fix(ci): skip the BuildKit check whose warning embedded this Dockerfile in CI output
Lint / hadolint (push) Successful in 10s
Lint / skill-floor (push) Failing after 13s
Lint / doc-drift (push) Successful in 18s
Lint / actionlint (push) Successful in 33s
Publish Docker Image / lint-gate (push) Successful in 32s
Publish Docker Image / resolve-versions (push) Successful in 17s
Publish Docker Image / base-decide (push) Successful in 13s
Publish Docker Image / build-base (push) Has been skipped
Publish Docker Image / smoke-studio (push) Successful in 5m38s
Publish Docker Image / smoke (push) Successful in 8m20s
Publish Docker Image / build-variant-studio (push) Successful in 20m34s
Publish Docker Image / build-variant (push) Successful in 21m5s
Publish Docker Image / update-description (push) Successful in 8s
Publish Docker Image / promote-base-latest (push) Successful in 9s

v1.10.1 (run 707) failed with ZERO failing steps: every step Success, `smoke`
printing "101 passed, 0 failed", `smoke-studio` "104 passed, 0 failed", both
jobs red. The clipboard fix from f3b3748 worked exactly as predicted; this is a
second, independent defect that run 704 had masked.

CHAIN, measured end to end rather than reasoned:

`ARG BASE_IMAGE` has no default on purpose (the two-phase build always supplies
it), which trips BuildKit's InvalidDefaultArgInFrom check. buildx attaches that
warning's source context to the build metadata as
buildx.build.warnings[].sourceInfo.data — the ENTIRE Dockerfile, base64, on ONE
line. docker/build-push-action writes that metadata to $GITHUB_OUTPUT as a
`name<<ghadelimiter_<uuid>` heredoc. Gitea's act_runner truncates any single
line at exactly 65536 chars, so the closing delimiter was cut off:

  invalid format delimiter 'ghadelimiter_...' not found before end of file

and the runner failed the job while attributing it to no step at all.

  v1.9.4  run 695 SUCCESS: longest metadata line 56355, 0 delimiter errors
  v1.10.0 run 704 failed : longest metadata line 65536, 1 delimiter error
  v1.10.1 run 707 failed : longest metadata line 65536, 1 delimiter error

65536 = 2^16: cut AT the cap, not merely long. Independent route via file size
rather than log parsing: 42251 B at v1.9.4 (base64 56335, matching the log) vs
50034 B now (base64 66712, truncated). The cap corresponds to a 49152 B
Dockerfile, so this cycle's comment growth crossed it by 882 B.

Located by asking which top-level metadata key CONTAINS the base64, instead of
assuming: it is buildx.build.warnings -> sourceInfo -> data in BOTH runs.

THIS IS THE SECOND FIX FOR THIS BUG. The first, `provenance: false` on the two
smoke build steps, was committed as 784fad7 and is REVERTED here: a real buildx
on another host showed provenance metadata present in both modes with a longest
string of 71 chars, i.e. the base64 was never in provenance. Shipping it would
have left the release broken a third time while looking like a fix.

Also rejected, each measured: floating action tags moving (act action-bundle
hashes byte-identical between runs 695 and 707, all four) and the build-check
annotation text changing (byte-identical).

FIX: `# check=skip=InvalidDefaultArgInFrom` as the FIRST line of
Dockerfile.variant — BuildKit parses `# check=` only before any other line, so
placement is load-bearing. No honest default exists for BASE_IMAGE: `scratch`
would satisfy the linter while being a lie, and would convert today's instant
"invalid reference format" into a failure deep in the build. Verified against
the actual edited file with `docker buildx build --check`: "Check complete, no
warnings found." Zero warnings means no sourceInfo, so the longest metadata line
drops 65536 -> ~1936 and the file's SIZE stops gating CI.

GUARD: scripts/check-dockerfile-directives.sh, wired into BOTH lint.yml and
docker-publish.yml's lint-gate, because a check that gates only `push` lets a
tag regress — the adoption slip that let doc-drift land 27 h after the v1.9.3
tag. It also fails if ARG BASE_IMAGE gains a default, so the directive cannot
rot into guarding a check that can no longer fire. Truth table, exit codes:
present 0, removed 1, demoted to line 2 → 1, ARG defaulted 1, file missing 2
(a gate that cannot run must not pass).

Release renamed v1.10.1 -> v1.10.2 with both failed tags left standing as
tombstones. Docs swept again (README "since" marker, Dockerfile decision
comments) because CI reads them from the TAG.

