From nobody Wed Aug 26 01:48:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785862499; cv=none; d=zohomail.com; s=zohoarc; b=EudZ3WKtUTGoNRi780kaX5Er2NFdvtP/JcT+68Y3uMfCchKC2wuzSqemln2bnfekXCvs30Kd5u8oekrVcDz4rngTJ6LuYYKO33YtXkVV9S1ORVyz6hm/jpVARWO/EUySF2P2RAoFel/fLxxCOlo+Ih/GIag7V8uyETLO9yZZQG4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785862499; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=CtzzvXkyrYWBS7h1wUGsGeGcIxg7SwuqbUot9EQyZ5I=; b=j1nXaiWymxWxcR96FzdcOnqFRGobk8Ryk24nRy4jGMXZYmVg3IbUTkYkJvA474mrW59EWzdrdZRB9dZVeJMjeQzFUcGj346h/0q+doWXWfHPNftpHZ8zm/FrDT3Z2JBjkC52HevdBcYD1O/DuR5vxYYylAnsO6T7iJWt/zgVy9Q= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785862499005274.7512068841869; Tue, 4 Aug 2026 09:54:59 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wrIPJ-0007GO-PA; Tue, 04 Aug 2026 12:54:25 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrIPJ-0007GG-5G for qemu-devel@nongnu.org; Tue, 04 Aug 2026 12:54:25 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrIPH-00083I-Fx for qemu-devel@nongnu.org; Tue, 04 Aug 2026 12:54:24 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-317-CH3ONSewNNecL9yXq5YiIw-1; Tue, 04 Aug 2026 12:54:17 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 8445F1956056; Tue, 4 Aug 2026 16:54:16 +0000 (UTC) Received: from localhost (unknown [10.2.16.106]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 04DEC195608E; Tue, 4 Aug 2026 16:54:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785862461; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=CtzzvXkyrYWBS7h1wUGsGeGcIxg7SwuqbUot9EQyZ5I=; b=cciEfUHysyL13P33Fw6NXfpNBm4/GCUowDYg0m7y0P2Hs9HU9620TIqzEI/hT7yyD6h2UD hWGiC1GRLrqDvPcii11RSg+lhqvwAQ+7gJrgwWaVZ2ctCLfGj/a3wChEbM7rF5mI8VrOh6 vNVnXxH6gyKy79K6rxqHX4XYN/dXsx8= X-MC-Unique: CH3ONSewNNecL9yXq5YiIw-1 X-Mimecast-MFC-AGG-ID: CH3ONSewNNecL9yXq5YiIw_1785862456 From: Stefan Hajnoczi To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Alex=20Benn=C3=A9e?= , Pierrick Bouvier , Stefan Hajnoczi , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , Thomas Huth Subject: [PATCH for-11.1] gitlab: disable provenance attestations to work around CI bug Date: Tue, 4 Aug 2026 12:54:14 -0400 Message-ID: <20260804165414.480435-1-stefanha@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=stefanha@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 4 X-Spam_score: 0.4 X-Spam_bar: / X-Spam_report: (0.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.795, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785862501915158500 QEMU's CI pipeline involves building container images that will be used to run builds and tests. A recent Docker change triggered the following error: $ docker push "$TAG" ... error from registry: blob unknown to registry - sha256:4401f6f779caf8841c= afd5f483e642fcac56a23a4e4a59523231e101c890dad9 https://gitlab.com/qemu-project/qemu/-/jobs/15701875927#L2372 This happens because Docker now pushes out-of-order and the GitLab Container Registry rejects due to an unknown reference: https://forum.gitlab.com/t/started-yesterday-docker-push-error-from-registr= y-blob-unknown-to-registry/134733/5 It is unclear at this point whether GitLab will modify the behavior of Container Registry or whether Docker will ship a fix. The current workaround is to disable the provenance attestation that is involved in this issue. QEMU's CI pipeline container images are used internally for testing and are not widely distributed. Provenance attestation can be disabled as there are no external consumers of these images. Expect to revert this commit in the future when GitLab or Docker have released their own fixes. Cc: Alex Benn=C3=A9e Cc: Daniel P. Berrang=C3=A9 Cc: Thomas Huth Signed-off-by: Stefan Hajnoczi Reviewed-by: Daniel P. Berrang=C3=A9 --- Note that this is an urgent patch so that the CI will pass again and I can tag v11.1.0-rc3 later today. Currently it is failing due to this issue! .gitlab-ci.d/container-template.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.gitlab-ci.d/container-template.yml b/.gitlab-ci.d/container-t= emplate.yml index 8c7311cca57..88317d650e2 100644 --- a/.gitlab-ci.d/container-template.yml +++ b/.gitlab-ci.d/container-template.yml @@ -14,7 +14,7 @@ - echo "TAG:$TAG" - echo "COMMON_TAG:$COMMON_TAG" - docker build --tag "$TAG" --cache-from "$TAG" --cache-from "$COMMON_= TAG" - --build-arg BUILDKIT_INLINE_CACHE=3D1 + --build-arg BUILDKIT_INLINE_CACHE=3D1 --provenance=3Dfalse -f "tests/docker/dockerfiles/$NAME.docker" "." - docker push "$TAG" after_script: --=20 2.55.0