diff --git a/go.mod b/go.mod index aedf0984e762..e56ec39d0b8f 100644 --- a/go.mod +++ b/go.mod @@ -16,7 +16,7 @@ require ( github.com/containerd/platforms v1.0.0-rc.5 github.com/creack/pty v1.1.24 github.com/distribution/reference v0.6.0 - github.com/docker/cli v29.8.1+incompatible + github.com/docker/cli v29.8.2+incompatible github.com/docker/cli-docs-tool v0.11.0 github.com/docker/docker v28.5.2+incompatible github.com/docker/go-units v0.5.0 @@ -28,10 +28,10 @@ require ( github.com/hashicorp/go-cty-funcs v0.0.0-20250818135842-6aab67130928 github.com/hashicorp/hcl/v2 v2.24.0 github.com/in-toto/in-toto-golang v0.11.0 - github.com/moby/buildkit v0.34.0-rc1 + github.com/moby/buildkit v0.34.0-rc2 github.com/moby/moby/api v1.56.0 github.com/moby/moby/client v0.6.0 - github.com/moby/policy-helpers v0.0.0-20260901142052-72f704e6cdb6 + github.com/moby/policy-helpers v0.0.0-20261006174519-bd98f4747414 github.com/moby/sys/atomicwriter v0.1.0 github.com/moby/sys/mountinfo v0.7.2 github.com/morikuni/aec v1.1.0 diff --git a/go.sum b/go.sum index 6356441a74cd..ac1c5700e728 100644 --- a/go.sum +++ b/go.sum @@ -181,8 +181,8 @@ github.com/distribution/reference v0.6.0 h1:0IXCQ5g4/QMHHkarYzh5l+u8T3t73zM5Qvfr github.com/distribution/reference v0.6.0/go.mod h1:BbU0aIcezP1/5jX/8MP0YiH4SdvB5Y4f/wlDRiLyi3E= github.com/dlclark/regexp2 v1.11.0 h1:G/nrcoOa7ZXlpoa/91N3X7mM3r8eIlMBBJZvsz/mxKI= github.com/dlclark/regexp2 v1.11.0/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8= -github.com/docker/cli v29.8.1+incompatible h1:qYL1bCp6cRw2SB1xmLlIOPyV171dilw9W2Jew38vy9c= -github.com/docker/cli v29.8.1+incompatible/go.mod h1:JLrzqnKDaYBop7H2jaqPtU4hHvMKP+vjCwu2uszcLI8= +github.com/docker/cli v29.8.2+incompatible h1:2zgdFuoFst2T80oS42vhKGxkd0JRo305eIEKTsxR7pQ= +github.com/docker/cli v29.8.2+incompatible/go.mod h1:JLrzqnKDaYBop7H2jaqPtU4hHvMKP+vjCwu2uszcLI8= github.com/docker/cli-docs-tool v0.11.0 h1:7d8QARFb7QEobizqxmEM7fOteZEHwH/zWgHQtHZEcfE= github.com/docker/cli-docs-tool v0.11.0/go.mod h1:ma8BKiisUo8D6W05XEYIh3oa1UbgrZhi1nowyKFJa8Q= github.com/docker/distribution v2.8.3+incompatible h1:AtKxIZ36LoNK51+Z6RpzLpddBirtxJnzDrHLEKxTAYk= @@ -397,8 +397,8 @@ github.com/mitchellh/go-wordwrap v1.0.1 h1:TLuKupo69TCn6TQSyGxwI1EblZZEsQ0vMlAFQ github.com/mitchellh/go-wordwrap v1.0.1/go.mod h1:R62XHJLzvMFRBbcrT7m7WgmE1eOyTSsCt+hzestvNj0= github.com/mitchellh/mapstructure v1.5.0 h1:jeMsZIYE/09sWLaz43PL7Gy6RuMjD2eJVyuac5Z2hdY= github.com/mitchellh/mapstructure v1.5.0/go.mod h1:bFUtVrKA4DC2yAKiSyO/QUcy7e+RRV2QTWOzhPopBRo= -github.com/moby/buildkit v0.34.0-rc1 h1:qOTkL8d6+OE0AWcys7TGoKin+GakmPB+xUnA6TV6ITY= -github.com/moby/buildkit v0.34.0-rc1/go.mod h1:lMgrNGaeFwArTsLFFdRps7P81vdAwACPJoRIvLjO5tQ= +github.com/moby/buildkit v0.34.0-rc2 h1:GRqHSi9Bia5l+KiiWqV5BQOzx36I85FMyawI0jQbsMk= +github.com/moby/buildkit v0.34.0-rc2/go.mod h1:e+Za70y2a3nL1U2Y0P8TvhPyKp2Ok2NS+Q4siSArDiM= github.com/moby/docker-image-spec v1.3.1 h1:jMKff3w6PgbfSa69GfNg+zN/XLhfXJGnEx3Nl2EsFP0= github.com/moby/docker-image-spec v1.3.1/go.mod h1:eKmb5VW8vQEh/BAr2yvVNvuiJuY6UIocYsFu/DxxRpo= github.com/moby/go-archive v0.2.0 h1:zg5QDUM2mi0JIM9fdQZWC7U8+2ZfixfTYoHL7rWUcP8= @@ -411,8 +411,8 @@ github.com/moby/moby/client v0.6.0 h1:AJjEB21QPbXSXjDsZorFBoDZPhMrfbpaPLgSMAW9Bg github.com/moby/moby/client v0.6.0/go.mod h1:OCo00wNRyA3m4lmJ228W3JbyCN4ZNNYjpOXiJydBdcQ= github.com/moby/patternmatcher v0.6.1 h1:qlhtafmr6kgMIJjKJMDmMWq7WLkKIo23hsrpR3x084U= github.com/moby/patternmatcher v0.6.1/go.mod h1:hDPoyOpDY7OrrMDLaYoY3hf52gNCR/YOUYxkhApJIxc= -github.com/moby/policy-helpers v0.0.0-20260901142052-72f704e6cdb6 h1:wxmKL9KLJGSNWvWZwkEmhN5RhGpmz+Jzp4Yu4scoM0I= -github.com/moby/policy-helpers v0.0.0-20260901142052-72f704e6cdb6/go.mod h1:hNMdiq4WjSmuyvy8lWcflH6erzSg/MgZlFyM7vC7Z2c= +github.com/moby/policy-helpers v0.0.0-20261006174519-bd98f4747414 h1:gOgxy0eXQlhvC5hB7CE+tJLLzrC9+gjTWlU+Bv5T8Ck= +github.com/moby/policy-helpers v0.0.0-20261006174519-bd98f4747414/go.mod h1:hNMdiq4WjSmuyvy8lWcflH6erzSg/MgZlFyM7vC7Z2c= github.com/moby/spdystream v0.5.1 h1:9sNYeYZUcci9R6/w7KDaFWEWeV4LStVG78Mpyq/Zm/Y= github.com/moby/spdystream v0.5.1/go.mod h1:xBAYlnt/ay+11ShkdFKNAG7LsyK/tmNBVvVOwrfMgdI= github.com/moby/sys/atomicwriter v0.1.0 h1:kw5D/EqkBwsBFi0ss9v1VG3wIkVhzGvLklJ+w3A14Sw= diff --git a/vendor/github.com/moby/buildkit/cmd/buildkitd/config/config.go b/vendor/github.com/moby/buildkit/cmd/buildkitd/config/config.go index b40f955bc8e1..e363b3e1a155 100644 --- a/vendor/github.com/moby/buildkit/cmd/buildkitd/config/config.go +++ b/vendor/github.com/moby/buildkit/cmd/buildkitd/config/config.go @@ -60,14 +60,15 @@ type Config struct { } type CompactionConfig struct { - Enabled bool `toml:"enabled"` - IdleTimeout *Duration `toml:"idleTimeout"` - MaxRetry *int `toml:"maxRetry"` - WritesPerCheck *uint64 `toml:"writesPerCheck"` - SizeWatermark *int64 `toml:"sizeWatermark"` - SizeGrowthPercent *int64 `toml:"sizeGrowthPercent"` - MinReclaimBytes *int64 `toml:"minReclaimBytes"` - MinReclaimPercent *int64 `toml:"minReclaimPercent"` + Enabled bool `toml:"enabled"` + IdleTimeout *Duration `toml:"idleTimeout"` + MaxRetry *int `toml:"maxRetry"` + WritesPerCheck *uint64 `toml:"writesPerCheck"` + SizeWatermark *int64 `toml:"sizeWatermark"` + SizeGrowthPercent *int64 `toml:"sizeGrowthPercent"` + MinReclaimBytes *int64 `toml:"minReclaimBytes"` + MinReclaimPercent *int64 `toml:"minReclaimPercent"` + MinReclaimPercentFloor *int64 `toml:"minReclaimPercentFloor"` } func (c CompactionConfig) Policy() (compaction.Config, error) { @@ -93,6 +94,12 @@ func (c CompactionConfig) Policy() (compaction.Config, error) { } if c.MinReclaimPercent != nil { policy.MinReclaimPercent = *c.MinReclaimPercent + if c.MinReclaimPercentFloor == nil { + policy.MinReclaimPercentFloor = min(policy.MinReclaimPercentFloor, policy.MinReclaimPercent) + } + } + if