Gates: doc-drift 23 OK / 0 DRIFT; base-hash, workflow-shell, skill-floor,
lint-shell (17 files now), dockerfile-directives all rc=0.
This commit is contained in:
Joakim Persson
2026-10-02 10:58:03 +02:00
parent 784fad78f3
commit 56e3742a2d
6 changed files with 186 additions and 60 deletions
+7 -44
View File
@@ -222,6 +222,13 @@ jobs:
- name: Components the next build would bake differently are named in the CHANGELOG
run: bash scripts/check-doc-drift.sh
# Runs HERE as well as in lint.yml deliberately. A guard that gates only
# `push` lets a tag regress — the adoption slip that let doc-drift land
# 27 h after the v1.9.3 tag. This one protects the tag build from the
# zero-failing-step failure mode that killed v1.10.0 and v1.10.1.
- name: Dockerfile.variant still opens with its BuildKit check directive
run: bash scripts/check-dockerfile-directives.sh Dockerfile.variant
resolve-versions:
# Gated: a defective tree must not reach a 46-minute base build.
needs: [lint-gate]
@@ -593,28 +600,6 @@ jobs:
platforms: linux/amd64
push: false
load: true
# provenance: false is LOAD-BEARING, not hygiene. buildx writes a
# provenance attestation into the metadata it hands back, and that
# metadata embeds the ENTIRE Dockerfile as one base64 "data" field on a
# single line. build-push-action writes the metadata to $GITHUB_OUTPUT
# as a `name<<ghadelimiter_<uuid>` heredoc, and Gitea's act_runner
# truncates any single line at exactly 65536 chars — so once
# base64(Dockerfile.variant) crosses 64 KiB the closing delimiter is
# cut off and the runner fails the job with
# invalid format delimiter 'ghadelimiter_...' not found before end of file
# and NO failing step: every step reports Success, the smoke suite
# reports "0 failed", and the job is red anyway.
# Measured: Dockerfile.variant was 42251 B at v1.9.4 (base64 56355,
# fine) and 50034 B at v1.10.1 (base64 66712, truncated to 65536) —
# the cap corresponds to a 49152 B Dockerfile, so the v1.10.0/v1.10.1
# comment growth crossed it by 882 B. v1.10.0 run 704 and v1.10.1
# run 707 both died here; in 704 it hid behind a stale clipboard
# assertion. Trimming comments would "fix" it until the next comment.
# These smoke images are built with load: true and thrown away, so the
# attestation has no consumer. The PUBLISHED images are built by raw
# `docker buildx build --push` in run: blocks, which never writes
# $GITHUB_OUTPUT metadata — so this changes nothing about what ships.
provenance: false
tags: pi-devbox:smoke
build-args: |
BASE_IMAGE=${{ env.IMAGE }}:${{ needs.base-decide.outputs.base_tag }}
@@ -680,28 +665,6 @@ jobs:
platforms: linux/amd64
push: false
load: true
# provenance: false is LOAD-BEARING, not hygiene. buildx writes a
# provenance attestation into the metadata it hands back, and that
# metadata embeds the ENTIRE Dockerfile as one base64 "data" field on a
# single line. build-push-action writes the metadata to $GITHUB_OUTPUT
# as a `name<<ghadelimiter_<uuid>` heredoc, and Gitea's act_runner
# truncates any single line at exactly 65536 chars — so once
# base64(Dockerfile.variant) crosses 64 KiB the closing delimiter is
# cut off and the runner fails the job with
# invalid format delimiter 'ghadelimiter_...' not found before end of file
# and NO failing step: every step reports Success, the smoke suite
# reports "0 failed", and the job is red anyway.
# Measured: Dockerfile.variant was 42251 B at v1.9.4 (base64 56355,
# fine) and 50034 B at v1.10.1 (base64 66712, truncated to 65536) —
# the cap corresponds to a 49152 B Dockerfile, so the v1.10.0/v1.10.1
# comment growth crossed it by 882 B. v1.10.0 run 704 and v1.10.1
# run 707 both died here; in 704 it hid behind a stale clipboard
# assertion. Trimming comments would "fix" it until the next comment.
# These smoke images are built with load: true and thrown away, so the
# attestation has no consumer. The PUBLISHED images are built by raw
# `docker buildx build --push` in run: blocks, which never writes
# $GITHUB_OUTPUT metadata — so this changes nothing about what ships.
provenance: false
tags: pi-devbox:smoke-studio
build-args: |
BASE_IMAGE=${{ env.IMAGE }}:${{ needs.base-decide.outputs.base_tag }}