Merge pull request #3993 from crazy-max/v0.36_backport_3991

[v0.36] cherry-picks for v0.36.1
This commit is contained in:
CrazyMax
2026-08-04 17:11:57 +02:00
committed by GitHub
6 changed files with 118 additions and 7 deletions
+23 -3
View File
@@ -65,6 +65,11 @@ var sendGitQueryAsInput = sync.OnceValue(func() bool {
return false return false
}) })
const (
noDefaultAttestationsEnv = "BUILDX_NO_DEFAULT_ATTESTATIONS"
noDefaultOCIArtifactEnv = "BUILDX_NO_DEFAULT_OCI_ARTIFACT"
)
// policyExplicitlyDisabled reports whether the user passed `--policy // policyExplicitlyDisabled reports whether the user passed `--policy
// disabled=true`, which suppresses both user-defined and builtin default // disabled=true`, which suppresses both user-defined and builtin default
// policies. // policies.
@@ -355,12 +360,11 @@ func toSolveOpt(ctx context.Context, np *noderesolver.ResolvedNode, multiDriver
} }
if _, ok := opt.Attests["provenance"]; !ok && supportAttestations { if _, ok := opt.Attests["provenance"]; !ok && supportAttestations {
const noAttestEnv = "BUILDX_NO_DEFAULT_ATTESTATIONS"
var noProv bool var noProv bool
if v, ok := os.LookupEnv(noAttestEnv); ok { if v, ok := os.LookupEnv(noDefaultAttestationsEnv); ok {
noProv, err = strconv.ParseBool(v) noProv, err = strconv.ParseBool(v)
if err != nil { if err != nil {
return nil, nil, errors.Wrap(err, "invalid "+noAttestEnv) return nil, nil, errors.Wrap(err, "invalid "+noDefaultAttestationsEnv)
} }
} }
if !noProv { if !noProv {
@@ -436,6 +440,14 @@ func toSolveOpt(ctx context.Context, np *noderesolver.ResolvedNode, multiDriver
} }
opt.Exports = exports opt.Exports = exports
var noDefaultOCIArtifact bool
if v, ok := os.LookupEnv(noDefaultOCIArtifactEnv); ok {
noDefaultOCIArtifact, err = strconv.ParseBool(v)
if err != nil {
return nil, nil, errors.Wrap(err, "invalid "+noDefaultOCIArtifactEnv)
}
}
// set up exporters // set up exporters
for i, e := range opt.Exports { for i, e := range opt.Exports {
if e.Type == "oci" && !nodeDriver.Features(ctx)[driver.OCIExporter] { if e.Type == "oci" && !nodeDriver.Features(ctx)[driver.OCIExporter] {
@@ -497,6 +509,14 @@ func toSolveOpt(ctx context.Context, np *noderesolver.ResolvedNode, multiDriver
opt.Exports[i].Attrs["buildinfo-attrs"] = v opt.Exports[i].Attrs["buildinfo-attrs"] = v
} }
} }
if noDefaultOCIArtifact && supportAttestations {
switch opt.Exports[i].Type {
case client.ExporterImage, client.ExporterOCI, "moby":
if _, ok := opt.Exports[i].Attrs[string(exptypes.OptKeyOCIArtifact)]; !ok {
opt.Exports[i].Attrs[string(exptypes.OptKeyOCIArtifact)] = "false"
}
}
}
} }
so.Exports = opt.Exports so.Exports = opt.Exports
+1 -1
View File
@@ -30,7 +30,7 @@ require (
github.com/hashicorp/hcl/v2 v2.24.0 github.com/hashicorp/hcl/v2 v2.24.0
github.com/in-toto/in-toto-golang v0.11.0 github.com/in-toto/in-toto-golang v0.11.0
github.com/mitchellh/hashstructure/v2 v2.0.2 github.com/mitchellh/hashstructure/v2 v2.0.2
github.com/moby/buildkit v0.32.0 github.com/moby/buildkit v0.32.2
github.com/moby/go-archive v0.2.1 github.com/moby/go-archive v0.2.1
github.com/moby/moby/api v1.55.0 github.com/moby/moby/api v1.55.0
github.com/moby/moby/client v0.5.0 github.com/moby/moby/client v0.5.0
+2 -2
View File
@@ -395,8 +395,8 @@ github.com/mitchellh/hashstructure/v2 v2.0.2 h1:vGKWl0YJqUNxE8d+h8f6NJLcCJrgbhC4
github.com/mitchellh/hashstructure/v2 v2.0.2/go.mod h1:MG3aRVU/N29oo/V/IhBX8GR/zz4kQkprJgF2EVszyDE= github.com/mitchellh/hashstructure/v2 v2.0.2/go.mod h1:MG3aRVU/N29oo/V/IhBX8GR/zz4kQkprJgF2EVszyDE=
github.com/mitchellh/mapstructure v1.5.0 h1:jeMsZIYE/09sWLaz43PL7Gy6RuMjD2eJVyuac5Z2hdY= github.com/mitchellh/mapstructure v1.5.0 h1:jeMsZIYE/09sWLaz43PL7Gy6RuMjD2eJVyuac5Z2hdY=
github.com/mitchellh/mapstructure v1.5.0/go.mod h1:bFUtVrKA4DC2yAKiSyO/QUcy7e+RRV2QTWOzhPopBRo= github.com/mitchellh/mapstructure v1.5.0/go.mod h1:bFUtVrKA4DC2yAKiSyO/QUcy7e+RRV2QTWOzhPopBRo=
github.com/moby/buildkit v0.32.0 h1:slXarYQoMo4cp2d9x30M9t0L4R+c0CVMov+5P1hhiHY= github.com/moby/buildkit v0.32.2 h1:Sfy7+u6dUv/2yuBc9KCoK70Re8atuV8aPZ5UOC068Vc=
github.com/moby/buildkit v0.32.0/go.mod h1:Y10FBWvqxl/Wmhdzjee1Y2wQfjifTiwxENIUdaVNdME= github.com/moby/buildkit v0.32.2/go.mod h1:0GB/EJ1d+4VIVqIAgy3asaoGkVXy7IrDfVy7mPhOvg8=
github.com/moby/docker-image-spec v1.3.1 h1:jMKff3w6PgbfSa69GfNg+zN/XLhfXJGnEx3Nl2EsFP0= github.com/moby/docker-image-spec v1.3.1 h1:jMKff3w6PgbfSa69GfNg+zN/XLhfXJGnEx3Nl2EsFP0=
github.com/moby/docker-image-spec v1.3.1/go.mod h1:eKmb5VW8vQEh/BAr2yvVNvuiJuY6UIocYsFu/DxxRpo= github.com/moby/docker-image-spec v1.3.1/go.mod h1:eKmb5VW8vQEh/BAr2yvVNvuiJuY6UIocYsFu/DxxRpo=
github.com/moby/go-archive v0.2.1 h1:fAa0wUS/ikZKyx7o/1fhUYmhZ7RgpthdeoDhJvunTLc= github.com/moby/go-archive v0.2.1 h1:fAa0wUS/ikZKyx7o/1fhUYmhZ7RgpthdeoDhJvunTLc=
+36
View File
@@ -79,6 +79,7 @@ var bakeTests = []func(t *testing.T, sb integration.Sandbox){
testBakeMetadataWarningsDedup, testBakeMetadataWarningsDedup,
testBakeMultiExporters, testBakeMultiExporters,
testBakeLoadPush, testBakeLoadPush,
testBakeNoDefaultOCIArtifact,
testBakeListTargets, testBakeListTargets,
testBakeListVariables, testBakeListVariables,
testBakeListTypedVariables, testBakeListTypedVariables,
@@ -2232,6 +2233,41 @@ target "default" {
// TODO: test metadata file when supported by multi exporters https://github.com/docker/buildx/issues/2181 // TODO: test metadata file when supported by multi exporters https://github.com/docker/buildx/issues/2181
} }
func testBakeNoDefaultOCIArtifact(t *testing.T, sb integration.Sandbox) {
if isMobyWorker(sb) {
t.Skip("attestations are not supported by the docker worker")
}
registry, err := sb.NewRegistry()
if errors.Is(err, integration.ErrRequirements) {
t.Skip(err.Error())
}
require.NoError(t, err)
target := registry + "/buildx/bake-no-default-oci-artifact:latest"
dockerfile := []byte(`
FROM scratch
COPY foo /foo
`)
bakefile := fmt.Appendf(nil, `
target "default" {
output = ["type=image,name=%s,push=true"]
attest = ["type=provenance"]
}
`, target)
dir := tmpdir(
t,
fstest.CreateFile("docker-bake.hcl", bakefile, 0600),
fstest.CreateFile("Dockerfile", dockerfile, 0600),
fstest.CreateFile("foo", []byte("foo"), 0600),
)
out, err := bakeCmd(sb, withDir(dir), withEnv("BUILDX_NO_DEFAULT_OCI_ARTIFACT=true"))
require.NoError(t, err, string(out))
requireLegacyAttestationStorage(t, sb, target)
}
