fix(docker): fail closed on bottle enumeration
lint / lint (push) Successful in 1m2s
test / integration-docker (pull_request) Failing after 56s
test / image-input-builds (pull_request) Successful in 57s
test / unit (pull_request) Successful in 1m3s
test / coverage (pull_request) Has been skipped
tracker-policy-pr / check-pr (pull_request) Successful in 11s

This commit is contained in:
2026-07-27 16:41:17 +00:00
parent a401310865
commit e49f9a4e53
2 changed files with 13 additions and 0 deletions
@@ -89,6 +89,11 @@ def running_agent_containers(
"docker", "network", "inspect", "--format",
"{{range .Containers}}{{.Name}}\n{{end}}", network,
])
if proc.returncode != 0:
detail = proc.stderr.strip() or f"exit {proc.returncode}"
raise InfraLaunchError(
f"could not enumerate bottles on gateway network {network}: {detail}"
)
return [
name for name in (line.strip() for line in proc.stdout.splitlines())
if name and name != gateway_name
@@ -262,6 +262,14 @@ class TestDockerAttachPrimitives(unittest.TestCase):
with self.assertRaises(FileNotFoundError):
docker.running_agent_containers()
def test_running_agent_containers_fails_hard_on_inspect_failure(self) -> None:
inspect = _proc(1, stderr="network unavailable")
with patch.object(docker, "run_docker", return_value=inspect):
with self.assertRaisesRegex(
docker.InfraLaunchError, "network unavailable",
):
docker.running_agent_containers(network="net")
def test_push_ca_cp_then_rebuilds_trust_store(self) -> None:
with patch.object(
docker, "run_docker", side_effect=[_proc(), _proc(), _proc()],