You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The coherent native release pipeline added by #85 cannot publish its required multi-architecture manager image on an AMD64 release host. Dockerfile.leash executes the build-host tool installation below independently for each target platform:
RUN go install github.com/cilium/ebpf/cmd/bpf2go@v0.19.0
RUN go generate ./internal/lsm
For linux/arm64, Buildx therefore runs the Go toolchain through QEMU. The go install bpf2go step does not complete within the release command's 10-minute operational cap, even after the OS/toolchain/dependency layers have been warmed across repeated attempts.
ARM64 binfmt verified with alpine:3.21 uname -m returning aarch64
AMD64 manager completes all nine build steps
ARM64 completes base setup, go mod download, and UI-prebuilt selection
ARM64 then remains at RUN go install github.com/cilium/ebpf/cmd/bpf2go@v0.19.0 until the command exits 124
three capped attempts retained 5.68 GB of BuildKit cache but never completed that layer
after every attempt, ghcr.io/sixtoad/leash-manager:native-v0.3.4, Git tag native-v0.3.4, and GitHub release native-v0.3.4 were absent
No credential or Walk workload was involved.
Expected
Release-only build tools execute on the native build platform or are reused as pre-generated artifacts. Producing the ARM64 target must not require emulating the Go compiler merely to install/run bpf2go.
Acceptance
build-time code generation runs once on $BUILDPLATFORM or consumes preservation-checked generated BPF artifacts
the resulting ARM64 manager binary and BPF assets remain functionally identical and carry the exact release revision/contract labels
a cold or bounded-cache AMD64-hosted linux/amd64,linux/arm64 manager build completes within 10 minutes
Defect
The coherent native release pipeline added by #85 cannot publish its required multi-architecture manager image on an AMD64 release host.
Dockerfile.leashexecutes the build-host tool installation below independently for each target platform:For
linux/arm64, Buildx therefore runs the Go toolchain through QEMU. Thego install bpf2gostep does not complete within the release command's 10-minute operational cap, even after the OS/toolchain/dependency layers have been warmed across repeated attempts.Exact evidence
walk-integrationcommit154d4cfd90146d6dc27da48acd48f8da9b0ab76bnative-v0.3.4linux/amd64,linux/arm64alpine:3.21 uname -mreturningaarch64go mod download, and UI-prebuilt selectionRUN go install github.com/cilium/ebpf/cmd/bpf2go@v0.19.0until the command exits 124ghcr.io/sixtoad/leash-manager:native-v0.3.4, Git tagnative-v0.3.4, and GitHub releasenative-v0.3.4were absentNo credential or Walk workload was involved.
Expected
Release-only build tools execute on the native build platform or are reused as pre-generated artifacts. Producing the ARM64 target must not require emulating the Go compiler merely to install/run
bpf2go.Acceptance
$BUILDPLATFORMor consumes preservation-checked generated BPF artifactslinux/amd64,linux/arm64manager build completes within 10 minutesscripts/release.sh native-v0.3.4can complete without changing or deleting an existing immutable tagBlocks publishing
native-v0.3.4and resuming the Leash #78 Walk/BME/Codex ACP dogfood.