fix: propagate registry auth error in swarm image pull

When a worker pull fails with unauthorized, the error was being
swallowed and replaced with misleading 'No such image' message.
Fix error propagation so the actual cause is reported.

Signed-off-by: Md_Mushfiqur Rahim <20mahin20201@gmail.com>
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
This commit is contained in:
Md_Mushfiqur Rahim
2026-05-25 11:29:19 +00:00
committed by Sebastiaan van Stijn
parent 57d28f76e5
commit a7cf7eac0a
2 changed files with 10 additions and 0 deletions

View File

@@ -174,6 +174,14 @@ func (r *controller) Prepare(ctx context.Context) error {
// If you don't want this behavior, lock down your image to an
// immutable tag or digest.
log.G(ctx).WithError(r.pullErr).Error("pulling image failed")
// If the pull failed with an authentication error, return it
// so the actual cause is propagated instead of the misleading
// "No such image" error that would otherwise result from the
// container create below.
if cerrdefs.IsUnauthorized(r.pullErr) {
return r.pullErr
}
}
}
}

View File

@@ -106,6 +106,8 @@ func translatePullError(err error, ref reference.Named) error {
switch v.Code {
case errcode.ErrorCodeDenied, v2.ErrorCodeManifestUnknown, v2.ErrorCodeNameUnknown:
return notFoundError{v, ref}
case errcode.ErrorCodeUnauthorized:
return errdefs.Unauthorized(v)
}
case xfer.DoNotRetry:
return translatePullError(v.Err, ref)