ng the registryRequire HTTPS and verify certificates when accessing the registryFailed to parse the authentication scope from the given challenge... started an upload instead of mounting, trying to cancel at %sTrying to reuse blob with cached digest %s in destination repo %sFailed to call additional-layer-store-auth-helper (stderr:%s): %vInvalid docker-archive: reference: index @%d must not be negative Use "%s [command] --help" for more information about a command.Unable to support both decryption and encryption in the same copyinvalid algorithm %q in option.EnsureCompressionVariantsExist: %wRemove the cached credentials for all registries in the auth fileadditional layer for TOCDigest %q reports unexpected TOCDigest %qTOC digest %q for layer %q is present but %q flag is not a stringThe blob upload encountered an error and can no longer proceed.user arena chunk size is not a multiple of the physical page sizeruntime: function marked with #cgo nocallback called back into Goruntime.SetFinalizer: pointer not at beginning of allocated blockInternal error: neither src nor configBlob set in manifestSchema2Internal error: Uploaded empty layer has digest %#v instead of %sapplication/vnd.oci.image.layer.nondistributable.v1.tar+encryptedhttp: response.WriteHeader on hijacked connection from %s (%s:%d)net/http: Transport.DialTLS or DialTLSContext returned (nil, nil)tls: internal error: attempted to read record with QUIC transporttls: server selected an invalid version after a HelloRetryRequesttls: session supported extended_master_secret but client does nottls: second client hello missing encrypted client hello extensionChown error detected. Ignoring due to ignoreChownErrors flag: %v reflect: StructOf does not support methods of embedded interfacesreference %s can’t be signed, it has neither a tag nor a digestx509: policy constraints inhibitPolicyMapping field overflows intx509: inner and outer signature algorithm identifiers don't matchx509: issuer name does not match subject from issuing certificateUncompressed digest for blob %s previously recorded as %s, now %sunexpected literal count, want %d bytes, but only %d is availablecan't retrieve digest of image big data value with empty name: %wcrypto/des: use of TripleDES is not allowed in FIPS 140-only modecryptobyte: high-tag number identifier octets not supported: 0x%xcryptobyte: pending child length %d exceeds %d-byte length prefixgo-jose/go-jose: invalid signature size, have %d bytes, wanted %dgo-jose/go-jose: invalid Ed25519 private key, missing %s value(s)nistec: internal error: p224Table called with out-of-bounds valuenistec: internal error: p384Table called with out-of-bounds valuenistec: internal error: p521Table called with out-of-bounds valuevarint,1052,rep,name=field_behavior,enum=google.api.FieldBehavioroidc: id token issued by a different provider, expected %q got %qkernel too old to provide multiple lowers feature for overlay: %wbinarylogging: message to log is neither proto.message nor []bytefindFieldInfo: error building index when looking for field %d: %vfailed to recreate missing backingFsBlockDev %s for projid %d: %w--encryption-key and --decryption-key cannot be specified togetherdocker-archive reference %s isn't of the form [:]Treating manifest lists as individual manifests is not implementedgetting registry from registry.conf, please specify a registry: %wsync: WaitGroup.Add called from inside and outside synctest bubbleinternal error: attempted to parse unknown event (please report): There was an error processing the upload and it must be restarted.runtime: unexpected error while checking standard file descriptor casGToWaitingForSuspendG with non-isWaitingForSuspendG wait reasonsender tried to send more than declared Content-Length of %d bytestls: certificate private key (%T) does not implement crypto.Signerclient doesn't support ECDHE, can only use legacy RSA key exchangetls: server sent an unexpected quic_transport_parameters extensiontls: client sent an unexpected quic_transport_parameters extensionreflect: indirection through nil pointer to embedded struct field x509: policy constraints requireExplicitPolicy field overflows intx509: certificate is not valid for any names, but wanted to match x509: requested SignatureAlgorithm does not match private key typeSELECT 1 FROM DigestUncompressedPairs WHERE uncompressedDigest = ?internal error: expected cumul[s.symbolLen] (%d) == tableSize (%d)While recovering from a failure (%s), error deleting layer %#v: %vexpected end of table array name delimiter ']', but got %q insteadattempted to update last-writer in lockfile without the write lockgo-jose/go-jose: invalid JWK, x5t#S256 header has invalid encodinggo-jose/go-jose: invalid JWK, x5t#S256 header is of incorrect size%w: trying to pop component %q but the last stack entry is %s (%q)[bug] non-empty remaining path when doing a non-partial lookup: %qgrpc: credentials.Bundle must return non-nil transport credentialspkcs7: failed unmarshaling key encryption algorithm parameters: %vECDH-ES output size too large, must be less than or equal to 1<<16overlay: additionallayerstore config %q contains unknown option %qmetadata: Pairs got the odd number of input pairs for metadata: %dDescriptor.Options called without importing the descriptor packageList tags in the transport/repository specified by the SOURCE-IMAGEinternal error: PutBlobPartial is not supported by the %q transportInternal error: newImageSource returned without trying any endpointInvalid path %q: paths including the separator %q are not supportedHelp provides help for any command in the application. Simply type destination does not support any supported manifest list types (%v)Uploading manifest list failed, attempted the following formats: %sError preparing updated manifest: layer count changed from %d to %dInvalid image name %q, expected colon-separated transport:referenceno registries found in registries.conf, a registry must be providedimage with ID %q already exists, but uses a different top layer: %wtls: server sent certificate containing RSA key larger than %d bitstls: client sent certificate containing RSA key larger than %d bitsLooking up in credential helper %s based on credHelpers entry in %sfound Pkcs11Blob with version %d but maximum supported version is 0crypto/cipher: invalid buffer overlap of output and additional dataincompatible types: TOML value has type %s; destination has type %sattempted to check last-writer in lockfile without locking it first%q requires API version %s, but the Docker daemon API version is %sgo-jose/go-jose: too many recipients in payload; expecting only onego-jose/go-jose: too many signatures in payload; expecting only oneIgnoring BlobInfoCache record of digest %q with unknown compressioninvalid logger type passed, must be Logger or LeveledLogger, was %TServer retry pushback specified multiple values (%q); not retrying.oidc: internal error, payload parsed did not match previous payload'overlay' is not supported over %s, a mount_program is required: %woverlay: additionallayerstore config of %q contains %q option twicetransport: cannot send secure credentials on an insecure connectiondelegating_resolver: unable to build the resolver for target %s: %vinvalid field: %v: unsupported type for opaque repeated message: %vfield %v with invalid Mutable call on field with non-composite typeHow to handle multi-architecture images (system, all, or index-only)Sync failed due to previous reported error(s) for one or more imagesReading blob body from %s failed (%v), reconnecting after %.3f ms…Too many requests to %s: sleeping for %f seconds before next attemptInvalid docker-archive: reference: colon in path %q is not supportedFailed to find flag %q and mark it as being required in a flag grouplayer %s should be decrypted, but we can’t modify the manifest: %slayer %s should be encrypted, but we can’t modify the manifest: %sinternal error: VerifySigstorePayload succeeded but returned no dataexpected SCALAR, SEQUENCE-START, MAPPING-START, or ALIAS, but got %vThe `Content-Length` header must be zero and the body must be empty.