Skip to content

tests/images with tailor [1]: tailor changes: fix image build arguments and signing - #842

Draft
bfjelds (bfjelds) wants to merge 3 commits into
mainfrom
user/bfjelds/tailor-fixes
Draft

bfjelds (bfjelds) wants to merge 3 commits into
mainfrom
user/bfjelds/tailor-fixes

Conversation

@bfjelds

@bfjelds bfjelds (bfjelds) commented Oct 10, 2026 •

Copy link
Copy Markdown
Member

Summary

  • add real outputs[].name support to tailor config/runtime
  • interpolate outputs[].name through render
  • publish artifacts using the configured name instead of the cell slug
  • fingerprint the published output name so incremental state stays correct

Validation

  • cargo test --manifest-path tools/tailor/Cargo.toml -p tailor-config
  • cargo test --manifest-path tools/tailor/Cargo.toml -p tailor-core
  • cargo test --manifest-path tools/tailor/Cargo.toml -p tailor

Fix several bugs in tailor discovered while validating signed and convert-based image builds:

- stop emitting --image-cache-dir for Image Customizer convert and inject-files operations
- restore fragment-level signing through render and build selection for signed VM image cells
- fall back to pesign when sbsign is unavailable on Azure Linux hosts
- bound leaf certificate common names to the X.509 64-character limit

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
1 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@bfjelds bfjelds (bfjelds) changed the title tailor: fix image build arguments and signing tests/images with tailor [1]: tailor changes: fix image build arguments and signing Oct 10, 2026
config: already resolved $include before merging each fragment's delta
(render_cell calls include::resolve_includes on fragment.doc.config), but
resolve_base merged each fragment's raw base: value directly, so a
base: { $include: ... } fragment hit merge.rs's generic "directive
$include ... must be resolved before merge" error - that generic message
exists precisely to catch an $include that should have already been
resolved by an earlier pass, and base: simply never had one.

Thread image_dir into resolve_base and call include::resolve_includes on
each fragment's base value before merging, mirroring config:'s handling
exactly. This lets a by-<axis>/<value>.yaml fragment's base: override
point at a shared snippet instead of repeating the same $set inline in
every family that needs the same base override - useful when several
otherwise-unrelated images share an identical by-arch (or similar)
fragment.

Added a regression test exercising two by-arch fragments that each
$include a different shared base snippet, confirming both resolve to the
expected path base per cell.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
bfjelds (bfjelds) added a commit that referenced this pull request Oct 10, 2026
Now that tools/tailor resolves $include under base: before merge (previous
commit, PR #842), the four identical by-arch/arm64.yaml fragments
(azurelinux-direct-streaming-testimage, trident-installer, trident-testimage,
trident-vm-testimage) can point at one shared
common/matrix/base-core-arm64.yaml snippet instead of repeating
`base: { $set: { ref: core_arm64 } }` verbatim in each family.

Verified: `tailor validate` (same 30 cells as before), and a dry-run/render
of an arm64 cell confirming the rendered Image Customizer invocation still
resolves --image-file to artifacts/core_arm64.vhdx and --platform to
linux/arm64 exactly as before this change.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant