diff --git a/.gitea/workflows/docker-publish.yml b/.gitea/workflows/docker-publish.yml index fa9b8ff..6257531 100644 --- a/.gitea/workflows/docker-publish.yml +++ b/.gitea/workflows/docker-publish.yml @@ -593,6 +593,28 @@ jobs: platforms: linux/amd64 push: false load: true + # provenance: false is LOAD-BEARING, not hygiene. buildx writes a + # provenance attestation into the metadata it hands back, and that + # metadata embeds the ENTIRE Dockerfile as one base64 "data" field on a + # single line. build-push-action writes the metadata to $GITHUB_OUTPUT + # as a `name<` heredoc, and Gitea's act_runner + # truncates any single line at exactly 65536 chars — so once + # base64(Dockerfile.variant) crosses 64 KiB the closing delimiter is + # cut off and the runner fails the job with + # invalid format delimiter 'ghadelimiter_...' not found before end of file + # and NO failing step: every step reports Success, the smoke suite + # reports "0 failed", and the job is red anyway. + # Measured: Dockerfile.variant was 42251 B at v1.9.4 (base64 56355, + # fine) and 50034 B at v1.10.1 (base64 66712, truncated to 65536) — + # the cap corresponds to a 49152 B Dockerfile, so the v1.10.0/v1.10.1 + # comment growth crossed it by 882 B. v1.10.0 run 704 and v1.10.1 + # run 707 both died here; in 704 it hid behind a stale clipboard + # assertion. Trimming comments would "fix" it until the next comment. + # These smoke images are built with load: true and thrown away, so the + # attestation has no consumer. The PUBLISHED images are built by raw + # `docker buildx build --push` in run: blocks, which never writes + # $GITHUB_OUTPUT metadata — so this changes nothing about what ships. + provenance: false tags: pi-devbox:smoke build-args: | BASE_IMAGE=${{ env.IMAGE }}:${{ needs.base-decide.outputs.base_tag }} @@ -658,6 +680,28 @@ jobs: platforms: linux/amd64 push: false load: true + # provenance: false is LOAD-BEARING, not hygiene. buildx writes a + # provenance attestation into the metadata it hands back, and that + # metadata embeds the ENTIRE Dockerfile as one base64 "data" field on a + # single line. build-push-action writes the metadata to $GITHUB_OUTPUT + # as a `name<` heredoc, and Gitea's act_runner + # truncates any single line at exactly 65536 chars — so once + # base64(Dockerfile.variant) crosses 64 KiB the closing delimiter is + # cut off and the runner fails the job with + # invalid format delimiter 'ghadelimiter_...' not found before end of file + # and NO failing step: every step reports Success, the smoke suite + # reports "0 failed", and the job is red anyway. + # Measured: Dockerfile.variant was 42251 B at v1.9.4 (base64 56355, + # fine) and 50034 B at v1.10.1 (base64 66712, truncated to 65536) — + # the cap corresponds to a 49152 B Dockerfile, so the v1.10.0/v1.10.1 + # comment growth crossed it by 882 B. v1.10.0 run 704 and v1.10.1 + # run 707 both died here; in 704 it hid behind a stale clipboard + # assertion. Trimming comments would "fix" it until the next comment. + # These smoke images are built with load: true and thrown away, so the + # attestation has no consumer. The PUBLISHED images are built by raw + # `docker buildx build --push` in run: blocks, which never writes + # $GITHUB_OUTPUT metadata — so this changes nothing about what ships. + provenance: false tags: pi-devbox:smoke-studio build-args: | BASE_IMAGE=${{ env.IMAGE }}:${{ needs.base-decide.outputs.base_tag }}