<?n=&last=>; rel="next"The upload is unknown to the registry. The upload must be restarted.can not look up shorthand which is more than one ASCII character: %qAllThreadsSyscall6 results differ between threads; runtime corruptedrejecting ambiguous manifest, unexpected fields %#v in supposedly %sOCI1Index.EditInstances: Modified digest %s is an invalid digest: %wno image found in image index for architecture %q, variant %q, OS %qpreparing to decrypt before conversion: %d layers vs. %d layer editspadding bytes must all be zeros unless AllowIllegalWrites is enabledhttp2: Transport conn %p received error from processing frame %v: %vhttp2: Transport received unsolicited DATA frame; closing connectionhttp: message cannot contain multiple Content-Length headers; got %qtls: internal error: sending non-handshake message to QUIC transportcrypto/hmac: hash generation function does not produce unique valuesdocker tarfile: input with unknown size, streaming to disk first ...Failed to map UID %v to the target mapping, using the overflow ID %vFailed to map GID %v to the target mapping, using the overflow ID %vreflect: reflect.Value.UnsafePointer on an invalid notinheap pointercrypto/rsa: only crypto/rand.Reader is allowed in FIPS 140-only mode2695994666715063979466701508701963067355791626002630814351006629888126959946667150639794667015087019625940457807714424391721682722368061Compressor for blob with digest %s previously recorded as %s, now %sembedded IPv4 address must replace the final 2 fields of the addressz.currentBuffer too large (most likely due to concurrent Write race)while cleaning up partially-created image %q we failed to create: %vbig: invalid 2nd argument to Int.Jacobi: need odd integer but got %sSignature: need to call Sign, SignUserId or SignKey before Serialize%v. * Are you trying to connect to a TLS-enabled daemon without TLS?go-jose/go-jose: invalid SHA-1 thumbprint (must be %d bytes, not %d)go-jose/go-jose: invalid SHA-1 thumbprint, does not match cert chaininvalid retry throttling config: tokenRatio (%v) may not be negativeIgnoring global metacopy option, not supported with booted kernel %sexpected a JSON struct with one entry; received entry %v at index %ddelegating_resolver: failed to determine proxy URL for target %s: %vinvalid descriptor: using edition features in a proto with syntax %sextension %v does not implement protoreflect.ExtensionTypeDescriptorcustom type: type: %v, does not implement the proto.custom interfaceError writing OCI-formatted configuration data to standard output: %wUsage: skopeo untrusted-signature-dump-without-verification signatureReading blob body from %s failed (%v), reconnecting after %d bytes…Unexpected path elements in Docker reference %s for signature storagedocker-archive: does not support any scopes except the default "" oneReturned when a client attempts to contact a service too many timesruntime.Pinner: found leaking pinned pointer; forgot to call Unpin()?Can not convert image index to MIME type %q, which is not a list typeInternal inconsistency: Path %s resolved to %s still cleaned up to %shttp2: Transport closing idle conn %p (forSingleUse=%v, maxStream=%v)%s matches more methods than %s, but has a more specific path pattern%s matches fewer methods than %s, but has a more general path patterntls: peer doesn't support the certificate custom signature algorithmstls: handshake message of length %d bytes exceeds maximum of %d bytestls: client certificate contains an unsupported public key of type %Tignored xattrs in archive: underlying filesystem doesn't support themreflect: embedded interface with unexported method(s) not implementedtoo many hex fields to fit an embedded IPv4 at the end of the addressinternal error: %d > %d, maxheader: %d, sl: %d, tl: %d, normcount: %vcan't retrieve digest of container big data value with empty name: %winternal error: missing part misses both local and remote data streamcrypto/ecdh: only crypto/rand.Reader is allowed in FIPS 140-only modego-jose/go-jose: invalid JWK, x5c thumbprint does not match x5t valueimagestore %s must either be not set or be a different than graphrootedwards25519: internal error: setShortBytes called with a long stringCached value indicated that idmapped mounts for overlay are supportedIgnoring global metacopy option, the mount program doesn't support itstandalone-verify MANIFEST DOCKER-REFERENCE KEY-FINGERPRINTS SIGNATUREsync from 'dir' to 'dir' not implemented, consider using rsync insteadCannot prompt for a passphrase for key %s, standard input is not a TTYencryption change (for layer %q) is not supported in schema1 manifestsencryption change (for layer %q) is not supported in schema2 manifestsThe access controller denied access for the operation on a resource.unexpected multiple certificates present in signature certificate dataInternal inconsistency: both "caRootsPath" and "caRootsData" specifiedInternal inconsistency: Fulcio CA specified without a Rekor public keybytes.Buffer: UnreadByte: previous operation was not a successful readRFC5988 compliant rel='next' with URL to next result set, if available{ "name": , "tags": [ , ... ] }The blob identified by `digest` is available at the provided location.Schema2List.EditInstances: Modified digest %s is an invalid digest: %wno image found in manifest list for architecture %q, variant %q, OS %qInvalid image configuration, needs more than the %d distributed layersapplication/vnd.oci.image.layer.nondistributable.v1.tar+gzip+encryptedapplication/vnd.oci.image.layer.nondistributable.v1.tar+zstd+encryptedgot %s for stream %d; expected CONTINUATION following %s for stream %dsync/atomic: compare and swap of inconsistently typed value into ValueInvalid destination docker-daemon:%s: a destination must be a name:tagInvalid docker-daemon: reference %s: only digest algorithm %s acceptedcrypto/ecdsa: only crypto/rand.Reader is allowed in FIPS 140-only modecrypto/ed25519: use of Ed25519ctx is not allowed in FIPS 140-only modex509: PKCS#8 wrapping contained private key with unknown algorithm: %vx509: certificate relies on legacy Common Name field, use SANs insteadNeed at least one public key to verify the sigstore payload, but got 0expected a comma or an