CocoonSet teardown calls DeleteManifest for :hibernate and policy-selected :latest tags even when those manifests were never pushed. Although the client treats a 404 as success, some OCI registries materialize an empty repository while authorizing the DELETE request, leaving repository entries with no tags.
This is common for snapshotPolicy: never: neither teardown snapshot exists, but deleting the CocoonSet still sends registry DELETE requests.
Fix
Probe each GC candidate with the existing Registry.HasManifest API.
Call DeleteManifest only when the tag exists.
Preserve the existing snapshot-policy behavior, including cleanup of stale :latest tags under never and non-main roles under main-only.
Update the reconcile-loop documentation and add a regression test for absent tags.
The HEAD/DELETE race remains safe because DeleteManifest already treats a missing manifest as success.
Validation
make fmt-check
make test
make lint
Verified against an OCI registry exhibiting the issue: deleting short-lived snapshotPolicy: never sets no longer created empty repository records.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
CocoonSet teardown calls DeleteManifest for :hibernate and policy-selected :latest tags even when those manifests were never pushed. Although the client treats a 404 as success, some OCI registries materialize an empty repository while authorizing the DELETE request, leaving repository entries with no tags.
This is common for snapshotPolicy: never: neither teardown snapshot exists, but deleting the CocoonSet still sends registry DELETE requests.
Fix
The HEAD/DELETE race remains safe because DeleteManifest already treats a missing manifest as success.
Validation