func testBakeLoadPush(t *testing.T, sb integration.Sandbox) { func testBakeLoadPush(t *testing.T, sb integration.Sandbox) {
if !isDockerContainerWorker(sb) { if !isDockerContainerWorker(sb) {
t.Skip("only testing with docker-container worker") t.Skip("only testing with docker-container worker")
+55
View File
@@ -66,6 +66,7 @@ var buildTests = []func(t *testing.T, sb integration.Sandbox){
testBuildLocalExportDeleteMode, testBuildLocalExportDeleteMode,
testBuildRegistryExport, testBuildRegistryExport,
testBuildRegistryExportAttestations, testBuildRegistryExportAttestations,
testBuildRegistryExportNoDefaultOCIArtifact,
testBuildTarExport, testBuildTarExport,
testBuildMobyFromLocalImage, testBuildMobyFromLocalImage,
testBuildDetailsLink, testBuildDetailsLink,
@@ -633,6 +634,60 @@ func testBuildRegistryExportAttestations(t *testing.T, sb integration.Sandbox) {
require.Len(t, att.Layers, 1) require.Len(t, att.Layers, 1)
} }
func testBuildRegistryExportNoDefaultOCIArtifact(t *testing.T, sb integration.Sandbox) {
if isMobyWorker(sb) {
t.Skip("attestations are not supported by the docker worker")
}
dir := createTestProject(t)
registry, err := sb.NewRegistry()
if errors.Is(err, integration.ErrRequirements) {
t.Skip(err.Error())
}
require.NoError(t, err)
target := registry + "/buildx/registry-no-default-oci-artifact:latest"
out, err := buildCmd(sb,
withEnv("BUILDX_NO_DEFAULT_OCI_ARTIFACT=true"),
withArgs(fmt.Sprintf("--output=type=image,name=%s,push=true", target), "--provenance=true", dir),
)
require.NoError(t, err, string(out))
requireLegacyAttestationStorage(t, sb, target)
}
func requireLegacyAttestationStorage(t *testing.T, sb integration.Sandbox, ref string) {
t.Helper()
cmd := buildxCmd(sb, withArgs("imagetools", "inspect", ref, "--raw"))
dt, err := cmd.CombinedOutput()
require.NoError(t, err, string(dt))
var idx ocispecs.Index
err = json.Unmarshal(dt, &idx)
require.NoError(t, err)
var attestation ocispecs.Descriptor
for _, desc := range idx.Manifests {
if desc.Annotations["vnd.docker.reference.type"] == "attestation-manifest" {
attestation = desc
break
}
}
require.NotEmpty(t, attestation.Digest)
cmd = buildxCmd(sb, withArgs("imagetools", "inspect", ref+"@"+attestation.Digest.String(), "--raw"))
dt, err = cmd.CombinedOutput()
require.NoError(t, err, string(dt))
var mfst ocispecs.Manifest
err = json.Unmarshal(dt, &mfst)
require.NoError(t, err)
require.Nil(t, mfst.Subject)
require.NotEmpty(t, mfst.Layers)
}
func testImageIDOutput(t *testing.T, sb integration.Sandbox) { func testImageIDOutput(t *testing.T, sb integration.Sandbox) {
dockerfile := []byte(`FROM busybox:latest`) dockerfile := []byte(`FROM busybox:latest`)
+1 -1
View File
@@ -644,7 +644,7 @@ github.com/mitchellh/go-wordwrap
# github.com/mitchellh/hashstructure/v2 v2.0.2 # github.com/mitchellh/hashstructure/v2 v2.0.2
## explicit; go 1.14 ## explicit; go 1.14
github.com/mitchellh/hashstructure/v2 github.com/mitchellh/hashstructure/v2
# github.com/moby/buildkit v0.32.0 # github.com/moby/buildkit v0.32.2
## explicit; go 1.26.3 ## explicit; go 1.26.3
github.com/moby/buildkit/api/services/control github.com/moby/buildkit/api/services/control
github.com/moby/buildkit/api/types github.com/moby/buildkit/api/types