diff --git a/Makefile.kube_git.var b/Makefile.kube_git.var index 64a966edca..7f30953f36 100644 --- a/Makefile.kube_git.var +++ b/Makefile.kube_git.var @@ -1,5 +1,5 @@ KUBE_GIT_MAJOR=1 KUBE_GIT_MINOR=36 -KUBE_GIT_VERSION=v1.36.2 -KUBE_GIT_COMMIT=98b35193b2ac7a23a673325f5e9b830ecd5ba406 +KUBE_GIT_VERSION=v1.36.3 +KUBE_GIT_COMMIT=7b29fb077260554429dcef8234272e9fd25fcfbd KUBE_GIT_TREE_STATE=clean diff --git a/Makefile.version.aarch64.var b/Makefile.version.aarch64.var index 1b287e6e86..0f583f71c0 100644 --- a/Makefile.version.aarch64.var +++ b/Makefile.version.aarch64.var @@ -1 +1 @@ -OCP_VERSION := 5.0.0-0.nightly-arm64-2026-07-27-004356 +OCP_VERSION := 5.1.0-0.nightly-arm64-2026-08-21-025249 diff --git a/Makefile.version.x86_64.var b/Makefile.version.x86_64.var index cf840335be..c29fb43878 100644 --- a/Makefile.version.x86_64.var +++ b/Makefile.version.x86_64.var @@ -1 +1 @@ -OCP_VERSION := 5.0.0-0.nightly-2026-07-23-224236 +OCP_VERSION := 5.1.0-0.nightly-2026-08-20-065836 diff --git a/assets/components/multus/kustomization.aarch64.yaml b/assets/components/multus/kustomization.aarch64.yaml index 2df3672ef8..af468b1fa1 100644 --- a/assets/components/multus/kustomization.aarch64.yaml +++ b/assets/components/multus/kustomization.aarch64.yaml @@ -2,7 +2,7 @@ images: - name: multus-cni-microshift newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:a0c089dbbd138b47d7467ce50d0ea3eff60bff9674a34d429078118eeabb78a3 + digest: sha256:6936d3ebc0a49d4b738d1e293260453ea1fe399e9f20e6dd0a29146b735fdcaa - name: containernetworking-plugins-microshift newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:1557d1200e7c7c8672f9cd9fa145874d43967f61f798f27894f643d5b857b99a + digest: sha256:778ced6e2bc8daa303e2267a8ddbac4987a7c4f9b1b127a215f364da7523ea7c diff --git a/assets/components/multus/kustomization.x86_64.yaml b/assets/components/multus/kustomization.x86_64.yaml index 234e0862de..39ff68d5fb 100644 --- a/assets/components/multus/kustomization.x86_64.yaml +++ b/assets/components/multus/kustomization.x86_64.yaml @@ -2,7 +2,7 @@ images: - name: multus-cni-microshift newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:29f31422d6d637e350f99a58001ef8929cb151497ccc4d4f128d3b408812f635 + digest: sha256:8bc05b935cbe9b205a725ae907fc06f50060c0707684dd09b911afa199b58bdf - name: containernetworking-plugins-microshift newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:c63df61df4155fb06d9da879bb7d0e96b5e34161e1ad78e43e87d0690fcae29a + digest: sha256:a66440a99b400344814a10a81ffb704dbc5cae63de9c20938edacb88575ab796 diff --git a/assets/components/multus/release-multus-aarch64.json b/assets/components/multus/release-multus-aarch64.json index da7ab1020d..08e0c04319 100644 --- a/assets/components/multus/release-multus-aarch64.json +++ b/assets/components/multus/release-multus-aarch64.json @@ -1,9 +1,9 @@ { "release": { - "base": "5.0.0-0.nightly-arm64-2026-07-27-004356" + "base": "5.1.0-0.nightly-arm64-2026-08-21-025249" }, "images": { - "multus-cni-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:a0c089dbbd138b47d7467ce50d0ea3eff60bff9674a34d429078118eeabb78a3", - "containernetworking-plugins-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:1557d1200e7c7c8672f9cd9fa145874d43967f61f798f27894f643d5b857b99a" + "multus-cni-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:6936d3ebc0a49d4b738d1e293260453ea1fe399e9f20e6dd0a29146b735fdcaa", + "containernetworking-plugins-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:778ced6e2bc8daa303e2267a8ddbac4987a7c4f9b1b127a215f364da7523ea7c" } } diff --git a/assets/components/multus/release-multus-x86_64.json b/assets/components/multus/release-multus-x86_64.json index eee6612c5f..397289b12f 100644 --- a/assets/components/multus/release-multus-x86_64.json +++ b/assets/components/multus/release-multus-x86_64.json @@ -1,9 +1,9 @@ { "release": { - "base": "5.0.0-0.nightly-2026-07-23-224236" + "base": "5.1.0-0.nightly-2026-08-20-065836" }, "images": { - "multus-cni-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:29f31422d6d637e350f99a58001ef8929cb151497ccc4d4f128d3b408812f635", - "containernetworking-plugins-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:c63df61df4155fb06d9da879bb7d0e96b5e34161e1ad78e43e87d0690fcae29a" + "multus-cni-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:8bc05b935cbe9b205a725ae907fc06f50060c0707684dd09b911afa199b58bdf", + "containernetworking-plugins-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:a66440a99b400344814a10a81ffb704dbc5cae63de9c20938edacb88575ab796" } } diff --git a/assets/components/openshift-router/deployment.yaml b/assets/components/openshift-router/deployment.yaml index 39b76ed0a5..1aa2bd7faa 100644 --- a/assets/components/openshift-router/deployment.yaml +++ b/assets/components/openshift-router/deployment.yaml @@ -248,7 +248,7 @@ spec: startupProbe: failureThreshold: 120 httpGet: - path: /healthz/ready + path: /healthz port: 1936 scheme: HTTP periodSeconds: 1 diff --git a/assets/components/service-ca/deployment.yaml b/assets/components/service-ca/deployment.yaml index f51d49b47d..a9dfd43a7a 100644 --- a/assets/components/service-ca/deployment.yaml +++ b/assets/components/service-ca/deployment.yaml @@ -29,6 +29,8 @@ spec: image: '{{ .ReleaseImage.service_ca_operator }}' imagePullPolicy: IfNotPresent command: ["service-ca-operator", "controller"] + args: + - -v=2 ports: - containerPort: 8443 securityContext: @@ -45,8 +47,8 @@ spec: name: signing-key - mountPath: /var/run/configmaps/signing-cabundle name: signing-cabundle - args: - - -v=2 + - mountPath: /var/run/configmaps/config + name: config volumes: - name: signing-key secret: @@ -54,6 +56,9 @@ spec: - name: signing-cabundle configMap: name: '{{.CAConfigMap}}' + - name: config + configMap: + name: service-ca-controller-config nodeSelector: node-role.kubernetes.io/master: "" priorityClassName: "system-cluster-critical" diff --git a/assets/crd/route.crd.yaml b/assets/crd/route.crd.yaml index b0c3b33e7d..f923ec9ae1 100644 --- a/assets/crd/route.crd.yaml +++ b/assets/crd/route.crd.yaml @@ -558,13 +558,13 @@ spec: - termination type: object x-kubernetes-validations: - - message: cannot have both spec.tls.certificate and spec.tls.externalCertificate - rule: '!(has(self.certificate) && has(self.externalCertificate))' - message: 'cannot have both spec.tls.termination: passthrough and spec.tls.insecureEdgeTerminationPolicy: Allow' rule: 'has(self.termination) && has(self.insecureEdgeTerminationPolicy) ? !((self.termination==''passthrough'') && (self.insecureEdgeTerminationPolicy==''Allow'')) : true' + - message: cannot have both spec.tls.certificate and spec.tls.externalCertificate + rule: '!(has(self.certificate) && has(self.externalCertificate))' to: description: |- to is an object the route should use as the primary backend. Only the Service kind diff --git a/assets/optional/ai-model-serving/release-ai-model-serving-x86_64.json b/assets/optional/ai-model-serving/release-ai-model-serving-x86_64.json index 3ede9bcebf..a3e0977f6e 100644 --- a/assets/optional/ai-model-serving/release-ai-model-serving-x86_64.json +++ b/assets/optional/ai-model-serving/release-ai-model-serving-x86_64.json @@ -1,6 +1,6 @@ { "release": { - "base": "2.25.9" + "base": "2.25.10" }, "images": { "ray-tls-generator-image": "registry.redhat.io/ubi9/ubi-minimal:latest", diff --git a/assets/optional/operator-lifecycle-manager/0000_50_olm_01-networkpolicies.yaml b/assets/optional/operator-lifecycle-manager/0000_50_olm_01-networkpolicies.yaml index c991681f8d..fead054ab1 100644 --- a/assets/optional/operator-lifecycle-manager/0000_50_olm_01-networkpolicies.yaml +++ b/assets/optional/operator-lifecycle-manager/0000_50_olm_01-networkpolicies.yaml @@ -103,3 +103,49 @@ spec: - {} egress: - {} +--- +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: olm-catalog-grpc-ingress + namespace: openshift-marketplace + annotations: + include.release.openshift.io/ibm-cloud-managed: "true" + include.release.openshift.io/self-managed-high-availability: "true" + capability.openshift.io/name: "OperatorLifecycleManager" + include.release.openshift.io/hypershift: "true" +spec: + podSelector: + matchExpressions: + - key: olm.catalogSource + operator: Exists + policyTypes: + - Ingress + ingress: + - ports: + - protocol: TCP + port: 50051 +--- +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: bundle-unpack-egress + namespace: openshift-marketplace + annotations: + include.release.openshift.io/ibm-cloud-managed: "true" + include.release.openshift.io/self-managed-high-availability: "true" + capability.openshift.io/name: "OperatorLifecycleManager" + include.release.openshift.io/hypershift: "true" +spec: + podSelector: + matchExpressions: + - key: operatorframework.io/bundle-unpack-ref + operator: Exists + - key: olm.managed + operator: In + values: + - "true" + policyTypes: + - Egress + egress: + - {} diff --git a/assets/optional/operator-lifecycle-manager/kustomization.aarch64.yaml b/assets/optional/operator-lifecycle-manager/kustomization.aarch64.yaml index cec9490c75..8d1647fe3c 100644 --- a/assets/optional/operator-lifecycle-manager/kustomization.aarch64.yaml +++ b/assets/optional/operator-lifecycle-manager/kustomization.aarch64.yaml @@ -2,13 +2,13 @@ images: - name: quay.io/operator-framework/olm newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:c8eebdd593891b886d0fb2fc554b2cbcf39c77c57c8582b72c9647cf9e0f8684 + digest: sha256:3bc1586472de2808a12b80bfe6595b977a33c16c5fa0413c6d421bcdf89e2f1c - name: quay.io/operator-framework/configmap-operator-registry newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:823e379c09c3e2c566efe5c95f91134eb4170643fe2ba5633bcd382738cc841c + digest: sha256:853f8544641e2875ee7167977f01c60fc63c36b2518cb87e4b09dc1692d223c3 - name: quay.io/openshift/origin-kube-rbac-proxy newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:fc51b97845de29e7a245f185d31ff8adb2c7b7a5350686876a700104499ae2f5 + digest: sha256:df64843344fa7bb71f4ab5a0abdb48c4c2c2b6d8bd5732028903d5eae3251527 patches: - patch: |- @@ -16,12 +16,12 @@ patches: path: /spec/template/spec/containers/0/env/- value: name: OPERATOR_REGISTRY_IMAGE - value: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:823e379c09c3e2c566efe5c95f91134eb4170643fe2ba5633bcd382738cc841c + value: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:853f8544641e2875ee7167977f01c60fc63c36b2518cb87e4b09dc1692d223c3 - op: add path: /spec/template/spec/containers/0/env/- value: name: OLM_IMAGE - value: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:c8eebdd593891b886d0fb2fc554b2cbcf39c77c57c8582b72c9647cf9e0f8684 + value: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:3bc1586472de2808a12b80bfe6595b977a33c16c5fa0413c6d421bcdf89e2f1c target: kind: Deployment labelSelector: app=catalog-operator diff --git a/assets/optional/operator-lifecycle-manager/kustomization.x86_64.yaml b/assets/optional/operator-lifecycle-manager/kustomization.x86_64.yaml index 139b453dee..dd50166328 100644 --- a/assets/optional/operator-lifecycle-manager/kustomization.x86_64.yaml +++ b/assets/optional/operator-lifecycle-manager/kustomization.x86_64.yaml @@ -2,13 +2,13 @@ images: - name: quay.io/operator-framework/olm newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:18957bcdaaa13c8c028b3742805b66d30d82fab2273dbeb71938844c44c5d5c5 + digest: sha256:4a528ac0df56212d2aba8cd5f6af80576a9f38786b90648e37f29bef077de765 - name: quay.io/operator-framework/configmap-operator-registry newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:714be6db62abadfce860b3ace30d35e63e087d9bf07ac3e667578d91e8659fcd + digest: sha256:84ab87490655d3c0b5ea6db72fdd1e7ab008842898f4420d28ab7abab6d662b2 - name: quay.io/openshift/origin-kube-rbac-proxy newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:849ba7d8ef4add8ef5841c14276f97cf9920b33bebf26ee021d72f08064e7abb + digest: sha256:01df5215d93cda24669fe9f3711223f34f674071321b3d0e7975feef702d0099 patches: - patch: |- @@ -16,12 +16,12 @@ patches: path: /spec/template/spec/containers/0/env/- value: name: OPERATOR_REGISTRY_IMAGE - value: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:714be6db62abadfce860b3ace30d35e63e087d9bf07ac3e667578d91e8659fcd + value: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:84ab87490655d3c0b5ea6db72fdd1e7ab008842898f4420d28ab7abab6d662b2 - op: add path: /spec/template/spec/containers/0/env/- value: name: OLM_IMAGE - value: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:18957bcdaaa13c8c028b3742805b66d30d82fab2273dbeb71938844c44c5d5c5 + value: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:4a528ac0df56212d2aba8cd5f6af80576a9f38786b90648e37f29bef077de765 target: kind: Deployment labelSelector: app=catalog-operator diff --git a/assets/optional/operator-lifecycle-manager/release-olm-aarch64.json b/assets/optional/operator-lifecycle-manager/release-olm-aarch64.json index fbad187d45..70ddee666c 100644 --- a/assets/optional/operator-lifecycle-manager/release-olm-aarch64.json +++ b/assets/optional/operator-lifecycle-manager/release-olm-aarch64.json @@ -1,10 +1,10 @@ { "release": { - "base": "5.0.0-0.nightly-arm64-2026-07-27-004356" + "base": "5.1.0-0.nightly-arm64-2026-08-21-025249" }, "images": { - "operator-lifecycle-manager": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:c8eebdd593891b886d0fb2fc554b2cbcf39c77c57c8582b72c9647cf9e0f8684", - "operator-registry": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:823e379c09c3e2c566efe5c95f91134eb4170643fe2ba5633bcd382738cc841c", - "kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:fc51b97845de29e7a245f185d31ff8adb2c7b7a5350686876a700104499ae2f5" + "operator-lifecycle-manager": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:3bc1586472de2808a12b80bfe6595b977a33c16c5fa0413c6d421bcdf89e2f1c", + "operator-registry": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:853f8544641e2875ee7167977f01c60fc63c36b2518cb87e4b09dc1692d223c3", + "kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:df64843344fa7bb71f4ab5a0abdb48c4c2c2b6d8bd5732028903d5eae3251527" } } diff --git a/assets/optional/operator-lifecycle-manager/release-olm-x86_64.json b/assets/optional/operator-lifecycle-manager/release-olm-x86_64.json index 2e22dd7e93..1267236d5f 100644 --- a/assets/optional/operator-lifecycle-manager/release-olm-x86_64.json +++ b/assets/optional/operator-lifecycle-manager/release-olm-x86_64.json @@ -1,10 +1,10 @@ { "release": { - "base": "5.0.0-0.nightly-2026-07-23-224236" + "base": "5.1.0-0.nightly-2026-08-20-065836" }, "images": { - "operator-lifecycle-manager": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:18957bcdaaa13c8c028b3742805b66d30d82fab2273dbeb71938844c44c5d5c5", - "operator-registry": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:714be6db62abadfce860b3ace30d35e63e087d9bf07ac3e667578d91e8659fcd", - "kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:849ba7d8ef4add8ef5841c14276f97cf9920b33bebf26ee021d72f08064e7abb" + "operator-lifecycle-manager": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:4a528ac0df56212d2aba8cd5f6af80576a9f38786b90648e37f29bef077de765", + "operator-registry": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:84ab87490655d3c0b5ea6db72fdd1e7ab008842898f4420d28ab7abab6d662b2", + "kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:01df5215d93cda24669fe9f3711223f34f674071321b3d0e7975feef702d0099" } } diff --git a/assets/optional/sriov/kustomization.aarch64.yaml b/assets/optional/sriov/kustomization.aarch64.yaml index a1cb7e606b..69a05f9551 100644 --- a/assets/optional/sriov/kustomization.aarch64.yaml +++ b/assets/optional/sriov/kustomization.aarch64.yaml @@ -1,7 +1,7 @@ images: - name: quay.io/openshift/sriov-network-operator newName: registry.redhat.io/openshift4/ose-sriov-network-rhel9-operator - digest: sha256:885ae30c9915b997e8d374ed7bed3c2e1258660b92186b04cf53b105beafeb74 + digest: sha256:b700324b4b5c6b8296ca4552cf1665acc4822d909f61a4e7b897c7793128fbda patches: - patch: |- @@ -9,47 +9,47 @@ patches: path: /spec/template/spec/containers/0/env/- value: name: SRIOV_CNI_IMAGE - value: registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:2bfab11571c1f20621fc0de872b1bba42b568a660eb4763e35f7aecffd2b8da8 + value: registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:934f162f5c6345e032adaffb2934bb36f8b3d710579768d3fceee616cf78d26f - op: add path: /spec/template/spec/containers/0/env/- value: name: SRIOV_DEVICE_PLUGIN_IMAGE - value: registry.redhat.io/openshift4/ose-sriov-network-device-plugin-rhel9@sha256:92228bbea421a820bc2dfa1b126415c83f2773bc94694dc078c65824c333155d + value: registry.redhat.io/openshift4/ose-sriov-network-device-plugin-rhel9@sha256:b0a2ab81aa26e9120962dbdfed25d9690d66b778d567a280b93e6d28f0d7de25 - op: add path: /spec/template/spec/containers/0/env/- value: name: NETWORK_RESOURCES_INJECTOR_IMAGE - value: registry.redhat.io/openshift4/ose-sriov-dp-admission-controller-rhel9@sha256:8f9b9d6bd1cd32574e2add548e5cf74f43b19818b204f90925792a516d5be4fd + value: registry.redhat.io/openshift4/ose-sriov-dp-admission-controller-rhel9@sha256:e76cd23d841a81b1fbdf019af1d33aae771b7a218ceae69a3d103872ac48fbf5 - op: add path: /spec/template/spec/containers/0/env/- value: name: SRIOV_NETWORK_CONFIG_DAEMON_IMAGE - value: registry.redhat.io/openshift4/ose-sriov-network-config-daemon-rhel9@sha256:5ea8bb5b1c3aac7bf59a3893d1d5a3152a0f8949a7e2999f6b958b1b2523ecd1 + value: registry.redhat.io/openshift4/ose-sriov-network-config-daemon-rhel9@sha256:2b3ffdbe2cfe9e57de00951a9ae3a9d6ced54528887abb04731d12fb806a2b80 - op: add path: /spec/template/spec/containers/0/env/- value: name: SRIOV_NETWORK_WEBHOOK_IMAGE - value: registry.redhat.io/openshift4/ose-sriov-network-webhook-rhel9@sha256:7081b836f20158c5514749439f0d5d04818fb16eac6e7111ffe5fca4026e0772 + value: registry.redhat.io/openshift4/ose-sriov-network-webhook-rhel9@sha256:d9719462e6e995924cb19a7974060e9e6b7b26e71bf303cb84ab395872cc5457 - op: add path: /spec/template/spec/containers/0/env/- value: name: SRIOV_INFINIBAND_CNI_IMAGE - value: registry.redhat.io/openshift4/ose-sriov-infiniband-cni-rhel9@sha256:c6e0e49baea7bc2fd7a485c03db00e625610a250f5266f54ca58af1b8d71271a + value: registry.redhat.io/openshift4/ose-sriov-infiniband-cni-rhel9@sha256:95da7b215db06cdc0475d28de84ab1ef900579f18257e4948d7999b6be44ef14 - op: add path: /spec/template/spec/containers/0/env/- value: name: RDMA_CNI_IMAGE - value: registry.redhat.io/openshift4/ose-sriov-rdma-cni-rhel9@sha256:870d98955d99b3df5f00149f750797c25149cea29dd25bfa883763779f521e8e + value: registry.redhat.io/openshift4/ose-sriov-rdma-cni-rhel9@sha256:b63caf0cb08139b825ce955aab9825bcf703d2ed4d6c87338552cf4f1a5626d1 - op: add path: /spec/template/spec/containers/0/env/- value: name: METRICS_EXPORTER_IMAGE - value: registry.redhat.io/openshift4/ose-sriov-network-metrics-exporter-rhel9@sha256:178fd1cdfb3d56cf59fb4ba952f16cb7e5bdde7cccebd6ac9845438f4f71eb62 + value: registry.redhat.io/openshift4/ose-sriov-network-metrics-exporter-rhel9@sha256:c1974679b6e3321076df5fa697f6b5674ffde54c3d159d81907d36febd04e7e9 - op: add path: /spec/template/spec/containers/0/env/- value: name: METRICS_EXPORTER_KUBE_RBAC_PROXY_IMAGE - value: registry.redhat.io/openshift4/ose-kube-rbac-proxy-rhel9@sha256:d1ad461cadefdbd635f6137f5217bf41d5eba437251af05574bcbe61c74ddb63 + value: registry.redhat.io/openshift4/ose-kube-rbac-proxy-rhel9@sha256:bef23cae77849dd5db4cca0ea831f1b113081576d4db63e1ab58203278b804c6 target: kind: Deployment name: sriov-network-operator diff --git a/assets/optional/sriov/kustomization.x86_64.yaml b/assets/optional/sriov/kustomization.x86_64.yaml index 40f8a2b17b..9d1a67231a 100644 --- a/assets/optional/sriov/kustomization.x86_64.yaml +++ b/assets/optional/sriov/kustomization.x86_64.yaml @@ -1,7 +1,7 @@ images: - name: quay.io/openshift/sriov-network-operator newName: registry.redhat.io/openshift4/ose-sriov-network-rhel9-operator - digest: sha256:d809810f02f63fd95f4587dadadf180cbd4f0397f6078567ffb63eeb52c12da9 + digest: sha256:d1aae7de925d2ae6d50bd5ea1ff6cff3737f4faa341ab410941f00d4d8ee2b72 patches: - patch: |- @@ -9,47 +9,47 @@ patches: path: /spec/template/spec/containers/0/env/- value: name: SRIOV_CNI_IMAGE - value: registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:32c884e1281ccf417a7f67afc830f0b8e9ae05f41235978a2ab81b693408dae8 + value: registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:dd1b75ccc1cb6180f0e9795f2db0f74be60bdcca985596385b8e3d1f544fc47e - op: add path: /spec/template/spec/containers/0/env/- value: name: SRIOV_DEVICE_PLUGIN_IMAGE - value: registry.redhat.io/openshift4/ose-sriov-network-device-plugin-rhel9@sha256:c91d6b38c80b660258e0701bdd25f33d308b3d3aef1ba0707c5e655bfc79eec4 + value: registry.redhat.io/openshift4/ose-sriov-network-device-plugin-rhel9@sha256:4dc2b99566e52c6103c5993cd62b89949c40ba88c7285c8c7ddac4f5e57c93f9 - op: add path: /spec/template/spec/containers/0/env/- value: name: NETWORK_RESOURCES_INJECTOR_IMAGE - value: registry.redhat.io/openshift4/ose-sriov-dp-admission-controller-rhel9@sha256:65fb69486d1fbc6ee69b22d02f0d0ee5b642bfa1b6e3758fe8ed8fc17346bf4f + value: registry.redhat.io/openshift4/ose-sriov-dp-admission-controller-rhel9@sha256:32b7d2d83a5c4b51a4f57706698c70350dd5320cc84f7f709e88388fe02bec3e - op: add path: /spec/template/spec/containers/0/env/- value: name: SRIOV_NETWORK_CONFIG_DAEMON_IMAGE - value: registry.redhat.io/openshift4/ose-sriov-network-config-daemon-rhel9@sha256:0c3a9ab3011969810aab65b5d35048397ef4561decd473d103405d9b7d4e241d + value: registry.redhat.io/openshift4/ose-sriov-network-config-daemon-rhel9@sha256:3e38bc414b16651b5075091669c047525749da17f939559e848ab82432cebb5a - op: add path: /spec/template/spec/containers/0/env/- value: name: SRIOV_NETWORK_WEBHOOK_IMAGE - value: registry.redhat.io/openshift4/ose-sriov-network-webhook-rhel9@sha256:41143d95412e12b1b614c87d1c1dfce9df6f498eb70425e5a91e3ff54636b0a5 + value: registry.redhat.io/openshift4/ose-sriov-network-webhook-rhel9@sha256:9a1b0b6b06dc959b814305e9b6ad8dea55819a4b53a91a6fac089b5248b19486 - op: add path: /spec/template/spec/containers/0/env/- value: name: SRIOV_INFINIBAND_CNI_IMAGE - value: registry.redhat.io/openshift4/ose-sriov-infiniband-cni-rhel9@sha256:52e81b9fac3aef83040d6d3399ce407aa0af351d79697a62312f1c81707986d6 + value: registry.redhat.io/openshift4/ose-sriov-infiniband-cni-rhel9@sha256:1e833e41cf59c0c0c885425601176979a9ec8d6f4f16fc569780c3d7a997f7d6 - op: add path: /spec/template/spec/containers/0/env/- value: name: RDMA_CNI_IMAGE - value: registry.redhat.io/openshift4/ose-sriov-rdma-cni-rhel9@sha256:2122463d6cbb4fb4cd5162018e96e588dc2f517f205da09529c4daf04746cbfb + value: registry.redhat.io/openshift4/ose-sriov-rdma-cni-rhel9@sha256:df46b6064fb7827ce0267369292affe7f50d0a263ea3b3ee30827ace1c3e180a - op: add path: /spec/template/spec/containers/0/env/- value: name: METRICS_EXPORTER_IMAGE - value: registry.redhat.io/openshift4/ose-sriov-network-metrics-exporter-rhel9@sha256:a124b5a6402c62cee0c0d0311d60c9bee4ba66f3fc0d98d30ff203cd6d2f21ea + value: registry.redhat.io/openshift4/ose-sriov-network-metrics-exporter-rhel9@sha256:64bd70a07f07f9ce1511684ae562c11a5f891f34149563a1ff8de8fc27a1f61a - op: add path: /spec/template/spec/containers/0/env/- value: name: METRICS_EXPORTER_KUBE_RBAC_PROXY_IMAGE - value: registry.redhat.io/openshift4/ose-kube-rbac-proxy-rhel9@sha256:d27efc617a0eef867916bd2e37ac5c9d2f80346b9596a583ff2675bcd1567bfb + value: registry.redhat.io/openshift4/ose-kube-rbac-proxy-rhel9@sha256:13b2c70f362511b0be1b22f3d28ad6f98c4f8771a0a5165361ddc15a6b305baf target: kind: Deployment name: sriov-network-operator diff --git a/assets/optional/sriov/release-sriov-aarch64.json b/assets/optional/sriov/release-sriov-aarch64.json index 4762525e44..1b0ef13dd8 100644 --- a/assets/optional/sriov/release-sriov-aarch64.json +++ b/assets/optional/sriov/release-sriov-aarch64.json @@ -1,17 +1,17 @@ { "release": { - "base": "4.21.0-202607141717" + "base": "4.21.0-202608112141" }, "images": { - "metrics-exporter-image": "registry.redhat.io/openshift4/ose-sriov-network-metrics-exporter-rhel9@sha256:178fd1cdfb3d56cf59fb4ba952f16cb7e5bdde7cccebd6ac9845438f4f71eb62", - "metrics-exporter-kube-rbac-proxy-image": "registry.redhat.io/openshift4/ose-kube-rbac-proxy-rhel9@sha256:d1ad461cadefdbd635f6137f5217bf41d5eba437251af05574bcbe61c74ddb63", - "network-resources-injector-image": "registry.redhat.io/openshift4/ose-sriov-dp-admission-controller-rhel9@sha256:8f9b9d6bd1cd32574e2add548e5cf74f43b19818b204f90925792a516d5be4fd", - "rdma-cni-image": "registry.redhat.io/openshift4/ose-sriov-rdma-cni-rhel9@sha256:870d98955d99b3df5f00149f750797c25149cea29dd25bfa883763779f521e8e", - "sriov-cni-image": "registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:2bfab11571c1f20621fc0de872b1bba42b568a660eb4763e35f7aecffd2b8da8", - "sriov-device-plugin-image": "registry.redhat.io/openshift4/ose-sriov-network-device-plugin-rhel9@sha256:92228bbea421a820bc2dfa1b126415c83f2773bc94694dc078c65824c333155d", - "sriov-infiniband-cni-image": "registry.redhat.io/openshift4/ose-sriov-infiniband-cni-rhel9@sha256:c6e0e49baea7bc2fd7a485c03db00e625610a250f5266f54ca58af1b8d71271a", - "sriov-network-config-daemon-image": "registry.redhat.io/openshift4/ose-sriov-network-config-daemon-rhel9@sha256:5ea8bb5b1c3aac7bf59a3893d1d5a3152a0f8949a7e2999f6b958b1b2523ecd1", - "sriov-network-operator": "registry.redhat.io/openshift4/ose-sriov-network-rhel9-operator@sha256:885ae30c9915b997e8d374ed7bed3c2e1258660b92186b04cf53b105beafeb74", - "sriov-network-webhook-image": "registry.redhat.io/openshift4/ose-sriov-network-webhook-rhel9@sha256:7081b836f20158c5514749439f0d5d04818fb16eac6e7111ffe5fca4026e0772" + "metrics-exporter-image": "registry.redhat.io/openshift4/ose-sriov-network-metrics-exporter-rhel9@sha256:c1974679b6e3321076df5fa697f6b5674ffde54c3d159d81907d36febd04e7e9", + "metrics-exporter-kube-rbac-proxy-image": "registry.redhat.io/openshift4/ose-kube-rbac-proxy-rhel9@sha256:bef23cae77849dd5db4cca0ea831f1b113081576d4db63e1ab58203278b804c6", + "network-resources-injector-image": "registry.redhat.io/openshift4/ose-sriov-dp-admission-controller-rhel9@sha256:e76cd23d841a81b1fbdf019af1d33aae771b7a218ceae69a3d103872ac48fbf5", + "rdma-cni-image": "registry.redhat.io/openshift4/ose-sriov-rdma-cni-rhel9@sha256:b63caf0cb08139b825ce955aab9825bcf703d2ed4d6c87338552cf4f1a5626d1", + "sriov-cni-image": "registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:934f162f5c6345e032adaffb2934bb36f8b3d710579768d3fceee616cf78d26f", + "sriov-device-plugin-image": "registry.redhat.io/openshift4/ose-sriov-network-device-plugin-rhel9@sha256:b0a2ab81aa26e9120962dbdfed25d9690d66b778d567a280b93e6d28f0d7de25", + "sriov-infiniband-cni-image": "registry.redhat.io/openshift4/ose-sriov-infiniband-cni-rhel9@sha256:95da7b215db06cdc0475d28de84ab1ef900579f18257e4948d7999b6be44ef14", + "sriov-network-config-daemon-image": "registry.redhat.io/openshift4/ose-sriov-network-config-daemon-rhel9@sha256:2b3ffdbe2cfe9e57de00951a9ae3a9d6ced54528887abb04731d12fb806a2b80", + "sriov-network-operator": "registry.redhat.io/openshift4/ose-sriov-network-rhel9-operator@sha256:b700324b4b5c6b8296ca4552cf1665acc4822d909f61a4e7b897c7793128fbda", + "sriov-network-webhook-image": "registry.redhat.io/openshift4/ose-sriov-network-webhook-rhel9@sha256:d9719462e6e995924cb19a7974060e9e6b7b26e71bf303cb84ab395872cc5457" } } diff --git a/assets/optional/sriov/release-sriov-x86_64.json b/assets/optional/sriov/release-sriov-x86_64.json index e0cfccd91a..aee175f838 100644 --- a/assets/optional/sriov/release-sriov-x86_64.json +++ b/assets/optional/sriov/release-sriov-x86_64.json @@ -1,17 +1,17 @@ { "release": { - "base": "4.21.0-202607141717" + "base": "4.21.0-202608112141" }, "images": { - "metrics-exporter-image": "registry.redhat.io/openshift4/ose-sriov-network-metrics-exporter-rhel9@sha256:a124b5a6402c62cee0c0d0311d60c9bee4ba66f3fc0d98d30ff203cd6d2f21ea", - "metrics-exporter-kube-rbac-proxy-image": "registry.redhat.io/openshift4/ose-kube-rbac-proxy-rhel9@sha256:d27efc617a0eef867916bd2e37ac5c9d2f80346b9596a583ff2675bcd1567bfb", - "network-resources-injector-image": "registry.redhat.io/openshift4/ose-sriov-dp-admission-controller-rhel9@sha256:65fb69486d1fbc6ee69b22d02f0d0ee5b642bfa1b6e3758fe8ed8fc17346bf4f", - "rdma-cni-image": "registry.redhat.io/openshift4/ose-sriov-rdma-cni-rhel9@sha256:2122463d6cbb4fb4cd5162018e96e588dc2f517f205da09529c4daf04746cbfb", - "sriov-cni-image": "registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:32c884e1281ccf417a7f67afc830f0b8e9ae05f41235978a2ab81b693408dae8", - "sriov-device-plugin-image": "registry.redhat.io/openshift4/ose-sriov-network-device-plugin-rhel9@sha256:c91d6b38c80b660258e0701bdd25f33d308b3d3aef1ba0707c5e655bfc79eec4", - "sriov-infiniband-cni-image": "registry.redhat.io/openshift4/ose-sriov-infiniband-cni-rhel9@sha256:52e81b9fac3aef83040d6d3399ce407aa0af351d79697a62312f1c81707986d6", - "sriov-network-config-daemon-image": "registry.redhat.io/openshift4/ose-sriov-network-config-daemon-rhel9@sha256:0c3a9ab3011969810aab65b5d35048397ef4561decd473d103405d9b7d4e241d", - "sriov-network-operator": "registry.redhat.io/openshift4/ose-sriov-network-rhel9-operator@sha256:d809810f02f63fd95f4587dadadf180cbd4f0397f6078567ffb63eeb52c12da9", - "sriov-network-webhook-image": "registry.redhat.io/openshift4/ose-sriov-network-webhook-rhel9@sha256:41143d95412e12b1b614c87d1c1dfce9df6f498eb70425e5a91e3ff54636b0a5" + "metrics-exporter-image": "registry.redhat.io/openshift4/ose-sriov-network-metrics-exporter-rhel9@sha256:64bd70a07f07f9ce1511684ae562c11a5f891f34149563a1ff8de8fc27a1f61a", + "metrics-exporter-kube-rbac-proxy-image": "registry.redhat.io/openshift4/ose-kube-rbac-proxy-rhel9@sha256:13b2c70f362511b0be1b22f3d28ad6f98c4f8771a0a5165361ddc15a6b305baf", + "network-resources-injector-image": "registry.redhat.io/openshift4/ose-sriov-dp-admission-controller-rhel9@sha256:32b7d2d83a5c4b51a4f57706698c70350dd5320cc84f7f709e88388fe02bec3e", + "rdma-cni-image": "registry.redhat.io/openshift4/ose-sriov-rdma-cni-rhel9@sha256:df46b6064fb7827ce0267369292affe7f50d0a263ea3b3ee30827ace1c3e180a", + "sriov-cni-image": "registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:dd1b75ccc1cb6180f0e9795f2db0f74be60bdcca985596385b8e3d1f544fc47e", + "sriov-device-plugin-image": "registry.redhat.io/openshift4/ose-sriov-network-device-plugin-rhel9@sha256:4dc2b99566e52c6103c5993cd62b89949c40ba88c7285c8c7ddac4f5e57c93f9", + "sriov-infiniband-cni-image": "registry.redhat.io/openshift4/ose-sriov-infiniband-cni-rhel9@sha256:1e833e41cf59c0c0c885425601176979a9ec8d6f4f16fc569780c3d7a997f7d6", + "sriov-network-config-daemon-image": "registry.redhat.io/openshift4/ose-sriov-network-config-daemon-rhel9@sha256:3e38bc414b16651b5075091669c047525749da17f939559e848ab82432cebb5a", + "sriov-network-operator": "registry.redhat.io/openshift4/ose-sriov-network-rhel9-operator@sha256:d1aae7de925d2ae6d50bd5ea1ff6cff3737f4faa341ab410941f00d4d8ee2b72", + "sriov-network-webhook-image": "registry.redhat.io/openshift4/ose-sriov-network-webhook-rhel9@sha256:9a1b0b6b06dc959b814305e9b6ad8dea55819a4b53a91a6fac089b5248b19486" } } diff --git a/assets/release/release-aarch64.json b/assets/release/release-aarch64.json index 3c4ef3df31..210c48ff0b 100644 --- a/assets/release/release-aarch64.json +++ b/assets/release/release-aarch64.json @@ -1,16 +1,16 @@ { "release": { - "base": "5.0.0-0.nightly-arm64-2026-07-27-004356" + "base": "5.1.0-0.nightly-arm64-2026-08-21-025249" }, "images": { - "cli": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:aa5ae933124990ac8342023e51870cf4d07884243e09afaf62417a0363a9729d", - "coredns": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:3bd36df30411a20a17e54c90ccf9d993832da0ada367da6e0c3f28a83216f879", - "haproxy-router": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:15e8952c1875922024db7b12af4990488d129afb1c25b7c5a653e830e0ec28f3", - "kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:fc51b97845de29e7a245f185d31ff8adb2c7b7a5350686876a700104499ae2f5", - "ovn-kubernetes-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:38885d2ed82f8089323768d6afffd298e8779dc440d88e91a97fab1d9310d486", - "pod": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:a3aba52ab6f516a28f1423d2f71e9e3320d8486a266ca0e8430e47b77c38de9c", - "service-ca-operator": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:648ad75c87d184155041dcd9cc76e135aea9050c07779edb473e26bd87342f19", + "cli": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:ac45d999484cf83722d905d10441fb40c20ffa24aa188f8212949e754bb77921", + "coredns": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:3b8020c2b63ee3bfbdb19fdfab554e59b3e425bd29a9fab27803739972795122", + "haproxy-router": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:5fb0486cfb90da93716aa905bd29fa3d1f60c66ebdede17ed900c85cfb4ea6be", + "kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:df64843344fa7bb71f4ab5a0abdb48c4c2c2b6d8bd5732028903d5eae3251527", + "ovn-kubernetes-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:82ee9a2b8e23498827dc098f104025086a9d4d63de4b1c33d28281deafb98e61", + "pod": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:b5afa3f89e706db49c48c9ec436f4865c88af28ae275c4b64501e5bac27983cc", + "service-ca-operator": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:574e91e7a8e1755ff45110f334d0cd3cf7aa9158ea2b7393a271cdfa14ead8ce", "lvms_operator": "registry.redhat.io/lvms4/lvms-rhel9-operator@sha256:e77365e44676fbd8ab9e4ce53f3a406856bbdfef3467c545a7df1197d84477af", - "csi-snapshot-controller": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:94fbbcfffd5a5503f3ea5ab43f13c325c3765c33db2b4e5d040c07ded10f8c6e" + "csi-snapshot-controller": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:e63791622ce3fc5ff0925131be5490ed8f7a15931685f1cc9b8cbeafb7a5e9fc" } } diff --git a/assets/release/release-x86_64.json b/assets/release/release-x86_64.json index f2adf17ca3..75f97ddc0b 100644 --- a/assets/release/release-x86_64.json +++ b/assets/release/release-x86_64.json @@ -1,16 +1,16 @@ { "release": { - "base": "5.0.0-0.nightly-2026-07-23-224236" + "base": "5.1.0-0.nightly-2026-08-20-065836" }, "images": { - "cli": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:45188944bb589e9b3fd88bd175a18b9414a2ba070e2a08a3964e22ceedaf2955", - "coredns": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:f8333c52e3b4ec5d1575a31276b9600f173ddda7d6f1a0cb11f0d364fe5be29a", - "haproxy-router": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:9d40caf7c3a21b802c6632cf968b8c17f5bb756b6ff0564b77ee2dc9898e38f3", - "kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:849ba7d8ef4add8ef5841c14276f97cf9920b33bebf26ee021d72f08064e7abb", - "ovn-kubernetes-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:e05f31e81de47bfb323c9015b117bf2dcf34abb56d7effcd43513378ef45aae6", - "pod": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:046dee0e64bb32cdb9d34b43abc4c1b8f2d1700e2243e3812b759e1436677c9b", - "service-ca-operator": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:dcdfe8696ab6c9c7098e3ea2d297af47b68e91eac931364e13e46edd28b2a479", + "cli": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:99103ea20bf57a699a31d0c2e4b7c4219ba8a62e47a0aec90a0ad3bfe3f42f64", + "coredns": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:10b514560eaf941d03c29e072c923871cf7078f81977e0d53708c844c7d49f10", + "haproxy-router": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:4a107da17ffa26788b082bcad89b8df2f4f8f85a13a195057d0492243f9fdea9", + "kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:01df5215d93cda24669fe9f3711223f34f674071321b3d0e7975feef702d0099", + "ovn-kubernetes-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:f51d50d685720338dd7e2cb3a6da223977b3162fb5373408851578d90bab05cd", + "pod": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:e1c1886f95f3790e60eba2c0d9b33719c38d970382ba46f306fcc3f632776594", + "service-ca-operator": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:1c59f8c3617379193814d738282a9db1aebd9f16ea9a7d7a777d3ba8c755d564", "lvms_operator": "registry.redhat.io/lvms4/lvms-rhel9-operator@sha256:10c9ccab4f2857d113b55e12cac29aed0dc97d5a4e29ed2e4ea0f77551ee55f8", - "csi-snapshot-controller": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:f0631a7e1e3aa1cf6ac01df7a7b0b8ce5f5ad333e2efc8f4599b4428a6d54c22" + "csi-snapshot-controller": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:2462ba108ca9fd65b1171775fbe25fc0cf8dd6c73772941609c5ec9c17c48e1c" } } diff --git a/cbom-microshift.json b/cbom-microshift.json new file mode 100644 index 0000000000..c2e043ab50 --- /dev/null +++ b/cbom-microshift.json @@ -0,0 +1,5272 @@ +{ + "bomFormat": "CycloneDX", + "specVersion": "1.6", + "serialNumber": "urn:uuid:55b8f2ae-38f0-44d8-aeaa-a8a9e54720ce", + "version": 1, + "metadata": { + "timestamp": "2026-08-21T04:35:57Z", + "tools": { + "components": [ + { + "type": "application", + "group": "SCANOSS", + "name": "crypto-finder", + "version": "1.26.5" + } + ] + } + }, + "components": [ + { + "bom-ref": "2543ed38-1317-4c41-8bb4-be78d4acdd22", + "type": "cryptographic-asset", + "name": "AES", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "keygen" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.aes.go.crypto.aes.key-generation" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 371, + "additionalContext": "scanoss:match,block, err := aes.NewCipher(kek)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 465, + "additionalContext": "scanoss:match,block, err := aes.NewCipher(key)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/symmetric.go", + "line": 92, + "additionalContext": "scanoss:match,aes, err := aes.NewCipher(key)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/symmetric.go", + "line": 289, + "additionalContext": "scanoss:match,block, err := aes.NewCipher(ctx.key)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/symmetric.go", + "line": 324, + "additionalContext": "scanoss:match,block, err := aes.NewCipher(key)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/symmetric.go", + "line": 379, + "additionalContext": "scanoss:match,block, err := aes.NewCipher(ctx.key)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/symmetric.go", + "line": 420, + "additionalContext": "scanoss:match,block, err := aes.NewCipher(key)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/server/options/encryptionconfig/config.go", + "line": 636, + "additionalContext": "scanoss:match,block, err := aes.NewCipher(key)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/aes/aes.go", + "line": 63, + "additionalContext": "scanoss:match,block, err := aes.NewCipher(key)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/aes/aes_extended_nonce.go", + "line": 146, + "additionalContext": "scanoss:match,block, err := aes.NewCipher(key)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/envelope/envelope.go", + "line": 160, + "additionalContext": "scanoss:match,block, err := aes.NewCipher(key)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/envelope/kmsv2/envelope.go", + "line": 329, + "additionalContext": "scanoss:match,block, err = aes.NewCipher(key)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "block-cipher", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "keygen" + ] + }, + "oid": "2.16.840.1.101.3.4.1" + } + }, + { + "bom-ref": "33754aed-6310-4a96-81b8-b5ba7a902c51", + "type": "cryptographic-asset", + "name": "AES-GCM", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "encrypt" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.aes.go.crypto.aes.gcm-mode" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/symmetric.go", + "line": 92, + "additionalContext": "scanoss:match,aes, err := aes.NewCipher(key) if err != nil { return nil, err } return cipher.NewGCM(aes)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "ae", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "mode": "gcm", + "cryptoFunctions": [ + "encrypt" + ] + }, + "oid": "2.16.840.1.101.3.4.1" + } + }, + { + "bom-ref": "81f951ae-c0a4-4d08-a8dc-c3c5a3de9612", + "type": "cryptographic-asset", + "name": "Blowfish", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "encrypt,keygen" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.xcrypto.algorithm.blowfish.go.xcrypto.blowfish.encrypt" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.xcrypto.algorithm.blowfish.go.xcrypto.blowfish.salted-key-generation" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.xcrypto.algorithm.blowfish.go.xcrypto.blowfish.key-expansion" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/golang.org/x/crypto/bcrypt/bcrypt.go", + "line": 207, + "additionalContext": "scanoss:match,c.Encrypt(cipherData[i:i+8], cipherData[i:i+8])" + }, + { + "location": "etcd-deps/golang.org/x/crypto/bcrypt/bcrypt.go", + "line": 228, + "additionalContext": "scanoss:match,c, err := blowfish.NewSaltedCipher(ckey, csalt)" + }, + { + "location": "etcd-deps/golang.org/x/crypto/bcrypt/bcrypt.go", + "line": 236, + "additionalContext": "scanoss:match,blowfish.ExpandKey(ckey, c)" + }, + { + "location": "etcd-deps/golang.org/x/crypto/bcrypt/bcrypt.go", + "line": 237, + "additionalContext": "scanoss:match,blowfish.ExpandKey(csalt, c)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "block-cipher", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "encrypt", + "keygen" + ] + } + } + }, + { + "bom-ref": "d7b61af4-12fc-4ba3-b498-0e7cdce21946", + "type": "cryptographic-asset", + "name": "CSHAKE128", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.sha3.go.crypto.sha3.shake-usage" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/golang.org/x/crypto/sha3/shake.go", + "line": 51, + "additionalContext": "scanoss:match,return \u0026shakeWrapper{sha3.NewCSHAKE128(N, S), 32, false, func() *sha3.SHAKE {" + }, + { + "location": "vendor-deps/golang.org/x/crypto/sha3/shake.go", + "line": 52, + "additionalContext": "scanoss:match,return sha3.NewCSHAKE128(N, S)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "xof", + "parameterSetIdentifier": "128", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + }, + "oid": "2.16.840.1.101.3.4.2" + } + }, + { + "bom-ref": "48dab3f7-8e3b-470a-8ff4-84204f07bd82", + "type": "cryptographic-asset", + "name": "CSHAKE256", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.sha3.go.crypto.sha3.shake-usage" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/golang.org/x/crypto/sha3/shake.go", + "line": 63, + "additionalContext": "scanoss:match,return \u0026shakeWrapper{sha3.NewCSHAKE256(N, S), 64, false, func() *sha3.SHAKE {" + }, + { + "location": "vendor-deps/golang.org/x/crypto/sha3/shake.go", + "line": 64, + "additionalContext": "scanoss:match,return sha3.NewCSHAKE256(N, S)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "xof", + "parameterSetIdentifier": "256", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + }, + "oid": "2.16.840.1.101.3.4.2" + } + }, + { + "bom-ref": "7b6c22a3-0cc4-49a3-aa0b-09f93e3077c7", + "type": "cryptographic-asset", + "name": "CSPRNG", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "other" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rand.go.crypto.rand.usage" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rand.go.crypto.rand.usage" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/go.etcd.io/etcd/client/pkg/v3/transport/listener.go", + "line": 262, + "additionalContext": "scanoss:match,serialNumber, err := rand.Int(rand.Reader, serialNumberLimit)" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/auth/simple_token.go", + "line": 114, + "additionalContext": "scanoss:match,bInt, err := rand.Int(rand.Reader, big.NewInt(int64(len(letters))))" + }, + { + "location": "etcd-deps/go.etcd.io/raft/v3/raft.go", + "line": 97, + "additionalContext": "scanoss:match,v, _ := rand.Int(rand.Reader, big.NewInt(int64(n)))" + }, + { + "location": "etcd-deps/golang.org/x/net/http2/server.go", + "line": 937, + "additionalContext": "scanoss:match,_, _ = rand.Read(sc.sentPingData[:])" + }, + { + "location": "etcd-deps/golang.org/x/net/http2/transport.go", + "line": 2613, + "additionalContext": "scanoss:match,if _, err := rand.Read(p[:]); err != nil {" + }, + { + "location": "etcd-deps/golang.org/x/net/http2/transport.go", + "line": 2702, + "additionalContext": "scanoss:match,rand.Read(payload[:])" + }, + { + "location": "etcd-deps/golang.org/x/oauth2/pkce.go", + "line": 34, + "additionalContext": "scanoss:match,if _, err := rand.Read(data); err != nil {" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/cert/cert.go", + "line": 