Skip to content

[BugFix][CI] Build with oci-mediatypes=false to produce Docker manifest list for SWR - #16130

Merged
wangxiyuan merged 3 commits into
vllm-project:mainfrom
JavaPythonAIForBAT:fix/oci-manifest-format
Sep 10, 2026
Merged

wangxiyuan merged 3 commits into
vllm-project:mainfrom
JavaPythonAIForBAT:fix/oci-manifest-format

Conversation

@JavaPythonAIForBAT

@JavaPythonAIForBAT JavaPythonAIForBAT commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

What this PR does / why we need it?

SWR rejects OCI image index (application/vnd.oci.image.index.v1+json) produced by docker buildx imagetools create when merging OCI-format single-arch images, returning 400 Bad Request: Invalid image, fail to parse 'manifest.json'.

Root cause: docker buildx imagetools create selects the output media type based on the source manifests. When all sources are Docker v2 schema2 (application/vnd.docker.*), it produces a Docker manifest list (application/vnd.docker.distribution.manifest.list.v2+json) which SWR accepts. With OCI sources it produces an OCI image index, which SWR rejects.

Fix: add oci-mediatypes=false to the build output so single-arch images are built as Docker v2 schema2. This lets docker buildx imagetools create produce a Docker manifest list directly, and eliminates the skopeo-based format conversion entirely (which required sudo/root not available on the self-hosted runner).

Changes

  • Build output: add oci-mediatypes=false
  • build-push-digest "Tag digest to prevent GC": replace skopeo copy with docker buildx imagetools create
  • merge-image: replace skopeo copy + docker manifest create/push with direct docker buildx imagetools create
  • merge-image-temp: same as merge-image
  • "Clean up temp tags" (both jobs): remove sudo apt-get install skopeo; guard skopeo delete with a command -v check so the job no longer fails when skopeo is unavailable

Does this PR introduce any user-facing change?

No. Only the CI image build/push workflow is changed.

How was this patch tested?

  • CI workflow changes verified locally (YAML valid, job structure intact)

  • No skopeo/sudo/apt-get dependencies remain in the merge path, so the previous skopeo: command not found failure on the self-hosted (non-root, no-sudo) runner is eliminated

  • vLLM main: vllm-project/vllm@b2f6858

@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

This pull request has conflicts, please resolve those before we can evaluate the pull request.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Note

Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported.

@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

👋 Hi! Thank you for contributing to the vLLM Ascend project. The following points will speed up your PR merge:‌‌

  • A PR should do only one thing, smaller PRs enable faster reviews.
  • Every PR should include unit tests and end-to-end tests ‌to ensure it works and is not broken by other future PRs.
  • Write the commit message by fulfilling the PR description to help reviewer and future developers understand.

If CI fails, you can run linting and testing checks locally according Contributing and Testing.


Tip

💡 Consider Linking a Related Issue or RFC

Your PR title contains the [BugFix] tag, indicating a bug fix or new feature.

Linking a related issue or RFC in the PR description is strongly encouraged — it gives reviewers helpful context and speeds up the review. You can use any of these keywords:

  • Fixes #<issue_number>
  • Closes #<issue_number>
  • Resolves #<issue_number>
  • Refs #<rfc_or_issue_number> (for RFCs)

🙏 Thanks for helping us keep the project well-organized!

…ist for SWR

SWR rejects OCI image index (application/vnd.oci.image.index.v1+json)
produced by 'docker buildx imagetools create' when combining OCI-format
single-arch images, returning 400 Bad Request 'Invalid image, fail to
parse manifest.json'.

Root cause: buildx imagetools create selects output media type based on
source manifests. When all sources are Docker v2 schema2, it produces
a Docker manifest list (application/vnd.docker.distribution.manifest.list.v2+json)
which SWR accepts. With OCI sources, it produces OCI image index which
SWR rejects.

Fix: add oci-mediatypes=false to the build output, so single-arch images
are built as Docker v2 schema2. This allows docker buildx imagetools create
to produce a Docker manifest list directly, eliminating the need for
skopeo-based format conversion (which required sudo/root not available
on the self-hosted runner).

Changes:
- Build output: add oci-mediatypes=false
- build-push-digest 'Tag digest to prevent GC': replace skopeo copy with
  docker buildx imagetools create
- merge-image: replace skopeo copy + docker manifest create/push with
  direct docker buildx imagetools create
- merge-image-temp: same as merge-image
- All 'Clean up temp tags': remove sudo apt-get install skopeo, guard
  skopeo delete with command -v check (no hard failure if unavailable)

Signed-off-by: JavaPythonAIForBAT <wuhejun@h-partners.com>
The schedule_tag_pattern was hardcoded to 'main' in the parent
workflow (schedule_image_build_and_push.yaml:161), so the final
image tag was always 'nightly-main-<suffix>-<digest>' regardless
of the branch/tag passed via workflow_dispatch.

Add a 'Prepare tag pattern' step in all three jobs (build-push-digest,
merge-image, merge-image-temp) that dynamically computes the pattern:
- Push tag / schedule events: use schedule_tag_pattern default ('main')
- workflow_dispatch with tag: use the tag itself
- workflow_dispatch with branch: use branch_ref with '/' replaced by '-'

All references to inputs.schedule_tag_pattern in tag generation,
Docker meta, GC temp tags, and cleanup are updated to use the
dynamic steps.tag_pattern.outputs.pattern.

Signed-off-by: JavaPythonAIForBAT <wuhejun@h-partners.com>
When a pull_request with the image-build label runs the image build,
image_build succeeds (build without push), which incorrectly triggers
the trigger-image-sync job to dispatch the quay.io sync.

Add github.event_name != 'pull_request' so sync only fires for non-PR
events (push tag, branch/main push, workflow_dispatch, schedule),
matching the intended behavior of syncing only after merge to main.

Signed-off-by: JavaPythonAIForBAT <wuhejun@h-partners.com>
@wangxiyuan
wangxiyuan merged commit bdab8bd into vllm-project:main Sep 10, 2026
13 checks passed
JavaPythonAIForBAT added a commit to JavaPythonAIForBAT/vllm-ascend that referenced this pull request Sep 10, 2026
… SWR compatibility

Replace the skopeo workaround (skopeo copy --format v2s2 + docker manifest
create/push) with the proper fix: add oci-mediatypes=false to build output
so docker buildx imagetools create produces a Docker manifest list instead
of an OCI image index, which is accepted by SWR.

Changes:
- Add oci-mediatypes=false to build output
- Replace all skopeo copy + docker manifest create/push with
  docker buildx imagetools create in merge and temp tag steps
- Guard skopeo delete in cleanup with command -v check (no sudo needed)

This is the same fix as PR vllm-project#16130.

Signed-off-by: JavaPythonAIForBAT <wuhejun@h-partners.com>
sunny-rain-63 pushed a commit to sunny-rain-63/vllm-ascend that referenced this pull request Sep 12, 2026
…st list for SWR (vllm-project#16130)

## What this PR does / why we need it?

SWR rejects OCI image index (`application/vnd.oci.image.index.v1+json`)
produced by `docker buildx imagetools create` when merging OCI-format
single-arch images, returning `400 Bad Request: Invalid image, fail to
parse 'manifest.json'`.

**Root cause**: `docker buildx imagetools create` selects the output
media type based on the source manifests. When all sources are Docker v2
schema2 (`application/vnd.docker.*`), it produces a **Docker manifest
list** (`application/vnd.docker.distribution.manifest.list.v2+json`)
which SWR accepts. With OCI sources it produces an OCI image index,
which SWR rejects.

**Fix**: add `oci-mediatypes=false` to the build output so single-arch
images are built as Docker v2 schema2. This lets `docker buildx
imagetools create` produce a Docker manifest list directly, and
eliminates the skopeo-based format conversion entirely (which required
`sudo`/root not available on the self-hosted runner).

### Changes
- **Build output**: add `oci-mediatypes=false`
- **build-push-digest "Tag digest to prevent GC"**: replace `skopeo
copy` with `docker buildx imagetools create`
- **merge-image**: replace `skopeo copy` + `docker manifest create/push`
with direct `docker buildx imagetools create`
- **merge-image-temp**: same as merge-image
- **"Clean up temp tags"** (both jobs): remove `sudo apt-get install
skopeo`; guard `skopeo delete` with a `command -v` check so the job no
longer fails when skopeo is unavailable

## Does this PR introduce any user-facing change?

No. Only the CI image build/push workflow is changed.

## How was this patch tested?

- CI workflow changes verified locally (YAML valid, job structure
intact)
- No skopeo/sudo/apt-get dependencies remain in the merge path, so the
previous `skopeo: command not found` failure on the self-hosted
(non-root, no-sudo) runner is eliminated

- vLLM main:
vllm-project/vllm@b2f6858

---------

Signed-off-by: JavaPythonAIForBAT <wuhejun@h-partners.com>
johnnysluckydays pushed a commit to johnnysluckydays/vllm-ascend that referenced this pull request Sep 14, 2026
…st list for SWR (vllm-project#16130)

## What this PR does / why we need it?

SWR rejects OCI image index (`application/vnd.oci.image.index.v1+json`)
produced by `docker buildx imagetools create` when merging OCI-format
single-arch images, returning `400 Bad Request: Invalid image, fail to
parse 'manifest.json'`.

**Root cause**: `docker buildx imagetools create` selects the output
media type based on the source manifests. When all sources are Docker v2
schema2 (`application/vnd.docker.*`), it produces a **Docker manifest
list** (`application/vnd.docker.distribution.manifest.list.v2+json`)
which SWR accepts. With OCI sources it produces an OCI image index,
which SWR rejects.

**Fix**: add `oci-mediatypes=false` to the build output so single-arch
images are built as Docker v2 schema2. This lets `docker buildx
imagetools create` produce a Docker manifest list directly, and
eliminates the skopeo-based format conversion entirely (which required
`sudo`/root not available on the self-hosted runner).

### Changes
- **Build output**: add `oci-mediatypes=false`
- **build-push-digest "Tag digest to prevent GC"**: replace `skopeo
copy` with `docker buildx imagetools create`
- **merge-image**: replace `skopeo copy` + `docker manifest create/push`
with direct `docker buildx imagetools create`
- **merge-image-temp**: same as merge-image
- **"Clean up temp tags"** (both jobs): remove `sudo apt-get install
skopeo`; guard `skopeo delete` with a `command -v` check so the job no
longer fails when skopeo is unavailable

## Does this PR introduce any user-facing change?

No. Only the CI image build/push workflow is changed.

## How was this patch tested?

- CI workflow changes verified locally (YAML valid, job structure
intact)
- No skopeo/sudo/apt-get dependencies remain in the merge path, so the
previous `skopeo: command not found` failure on the self-hosted
(non-root, no-sudo) runner is eliminated

- vLLM main:
vllm-project/vllm@b2f6858

---------

Signed-off-by: JavaPythonAIForBAT <wuhejun@h-partners.com>
Signed-off-by: tianming2009 <13246728590@163.com>
like-0517 pushed a commit to like-0517/vllm-ascend that referenced this pull request Sep 15, 2026
…st list for SWR (vllm-project#16130)

## What this PR does / why we need it?

SWR rejects OCI image index (`application/vnd.oci.image.index.v1+json`)
produced by `docker buildx imagetools create` when merging OCI-format
single-arch images, returning `400 Bad Request: Invalid image, fail to
parse 'manifest.json'`.

**Root cause**: `docker buildx imagetools create` selects the output
media type based on the source manifests. When all sources are Docker v2
schema2 (`application/vnd.docker.*`), it produces a **Docker manifest
list** (`application/vnd.docker.distribution.manifest.list.v2+json`)
which SWR accepts. With OCI sources it produces an OCI image index,
which SWR rejects.

**Fix**: add `oci-mediatypes=false` to the build output so single-arch
images are built as Docker v2 schema2. This lets `docker buildx
imagetools create` produce a Docker manifest list directly, and
eliminates the skopeo-based format conversion entirely (which required
`sudo`/root not available on the self-hosted runner).

### Changes
- **Build output**: add `oci-mediatypes=false`
- **build-push-digest "Tag digest to prevent GC"**: replace `skopeo
copy` with `docker buildx imagetools create`
- **merge-image**: replace `skopeo copy` + `docker manifest create/push`
with direct `docker buildx imagetools create`
- **merge-image-temp**: same as merge-image
- **"Clean up temp tags"** (both jobs): remove `sudo apt-get install
skopeo`; guard `skopeo delete` with a `command -v` check so the job no
longer fails when skopeo is unavailable

## Does this PR introduce any user-facing change?

No. Only the CI image build/push workflow is changed.

## How was this patch tested?

- CI workflow changes verified locally (YAML valid, job structure
intact)
- No skopeo/sudo/apt-get dependencies remain in the merge path, so the
previous `skopeo: command not found` failure on the self-hosted
(non-root, no-sudo) runner is eliminated

- vLLM main:
vllm-project/vllm@b2f6858

---------

Signed-off-by: JavaPythonAIForBAT <wuhejun@h-partners.com>
Signed-off-by: like-0517 <ithwlike@126.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants