fix: report a clear error when chart-testing blob verification fails#210
Open
somaz94 wants to merge 1 commit into
Open
fix: report a clear error when chart-testing blob verification fails#210somaz94 wants to merge 1 commit into
somaz94 wants to merge 1 commit into
Conversation
Signed-off-by: somaz <genius5711@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Under
set -o errexit, theretVal=$?check aftercosign verify-blobwasunreachable: a non-zero
cosign verify-blobaborts the script immediately, sothe intended "Unable to validate chart-testing version" message never fired. The
error branch also called
log_error, which is not defined anywhere inct.sh(it would fail with
command not foundif it were ever reached).This rewrites the check as
if ! cosign verify-blob ...; then, which suspendserrexit for the tested command so the failure branch is actually reached, and
replaces the undefined
log_errorwithecho "ERROR: ..." >&2, matching theexisting error style used in
parse_command_line. Behavior on success isunchanged; on verification failure the script now prints the intended clear
error and exits 1.
Validation:
bash -n ct.shandzsh -n ct.shparse cleanshellcheck ct.shcleanif ! cmdreaches the failure branch underset -o errexitNote: open PR #205 wraps this same block in a
verify_blobtoggle but copies thebroken
retVal/log_errorpattern verbatim, so this fix is complementaryregardless of merge order.