Skip to content

Fix/registry edge case retries - #2535

Open
am9zZWY wants to merge 4 commits into
pulp:mainfrom
am9zZWY:fix/registry-edge-case-retries
Open

am9zZWY wants to merge 4 commits into
pulp:mainfrom
am9zZWY:fix/registry-edge-case-retries

Conversation

@am9zZWY

@am9zZWY am9zZWY commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

📜 Checklist

  • Commits are cleanly separated with meaningful messages (simple features and bug fixes should be squashed to one commit)
  • A changelog entry or entries has been added for any significant changes
  • Follows the Pulp policy on AI Usage
  • (For new features) - User documentation and test coverage has been added

See: Pull Request Walkthrough

Some registries (e.g. ECR Public) reject HEAD requests on blob
endpoints regardless of authentication. Retry with GET in that case
to still verify blob existence.
Assisted By: Claude Opus 5

Some registries reject HEAD on blob endpoints regardless of auth
(public.ecr.aws answers 401 where the same token succeeds on GET),
which surfaced as a 502 on pull-through. Fall back to a GET with
Range: bytes=0-0 on 401/405. Those responses carry no
docker-content-digest, so the digest check is skipped there; the
sha256 is still verified on the actual download.
Assisted By: Claude Opus 5

extra_data["headers"] is usually the V2_ACCEPT_HEADERS constant, and
headers.update(auth_headers) mutated it in place. The first token
negotiated in a process leaked into every later request, including
those to other registries.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant