provenance: record request provenance for LLB refs#6739
Open
tonistiigi wants to merge 2 commits intomoby:masterfrom
Open
provenance: record request provenance for LLB refs#6739tonistiigi wants to merge 2 commits intomoby:masterfrom
tonistiigi wants to merge 2 commits intomoby:masterfrom
Conversation
Keep request provenance for solved refs by their LLB digest while the producing build is still active. Use the stored request when another solve later provides the same LLB definition as a frontend input. This lets max provenance report root and nested input requests for gateway and builtin Dockerfile frontend solves without accepting client-supplied request metadata. Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
1c9bfc3 to
e39bdc1
Compare
crazy-max
reviewed
May 5, 2026
Apply min provenance request scrubbing recursively to named inputs and root requests so nested build args and labels do not leak into explicit min provenance. Keep non-sensitive input request metadata and mark request completeness incomplete only when scrubbed args are omitted. Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
f8ab930 to
d532333
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Keep request provenance for solved refs by their LLB digest while the producing build is still active. Use the stored request when another solve later provides the same LLB definition as a frontend input.
This lets max provenance report root and nested input requests for gateway and builtin Dockerfile frontend solves without accepting client-supplied request metadata.