Merge upstream 2026-07-01 - #504
Conversation
Restore delete permission on secrets because owner reference updates can be rejected by the API server without it. Fixes: metal3-io#3304 Change-Id: Ib4df61b28205ca3582ea5ce586da1872666a0724 Signed-off-by: rabi <ramishra@redhat.com>
Signed-off-by: Nuutti Hakala <nuutti.hakala@est.tech>
Changed the dependabot cooldown from 7 days to 3 days. Instead of suppressing the zizmor warning with `zizmor: ignored`, this adds a proper `.zizmor.yml` config at the repo root. The workflow at `.github/workflows/zizmor.yml` picks it up via the `config:` input. Signed-off-by: Migi Jylhä <migi.jylha@est.tech>
…oft-reboot fallback Fixes metal3-io#3271 Signed-off-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
OpenDev runners cache cirros images but not systemrescue ones. Signed-off-by: Dmitry Tantsur <dtantsur@protonmail.com>
This commit: - Makes sure that the correct IPA nordix proxy is used. Previous address circumvented the proper cache refresh trigger so in case the cache was empty after a cleanup, cache refresh was not triggered. Signed-off-by: Adam Rozman <adam.rozman@est.tech>
🌱 Use proper IPA cache address
Remove custom mariadb-image container logic. Use MariaDB Operator instead. Signed-off-by: Migi Jylhä <migi.jylha@est.tech>
Signed-off-by: Matt Van Horn <mvanhorn@gmail.com>
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.29.0 to 2.31.0. - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](onsi/ginkgo@v2.29.0...v2.31.0) --- updated-dependencies: - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.31.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps the kubernetes group with 3 updates in the / directory: [k8s.io/api](https://github.com/kubernetes/api), [k8s.io/client-go](https://github.com/kubernetes/client-go) and [k8s.io/component-base](https://github.com/kubernetes/component-base). Bumps the kubernetes group with 1 update in the /apis directory: [k8s.io/api](https://github.com/kubernetes/api). Bumps the kubernetes group with 2 updates in the /test directory: [k8s.io/api](https://github.com/kubernetes/api) and [k8s.io/apiextensions-apiserver](https://github.com/kubernetes/apiextensions-apiserver). Updates `k8s.io/api` from 0.35.5 to 0.35.6 - [Commits](kubernetes/api@v0.35.5...v0.35.6) Updates `k8s.io/apimachinery` from 0.35.5 to 0.35.6 - [Commits](kubernetes/apimachinery@v0.35.5...v0.35.6) Updates `k8s.io/client-go` from 0.35.5 to 0.35.6 - [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md) - [Commits](kubernetes/client-go@v0.35.5...v0.35.6) Updates `k8s.io/component-base` from 0.35.5 to 0.35.6 - [Commits](kubernetes/component-base@v0.35.5...v0.35.6) Updates `k8s.io/api` from 0.35.5 to 0.35.6 - [Commits](kubernetes/api@v0.35.5...v0.35.6) Updates `k8s.io/apimachinery` from 0.35.5 to 0.35.6 - [Commits](kubernetes/apimachinery@v0.35.5...v0.35.6) Updates `k8s.io/api` from 0.35.5 to 0.35.6 - [Commits](kubernetes/api@v0.35.5...v0.35.6) Updates `k8s.io/apimachinery` from 0.35.5 to 0.35.6 - [Commits](kubernetes/apimachinery@v0.35.5...v0.35.6) Updates `k8s.io/api` from 0.35.5 to 0.35.6 - [Commits](kubernetes/api@v0.35.5...v0.35.6) Updates `k8s.io/apimachinery` from 0.35.5 to 0.35.6 - [Commits](kubernetes/apimachinery@v0.35.5...v0.35.6) Updates `k8s.io/api` from 0.35.5 to 0.35.6 - [Commits](kubernetes/api@v0.35.5...v0.35.6) Updates `k8s.io/apimachinery` from 0.35.5 to 0.35.6 - [Commits](kubernetes/apimachinery@v0.35.5...v0.35.6) Updates `k8s.io/api` from 0.35.5 to 0.35.6 - [Commits](kubernetes/api@v0.35.5...v0.35.6) Updates `k8s.io/apimachinery` from 0.35.5 to 0.35.6 - [Commits](kubernetes/apimachinery@v0.35.5...v0.35.6) Updates `k8s.io/api` from 0.35.5 to 0.35.6 - [Commits](kubernetes/api@v0.35.5...v0.35.6) Updates `k8s.io/apimachinery` from 0.35.5 to 0.35.6 - [Commits](kubernetes/apimachinery@v0.35.5...v0.35.6) Updates `k8s.io/api` from 0.35.5 to 0.35.6 - [Commits](kubernetes/api@v0.35.5...v0.35.6) Updates `k8s.io/apimachinery` from 0.35.5 to 0.35.6 - [Commits](kubernetes/apimachinery@v0.35.5...v0.35.6) Updates `k8s.io/api` from 0.35.5 to 0.35.6 - [Commits](kubernetes/api@v0.35.5...v0.35.6) Updates `k8s.io/apiextensions-apiserver` from 0.35.5 to 0.35.6 - [Release notes](https://github.com/kubernetes/apiextensions-apiserver/releases) - [Commits](kubernetes/apiextensions-apiserver@v0.35.5...v0.35.6) Updates `k8s.io/apimachinery` from 0.35.5 to 0.35.6 - [Commits](kubernetes/apimachinery@v0.35.5...v0.35.6) --- updated-dependencies: - dependency-name: k8s.io/api dependency-version: 0.35.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: kubernetes - dependency-name: k8s.io/api dependency-version: 0.35.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: kubernetes - dependency-name: k8s.io/api dependency-version: 0.35.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: kubernetes - dependency-name: k8s.io/apiextensions-apiserver dependency-version: 0.35.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: kubernetes - dependency-name: k8s.io/apimachinery dependency-version: 0.35.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: kubernetes - dependency-name: k8s.io/apimachinery dependency-version: 0.35.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: kubernetes - dependency-name: k8s.io/apimachinery dependency-version: 0.35.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: kubernetes - dependency-name: k8s.io/client-go dependency-version: 0.35.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: kubernetes - dependency-name: k8s.io/component-base dependency-version: 0.35.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: kubernetes ... Signed-off-by: dependabot[bot] <support@github.com>
