriptor to cover all three excluded config types staying empty, on top of the fallback case. PTAL.

@TerryHowe TerryHowe left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@TerryHowe

Copy link
Copy Markdown
Member

In test/e2e/internal/testdata/nonjson_config/const.go:

var (
      Descriptor = ocispec.Descriptor{
              MediaType:    "application/vnd.oci.image.manifest.v1+json",
              Digest:       "sha256:9d16f5505246424aed7116cb21216704ba8c919997d0f1f37e154c11d509e1d2",
              Size:         529,
              ArtifactType: "application/vnd.unknown.config.v1+json", // ← add this
      }
)

@TerryHowe TerryHowe left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Test is broken

Signed-off-by: Terry Howe <thowe@nvidia.com>
Signed-off-by: Terry Howe <thowe@nvidia.com>
@codecov

codecov Bot commented Oct 9, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 57.59%. Comparing base (e58fee3) to head (990e68f).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #2114      +/-   ##
==========================================
+ Coverage   57.52%   57.59%   +0.06%     
==========================================
  Files         139      139              
  Lines        6067     6072       +5     
==========================================
+ Hits         3490     3497       +7     
+ Misses       2357     2356       -1     
+ Partials      220      219       -1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@TerryHowe
TerryHowe merged commit 8b3b8bd into oras-project:main Oct 9, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Specification Deviation in Multi Arch Artifacts

2 participants