inline table terminator '}', but got %s insteadToNearestEvenToNearestAwayToZeroAwayFromZeroToNegativeInfToPositiveInfPrivate key password array length must be same as that of private keysprivate key password array length must be same as that of private keysgo-jose/go-jose: invalid SHA-256 thumbprint (must be %d bytes, not %d)second return value of SQLite aggregator Done() function must be errorblockingPicker: the picked transport is not ready, loop back to repickinvalid retry throttling config: maxTokens (%v) out of range (0, 1000]Cached value indicated that data-only layers for overlay are supportedMissing command '%[1]s COMMAND' Try '%[1]s --help' for more informationVarious operations with container images and container image registriesFile containing public keys. If not specified, will use local GPG keys.if any flags in the group [%v] are set they must all be set; missing %vDigest of source image's manifest would not match destination reference[A-Za-z][A-Za-z0-9]*(?:[-_+.][A-Za-z][A-Za-z0-9]*)*[:][[:xdigit:]]{32,}json: invalid use of ,string struct tag, trying to unmarshal %q into %vError creating parent directories for %s, using a memory-only cache: %vInternal inconsistency: A public key, Fulcio, or PKI must be specified.sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4{ "name": , "tags": [ , ... ], }Retrieve a sorted, json list of repositories available in the registry.range function recovered a loop body panic and did not resume panickingCan not convert manifest list to MIME type %q, which is not a list typeInconsistent schema 1 manifest: %d history entries, %d fsLayers entriesInternal error: uploaded %d blobs, but schema1 manifest has %d fsLayersError converting image: layer edits for %d layers vs %d existing layersinternal error: attempt to send frame on a half-closed-local stream: %vtls: peer doesn't support any of the certificate's signature algorithmsAuthFilePath and DockerCompatAuthFilePath can not be set simultaneouslyexec: command with a non-nil Cancel was not created with CommandContexttoo many concurrent operations on a single file or socket (max 1048575)crypto/ecdsa: use of custom curves is not allowed in FIPS 140-only modex509: issuer has name constraints but leaf doesn't have a SAN extensionsha256:e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855dynamic table size update MUST occur at the beginning of a header blockSwitching default driver from overlay2 to the equivalent overlay drivertransport: set send compressor called after headers sent or stream donegrpc: error unmarshalling service config %s due to methodConfig[%d]: %vunknown color model: 4-component JPEG doesn't have Adobe APP14 metadatafailed to allocate lock in %q after %d attempts; last failure on %q: %wINVALIDBOOLINT64FLOAT64STRINGBOOLSLICEINT64SLICEFLOAT64SLICESTRINGSLICE%v.%s cannot be a pointer to a interface or a slice of interface values%T.%s cannot be a pointer to a interface or a slice of interface values'--tls-verify' is deprecated, please set this on the specific subcommandnot a containers image directory, don't want to overwrite important dataDetected insufficient_scope error, will retry request with updated scopeDocker references with both a tag and digest are currently not supportedFailed to find flag %q and mark it as being in a one-required flag groupInternal error writing blob %s, blob with digest %s saved with digest %sSource is a manifest list; copying (only) instance %s for current systeminternal error: forceManifestMIMEType was rejected for an unknown reasonEnsureCompressionVariantsExist is not implemented for CopySpecificImagesInternal error: copying uncompressed config blob %s changed digest to %sinvalid repository name (%s), cannot specify 64-byte hexadecimal stringsreading subuid mappings for user %q and subgid mappings for group %q: %wimage config has only %d DiffID values, but a layer with index %d existserror creating image: image with ID %q exists, but uses different layersThe blob, identified by `name` and `digest`, is unknown to the registry.runtime.Goexit called in a thread that was not created by the Go runtimeclient doesn't support any cipher suites compatible with the certificatetls: server's certificate contains an unsupported type of public key: %Ttls: second client hello encrypted client hello extension does not matchtls: certificate private key of type %T does not implement crypto.Signerreflect: embedded type with methods not implemented for non-pointer typefound Pkcs11Recipient with version %d but maximum supported version is 0crypto/rsa: use of multi-prime keys is not allowed in FIPS 140-only modeError opening (previously-successfully-opened) blob info cache at %q: %vwhile cleaning up partially-created container %q we failed to create: %vzstd:chunked manifest too big to process in memory (%d bytes compressed)crypto/fips140: FIPS 140-3 mode enabled, but integrity check didn't passCannot connect to the Docker daemon at %s. Is the docker daemon running?go-jose/go-jose: invalid call to newFixedSizeBuffer (len(data) > length)%s: %s, error found in #%v byte of ...|%s|..., bigger context ...|%s|...grpc: Server.RegisterService found duplicate service registration for %qgot Content-Type = application/json, but could not unmarshal as JSON: %vWhile recovering from a failure creating a layer, error deleting %#v: %vuse `ARCH` instead of the architecture of the machine for choosing imagesConsuming rest of the original blob to satisfy getOriginalLayerCopyWritercaIntermediatesPath and caIntermediatesData cannot be used simultaneouslygo package net: GODEBUG=netdns contains an invalid dns mode, ignoring it Skipping commit for layer %q, manifest not yet available for DiffID checkMount a blob identified by the `mount` parameter from another repository.tls: received unexpected handshake message of type %T when waiting for %Ttls: internal error: handshake returned an error but is marked successfultls: found a certificate rather than a key in the PEM for the private keyspecifying a root certificates file with the insecure flag is not allowedBase compressor for blob with digest %s previously recorded as %s, now %sthe specified UID and/or GID mapping %s conflicts with other mappings: %wthe specified UID and/or GID mappings %s conflict with other mappings: %wcould not properly decrypt byte stream; exp hmac: '%x', actual hmac: '%s'go-jose/go-jose: key algorithm '%s' not supported in multi-recipient modego-jose/go-jose: invalid or SHA-256 thumbprint, does not match cert chaingo-jose/go-jose: invalid JWK, found 'oct' (symmetric) key with cert chainMissing '_auth_user' while user authentication was requested with '_auth'Missing '_auth_pass' while user authentication was requested with '_auth'Cached value indicated that idmapped mounts for overlay are not supportedReceived a RST_STREAM frame with code %q, but found no mapped gRPC statusIgnoring resolver error because balancer is using a previous good update.Unrecognized command `%[1]s %[2]s` Try '%[1]s --help' for more informationsync [command options] --src TRANSPORT --dest TRANSPORT SOURCE DESTINATIONImages at DESTINATION are prefix using the full source image path as scope%w (after reconnecting, server did not process a Range: header, status %d) if [[ -z "${BASH_VERSION:-}" || "${BASH_VERSINFO[0]:-}" -gt 3 ]]; thenInternal error writing blob %s, digest verification failed but was ignoredbytes.Buffer: UnreadRune: previous operation was not a successful ReadRuneExisting credentials are invalid, please enter valid username and passwordadding a schema2 list instance with no platform specified is not supportedmalformed response from server: malformed non-numeric status pseudo headernet/http: server replied with more than declared Content-Length; truncatedtls: certificate RSA key size too small for supported signature algorithmsInternal error in V2RegistriesConf.PostProcess: entry in regMap is missingregistry '%s' is defined multiple times with conflicting 'blocked' settingcrypto/rand: failed to read random data (see https://go.dev/issue/66821): Invalid scope %s: Uses non-canonical path format, perhaps try with path %scrypto/rsa: use of keys with odd size is not allowed in FIPS 140-only modeUncompressed digest for blob with TOC %q previously recorded as %q, now %qSELECT uncompressedDigest FROM DigestUncompressedPairs WHERE anyDigest = ?INSERT OR REPLACE INTO DigestCompressors(digest, compressor) VALUES (?, ?)SELECT anyDigest FROM DigestUncompressedPairs WHERE uncompressedDigest = ?internal error: layerStore.load has shouldSave but !r.lockfile.IsReadWriteProcessLabel and Mountlabel must either not be specified or both specifiedzstd:chunked manifest too big to process in memory (%d bytes uncompressed)gcm: internal error: using generic implementation despite hardware supportgo-jose/go-jose: invalid JWK, x5c thumbprint does not match x5t#S256 valueInvalid _auto_vacuum: %v, expecting value of '0 NONE 1 FULL 2 INCREMENTAL'failed to get interactive success html, defaulting to original static pagebackingFs=%s, projectQuotaSupported=%v, useNativeDiff=%v, usingMetacopy=%vCached value indicated that data-only layers for overlay are not supportedSubConn %p reported connectivity state READY. Registering health listener.AddAttrs unsafely called on copy of Record made without using Record.CloneCannot obtain a valid image reference for transport %q and reference %q: %wCannot obtain a valid image reference for transport %q and reference %s: %wrequire HTTPS and verify certificates when accessing the container registry%w (after reconnecting at offset %d, got unexpected Content-Range %d-%d/%d)Reading blob body from %s failed (%v), reconnecting (first reconnection)… No signature storage configuration found for %s, using built-in default %sInvalid docker-archive: reference: cannot use both a tag and a source index%[2]s is a special command that is used by the shell completion logic %[1]scannot use ForceCompressionFormat with undefined default compression formatInternal inconsistency: publicKey not set before verifying sigstore payloadInternal error: commitLayer called with previous layer %d not committed yetUnsolicited response received on idle HTTP channel starting with %q; err=%vtls: internal error: attempted to read record with pending application datatls: client sent encrypted_client_hello extension with unsupported versionstls: client sent encrypted_client_hello extension but did not offer TLS 1.3registry '%s' is defined multiple times with conflicting 'insecure' settingInternal inconsistency: Docker reference %s with neither a tag nor a digestInternal error: Trying to reuse ManifestItem values with layers %#v vs. %#vRekor /api/v1/log/entries/{entryUUID} failed with unexpected status %d: %+vcannot create an image with canonical UID/GID mappings in a read-only storepermission denied while trying to connect to the Docker daemon socket at %vrequest returned %s; check if the server supports the requested API versionpkcs7: cannot decrypt data: only RSA PKCS#1 v1.5 and RSA OAEP are supportedpkcs7: cannot encrypt content: only DES-CBC, AES-CBC, and AES-GCM supportedoverlay: additionallayerstore path %q is not absolute. Can not be relativeheader list size to send violates the maximum size (%d bytes) set by serverHeader list size to send violates the maximum size (%d bytes) set by clientEXPERIMENTAL. Number of times the selected subchannel becomes disconnected.Fetching sigstore attachment manifest failed, assuming it does not exist: %vInternal error: NewReaderForReference called for a reader-bound reference %sError creating a SQLite blob info cache at %s, using a memory-only cache: %vunable to redefine %q shorthand in %q flagset: it's already used for %q flagupdate %d of %d passed to OCI1Index.UpdateInstances had an invalid size (%d)HTTP/1.0 400 Bad Request Client sent an HTTP request to an HTTPS server. tls: failed to send closeNotify alert (but connection was closed anyway): %wtls: no cipher suite supported by both client and server; client offered: %xtls: server certificate contains incorrect key type for selected ciphersuiteInternal error: Trying to reuse ManifestItem values with configs %#v vs. %#vinvalid image reference %s, expected format: 'hostname/namespace/stream:tag'crypto/rsa: use of even public exponent is not allowed in FIPS 140-only modeinternal error: nothing to sign with, should have been detected in NewSignercannot encrypt because no candidate hash functions are compiled in. (Wanted While recovering from a failure to save layers, error deleting layer %#v: %vTOC requires a tar-split, but the %s annotation does not describe a positiongo-jose/go-jose: invalid JWK, public keys in key and x5c fields do not matchInvalid _synchronous: %v, expecting value of '0 OFF 1 NORMAL 2 FULL 3 EXTRA'reached %d iterations in overlay graph driver’s recreateSymlink, giving uptransport: trying to send header list size larger than the limit set by peertransport: http2Server.HandleStreams received bogus greeting from client: %qtransport: http2Server.HandleStreams saw invalid preface type %T from client See skopeo-list-tags(1) section "REPOSITORY NAMES" for the expected format use `VARIANT` instead of the running architecture variant for choosing imagesinternal inconsistency: policy verification failed without returning an errorRun skopeo as a proxy, supporting HTTP requests to fetch manifests and blobs.Can not convert image to %s, preparing DiffIDs for this case is not supportedError preparing updated manifest: unknown media type of original layer %q: %qregistry not specified, default to the first registry %q from registries.confInternal inconsistency: More than one of public key, Fulcio, or PKI specifiedinvalid Body.Read call. After hijacked, the original Request must not be usedcrypto/tls: ExportKeyingMaterial is unavailable when renegotiation is enabledMapIter.Next called on an iterator that does not have an associated map Valueinvalid function signature for %s: second return value should be error; is %sCouldn't get cpu model name, it may be the corner case where variant is 6: %vinvalid image reference: %s, expected format: 'hostname/namespace/stream:tag'unknown Public key PEM file type: %v. Are you passing the correct public key?Specific compressor for blob with digest %s previously recorded as %s, now %sSELECT uncompressedDigest FROM DigestTOCUncompressedPairs WHERE tocDigest = ?len(z.currentBuffer) > z.blockSize (most likely due to concurrent Write race)While recovering from a failure to set big data, error deleting layer %#v: %vcrypto/cipher: GCM tag and nonce sizes can't be non-standard at the same timegrpc: credentials.Bundle may not be used with individual TransportCredentialsClientConn's authority from transport creds %q and dial option %q don't matchLayer %s has already been removed; ignore it and continue to delete the cacheserver provided %d signatures, assuming that's unreasonable and a server errorDocker reference %s is not for an unknown digest case; tag or digest is neededFailed to find flag %q and mark it as being in a mutually exclusive flag groupencryption required together with format %s, which does not support encryptionUnexpectedly received a manifest list instead of a manifest for a single imagewhen choosing layers to encrypt, layer index %d out of range (%d layers exist)This error may be returned when a manifest blob is unknown to the registry.range function continued iteration after function for loop body returned falseupdate %d of %d passed to Schema2List.UpdateInstances had an invalid size (%d)update %d of %d passed to OCI1Index.UpdateInstances had no media type (was %q)pattern %q (registered at %s) conflicts with pattern %q (registered at %s): %sinvalid prefix '%v' for empty location, should be in the format: *.example.comreflect: embedded type with methods not implemented if type is not first fieldcrypto/rsa: use of PKCS#1 v1.5 encryption is not allowed in FIPS 140-only modex509: signature check attempts limit reached while verifying certificate chain115792089210356248762697446949407573530086143415290314195533631308867097853951115792089210356248762697446949407573529996955224135760342422259061068512044369Internal error: signature verification failed but no errors have been recordedgraph driver %s does not support partial pull but convert_images requires thatCould not parse '%s' as a hexadecimal number, but the lexer claims it's OK: %soidc: issuer did not match the issuer returned by provider, expected %q got %qoverlay: test mount did not indicate whether or not metacopy is being used: %vkernel returned %v when we tried to delete an item in the merged directory: %wtransport: http2Server.HandleStreams failed to read initial settings frame: %v{{with .DisplayName}}{{printf "%s " .}}{{end}}{{printf "version %s" .Version}} Retrieve the progress of the current upload, as reported by the `Range` header.cannot convert slice with length %y to array or pointer to array with length %xOCI1Index.EditInstances: Attempting to update %s which is an invalid digest: %whttp2: server closing client connection; error reading frame from client %s: %vtls: client certificate private key of type %T does not implement crypto.Signermore than one authentication method found for %v; found %v, only one is allowedcannot manually encode TypeXHeader, TypeGNULongName, or TypeGNULongLink headersCannot connect to the Docker daemon. Is the docker daemon running on this host?Ignoring BlobInfoCache record of digest %q with unrecognized compression %q: %vBad label option %q, valid options 'disable, user, role, level, type, filetype'overlay: metacopy option not supported on this kernel, checked using options %qoverlay: override_kernel_check option was specified, but is no longer necessary--storage-opt is supported only for overlay over xfs with 'pquota' mount optionmetadata: FromOutgoingContext got an odd number of input pairs for metadata: %duse registry configuration files in `DIR` (e.g. for container signature storage)unknown format %q. Choose one of the supported formats: 'oci', 'v2s1', or 'v2s2'Not reconnecting to %s: insufficient progress %d / time since last retry %.3f msInternal error: there must be exactly 2 colons in the cacheKey ('%s') but got %dInternal inconsistency: Reference %s unexpectedly has neither a digest nor a tagcompression using %s required together with format %s, which does not support itcompression using %s required, but none of the known manifest formats support itInternal inconsistency: PKI use set up without subject email or subject hostnameInternal inconsistency: Rekor SET did not match any key but we have no failures.Ordinary storage image ID %s; a layer was looked up by TOC, so using image ID %supdate %d of %d passed to Schema2List.UpdateInstances had no media type (was %q)Internal error: collected %d DiffID values, but schema1 manifest has %d fsLayershttp: RoundTripper implementation (%T) returned a nil *Response with a nil errorbug: unexpected way for two patterns %s and %s to conflict: methods %s, paths %stls: either ServerName or InsecureSkipVerify must be specified in the tls.ConfigError parsing the "auth" field of a credential entry %q in %q, missing semicolondocker-daemon: references with both a tag and digest are currently not supportedx509: invalid signature: parent certificate cannot sign this kind of certificatelocating image with ID %q (consider removing the image to resolve the issue): %wcrypto/ecdh: internal error: nistec ScalarBaseMult failed for a fixed-size inputfiles cannot contain NULL bytes; probably using UTF-16; TOML files must be UTF-8crypto/rand: blocked for 60 seconds waiting to read random data from the kernel opaque flag erroneously copied up, consider update to kernel 4.8 or later to fixFixed delay between retries. If not set, retry uses an exponential backoff delay.reading images from docker: reference %q without a tag or digest is not supportedDocker reference %q is for an unknown digest case, has neither a digest nor a tagInvalid oci: layout reference: cannot use both an image %s and a source index @%dif any flags in the group [%v] are set none of the others can be; %v were all setinternal inconsistency: layer (%d, %q) is not identified by TOC and has no diffIDLength of the chunk being uploaded, corresponding the length of the request body.An error was encountered processing the delete. The client may ignore this error. (bad use of unsafe.Pointer or having race conditions? try -d=checkptr or -race) Schema2List.EditInstances: Attempting to update %s which is an invalid digest: %wInternal error: Image.Signatures() is not supported for images modified in memoryCredentials cannot be recorded in Docker-compatible format with namespaced key %qcrypto/rsa: use of public exponent <= 2¹⁶ is not allowed in FIPS 140-only modecrypto/rsa: use of primes of different sizes is not allowed in FIPS 140-only modepublic key or cert to be matched against publicKey in Rekor SET has trailing datacontainer store is inconsistent and the current caller does not hold a write lockcrypto/aes: internal error: using generic implementation despite hardware supportUnsupported keyprovider invocation. Supported invocation methods are grpc and cmdInvalid _journal: %v, expecting value of 'DELETE TRUNCATE PERSIST MEMORY WAL OFF'Trying to create a layer %#v while directory %q already exists; removing it firstblob %s with type %s should be compressed with %s, but compressor appears to be %s%s is a prerelease version and the constraint