On Tue, Aug 04, 2026 at 12:54:14PM -0400, Stefan Hajnoczi wrote: > QEMU's CI pipeline involves building container images that will be used > to run builds and tests. A recent Docker change triggered the following > error: > > $ docker push "$TAG" > ... > error from registry: blob unknown to registry - sha256:4401f6f779caf8841cafd5f483e642fcac56a23a4e4a59523231e101c890dad9 > > https://gitlab.com/qemu-project/qemu/-/jobs/15701875927#L2372 > > This happens because Docker now pushes out-of-order and the GitLab > Container Registry rejects due to an unknown reference: > https://forum.gitlab.com/t/started-yesterday-docker-push-error-from-registry-blob-unknown-to-registry/134733/5 > > It is unclear at this point whether GitLab will modify the behavior of > Container Registry or whether Docker will ship a fix. > > The current workaround is to disable the provenance attestation that is > involved in this issue. QEMU's CI pipeline container images are used > internally for testing and are not widely distributed. Provenance > attestation can be disabled as there are no external consumers of these > images. Expect to revert this commit in the future when GitLab or Docker > have released their own fixes. > > Cc: Alex Bennée > Cc: Daniel P. Berrangé > Cc: Thomas Huth > Signed-off-by: Stefan Hajnoczi > --- > Note that this is an urgent patch so that the CI will pass again and I > can tag v11.1.0-rc3 later today. Currently it is failing due to this > issue! > > .gitlab-ci.d/container-template.yml | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) Thanks, applied to my staging tree: https://gitlab.com/stefanha/qemu/commits/staging Stefan