Persist attestation manifest and any manifest cosign-based
signatures when creating new images.
When creating index from single-arch manifests where attestation
manifest is not inlined, it can be loaded from referrers API.
Note that for this to work the attestation manifest needs to be
in artifact type when image was built.
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
(cherry picked from commit aab8171f824d13d703e869107e1720ad71d24bff)
The solve error that gets returned sometimes has a platform when the LLB
returned by `ToState` doesn't. In order to ensure we find the failed
digest, we now search for both the digest of what was returned and also
clear out the platform and search for the digest without that in case
that one matches instead.
Signed-off-by: Jonathan A. Sternberg <jonathan.sternberg@docker.com>
If a breakpoint occurs before the step pointed to by next or out, dap
will now stop there instead of the desired location.
This also updates the loop to always set the breakpoints rather than
only when continue is chosen.
Signed-off-by: Jonathan A. Sternberg <jonathan.sternberg@docker.com>
This change modifies how steps are evaluated in the program. Previously,
the execution relied on looking for the digest we were going to stop at
and evaluating the step right before that digest. This could result in
some gaps where it erroneously didn't execute inputs for the current
step as it skipped those digests.
Now, the evaluation reads the inputs and executed those directly rather
than relying on the evaluation of previous steps in the sequence. This
should make the evaluation of inputs more accurate and allow us to have
better breakpoints on things like the copy operation.
Due to the change, it's also easier for us to include the different
inputs in the file explorer.
Signed-off-by: Jonathan A. Sternberg <jonathan.sternberg@docker.com>
The setBreakpoints response body is defined to be an array of
breakpoints but the debug adapter incorrectly serialized an empty array
as null in the JSON message. Explicitly initializing the array will
force the JSON serialization process to send an empty array back instead
of null.
Signed-off-by: Remy Suen <remy.suen@docker.com>
Deprecate these commands in favor of using `docker buildx` directly,
without relying on the `docker builder` alias.
The commands have been hidden since the beginning.
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
The run in terminal request sent by exec would not work if `buildx` had
been invoked directly instead of through `docker`. If we don't find the
reexec environment variable, we use `os.Args[0]` to launch buildx
directly when invoking attach.
Signed-off-by: Jonathan A. Sternberg <jonathan.sternberg@docker.com>
A value-less, untyped variable has always been converted to an empty
string. The intention was that value-less, typed variables convert to a
typed null, which was even specified in a code comment, but was never
actually implemented.
This resulted in a null value with a nil type. A value with a nil type
cannot be coerced ("unified") with any other standard types. When this
mismatch occurs, HCL attempts to return a diagnostic error, which in
turn panics as the nil type is literally a nil pointer.
Signed-off-by: Roberto Villarreal <rrjjvv@yahoo.com>