is only looking for release versionsx509: a root or intermediate certificate is not authorized to sign for this name: refusing to use HTTP_PROXY value in CGI environment; see golang.org/s/cgihttpproxyInvalid _query_only: %v, expecting boolean value of '0 1 false true no yes off on'grpc: Server.RegisterService found the handler of type %v that does not satisfy %voverlay: test mount with multiple lowers failed, but succeeded with a single lowerreceived goaway with stream id: %v, which exceeds stream id of previous goaway: %vtransport: http2Server.HandleStreams failed to receive the preface from client: %vUsage: skopeo standalone-verify manifest docker-reference key-fingerprint signatureDocker reference %s is for an unknown digest case but reference has a tag or digestmultiple private key sources specified when preparing to create sigstore signaturesjson: invalid use of ,string struct tag, trying to unmarshal unquoted value into %vThis is returned if the name used during an operation is unknown to the registry.expected all size classes up to min size for malloc header to fit in one-page spanstls: failed to decrypt second client hello encrypted client hello extension payloadcrypto/hkdf: use of keys shorter than 112 bits is not allowed in FIPS 140-only modeinternal error: modifyDockerConfigJSON called with DockerCompatAuthFilePath not setinvalid condition: location is unset and prefix is not in the format: *.example.comreflect: embedded type with methods not implemented if there is more than one fieldcrypto/rsa: use of keys smaller than 2048 bits is not allowed in FIPS 140-only modex509: issuer has name constraints but leaf contains unknown or unconstrained name: (possibly because of %q while trying to verify candidate authority certificate %q)While recovering from a failure to create a container, error deleting layer %#v: %vcrypto/cipher: use of CBC with non-AES ciphers is not allowed in FIPS 140-only modecrypto/cipher: use of CTR with non-AES ciphers is not allowed in FIPS 140-only modecrypto/cipher: use of GCM with non-AES ciphers is not allowed in FIPS 140-only modecrypto/hmac: use of keys shorter than 112 bits is not allowed in FIPS 140-only modeThe storage 'driver' option should be set in %s. A driver was picked automatically.method configs in service config will be ignored due to presence of config selectorUsage: skopeo standalone-sign manifest docker-reference key-fingerprint -o signatureskopeo sync --src docker --dest dir --scoped registry.example.com/busybox /media/usbTrying to reuse blob with cached digest %s compressed with %s in destination repo %sInternal inconsistency: policyconfiguration.DockerReferenceIdentity returned %#v, %vExactly one of keyPath, keyPaths and keyData must be specified, none of them presentInternal inconsistency: both "rekorPublicKeyPath" and "rekorPublicKeyData" specifiedDocker reference match attempted on image %s with no known Docker reference identityThe blob has been created in the registry and is available at the provided location.during manifest conversion: encrypted layers (%q) are not supported in docker imagestls: downgrade attempt detected, possibly due to a MitM attack or a broken middleboxx509: signature algorithm specifies an %s public key, but have public key of type %Tpublic key or cert to be matched against publicKey in Rekor SET is not in PEM formatexpected a top-level item to end with a newline, comment, or EOF, but got %q insteadInvalid _foreign_keys: %v, expecting boolean value of '0 1 false true no yes off on'failed to set quota limit for projid %d on %s after backingFsBlockDev recreation: %wInternal error: copy needs an updated manifest but that was known to be forbidden: %qExactly one of keyPath, keyPaths and keyData must be specified, more than one presenthttp: WriteHeader called with both Transfer-Encoding of %q and a Content-Length of %dreflect.Value.Interface: cannot return value obtained from unexported field or methoddocker-daemon: reference must have at least one of an image ID and a reference stringcrypto/rsa: use of PSS salt longer than the hash is not allowed in FIPS 140-only modex509: failed to parse private key (use ParseECPrivateKey instead for this key format)x509: failed to parse public key (use ParsePKIXPublicKey instead for this key format)attempt to delete child with id %d from a parent (id=%d) that doesn't currently existuse certificates at `PATH` (*.crt, *.cert, *.key) to connect to the registry or daemonrequire HTTPS and verify certificates when talking to the container registry or daemonIgnoring exact blob match, compression %s does not match required %s or MIME types %#vCopying this image would require changing layer representation, which we cannot do: %qexactly one of keyPath, keyPaths, keyData, keyDatas, fulcio, and pki must be specifiedInternal inconsistency: Fulcio specified with not exactly one of "caPath" nor "caData"Internal inconsistency: both "caIntermediatesPath" and "caIntermediatesData" specifiedThe specified `name` or `reference` were invalid and the delete was unable to proceed.The blob has been mounted in the repository and is available at the provided location.tls: MinVersion must be >= VersionTLS13 if EncryptedClientHelloConfigList is populatedtls: MaxVersion must be >= VersionTLS13 if EncryptedClientHelloConfigList is populatedreflect: New of type that may not be allocated in heap (possibly undefined cgo C type)Aborting upload, daemonImageDestination closed without a previous .CommitWithOptions()x509: a root or intermediate certificate is not authorized for an extended key usage: x509: failed to parse public key (use ParsePKCS1PublicKey instead for this key format)internal error using pkg/blobinfocache/sqlite.cache: Close() without a matching Open()Subchannel health check is unimplemented at server side, thus health check is disabledtarget rename dir '%s' exists but should not, this needs to be manually cleaned up: %woverlay: force_mask option for writeable layers is only supported with a mount_programInternal error: NewReaderForReference called for a non-docker/archive ImageReference %slooking up signatures data for image %q (%s): expected at least %d bytes, only found %dclient-key-data and client-key are both specified for %v; client-key-data will overrideSELECT specificVariantCompressor FROM DigestSpecificVariantCompressors WHERE digest = ?Invalid _writable_schema: %v, expecting boolean value of '0 1 false true no yes off on'oidc: invalid configuration, clientID must be provided or SkipClientIDCheck must be setdocker: image reference %q has unknown digest set but it contains either a tag or digestsaving credentials to ~/.docker/config.json, but not using Docker-compatible file formatpath of the authentication file. Use REGISTRY_AUTH_FILE environment variable to overrideInternal inconsistency: not exactly one of "keyPath", "keyPaths" and "keyData" specifiedinternal error: PrepareStagedLayer returned CompressedDigest %q not matching expected %qInternal error: storageImageDestination.CommitWithOptions() called without PutManifest()x509: failed to parse private key (use ParsePKCS8PrivateKey instead for this key format)x509: failed to parse private key (use ParsePKCS1PrivateKey instead for this key format)expected %d bytes of padding after previous file, but next SegmentType only has %d bytespath of the registry credentials file. Default is ${XDG_RUNTIME_DIR}/containers/auth.jsonError parsing signature storage configuration: "default-docker" defined both in %q and %qImage operating system mismatch: image uses OS %q+architecture %q+%q, expecting one of %qv2s1 image uses a layer identified by TOC with unknown diffID; choosing a random image IDError during manifest conversion: %q: zstd compression is not supported for docker imagesstorage option overlay.size and overlay.inodes only supported for backingFS XFS. Found %vUnexpected error by Additional Layer Store %v during use; GC doesn't seem to be supportedInternal error: ManifestTagsForReference called for a non-docker/archive ImageReference %sComplete the upload specified by `uuid`, optionally appending the body as the final chunk.{ "repositories": [ , ... ] "next": "?last=&n=" }http2: server sent GOAWAY and closed the connection; LastStreamID=%v, ErrCode=%v, debug=%qclient-cert-data and client-cert are both specified for %v. client-cert-data will overrideInvalid _defer_foreign_keys: %v, expecting boolean value of '0 1 false true no yes off on'Invalid _recursive_triggers: %v, expecting boolean value of '0 1 false true no yes off on'Invalid _secure_delete: %v, expecting boolean value of '0 1 false true no yes off on fast'pkcs7: cannot decrypt data: only RSA, DES, DES-EDE3, AES-256-CBC and AES-128-GCM supportedUnable to delete %v. Image may not exist or is not stored with a v2 Schema in a v2 registryerror preparing updated manifest: encryption specified but no counterpart for mediatype: %qa library subroutine needed to run a subprocess, but reexec.Init() was not called in main()Limit the number of entries in each response. It not present, all entries will be returned.tls: unexpected encrypted client hello extension in server hello despite ECH being acceptedINSERT OR REPLACE INTO DigestUncompressedPairs(anyDigest, uncompressedDigest) VALUES (?, ?)Invalid _case_sensitive_like: %v, expecting boolean value of '0 1 false true no yes off on'Unsupported codec %q. Defaulting to %q for now. This will start to fail in future releases.attempt to add child of type %T with id %d to a parent (id=%d) that doesn't currently existReturn the list of tags from the transport/repository "SOURCE-IMAGE" Supported transports: Only one of --sign-by and sign-by-sigstore-private-key can be used with sign-passphrase-fileinternal error: untrustedLayerDiffID has no value available and fallback was not implementedIf a blob upload has been cancelled or was never started, this error code may be returned.tls: server sent encrypted client hello retry configs after accepting encrypted client hellotls: handshake hash for a client certificate requested after discarding the handshake bufferFound an empty credential entry %q in %q (an unhandled credential helper marker?), moving on--system --shell /bin/false --no-create-home --disabled-login --disabled-password --group %sno suitable key unwrapper found or none of the private keys could be used for decryption: %s%w: symlink %s/%s has an overmount obscuring the real link (mount ids do not match %d != %d)a network file system with user namespaces is not supported. Please use a mount_program: %wskopeo copy docker://quay.io/skopeo/stable:latest docker://registry.example.com/skopeo:latestThe operation was unsupported due to a missing implementation or invalid set of parameters.Internal inconsistency: PKI specified with not exactly one of "caRootsPath" nor "caRootsData"Invalid repository name encountered either during manifest validation or any API operation.tls: unsupported certificate: private key is *ed25519.PrivateKey, expected ed25519.PrivateKeycrypto/rsa: %d-bit keys are insecure (see https://go.dev/pkg/crypto/rsa#hdr-Minimum_key_size)estargz layers don't support partial pulls with guaranteed consistency with non-partial pullsparseLine only accepts {*string, *int, *int64, *[]string} as arguments! %#v is not a pointer!Unexpected error by Additional Layer Store %v during release; GC doesn't seem to be supportedError parsing signature storage configuration: "docker" namespace %q defined both in %q and %qEnsureCompressionVariantsExist is not implemented when not creating a multi-architecture imageChecking if we can reuse blob %s: general substitution = %v, compression for MIME type %q = %vinternal error: PrepareStagedLayer succeeded with neither TOCDigest nor UncompressedDigest setA uuid identifying the upload. This field can accept characters that match `[a-zA-Z0-9-_.=]+`.INSERT OR REPLACE INTO DigestTOCUncompressedPairs(tocDigest, uncompressedDigest) VALUES (?, ?)sqlite3: Serialize requires the sqlite_serialize build tag when using the libsqlite3 build tagdeprecated: golang.org/x/oauth2: Transport.CancelRequest no longer does anything; use contextsNot using native diff for overlay, this may cause degraded performance for building images: %vgrpc-status-details-bin mismatch: grpc-status=%v, grpc-message=%q, grpc-status-details-bin=%+vsize mismatch (see https://github.com/golang/protobuf/issues/1609): calculated=%d, measured=%d(heuristic tuning data: total %d @%.3f ms, last retry %d @%.3f ms, last progress @ %.3f ms): %wWriting directly to a %s lookaside %s is not supported. Configure a lookaside-staging: locationinternal error: in.destSupportedManifestMIMETypes is empty but supportedByDest is empty as wellCompression using zstd:chunked is not beneficial for encrypted layers, using plain zstd insteadInternal inconsistency: more than one of "keyPath", "keyPaths", "keyData", "keyDatas" specifiedInternal inconsistency: "keyPath", "keyPaths", "keyData" and "keyDatas" produced no public keysinternal error: PrepareStagedLayer returned a TOC-only identity for layer %q with no TOC digestPut the manifest identified by `name` and `reference` where `reference` can be a tag or digest.unable to verify signature: EC Public Key with curve %q does not support signature algorithm %q%s does not equal %s. Expect version and constraint to equal when major and minor versions are 0internal error: layer %d for blob %s was identified by TOC, but we don't have a DiffID in configOperations on blobs identified by `name` and `digest`. Used to fetch or delete layers by digest.Not removing credentials because namespaced keys are not supported for the credential helper: %scrypto/rsa: use of hash functions other than SHA-2 or SHA-3 is not allowed in FIPS 140-only modeb3312fa7e23ee7e4988e056be3f82d19181d9c6efe8141120314088f5013875ac656398d8a2ed19d2a85c8edd3ec2aefaa87ca22be8b05378eb1c71ef320ad746e1d3b628ba79b9859f741e082542a385502f25dbf55296c3a545e3872760ab73617de4a96262c6f5d9e98bf9292dc29f8f41dbd289a147ce9da3113b5f0b8c00a60b1ce1d7e819d7a431d7c90ea0e5fInvalid _ignore_check_constraints: %v, expecting boolean value of '0 1 false true no yes off on'sqlite3: Deserialize requires the sqlite_serialize build tag when using the libsqlite3 build tagstandalone-sign [command options] MANIFEST DOCKER-REFERENCE KEY-FINGERPRINT --output|-o