c.MinReclaimPercentFloor != nil { + policy.MinReclaimPercentFloor = *c.MinReclaimPercentFloor } return policy, policy.Validate() } diff --git a/vendor/github.com/moby/buildkit/exporter/containerimage/exptypes/annotations.go b/vendor/github.com/moby/buildkit/exporter/containerimage/exptypes/annotations.go index a9b74d6b9681..6b77014ccdef 100644 --- a/vendor/github.com/moby/buildkit/exporter/containerimage/exptypes/annotations.go +++ b/vendor/github.com/moby/buildkit/exporter/containerimage/exptypes/annotations.go @@ -103,6 +103,7 @@ func ParseAnnotationKey(result string) (AnnotationKey, bool, error) { if err != nil { return AnnotationKey{}, true, err } + p = platforms.Normalize(p) ociPlatform = &p } diff --git a/vendor/github.com/moby/buildkit/frontend/gateway/grpcclient/client.go b/vendor/github.com/moby/buildkit/frontend/gateway/grpcclient/client.go index 34eeb70909dc..0188e2b22e89 100644 --- a/vendor/github.com/moby/buildkit/frontend/gateway/grpcclient/client.go +++ b/vendor/github.com/moby/buildkit/frontend/gateway/grpcclient/client.go @@ -866,6 +866,9 @@ type messageForwarder struct { mu sync.Mutex pids map[string]*procMessageForwarder stream pb.LLBBridge_ExecProcessClient + // Keep send serialization separate from mu so the receive loop can deliver + // process output while Send is blocked on flow control. + sendMu sync.Mutex // startOnce used to only start the exec message forwarder once, // so we only have one exec stream per client startOnce sync.Once @@ -955,11 +958,13 @@ func debugMessage(msg *pb.ExecMessage) string { func (m *messageForwarder) Send(msg *pb.ExecMessage) error { m.mu.Lock() _, ok := m.pids[msg.ProcessID] - defer m.mu.Unlock() + m.mu.Unlock() if !ok { return errors.Errorf("process %s has ended, not sending message %#v", msg.ProcessID, msg.Input) } bklog.G(m.ctx).Debugf("|---> %s", debugMessage(msg)) + m.sendMu.Lock() + defer m.sendMu.Unlock() return m.stream.Send(msg) } @@ -1180,6 +1185,7 @@ func (ctr *container) Start(ctx context.Context, req client.StartRequest) (clien ctrProc.eg.Go(func() error { var closeDoneOnce sync.Once + defer closeDoneOnce.Do(func() { close(done) }) var exitError error for { msg, ok := msgs.Recv(ctx) diff --git a/vendor/github.com/moby/buildkit/util/db/compact.go b/vendor/github.com/moby/buildkit/util/db/compact.go index 07811b2c5a12..6e51e1a00365 100644 --- a/vendor/github.com/moby/buildkit/util/db/compact.go +++ b/vendor/github.com/moby/buildkit/util/db/compact.go @@ -9,11 +9,12 @@ import ( var ErrCompactionBusy = errors.New("database maintenance in progress") -// CompactOptions controls when a database is compacted. When both reclaim -// thresholds are set, satisfying either threshold permits compaction. +// CompactOptions controls when a database is compacted. The percentage floor +// applies even when the reclaimable byte threshold is met. type CompactOptions struct { - MinReclaimBytes int64 - MinReclaimPercent int64 + MinReclaimBytes int64 + MinReclaimPercent int64 + MinReclaimPercentFloor int64 // MinInterval also throttles failed attempts. MinInterval time.Duration // PauseTimeout bounds draining transactions. Zero selects the default. @@ -25,19 +26,25 @@ type CompactOptions struct { Progress chan<- string } -// MeetsReclaimThreshold reports whether the reclaimable space satisfies at -// least one configured threshold. With no configured thresholds, it returns true. +// MeetsReclaimThreshold reports whether reclaimable space meets the percentage +// floor and at least one configured byte or percentage threshold. func (o CompactOptions) MeetsReclaimThreshold(size, reclaimable int64) bool { + if o.MinReclaimPercentFloor > 0 && !meetsReclaimPercent(size, reclaimable, o.MinReclaimPercentFloor) { + return false + } if o.MinReclaimBytes <= 0 && o.MinReclaimPercent <= 0 { return true } if o.MinReclaimBytes > 0 && reclaimable >= o.MinReclaimBytes { return true } - if o.MinReclaimPercent <= 0 || size <= 0 { + return o.MinReclaimPercent > 0 && meetsReclaimPercent(size, reclaimable, o.MinReclaimPercent) +} + +func meetsReclaimPercent(size, reclaimable, percent int64) bool { + if size <= 0 { return false } - percent := o.MinReclaimPercent return reclaimable >= size/100*percent+(size%100*percent+99)/100 } diff --git a/vendor/github.com/moby/buildkit/util/db/compaction/compaction.go b/vendor/github.com/moby/buildkit/util/db/compaction/compaction.go index 66796dcd7130..d65849118cdb 100644 --- a/vendor/github.com/moby/buildkit/util/db/compaction/compaction.go +++ b/vendor/github.com/moby/buildkit/util/db/compaction/compaction.go @@ -29,31 +29,33 @@ var ( ) type Config struct { - ManualOnly bool - WritesPerCheck uint64 - SizeWatermark int64 - SizeGrowthPercent int64 - MinReclaimBytes int64 - IdleTimeout time.Duration - MaxRetry int - MinReclaimPercent int64 - Metrics *Metrics `json:"-"` + ManualOnly bool + WritesPerCheck uint64 + SizeWatermark int64 + SizeGrowthPercent int64 + MinReclaimBytes int64 + IdleTimeout time.Duration + MaxRetry int + MinReclaimPercent int64 + MinReclaimPercentFloor int64 + Metrics *Metrics `json:"-"` } func DefaultConfig() Config { return Config{ - WritesPerCheck: 10000, - SizeWatermark: 128 << 20, - SizeGrowthPercent: 100, - MinReclaimBytes: 256 << 20, - IdleTimeout: time.Minute, - MaxRetry: 3, - MinReclaimPercent: 25, + WritesPerCheck: 10000, + SizeWatermark: 128 << 20, + SizeGrowthPercent: 100, + MinReclaimBytes: 256 << 20, + IdleTimeout: time.Minute, + MaxRetry: 3, + MinReclaimPercent: 30, + MinReclaimPercentFloor: 10, } } func (c Config) Validate() error { - if c.WritesPerCheck == 0 || c.SizeWatermark <= 0 || c.SizeGrowthPercent <= 0 || c.MinReclaimBytes <= 0 || c.IdleTimeout <= 0 || c.MaxRetry < 0 || c.MinReclaimPercent <= 0 || c.MinReclaimPercent > 100 { + if c.WritesPerCheck == 0 || c.SizeWatermark <= 0 || c.SizeGrowthPercent <= 0 || c.MinReclaimBytes <= 0 || c.IdleTimeout <= 0 || c.MaxRetry < 0 || c.MinReclaimPercent <= 0 || c.MinReclaimPercent > 100 || c.MinReclaimPercentFloor <= 0 || c.MinReclaimPercentFloor > c.MinReclaimPercent { return errors.New("invalid database compaction policy") } return nil @@ -289,7 +291,7 @@ func (s *Scheduler) check() { } return } - opt := db.CompactOptions{MinReclaimBytes: s.config.MinReclaimBytes, MinReclaimPercent: s.config.MinReclaimPercent} + opt := db.CompactOptions{MinReclaimBytes: s.config.MinReclaimBytes, MinReclaimPercent: s.config.MinReclaimPercent, MinReclaimPercentFloor: s.config.MinReclaimPercentFloor} sizeReached := stats.Size >= watermark writesReached := fullCheck && stats.Size >= s.config.SizeWatermark pending := (sizeReached || writesReached) && opt.MeetsReclaimThreshold(stats.Size, stats.Reclaimable) @@ -324,7 +326,7 @@ func (s *Scheduler) compact() { s.metrics.wait(false, false) writes := s.state.Writes s.mu.Unlock() - res, err := s.backend.Compact(ctx, db.CompactOptions{MinReclaimBytes: s.config.MinReclaimBytes, MinReclaimPercent: s.config.MinReclaimPercent}) + res, err := s.backend.Compact(ctx, db.CompactOptions{MinReclaimBytes: s.config.MinReclaimBytes, MinReclaimPercent: s.config.MinReclaimPercent, MinReclaimPercentFloor: s.config.MinReclaimPercentFloor}) cause := context.Cause(ctx) cancel(context.Canceled) <-capacity diff --git a/vendor/github.com/moby/buildkit/util/db/compaction/request.go b/vendor/github.com/moby/buildkit/util/db/compaction/request.go index c5ff271eba3a..b05964728725 100644 --- a/vendor/github.com/moby/buildkit/util/db/compaction/request.go +++ b/vendor/github.com/moby/buildkit/util/db/compaction/request.go @@ -101,7 +101,7 @@ func (s *Scheduler) runRequest(r *Request, checkpoint <-chan time.Time) { s.metrics.wait(true, false) writes := s.state.Writes s.mu.Unlock() - result, err := s.backend.Compact(ctx, db.CompactOptions{MinReclaimBytes: s.config.MinReclaimBytes, MinReclaimPercent: s.config.MinReclaimPercent, Progress: r.events}) + result, err := s.backend.Compact(ctx, db.CompactOptions{MinReclaimBytes: s.config.MinReclaimBytes, MinReclaimPercent: s.config.MinReclaimPercent, MinReclaimPercentFloor: s.config.MinReclaimPercentFloor, Progress: r.events}) cause := context.Cause(ctx) <-capacity outcome.Result = result diff --git a/vendor/github.com/moby/policy-helpers/docker-bake.hcl b/vendor/github.com/moby/policy-helpers/docker-bake.hcl index dd65814b8869..4e67dd3395e2 100644 --- a/vendor/github.com/moby/policy-helpers/docker-bake.hcl +++ b/vendor/github.com/moby/policy-helpers/docker-bake.hcl @@ -2,7 +2,7 @@ variable "ROOT_SIGNING_VERSION" { type = string # default = "8842feefbb65effea46ff4a0f2b6aad91e685fe9" # expired root # default = "9d8b5c5e3bed603c80b57fcc316b7a1af688c57e" # expired timestamp - default = "e3399e7e6f2c3f4039aa2464f95f7d8fcf57910c" + default = "63134820c97beb38a82a7d34221f4c3db8215df5" description = "The git commit hash of sigstore/root-signing to use for embedded roots." } diff --git a/vendor/github.com/moby/policy-helpers/image/dhi.go b/vendor/github.com/moby/policy-helpers/image/dhi.go index 87c34531ca0e..83ee2cc2fe85 100644 --- a/vendor/github.com/moby/policy-helpers/image/dhi.go +++ b/vendor/github.com/moby/policy-helpers/image/dhi.go @@ -18,7 +18,7 @@ func isDHIIndex(idx ocispecs.Index) bool { return false } } - return strings.HasPrefix(idx.Annotations["org.opencontainers.image.title"], "dhi/") + return strings.HasPrefix(idx.Annotations[ocispecs.AnnotationTitle], "dhi/") } func contextWithDHI(ctx context.Context) context.Context { diff --git a/vendor/github.com/moby/policy-helpers/roots/tuf-root/timestamp.json b/vendor/github.com/moby/policy-helpers/roots/tuf-root/timestamp.json index 311706bd26ae..29dcb9ec6ccc 100644 --- a/vendor/github.com/moby/policy-helpers/roots/tuf-root/timestamp.json +++ b/vendor/github.com/moby/policy-helpers/roots/tuf-root/timestamp.json @@ -2,18 +2,18 @@ "signatures": [ { "keyid": "0c87432c3bf09fd99189fdc32fa5eaedf4e4a5fac7bab73fa04a2e0fc64af6f5", - "sig": "30440220665a1db2a64a732d602c8b7bcf70550b252ca758b912e4bea730208bcec0d55402204624a80305487a0a089e0665ddf234bad9bbb2548ac19e8212686a1bf8e67011" + "sig": "3044022010046c0182b6e0b8e98394a93f5f44b62eff74fb403f032a245f451492df248b02205a7b7b3da669b75f3187b661f9e2fc39bc1e26e9e981f275ee2b215b2d373458" } ], "signed": { "_type": "timestamp", - "expires": "2026-09-07T19:20:59Z", + "expires": "2026-10-12T19:27:44Z", "meta": { "snapshot.json": { "version": 165 } }, "spec_version": "1.0", - "version": 771 + "version": 800 } } \ No newline at end of file diff --git a/vendor/modules.txt b/vendor/modules.txt index 256487386420..cb1a62556dfd 100644 --- a/vendor/modules.txt +++ b/vendor/modules.txt @@ -302,7 +302,7 @@ github.com/digitorus/timestamp # github.com/distribution/reference v0.6.0 ## explicit; go 1.20 github.com/distribution/reference -# github.com/docker/cli v29.8.1+incompatible +# github.com/docker/cli v29.8.2+incompatible ## explicit github.com/docker/cli/cli github.com/docker/cli/cli-plugins/metadata @@ -649,7 +649,7 @@ github.com/mattn/go-shellwords # github.com/mitchellh/go-wordwrap v1.0.1 ## explicit; go 1.14 github.com/mitchellh/go-wordwrap -# github.com/moby/buildkit v0.34.0-rc1 +# github.com/moby/buildkit v0.34.0-rc2 ## explicit; go 1.26.8 github.com/moby/buildkit/api/services/control github.com/moby/buildkit/api/types @@ -797,7 +797,7 @@ github.com/moby/moby/client/pkg/versions ## explicit; go 1.19 github.com/moby/patternmatcher github.com/moby/patternmatcher/ignorefile -# github.com/moby/policy-helpers v0.0.0-20260901142052-72f704e6cdb6 +# github.com/moby/policy-helpers v0.0.0-20261006174519-bd98f4747414 ## explicit; go 1.25.8 github.com/moby/policy-helpers github.com/moby/policy-helpers/image