The EndBug's step needs the persisted credentials to make the push. Signed-off-by: Tuomo Tanskanen <tuomo.tanskanen@est.tech>
…s/main/github.com/onsi/ginkgo/v2-2.31.0 🌱 Bump github.com/onsi/ginkgo/v2 from 2.29.0 to 2.31.0
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.29.0 to 2.32.0. - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](onsi/ginkgo@v2.29.0...v2.32.0) --- updated-dependencies: - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.31.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
…s/test/main/github.com/onsi/ginkgo/v2-2.31.0 🌱 Bump github.com/onsi/ginkgo/v2 from 2.29.0 to 2.32.0 in /test
…ild-step 🌱 fix dependabots build workflop step
🌱 Set cooldown days to 3 for dependabot
…s/main/kubernetes-30dfab687a 🌱 Bump the kubernetes group to v0.35.6
🌱 e2e: decouple systemrescue and cirros downloads
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.41.0 to 1.42.0. - [Release notes](https://github.com/onsi/gomega/releases) - [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md) - [Commits](onsi/gomega@v1.41.0...v1.42.0) --- updated-dependencies: - dependency-name: github.com/onsi/gomega dependency-version: 1.42.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/moby/moby/api](https://github.com/moby/moby) from 1.54.2 to 1.55.0. - [Release notes](https://github.com/moby/moby/releases) - [Commits](moby/moby@api/v1.54.2...api/v1.55.0) --- updated-dependencies: - dependency-name: github.com/moby/moby/api dependency-version: 1.55.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
…guards 🐛 Fix webhook state guard status checks
…l-bmo 🌱 Remove mariadb-image from run_local_ironic.sh
…s/main/github.com/onsi/gomega-1.42.0 🌱 Bump github.com/onsi/gomega from 1.41.0 to 1.42.0
…s/test/main/github.com/moby/moby/api-1.55.0 🌱 Bump github.com/moby/moby/api from 1.54.2 to 1.55.0 in /test
Bumps [github.com/moby/moby/client](https://github.com/moby/moby) from 0.4.1 to 0.5.0. - [Release notes](https://github.com/moby/moby/releases) - [Changelog](https://github.com/moby/moby/blob/v0.5.0/CHANGELOG.md) - [Commits](moby/moby@v0.4.1...v0.5.0) --- updated-dependencies: - dependency-name: github.com/moby/moby/client dependency-version: 0.5.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
…s/test/main/github.com/moby/moby/client-0.5.0 🌱 Bump github.com/moby/moby/client from 0.4.1 to 0.5.0 in /test
For OCI images, the checksum is embedded in the URL and GetChecksum() returns an empty string. The error message now only includes the checksum field when it is non-empty. Signed-off-by: mabulgu <mabulgu@gmail.com>
Verify that the error message omits the checksum field when provisioning of an OCI image fails. Signed-off-by: mabulgu <mabulgu@gmail.com>
Signed-off-by: smoshiur1237 <moshiur.rahman@est.tech>
Signed-off-by: Nuutti Hakala <nuutti.hakala@est.tech>
🚀 Release v0.12.5
…ts-v2 ✨ Implement structured logging pattern from CAPM3
Signed-off-by: Nuutti Hakala <nuutti.hakala@est.tech>
The VM.xml.tpl template had two values hardcoded for Ubuntu's QEMU packages: 1. `machine='pc-q35-6.2'` — a versioned machine type that only exists in Ubuntu's QEMU. CentOS/RHEL ships different versions (`pc-q35-rhel9.*`), causing "unsupported machine type" errors. 2. `<emulator>/usr/bin/qemu-system-x86_64</emulator>` — the QEMU binary path on Ubuntu. On CentOS/RHEL it's at `/usr/libexec/qemu-kvm`. Fix: - Use the `q35` machine type alias, which QEMU resolves to the latest available q35 version on any distro. - Remove the `<emulator>` element so libvirt auto-detects the correct QEMU binary path for the host. Signed-off-by: Muhammad Adil Ghaffar <muhammad.adil.ghaffar@est.tech>
…-fix-phased-reboot-annotation-preserved 🐛 preserve phased-reboot annotations instead of deleting them on soft-reboot fallback
🚀 Release v0.13.1
…rt/adil 🌱 vbmctl: Make VM template portable across distros
…on can add a finalizer to the Secret Signed-off-by: MahnoorAsghar <masghar@redhat.com>
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.31.0 to 2.32.0. - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](onsi/ginkgo@v2.31.0...v2.32.0) --- updated-dependencies: - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.32.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
…s/main/github.com/onsi/ginkgo/v2-2.32.0 🌱 Bump github.com/onsi/ginkgo/v2 from 2.31.0 to 2.32.0
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.42.0 to 1.42.1. - [Release notes](https://github.com/onsi/gomega/releases) - [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md) - [Commits](onsi/gomega@v1.42.0...v1.42.1) --- updated-dependencies: - dependency-name: github.com/onsi/gomega dependency-version: 1.42.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.42.0 to 1.42.1. - [Release notes](https://github.com/onsi/gomega/releases) - [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md) - [Commits](onsi/gomega@v1.42.0...v1.42.1) --- updated-dependencies: - dependency-name: github.com/onsi/gomega dependency-version: 1.42.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
…s/main/github.com/onsi/gomega-1.42.1 🌱 Bump github.com/onsi/gomega from 1.42.0 to 1.42.1
…s/test/main/github.com/onsi/gomega-1.42.1 🌱 Bump github.com/onsi/gomega from 1.42.0 to 1.42.1 in /test
…Data 🌱 Rename getSecretData() to getSecretDataWithFinalizer()
🐛 Restore delete permission on secrets
WalkthroughThis PR standardizes structured logging via new verbosity/field constants applied across BareMetalHost, HostFirmwareSettings, and HostFirmwareComponents controllers and main.go, adjusts reboot-annotation cleanup, secret-finalizer handling, HardwareData creation during deletion, webhook validation gating, an Ironic error message, RBAC secrets delete permission, plus dependency bumps and tooling/CI/template updates. ChangesStructured Logging and Controller Behavior
Dependency Bumps, CI/Tooling, and Templates
Estimated code review effort: 4 (Complex) | ~60 minutes Sequence Diagram(s)sequenceDiagram
participant Reconcile
participant clearRebootAnnotations
participant HostAnnotations
Reconcile->>clearRebootAnnotations: host with reboot annotations
clearRebootAnnotations->>HostAnnotations: delete base reboot annotation only
clearRebootAnnotations-->>Reconcile: dirty flag, suffixed annotations retained
sequenceDiagram
participant Controller
participant SecretManager
participant Secret
Controller->>SecretManager: getSecretDataWithFinalizer(addFinalizer)
SecretManager->>Secret: ObtainSecretWithFinalizer
Secret-->>SecretManager: secret data or NoDataInSecretError
SecretManager-->>Controller: data / error
Related Issues: Not specified in the diff. Related PRs: Not specified in the diff. Suggested labels: dependencies, logging, ok-to-test Suggested reviewers: dtantsur, zaneb, hardys 🐰 A rabbit hops through logs anew, Important Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional. ❌ Failed checks (1 error, 1 warning)
✅ Passed checks (13 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: dtantsur The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
There was a problem hiding this comment.
Actionable comments posted: 6
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
hack/ci-e2e.sh (1)
102-123: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick winPin the downloaded boot artifacts by digest.
These files are fetched at runtime and then used directly in the e2e boot path, but the new SystemRescue ISO and the IPA tarball are not verified against pinned digests. That makes CI trust whatever those endpoints serve on the day of the run.
🔐 Example hardening
ISO_FILE="systemrescue-11.00-amd64.iso" +ISO_FILE_SHA256="<published-systemrescue-sha256>" ... IPA_FILE="ipa-centos9-master.tar.gz" +IPA_FILE_SHA256="<published-ipa-sha256>" if [[ ! -f "${IMAGE_DIR}/${ISO_FILE}" ]]; then wget --quiet -P "${IMAGE_DIR}/" https://artifactory.nordix.org/artifactory/metal3/images/sysrescue/"${ISO_FILE}" fi +printf '%s %s\n' "${ISO_FILE_SHA256}" "${IMAGE_DIR}/${ISO_FILE}" | sha256sum -c - ... if [[ ! -f "${IMAGE_DIR}/${IPA_FILE}" ]]; then wget --quiet -P "${IMAGE_DIR}/" "${IPA_BASEURI}/${IPA_FILE}" fi +printf '%s %s\n' "${IPA_FILE_SHA256}" "${IMAGE_DIR}/${IPA_FILE}" | sha256sum -c -As per coding guidelines, "Pin external dependencies by SHA (containers, GitHub Actions, binaries)".
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@hack/ci-e2e.sh` around lines 102 - 123, The boot artifact downloads in ci-e2e.sh are trusted at fetch time but not verified, so pin both the SystemRescue ISO and the IPA tarball by digest. Update the download flow around IMAGE_FILE, ISO_FILE, IPA_FILE, and IPA_BASEURI to add fixed SHA256 values and verify each file after wget completes before it is used in e2e boot tests. Ensure the script fails fast if the checksum does not match, rather than proceeding with an unverified artifact.Source: Coding guidelines
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@internal/controller/metal3.io/baremetalhost_controller.go`:
- Around line 1908-1909: The DataImage attachment logs in
baremetalhost_controller should not emit requestedURL/DataImage.Spec.URL because
it may expose internal hostnames or signed credentials. Update the logging in
the DataImage attach flow around the info.log.V(...).Info calls to log the
DataImage object identity instead (for example name/namespace or another
non-sensitive identifier) and remove the URL from the message/fields. Apply the
same fix to the related DataImage logging block later in the controller so all
DataImage log statements use the safe identifier consistently.
- Around line 2607-2615: The event logging in BareMetalHost controller is
duplicating the raw Event message, which can expose sensitive provisioner or
user-supplied data. Update the logging in the event publish/error path around
the event creation call in the baremetalhost controller to stop including the
event message field and rely on the event reason plus error details only. Keep
the existing reqLogger.V(...).Info calls and LogFieldReason/LogFieldError usage,
but remove any direct logging of event.Message.
- Around line 465-470: The reboot annotation parse-failure handling in
BareMetalHostController is logging a user-controlled payload, so remove the raw
annotation value from both the InvalidAnnotationValue event and the info.log
call. Keep the failure context in the same error path by reporting that the
reboot annotation was invalid JSON and that soft-reboot is assumed, but only
include non-sensitive metadata such as the parse error from json.Unmarshal and
omit annotation content entirely.
In `@internal/controller/metal3.io/host_state_machine.go`:
- Line 590: Keep the retry-exhaustion cleanup/power-off messages in
HostStateMachine at info level, not debug. In host_state_machine.go, update the
logging in the cleanup/power-off retry paths around the existing info.log.Info
calls so the “giving up after 3 attempts” and similar fallback notices remain
visible in production, and do not move them to V(VerbosityLevelDebug).
In `@internal/webhooks/metal3.io/v1alpha1/baremetalhost_validation.go`:
- Around line 120-124: The Available-state gate in the externall yProvisioned
validation is using the wrong boolean condition and only rejects when both old
and new provisioning states are non-Available. Update the check in
baremetalhost_validation.go so the validation in the same code path as the
StateAvailable comparison requires both oldObj.Status.Provisioning.State and
newObj.Status.Provisioning.State to be StateAvailable before allowing the field
change. Keep the existing error path in the validation function, but adjust the
condition and any error context to reflect the actual state being validated.
- Around line 107-110: The BMC address update guard in validateBMCAddressChange
is using the wrong registering check: it currently allows the update when only
one side is Registering because the oldObj.Status.Provisioning.State and
newObj.Status.Provisioning.State checks are combined with &&. Change this
condition so the update is allowed only when both the old and new objects are in
the Registering state, while still preserving the existing detached-state
exception in the same validation path.
---
Outside diff comments:
In `@hack/ci-e2e.sh`:
- Around line 102-123: The boot artifact downloads in ci-e2e.sh are trusted at
fetch time but not verified, so pin both the SystemRescue ISO and the IPA
tarball by digest. Update the download flow around IMAGE_FILE, ISO_FILE,
IPA_FILE, and IPA_BASEURI to add fixed SHA256 values and verify each file after
wget completes before it is used in e2e boot tests. Ensure the script fails fast
if the checksum does not match, rather than proceeding with an unverified
artifact.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 78269839-2001-4195-9785-5766978616ba
⛔ Files ignored due to path filters (105)
apis/go.sumis excluded by!**/*.sumapis/vendor/modules.txtis excluded by!**/vendor/**go.sumis excluded by!**/*.sumhack/tools/go.sumis excluded by!**/*.sumhack/tools/vendor/modules.txtis excluded by!**/vendor/**test/go.sumis excluded by!**/*.sumtest/vendor/github.com/moby/moby/api/types/image/attestation.gois excluded by!**/vendor/**test/vendor/github.com/moby/moby/client/client.gois excluded by!**/vendor/**test/vendor/github.com/moby/moby/client/client_interfaces.gois excluded by!**/vendor/**test/vendor/github.com/moby/moby/client/image_attestations.gois excluded by!**/vendor/**test/vendor/github.com/moby/moby/client/image_attestations_opts.gois excluded by!**/vendor/**test/vendor/github.com/onsi/ginkgo/v2/CHANGELOG.mdis excluded by!**/vendor/**test/vendor/github.com/onsi/ginkgo/v2/README.mdis excluded by!**/vendor/**test/vendor/github.com/onsi/ginkgo/v2/core_dsl.gois excluded by!**/vendor/**test/vendor/github.com/onsi/ginkgo/v2/ginkgo/run/run_command.gois excluded by!**/vendor/**test/vendor/github.com/onsi/ginkgo/v2/ginkgo/watch/watch_command.gois excluded by!**/vendor/**test/vendor/github.com/onsi/ginkgo/v2/internal/global/init.gois excluded by!**/vendor/**test/vendor/github.com/onsi/ginkgo/v2/internal/suite.gois excluded by!**/vendor/**test/vendor/github.com/onsi/ginkgo/v2/reporters/default_reporter.gois excluded by!**/vendor/**test/vendor/github.com/onsi/ginkgo/v2/types/config.gois excluded by!**/vendor/**test/vendor/github.com/onsi/ginkgo/v2/types/errors.gois excluded by!**/vendor/**test/vendor/github.com/onsi/ginkgo/v2/types/version.gois excluded by!**/vendor/**test/vendor/github.com/onsi/gomega/CHANGELOG.mdis excluded by!**/vendor/**test/vendor/github.com/onsi/gomega/README.mdis excluded by!**/vendor/**test/vendor/github.com/onsi/gomega/gomega_dsl.gois excluded by!**/vendor/**test/vendor/golang.org/x/crypto/cryptobyte/asn1.gois excluded by!**/vendor/**test/vendor/golang.org/x/crypto/cryptobyte/asn1/asn1.gois excluded by!**/vendor/**test/vendor/golang.org/x/crypto/cryptobyte/builder.gois excluded by!**/vendor/**test/vendor/golang.org/x/crypto/cryptobyte/string.gois excluded by!**/vendor/**test/vendor/golang.org/x/crypto/ssh/channel.gois excluded by!**/vendor/**test/vendor/golang.org/x/crypto/ssh/client.gois excluded by!**/vendor/**test/vendor/golang.org/x/crypto/ssh/client_auth.gois excluded by!**/vendor/**test/vendor/golang.org/x/crypto/ssh/connection.gois excluded by!**/vendor/**test/vendor/golang.org/x/crypto/ssh/control.gois excluded by!**/vendor/**test/vendor/golang.org/x/crypto/ssh/kex.gois excluded by!**/vendor/**test/vendor/golang.org/x/crypto/ssh/keys.gois excluded by!**/vendor/**test/vendor/golang.org/x/crypto/ssh/mux.gois excluded by!**/vendor/**test/vendor/golang.org/x/crypto/ssh/server.gois excluded by!**/vendor/**test/vendor/golang.org/x/crypto/ssh/session.gois excluded by!**/vendor/**test/vendor/golang.org/x/net/html/entity.gois excluded by!**/vendor/**test/vendor/golang.org/x/net/html/escape.gois excluded by!**/vendor/**test/vendor/golang.org/x/net/html/foreign.gois excluded by!**/vendor/**test/vendor/golang.org/x/net/html/parse.gois excluded by!**/vendor/**test/vendor/golang.org/x/net/html/token.gois excluded by!**/vendor/**test/vendor/golang.org/x/net/http2/server_wrap.gois excluded by!**/vendor/**test/vendor/golang.org/x/net/http2/transport_wrap.gois excluded by!**/vendor/**test/vendor/golang.org/x/sync/errgroup/errgroup.gois excluded by!**/vendor/**test/vendor/golang.org/x/tools/go/ast/edge/edge.gois excluded by!**/vendor/**test/vendor/golang.org/x/tools/go/packages/golist.gois excluded by!**/vendor/**test/vendor/golang.org/x/tools/go/packages/packages.gois excluded by!**/vendor/**test/vendor/golang.org/x/tools/go/types/objectpath/objectpath.gois excluded by!**/vendor/**test/vendor/golang.org/x/tools/internal/gcimporter/ureader.gois excluded by!**/vendor/**test/vendor/golang.org/x/tools/internal/gocommand/version.gois excluded by!**/vendor/**test/vendor/k8s.io/apimachinery/pkg/api/validation/objectmeta.gois excluded by!**/vendor/**test/vendor/modules.txtis excluded by!**/vendor/**test/vendor/sigs.k8s.io/cluster-api/internal/controllers/topology/machineset/machineset_controller.gois excluded by!**/vendor/**test/vendor/sigs.k8s.io/cluster-api/test/framework/bootstrap/kind_provider.gois excluded by!**/vendor/**test/vendor/sigs.k8s.io/cluster-api/test/infrastructure/kind/mapper.gois excluded by!**/vendor/**vendor/github.com/onsi/ginkgo/v2/CHANGELOG.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/README.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/core_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/run/run_command.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/watch/watch_command.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/internal/global/init.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/internal/suite.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/reporters/default_reporter.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/config.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/errors.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/version.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/CHANGELOG.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/README.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/gomega_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/entity.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/escape.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/foreign.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/parse.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/token.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/server_wrap.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/transport_wrap.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sync/errgroup/errgroup.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sync/singleflight/singleflight.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_386.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_amd64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_arm.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_loong64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_mips.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_mips64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_mips64le.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_mipsle.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_ppc.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_ppc64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_ppc64le.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_riscv64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_s390x.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_sparc64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/edge/edge.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/packages/golist.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/packages/packages.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/types/objectpath/objectpath.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gcimporter/ureader.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gocommand/version.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/apimachinery/pkg/api/validation/objectmeta.gois excluded by!**/vendor/**,!vendor/**vendor/modules.txtis excluded by!**/vendor/**,!vendor/**
📒 Files selected for processing (25)
.zizmor.ymlapis/go.modconfig/base/rbac/role.yamlgo.modhack/ci-e2e.shhack/tools/go.modinternal/controller/metal3.io/action_result.gointernal/controller/metal3.io/baremetalhost_controller.gointernal/controller/metal3.io/baremetalhost_controller_test.gointernal/controller/metal3.io/host_config_data.gointernal/controller/metal3.io/host_state_machine.gointernal/controller/metal3.io/hostfirmwarecomponents_controller.gointernal/controller/metal3.io/hostfirmwaresettings_controller.gointernal/controller/metal3.io/logging.gointernal/webhooks/metal3.io/v1alpha1/baremetalhost_validation.gointernal/webhooks/metal3.io/v1alpha1/baremetalhost_validation_test.gomain.gomain_test.gopkg/provisioner/ironic/ironic.gopkg/provisioner/ironic/provision_test.goreleasenotes/v0.12.5.mdreleasenotes/v0.13.1.mdtest/go.modtest/vbmctl/pkg/libvirt/templates/VM.xml.tpltools/run_local_ironic.sh
| err := json.Unmarshal([]byte(annotation), &result) | ||
| if err != nil { | ||
| info.publishEvent("InvalidAnnotationValue", fmt.Sprintf("could not parse reboot annotation (%s) - invalid json, assuming soft-reboot", annotation)) | ||
| info.log.Info(fmt.Sprintf("Could not parse reboot annotation (%q) - invalid json, assuming soft-reboot", annotation)) | ||
| info.log.Info("could not parse reboot annotation, assuming soft-reboot", | ||
| LogFieldAnnotationValue, annotation, | ||
| LogFieldError, err.Error()) |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
Avoid emitting the raw reboot annotation value.
The annotation value is user-controlled and currently goes to both the Event message and controller log. Keep the parse failure context without storing the raw payload.
Proposed fix
- info.publishEvent("InvalidAnnotationValue", fmt.Sprintf("could not parse reboot annotation (%s) - invalid json, assuming soft-reboot", annotation))
+ info.publishEvent("InvalidAnnotationValue", "could not parse reboot annotation - invalid json, assuming soft-reboot")
info.log.Info("could not parse reboot annotation, assuming soft-reboot",
- LogFieldAnnotationValue, annotation,
LogFieldError, err.Error())As per coding guidelines, **/*.{go,js,ts,java,py,rb,cs,cpp,c} must flag logging that may expose passwords, tokens, PII, internal hostnames, or customer data.
📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| err := json.Unmarshal([]byte(annotation), &result) | |
| if err != nil { | |
| info.publishEvent("InvalidAnnotationValue", fmt.Sprintf("could not parse reboot annotation (%s) - invalid json, assuming soft-reboot", annotation)) | |
| info.log.Info(fmt.Sprintf("Could not parse reboot annotation (%q) - invalid json, assuming soft-reboot", annotation)) | |
| info.log.Info("could not parse reboot annotation, assuming soft-reboot", | |
| LogFieldAnnotationValue, annotation, | |
| LogFieldError, err.Error()) | |
| err := json.Unmarshal([]byte(annotation), &result) | |
| if err != nil { | |
| info.publishEvent("InvalidAnnotationValue", "could not parse reboot annotation - invalid json, assuming soft-reboot") | |
| info.log.Info("could not parse reboot annotation, assuming soft-reboot", | |
| LogFieldError, err.Error()) |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@internal/controller/metal3.io/baremetalhost_controller.go` around lines 465 -
470, The reboot annotation parse-failure handling in BareMetalHostController is
logging a user-controlled payload, so remove the raw annotation value from both
the InvalidAnnotationValue event and the info.log call. Keep the failure context
in the same error path by reporting that the reboot annotation was invalid JSON
and that soft-reboot is assumed, but only include non-sensitive metadata such as
the parse error from json.Unmarshal and omit annotation content entirely.
Source: Coding guidelines
| info.log.V(VerbosityLevelDebug).Info("attaching DataImage", | ||
| LogFieldDataImage, requestedURL) |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
Do not log the DataImage URL.
DataImage.Spec.URL can contain internal hostnames or signed URL credentials. Log the DataImage object identity instead.
Proposed fix
info.log.V(VerbosityLevelDebug).Info("attaching DataImage",
- LogFieldDataImage, requestedURL)
+ "dataImageName", dataImage.Name) info.log.Info("error while attaching DataImage",
- LogFieldDataImage, dataImage.Spec.URL,
+ "dataImageName", dataImage.Name,
LogFieldError, err.Error())As per coding guidelines, **/*.{go,js,ts,java,py,rb,cs,cpp,c} must flag logging that may expose passwords, tokens, PII, internal hostnames, or customer data.
Also applies to: 1951-1954
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@internal/controller/metal3.io/baremetalhost_controller.go` around lines 1908
- 1909, The DataImage attachment logs in baremetalhost_controller should not
emit requestedURL/DataImage.Spec.URL because it may expose internal hostnames or
signed credentials. Update the logging in the DataImage attach flow around the
info.log.V(...).Info calls to log the DataImage object identity instead (for
example name/namespace or another non-sensitive identifier) and remove the URL
from the message/fields. Apply the same fix to the related DataImage logging
block later in the controller so all DataImage log statements use the safe
identifier consistently.
Source: Coding guidelines
| reqLogger.V(VerbosityLevelDebug).Info("publishing event", | ||
| LogFieldReason, event.Reason, | ||
| "message", event.Message) | ||
| err := r.Create(ctx, &event) | ||
| if err != nil { | ||
| reqLogger.Info("failed to record event, ignoring", | ||
| "reason", event.Reason, "message", event.Message, "error", err) | ||
| reqLogger.V(VerbosityLevelDebug).Info("failed to record event, ignoring", | ||
| LogFieldReason, event.Reason, | ||
| "message", event.Message, | ||
| LogFieldError, err) |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
Avoid duplicating raw Event messages into logs.
Event messages can include provisioner errors and user-supplied values. Logging the reason and error is enough here.
Proposed fix
reqLogger.V(VerbosityLevelDebug).Info("publishing event",
- LogFieldReason, event.Reason,
- "message", event.Message)
+ LogFieldReason, event.Reason)
err := r.Create(ctx, &event)
if err != nil {
reqLogger.V(VerbosityLevelDebug).Info("failed to record event, ignoring",
LogFieldReason, event.Reason,
- "message", event.Message,
LogFieldError, err)
}As per coding guidelines, **/*.{go,js,ts,java,py,rb,cs,cpp,c} must flag logging that may expose passwords, tokens, PII, internal hostnames, or customer data.
📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| reqLogger.V(VerbosityLevelDebug).Info("publishing event", | |
| LogFieldReason, event.Reason, | |
| "message", event.Message) | |
| err := r.Create(ctx, &event) | |
| if err != nil { | |
| reqLogger.Info("failed to record event, ignoring", | |
| "reason", event.Reason, "message", event.Message, "error", err) | |
| reqLogger.V(VerbosityLevelDebug).Info("failed to record event, ignoring", | |
| LogFieldReason, event.Reason, | |
| "message", event.Message, | |
| LogFieldError, err) | |
| reqLogger.V(VerbosityLevelDebug).Info("publishing event", | |
| LogFieldReason, event.Reason) | |
| err := r.Create(ctx, &event) | |
| if err != nil { | |
| reqLogger.V(VerbosityLevelDebug).Info("failed to record event, ignoring", | |
| LogFieldReason, event.Reason, | |
| LogFieldError, err) |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@internal/controller/metal3.io/baremetalhost_controller.go` around lines 2607
- 2615, The event logging in BareMetalHost controller is duplicating the raw
Event message, which can expose sensitive provisioner or user-supplied data.
Update the logging in the event publish/error path around the event creation
call in the baremetalhost controller to stop including the event message field
and rely on the event reason plus error details only. Keep the existing
reqLogger.V(...).Info calls and LogFieldReason/LogFieldError usage, but remove
any direct logging of event.Message.
Source: Coding guidelines
| if hsm.Host.Status.ErrorCount > retryCount { | ||
| info.log.Info("Giving up on host clean up after 3 attempts. The host may still be operational " + | ||
| "and cause issues in your clusters. You should clean it up manually now.") | ||
| info.log.Info("giving up on host clean up after 3 attempts, the host may still be operational and cause issues in your clusters - clean it up manually") |
There was a problem hiding this comment.
🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
Keep retry-exhaustion logs at Info.
These are the only visible signals that cleanup/power-off was abandoned and the host may still need manual intervention. Moving them to V(VerbosityLevelDebug) makes that fallback easy to miss in production.
🔧 Proposed fix
- info.log.V(VerbosityLevelDebug).Info("giving up on host clean up after 3 attempts, the host may still be operational and cause issues in your clusters - clean it up manually")
+ info.log.Info("giving up on host clean up after 3 attempts, the host may still be operational and cause issues in your clusters - clean it up manually")
...
- info.log.V(VerbosityLevelDebug).Info("giving up on host power off after 3 attempts")
+ info.log.Info("giving up on host power off after 3 attempts")Also applies to: 626-626
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@internal/controller/metal3.io/host_state_machine.go` at line 590, Keep the
retry-exhaustion cleanup/power-off messages in HostStateMachine at info level,
not debug. In host_state_machine.go, update the logging in the cleanup/power-off
retry paths around the existing info.log.Info calls so the “giving up after 3
attempts” and similar fallback notices remain visible in production, and do not
move them to V(VerbosityLevelDebug).
| oldObj.Status.OperationalStatus != metal3api.OperationalStatusDetached && | ||
| newObj.Status.OperationalStatus != metal3api.OperationalStatusDetached && | ||
| oldObj.Status.Provisioning.State != metal3api.StateRegistering && | ||
| newObj.Status.Provisioning.State != metal3api.StateRegistering { |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
Require both objects to be Registering here.
Lines 109-110 still use &&, so this rejects the update only when neither object is Registering. If one side is Registering and the other is not, the BMC address change is admitted even though this rule is meant to allow it only while detached or while both sides are in the registering phase.
Proposed fix
if oldObj.Spec.BMC.Address != "" &&
newObj.Spec.BMC.Address != oldObj.Spec.BMC.Address &&
oldObj.Status.OperationalStatus != metal3api.OperationalStatusDetached &&
newObj.Status.OperationalStatus != metal3api.OperationalStatusDetached &&
- oldObj.Status.Provisioning.State != metal3api.StateRegistering &&
- newObj.Status.Provisioning.State != metal3api.StateRegistering {
+ (oldObj.Status.Provisioning.State != metal3api.StateRegistering ||
+ newObj.Status.Provisioning.State != metal3api.StateRegistering) {📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| oldObj.Status.OperationalStatus != metal3api.OperationalStatusDetached && | |
| newObj.Status.OperationalStatus != metal3api.OperationalStatusDetached && | |
| oldObj.Status.Provisioning.State != metal3api.StateRegistering && | |
| newObj.Status.Provisioning.State != metal3api.StateRegistering { | |
| oldObj.Status.OperationalStatus != metal3api.OperationalStatusDetached && | |
| newObj.Status.OperationalStatus != metal3api.OperationalStatusDetached && | |
| (oldObj.Status.Provisioning.State != metal3api.StateRegistering || | |
| newObj.Status.Provisioning.State != metal3api.StateRegistering) { |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@internal/webhooks/metal3.io/v1alpha1/baremetalhost_validation.go` around
lines 107 - 110, The BMC address update guard in validateBMCAddressChange is
using the wrong registering check: it currently allows the update when only one
side is Registering because the oldObj.Status.Provisioning.State and
newObj.Status.Provisioning.State checks are combined with &&. Change this
condition so the update is allowed only when both the old and new objects are in
the Registering state, while still preserving the existing detached-state
exception in the same validation path.
| oldObj.Status.Provisioning.State != metal3api.StateAvailable && | ||
| newObj.Status.Provisioning.State != metal3api.StateAvailable { | ||
| errs = append(errs, fmt.Errorf( | ||
| "externallyProvisioned can only be enabled when in Available state, currently in %s", | ||
| newObj.Status.Provisioning.State)) | ||
| oldObj.Status.Provisioning.State)) |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
The Available gate has the same boolean inversion.
Lines 120-121 only fail when both old and new states are non-Available. That means enabling externallyProvisioned still slips through when exactly one side is Available, which is weaker than the “old and new must both be Available” behavior described for this change.
Proposed fix
if !oldObj.Spec.ExternallyProvisioned && newObj.Spec.ExternallyProvisioned &&
- oldObj.Status.Provisioning.State != metal3api.StateAvailable &&
- newObj.Status.Provisioning.State != metal3api.StateAvailable {
+ (oldObj.Status.Provisioning.State != metal3api.StateAvailable ||
+ newObj.Status.Provisioning.State != metal3api.StateAvailable) {📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| oldObj.Status.Provisioning.State != metal3api.StateAvailable && | |
| newObj.Status.Provisioning.State != metal3api.StateAvailable { | |
| errs = append(errs, fmt.Errorf( | |
| "externallyProvisioned can only be enabled when in Available state, currently in %s", | |
| newObj.Status.Provisioning.State)) | |
| oldObj.Status.Provisioning.State)) | |
| if !oldObj.Spec.ExternallyProvisioned && newObj.Spec.ExternallyProvisioned && | |
| (oldObj.Status.Provisioning.State != metal3api.StateAvailable || | |
| newObj.Status.Provisioning.State != metal3api.StateAvailable) { | |
| errs = append(errs, fmt.Errorf( | |
| "externallyProvisioned can only be enabled when in Available state, currently in %s", | |
| oldObj.Status.Provisioning.State)) |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@internal/webhooks/metal3.io/v1alpha1/baremetalhost_validation.go` around
lines 120 - 124, The Available-state gate in the externall yProvisioned
validation is using the wrong boolean condition and only rejects when both old
and new provisioning states are non-Available. Update the check in
baremetalhost_validation.go so the validation in the same code path as the
StateAvailable comparison requires both oldObj.Status.Provisioning.State and
newObj.Status.Provisioning.State to be StateAvailable before allowing the field
change. Keep the existing error path in the validation function, but adjust the
condition and any error context to reflect the actual state being validated.
|
/test e2e-metal-ipi-virtualmedia |
|
@dtantsur: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
Superseded by #513 which includes all these commits plus newer upstream changes. |
|
PR needs rebase. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
cc170cf 🌱 Bump github.com/onsi/gomega from 1.42.0 to 1.42.1 in /test
048d152 🌱 Bump github.com/onsi/gomega from 1.42.0 to 1.42.1
1465718 🌱 Bump github.com/onsi/ginkgo/v2 from 2.31.0 to 2.32.0
85c6fe0 Rename getSecretData() to getSecretDataWithFinalizer(), as the function can add a finalizer to the Secret
2eb6d82 vbmctl: Make VM template portable across distros
8ef8c1b 🚀 Release v0.13.1
3ba039f 🚀 Release v0.12.5
903bb5c feat: implement structured logging pattern
9c52495 🌱 Bump github.com/onsi/gomega from 1.41.0 to 1.42.0 in /test
509c00d 🌱 Bump golang.org/x/crypto from 0.52.0 to 0.53.0 in /test
579e0cd Bump cluster-api to v1.13.3
8f9dcab Add test for OCI image provisioning failure error message
720f8c2 Omit empty checksum from provisioning error message
e13122b 🌱 Bump github.com/moby/moby/client from 0.4.1 to 0.5.0 in /test
5da9522 🌱 Bump github.com/moby/moby/api from 1.54.2 to 1.55.0 in /test
530bbef 🌱 Bump github.com/onsi/gomega from 1.41.0 to 1.42.0
b47c32a 🌱 Bump github.com/onsi/ginkgo/v2 from 2.29.0 to 2.32.0 in /test
c7fe88e fix dependabots build workflop step
921274e 🌱 Bump the kubernetes group across 3 directories with 5 updates
8ed80ca 🌱 Bump github.com/onsi/ginkgo/v2 from 2.29.0 to 2.31.0
a8f86bd 🌱 re-trigger CI (golangci-lint apis shard hit the 6h job timeout)
e5e15c7 Remove mariadb-image from run_local_ironic.sh
9bf1828 use proper IPA cache address
5623cac e2e: decouple systemrescue and cirros downloads
f0c6fe7 fix: preserve phased-reboot annotations instead of deleting them on soft-reboot fallback
c16043f Set cooldown days to 3 for dependabot
3d51494 Fix webhook state guard status checks
7288182 Restore delete permission on secrets
Summary by CodeRabbit
New Features
Bug Fixes
Chores