SIGNATUREinternal error: missing compressor names (src base: %q, uploaded base: %q, uploaded specific: %q)The upload is known and in progress. The last received offset is available in the `Range` header.http: RoundTripper implementation (%T) returned a *Response with content length %d but a nil Bodycrypto/hkdf: use of hash functions other than SHA-2 or SHA-3 is not allowed in FIPS 140-only modemissing key %s for client certificate %s. Note that CA certificates should use the extension .crtcrypto/hmac: use of hash functions other than SHA-2 or SHA-3 is not allowed in FIPS 140-only modeNone of the challenges sent by server (%s) are supported, trying an unauthenticated request anywayerror preparing updated manifest: decryption specified but original mediatype is not encrypted: %qinternal inconsistency: SigningParameterFileOIDCModeStaticToken was supposed to already be handledThe manifest has been accepted by the registry and is stored under the specified `name` and `tag`.NoClientCertRequestClientCertRequireAnyClientCertVerifyClientCertIfGivenRequireAndVerifyClientCertclient-key-data or client-key must be specified for %v to use the clientCert authentication methodcrypto/ecdsa: use of hash functions other than SHA-2 or SHA-3 is not allowed in FIPS 140-only modelocating item named %q for image with ID %q (consider removing the image to resolve the issue): %wLoopback device and filesystem disagree on device/inode for %q: %#x(%d):%#x(%d) vs %#x(%d):%#x(%d)unknown multi-arch option %q. Choose one of the supported options: 'system', 'all', or 'index-only'compression using %s, and encryption, required together with format %s, which does not support bothinternal error: compressed layer %q (for compressed digest %q) does not have an uncompressed digestgrpc: the credentials require transport level security (use grpc.WithTransportCredentials() to set)Precompute digests to prevent uploading layers already on the registry using the 'docker' transport.Manifest list must be converted to type %q to be written to destination, but we cannot modify it: %qInitiate a blob upload. This endpoint can be used to create resumable uploads or monolithic uploads.This error is returned when the manifest, identified by name and tag is unknown to the repository.During manifest upload, if the manifest fails signature verification, this error will be returned.Wildcarded prefix should be in the format: *.example.com. Current prefix %q is incorrectly formatteddocker-daemon: reference must not have an image ID and a reference string specified at the same timeed25519: expected opts.Hash zero (unhashed message, for standard Ed25519) or SHA-512 (for Ed25519ph)Balancer retrieved for name %q. grpc-go will be switching to case sensitive balancer registries soonnum values of :authority: %v, num values of host: %v, both must only have 1 value as per HTTP/2 speccopying multiple images: destination transport %q does not support copying multiple images as a groupThe current kernel doesn't support mounting EROFS directly from a file, fallback to a loopback device%s: the backing %s filesystem is formatted without d_type support, which leads to incorrect behavior.Unrecognized command `%[1]s %[2]s` Did you mean this? %[3]s Try '%[1]s --help' for more informationcgocheck > 1 mode is no longer supported at runtime. Use GOEXPERIMENT=cgocheck2 at build time instead.http2: failed reading the frame payload: %w, note that the frame header looked like an HTTP/1.1 headerINSERT OR REPLACE INTO KnownLocations(transport, scope, digest, location, time) VALUES (?, ?, ?, ?, ?)Not considering unrecognized specific compression variant %q for BlobInfoCache record of digest %q: %vignoring service config from resolver (%v) and applying the default because service config is disabledBalancer registered with name %q. grpc-go will be switching to case sensitive balancer registries soonencryption required but the destination only supports MIME types [%s], none of which support encryptioninternal error: in PutBlobPartial, untrustedLayerDiffID returned errUntrustedLayerDiffIDNotYetAvailableHTTP/1.1 400 Bad Request Content-Type: text/plain; charset=utf-8 Connection: close 400 Bad Requestrequest returned %s with a message (> %d bytes); check if the server supports the requested API versionIgnoring BlobInfoCache record of digest %q, compression %q does not match required %s or MIME types %#vrequest returned %s for API route and version %s, check if the server supports the requested API versionClient received GoAway with error code ENHANCE_YOUR_CALM and debug data equal to ASCII "too_many_pings".compression using %s required but the destination only supports MIME types [%s], none of which support itSELECT location, time FROM KnownLocations WHERE transport = ? AND scope = ? AND KnownLocations.digest = ?Can't read parent link %q because it does not exist. Going through storage to recreate the missing links.Failed to write a GOAWAY frame as part of connection close after %s. Giving up and closing the transport.The blob identified by `digest` is available. The blob content will be present in the body of the request.ed25519: expected opts.HashFunc() zero (unhashed message, for standard Ed25519) or SHA-512 (for Ed25519ph)asn1: time did not serialize back to the original value and may be invalid: given %q, but serialized as %qState: %v, Target: %s, CallsStarted: %v, CallsSucceeded: %v, CallsFailed: %v, LastCallStartedTimestamp: %vWrite the digests and Image References of the resulting images to the specified file, separated by newlinesTrying to reuse blob with cached digest %s compressed with %s with no location match, checking current repoInternal error: storageImageDestination.CommitWithOptions(): commitLayer() not ready to commit for layer %qTrying to reuse blob with cached digest %s in destination repo with no location match, checking current repoInternal inconsistency: PKI specified with invalid value from "caIntermediatesPath" or "caIntermediatesData"CREATE TABLE IF NOT EXISTS DigestCompressors(digest TEXT PRIMARY KEY NOT NULL,compressor TEXT NOT NULL )%s contains several valid graphdrivers: %s; Please cleanup or explicitly choose storage driver (-s )crypto/cipher: use of GCM with arbitrary IVs is not allowed in FIPS 140-only mode, use NewGCMWithRandomNonceIgnoring BlobInfoCache record of digest %q, uncompressed format does not match required %s or MIME types %#vstorage options overlay.size and overlay.inodes not supported. Filesystem does not support Project Quota: %wCan't stat lower layer %q because it does not exist. Going through storage to recreate the missing symlinks.Received a HEADERS frame with a :connection header which makes the request malformed, as per the HTTP/2 specexplicitly requested to combine zstd:chunked with encryption, which is not beneficial; use plain zstd insteadrekorPublickeyPath, rekorPublicKeyPaths, rekorPublickeyData and rekorPublicKeyDatas are not supported for pkiBlob mount is not allowed because the registry is configured as a pull-through cache or for some other reasonInvalid docker-daemon: reference %s: The %s repository name is reserved for (non-shortened) digest references[