63, + "additionalContext": "scanoss:match,serial, err := cryptorand.Int(cryptorand.Reader, new(big.Int).SetInt64(math.MaxInt64-1))" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/cert/cert.go", + "line": 178, + "additionalContext": "scanoss:match,serial, err := cryptorand.Int(cryptorand.Reader, new(big.Int).SetInt64(math.MaxInt64-1))" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/cert/cert.go", + "line": 211, + "additionalContext": "scanoss:match,serial, err = cryptorand.Int(cryptorand.Reader, new(big.Int).SetInt64(math.MaxInt64-1))" + }, + { + "location": "vendor-deps/github.com/Azure/go-ntlmssp/authenticate_message.go", + "line": 121, + "additionalContext": "scanoss:match,rand.Reader.Read(clientChallenge)" + }, + { + "location": "vendor-deps/github.com/Azure/go-ntlmssp/authenticate_message.go", + "line": 167, + "additionalContext": "scanoss:match,rand.Reader.Read(clientChallenge)" + }, + { + "location": "vendor-deps/github.com/Microsoft/go-winio/pkg/guid/guid.go", + "line": 49, + "additionalContext": "scanoss:match,if _, err := rand.Read(b[:]); err != nil {" + }, + { + "location": "vendor-deps/github.com/godbus/dbus/v5/auth_sha1_windows.go", + "line": 92, + "additionalContext": "scanoss:match,n, err := rand.Read(b)" + }, + { + "location": "vendor-deps/go.etcd.io/etcd/client/pkg/v3/transport/listener.go", + "line": 262, + "additionalContext": "scanoss:match,serialNumber, err := rand.Int(rand.Reader, serialNumberLimit)" + }, + { + "location": "vendor-deps/golang.org/x/net/http2/server.go", + "line": 937, + "additionalContext": "scanoss:match,_, _ = rand.Read(sc.sentPingData[:])" + }, + { + "location": "vendor-deps/golang.org/x/net/http2/transport.go", + "line": 2613, + "additionalContext": "scanoss:match,if _, err := rand.Read(p[:]); err != nil {" + }, + { + "location": "vendor-deps/golang.org/x/net/http2/transport.go", + "line": 2702, + "additionalContext": "scanoss:match,rand.Read(payload[:])" + }, + { + "location": "vendor-deps/golang.org/x/oauth2/pkce.go", + "line": 34, + "additionalContext": "scanoss:match,if _, err := rand.Read(data); err != nil {" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/authentication/token/cache/cached_token_authenticator.go", + "line": 102, + "additionalContext": "scanoss:match,if _, err := rand.Read(randomCacheKey); err != nil {" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/aes/aes.go", + "line": 108, + "additionalContext": "scanoss:match,_, err := rand.Read(b)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/aes/aes.go", + "line": 140, + "additionalContext": "scanoss:match,if _, err = rand.Read(key); err != nil {" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/envelope/envelope.go", + "line": 197, + "additionalContext": "scanoss:match,if _, err = rand.Read(key); err != nil {" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/secretbox/secretbox.go", + "line": 62, + "additionalContext": "scanoss:match,n, err := rand.Read(nonce[:])" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/cert/cert.go", + "line": 63, + "additionalContext": "scanoss:match,serial, err := cryptorand.Int(cryptorand.Reader, new(big.Int).SetInt64(math.MaxInt64-1))" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/cert/cert.go", + "line": 178, + "additionalContext": "scanoss:match,serial, err := cryptorand.Int(cryptorand.Reader, new(big.Int).SetInt64(math.MaxInt64-1))" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/cert/cert.go", + "line": 211, + "additionalContext": "scanoss:match,serial, err = cryptorand.Int(cryptorand.Reader, new(big.Int).SetInt64(math.MaxInt64-1))" + }, + { + "location": "vendor-deps/k8s.io/cluster-bootstrap/token/util/helpers.go", + "line": 68, + "additionalContext": "scanoss:match,val, err := rand.Int(rand.Reader, max)" + }, + { + "location": "vendor-deps/k8s.io/cri-streaming/pkg/streaming/request_cache.go", + "line": 119, + "additionalContext": "scanoss:match,if _, err := rand.Read(rawToken); err != nil {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/controller/certificates/authority/authority.go", + "line": 52, + "additionalContext": "scanoss:match,serialNumber, err := rand.Int(rand.Reader, serialNumberLimit)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "drbg", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "other" + ] + } + } + }, + { + "bom-ref": "73bf8df8-0193-4747-a7a4-37b1badbb975", + "type": "cryptographic-asset", + "name": "ECDH-", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "keyexchange" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.ecdh.go.crypto.ecdh.key-generation" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/github.com/miekg/dns/dnssec_keygen.go", + "line": 68, + "additionalContext": "scanoss:match,pub, priv, err := ed25519.GenerateKey(rand.Reader)" + }, + { + "location": "vendor-deps/golang.org/x/crypto/ed25519/ed25519.go", + "line": 51, + "additionalContext": "scanoss:match,return ed25519.GenerateKey(rand)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/envelope/kmsv2/envelope.go", + "line": 369, + "additionalContext": "scanoss:match,seed, err := aestransformer.GenerateKey(aestransformer.MinSeedSizeExtendedNonceGCM)" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/podcertificate/podcertificatemanager.go", + "line": 909, + "additionalContext": "scanoss:match,_, priv, err := ed25519.GenerateKey(rand.Reader)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "key-agree", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "other" + ] + }, + "oid": "1.2.840.10045.2.1" + } + }, + { + "bom-ref": "27c21535-52c2-4fa4-a009-b88fcfd06b28", + "type": "cryptographic-asset", + "name": "ECDSA", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "keygen,verify,sign" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.ecdsa.go.crypto.ecdsa.key-type" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.ecdsa.go.crypto.ecdsa.verify" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.ecdsa.go.crypto.ecdsa.key-type" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.ecdsa.go.crypto.ecdsa.sign" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.x509.go.crypto.x509.parse-ec-private-key" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.x509.go.crypto.x509.parse-ec-private-key" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.ecdsa.go.crypto.ecdsa.verify" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ecdsa.go", + "line": 60, + "additionalContext": "scanoss:match,var ecdsaKey *ecdsa.PublicKey" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ecdsa.go", + "line": 83, + "additionalContext": "scanoss:match,if verifystatus := ecdsa.Verify(ecdsaKey, hasher.Sum(nil), r, s); verifystatus {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ecdsa.go", + "line": 94, + "additionalContext": "scanoss:match,var ecdsaKey *ecdsa.PrivateKey" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ecdsa.go", + "line": 111, + "additionalContext": "scanoss:match,if r, s, err := ecdsa.Sign(rand.Reader, ecdsaKey, hasher.Sum(nil)); err == nil {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ecdsa_utils.go", + "line": 27, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParseECPrivateKey(block.Bytes); err != nil {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ecdsa_utils.go", + "line": 33, + "additionalContext": "scanoss:match,var pkey *ecdsa.PrivateKey" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ecdsa_utils.go", + "line": 62, + "additionalContext": "scanoss:match,var pkey *ecdsa.PublicKey" + }, + { + "location": "etcd-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 1219, + "additionalContext": "scanoss:match,keyBytes, err := x509.MarshalECPrivateKey(key)" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/client/pkg/v3/transport/listener.go", + "line": 329, + "additionalContext": "scanoss:match,b, err := x509.MarshalECPrivateKey(priv)" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/auth/options.go", + "line": 159, + "additionalContext": "scanoss:match,priv *ecdsa.PrivateKey" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/auth/options.go", + "line": 160, + "additionalContext": "scanoss:match,pub *ecdsa.PublicKey" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 51, + "additionalContext": "scanoss:match,derBytes, err := x509.MarshalECPrivateKey(privateKey)" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 101, + "additionalContext": "scanoss:match,derBytes, err := x509.MarshalECPrivateKey(t)" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 171, + "additionalContext": "scanoss:match,if key, err := x509.ParseECPrivateKey(privateKeyPemBlock.Bytes); err == nil {" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 295, + "additionalContext": "scanoss:match,var pubKey *ecdsa.PublicKey" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 310, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParseECPrivateKey(data); err != nil {" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 315, + "additionalContext": "scanoss:match,var privKey *ecdsa.PrivateKey" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 467, + "additionalContext": "scanoss:match,if ecdsa.Verify(pubkey, h.Sum(nil), r, s) {" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 574, + "additionalContext": "scanoss:match,pubkey := new(ecdsa.PublicKey)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec_keyscan.go", + "line": 109, + "additionalContext": "scanoss:match,p := new(ecdsa.PrivateKey)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/sig0.go", + "line": 178, + "additionalContext": "scanoss:match,if ecdsa.Verify(pk, hashed, r, s) {" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 1219, + "additionalContext": "scanoss:match,keyBytes, err := x509.MarshalECPrivateKey(key)" + }, + { + "location": "vendor-deps/go.etcd.io/etcd/client/pkg/v3/transport/listener.go", + "line": 329, + "additionalContext": "scanoss:match,b, err := x509.MarshalECPrivateKey(priv)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 528, + "additionalContext": "scanoss:match,r, s, err := ecdsa.Sign(RandReader, ctx.privateKey, hashed)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 589, + "additionalContext": "scanoss:match,match := ecdsa.Verify(ctx.publicKey, hashed, r, s)" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/certificate/certificate_manager.go", + "line": 771, + "additionalContext": "scanoss:match,der, err := x509.MarshalECPrivateKey(privateKey)" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 51, + "additionalContext": "scanoss:match,derBytes, err := x509.MarshalECPrivateKey(privateKey)" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 101, + "additionalContext": "scanoss:match,derBytes, err := x509.MarshalECPrivateKey(t)" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 171, + "additionalContext": "scanoss:match,if key, err := x509.ParseECPrivateKey(privateKeyPemBlock.Bytes); err == nil {" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 295, + "additionalContext": "scanoss:match,var pubKey *ecdsa.PublicKey" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 310, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParseECPrivateKey(data); err != nil {" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 315, + "additionalContext": "scanoss:match,var privKey *ecdsa.PrivateKey" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/apis/certificates/validation/validation.go", + "line": 704, + "additionalContext": "scanoss:match,if !ecdsa.VerifyASN1(pub, hashBytes([]byte(req.Spec.PodUID)), req.Spec.ProofOfPossession) {" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "signature", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "keygen", + "verify", + "sign" + ] + }, + "oid": "1.2.840.10045.2.1" + } + }, + { + "bom-ref": "041b3f2f-afa6-4fa3-bd8f-b287dc52534a", + "type": "cryptographic-asset", + "name": "ECDSA-P256", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "keygen" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.ecdsa.go.crypto.ecdsa.key-generation" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 46, + "additionalContext": "scanoss:match,privateKey, err := ecdsa.GenerateKey(elliptic.P256(), cryptorand.Reader)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec_keygen.go", + "line": 61, + "additionalContext": "scanoss:match,priv, err := ecdsa.GenerateKey(c, rand.Reader)" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/certificate/certificate_manager.go", + "line": 767, + "additionalContext": "scanoss:match,privateKey, err := ecdsa.GenerateKey(elliptic.P256(), cryptorand.Reader)" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 46, + "additionalContext": "scanoss:match,privateKey, err := ecdsa.GenerateKey(elliptic.P256(), cryptorand.Reader)" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/podcertificate/podcertificatemanager.go", + "line": 891, + "additionalContext": "scanoss:match,priv, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "signature", + "parameterSetIdentifier": "256", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "keygen" + ] + }, + "oid": "1.2.840.10045.2.1" + } + }, + { + "bom-ref": "f646652b-b145-45db-aeb2-cbc1e32181c5", + "type": "cryptographic-asset", + "name": "ECDSA-P384", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "keygen" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.ecdsa.go.crypto.ecdsa.key-generation" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/podcertificate/podcertificatemanager.go", + "line": 897, + "additionalContext": "scanoss:match,priv, err := ecdsa.GenerateKey(elliptic.P384(), rand.Reader)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "signature", + "parameterSetIdentifier": "384", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "keygen" + ] + }, + "oid": "1.2.840.10045.2.1" + } + }, + { + "bom-ref": "81bf7105-e376-4d46-8f3e-8e92e3fc1f49", + "type": "cryptographic-asset", + "name": "ECDSA-P521", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "keygen" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.ecdsa.go.crypto.ecdsa.key-generation" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/go.etcd.io/etcd/client/pkg/v3/transport/listener.go", + "line": 297, + "additionalContext": "scanoss:match,priv, err := ecdsa.GenerateKey(elliptic.P521(), rand.Reader)" + }, + { + "location": "vendor-deps/go.etcd.io/etcd/client/pkg/v3/transport/listener.go", + "line": 297, + "additionalContext": "scanoss:match,priv, err := ecdsa.GenerateKey(elliptic.P521(), rand.Reader)" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/podcertificate/podcertificatemanager.go", + "line": 903, + "additionalContext": "scanoss:match,priv, err := ecdsa.GenerateKey(elliptic.P521(), rand.Reader)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "signature", + "parameterSetIdentifier": "521", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "keygen" + ] + }, + "oid": "1.2.840.10045.2.1" + } + }, + { + "bom-ref": "0ae93b43-c556-41e0-a7c6-d5075728db19", + "type": "cryptographic-asset", + "name": "Ed25519", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "verify,keygen,sign" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.ed25519.go.crypto.ed25519.verify" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.ed25519.go.crypto.ed25519.generatekey" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.ed25519.go.crypto.ed25519.newkey-from-seed" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.ed25519.go.crypto.ed25519.sign" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.xcrypto.algorithm.ed25519.go.xcrypto.ed25519.verify" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.ed25519.go.crypto.ed25519.key-type" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.ed25519.go.crypto.ed25519.key-type" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ed25519.go", + "line": 49, + "additionalContext": "scanoss:match,if !ed25519.Verify(ed25519Key, []byte(signingString), sig) {" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 478, + "additionalContext": "scanoss:match,if ed25519.Verify(pubkey, append(signeddata, wire...), sigbuf) {" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec_keygen.go", + "line": 68, + "additionalContext": "scanoss:match,pub, priv, err := ed25519.GenerateKey(rand.Reader)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec_keyscan.go", + "line": 140, + "additionalContext": "scanoss:match,p = ed25519.NewKeyFromSeed(p1)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec_keyscan.go", + "line": 140, + "additionalContext": "scanoss:match,p = ed25519.NewKeyFromSeed(p1)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/sig0.go", + "line": 186, + "additionalContext": "scanoss:match,if ed25519.Verify(pk, hashed, sig) {" + }, + { + "location": "vendor-deps/golang.org/x/crypto/ed25519/ed25519.go", + "line": 51, + "additionalContext": "scanoss:match,return ed25519.GenerateKey(rand)" + }, + { + "location": "vendor-deps/golang.org/x/crypto/ed25519/ed25519.go", + "line": 59, + "additionalContext": "scanoss:match,return ed25519.NewKeyFromSeed(seed)" + }, + { + "location": "vendor-deps/golang.org/x/crypto/ed25519/ed25519.go", + "line": 59, + "additionalContext": "scanoss:match,return ed25519.NewKeyFromSeed(seed)" + }, + { + "location": "vendor-deps/golang.org/x/crypto/ed25519/ed25519.go", + "line": 65, + "additionalContext": "scanoss:match,return ed25519.Sign(privateKey, message)" + }, + { + "location": "vendor-deps/golang.org/x/crypto/ed25519/ed25519.go", + "line": 71, + "additionalContext": "scanoss:match,return ed25519.Verify(publicKey, message, sig)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 493, + "additionalContext": "scanoss:match,ok := ed25519.Verify(ctx.publicKey, payload, signature)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 493, + "additionalContext": "scanoss:match,ok := ed25519.Verify(ctx.publicKey, payload, signature)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/jwk.go", + "line": 385, + "additionalContext": "scanoss:match,input, err = edThumbprintInput(ed25519.PublicKey(key[32:]))" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/jwk.go", + "line": 578, + "additionalContext": "scanoss:match,rv := ed25519.PrivateKey(privateKey)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/jwk.go", + "line": 588, + "additionalContext": "scanoss:match,rv := ed25519.PublicKey(publicKey)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/jwk.go", + "line": 638, + "additionalContext": "scanoss:match,raw := fromEdPublicKey(ed25519.PublicKey(ed[32:]))" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/apis/certificates/validation/validation.go", + "line": 694, + "additionalContext": "scanoss:match,if !ed25519.Verify(pub, []byte(req.Spec.PodUID), req.Spec.ProofOfPossession) {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/podcertificate/podcertificatemanager.go", + "line": 909, + "additionalContext": "scanoss:match,_, priv, err := ed25519.GenerateKey(rand.Reader)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "signature", + "parameterSetIdentifier": "Ed25519", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "verify", + "keygen", + "sign" + ] + }, + "oid": "1.3.101.112" + } + }, + { + "bom-ref": "048b8942-789c-4a90-ab89-aac8d2c1be90", + "type": "cryptographic-asset", + "name": "HKDF-", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "keyderive" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.hkdf.go.crypto.hkdf.extract" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.xcrypto.algorithm.hkdf.go.xcrypto.hkdf.expand" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/golang.org/x/crypto/hkdf/hkdf.go", + "line": 33, + "additionalContext": "scanoss:match,out, err := hkdf.Extract(hash, secret, salt)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/aes/aes_extended_nonce.go", + "line": 135, + "additionalContext": "scanoss:match,kdf := hkdf.Expand(sha256.New, e.seed, info)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "kdf", + "parameterSetIdentifier": "HKDF-", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "keyderive" + ] + } + } + }, + { + "bom-ref": "80d88111-2892-4fd6-98f0-d7d9479aaf39", + "type": "cryptographic-asset", + "name": "HMAC", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "verify" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.hmac.go.crypto.hmac.equal" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/hmac.go", + "line": 75, + "additionalContext": "scanoss:match,if !hmac.Equal(sig, hasher.Sum(nil)) {" + }, + { + "location": "vendor-deps/github.com/miekg/dns/tsig.go", + "line": 71, + "additionalContext": "scanoss:match,if !hmac.Equal(b, mac) {" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "mac", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "verify" + ] + }, + "oid": "1.2.840.113549.2" + } + }, + { + "bom-ref": "b98c3b60-4060-464e-abcd-6ebe4a398ccb", + "type": "cryptographic-asset", + "name": "HMAC-", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "sign" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.hmac.go.crypto.hmac.usage" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/hmac.go", + "line": 73, + "additionalContext": "scanoss:match,hasher := hmac.New(m.Hash.New, keyBytes)" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/hmac.go", + "line": 97, + "additionalContext": "scanoss:match,hasher := hmac.New(m.Hash.New, keyBytes)" + }, + { + "location": "vendor-deps/golang.org/x/crypto/hkdf/hkdf.go", + "line": 91, + "additionalContext": "scanoss:match,expander := hmac.New(hash, pseudorandomKey)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/cipher/cbc_hmac.go", + "line": 147, + "additionalContext": "scanoss:match,hmac := hmac.New(ctx.hash, ctx.integrityKey)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/symmetric.go", + "line": 482, + "additionalContext": "scanoss:match,hmac := hmac.New(hash, ctx.key)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "mac", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "sign" + ] + }, + "oid": "1.2.840.113549.2" + } + }, + { + "bom-ref": "caf742e8-f696-4774-a47b-cd83c3ba26fc", + "type": "cryptographic-asset", + "name": "HMAC-md5", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "sign" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.hmac.go.crypto.hmac.usage" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/github.com/Azure/go-ntlmssp/nlmp.go", + "line": 46, + "additionalContext": "scanoss:match,mac := hmac.New(md5.New, key)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "mac", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "sign" + ] + }, + "oid": "1.2.840.113549.2.6" + } + }, + { + "bom-ref": "5eca8f1d-97f8-4544-b881-168ff482517f", + "type": "cryptographic-asset", + "name": "HMAC-sha1", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "sign" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.hmac.go.crypto.hmac.usage" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/github.com/miekg/dns/tsig.go", + "line": 46, + "additionalContext": "scanoss:match,h = hmac.New(sha1.New, rawsecret)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "mac", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "sign" + ] + }, + "oid": "1.2.840.113549.2.7" + } + }, + { + "bom-ref": "1f17db33-4a92-49b7-9719-500322015721", + "type": "cryptographic-asset", + "name": "HMAC-sha256", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "sign" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.hmac.go.crypto.hmac.usage" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/github.com/miekg/dns/tsig.go", + "line": 48, + "additionalContext": "scanoss:match,h = hmac.New(sha256.New224, rawsecret)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/tsig.go", + "line": 50, + "additionalContext": "scanoss:match,h = hmac.New(sha256.New, rawsecret)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/authentication/token/cache/cached_token_authenticator.go", + "line": 122, + "additionalContext": "scanoss:match,return hmac.New(sha256.New, randomCacheKey)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "mac", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "sign" + ] + }, + "oid": "1.2.840.113549.2.9" + } + }, + { + "bom-ref": "7846476f-ce2c-41b6-881d-96b7b91077d1", + "type": "cryptographic-asset", + "name": "HMAC-sha512", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "sign" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.hmac.go.crypto.hmac.usage" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/github.com/miekg/dns/tsig.go", + "line": 52, + "additionalContext": "scanoss:match,h = hmac.New(sha512.New384, rawsecret)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/tsig.go", + "line": 54, + "additionalContext": "scanoss:match,h = hmac.New(sha512.New, rawsecret)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "mac", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "sign" + ] + }, + "oid": "1.2.840.113549.2.11" + } + }, + { + "bom-ref": "6db828a5-46d0-4342-8227-94c0edb1b990", + "type": "cryptographic-asset", + "name": "HSalsa20", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.xcrypto.algorithm.salsa20.go.xcrypto.salsa20.hsalsa20" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/golang.org/x/crypto/nacl/secretbox/secretbox.go", + "line": 52, + "additionalContext": "scanoss:match,salsa.HSalsa20(subKey, \u0026hNonce, key, \u0026salsa.Sigma)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "hash", + "parameterSetIdentifier": "256", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + } + } + }, + { + "bom-ref": "bb801e73-9d25-4fbb-ae95-53d5402983fc", + "type": "cryptographic-asset", + "name": "Keccak-256", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.xcrypto.algorithm.sha3.go.xcrypto.sha3.legacy-keccak" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/github.com/go-playground/validator/v10/baked_in.go", + "line": 730, + "additionalContext": "scanoss:match,h := sha3.NewLegacyKeccak256()" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "hash", + "parameterSetIdentifier": "256", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + }, + "oid": "2.16.840.1.101.3.4.2" + } + }, + { + "bom-ref": "2ff6d7ce-6a32-434b-9476-415b95896430", + "type": "cryptographic-asset", + "name": "MD4", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.xcrypto.algorithm.md4.go.xcrypto.md4.hash-usage" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/github.com/Azure/go-ntlmssp/nlmp.go", + "line": 22, + "additionalContext": "scanoss:match,hash := md4.New()" + }, + { + "location": "vendor-deps/github.com/go-ldap/ldap/v3/bind.go", + "line": 630, + "additionalContext": "scanoss:match,hash := md4.New()" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "hash", + "parameterSetIdentifier": "128", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + }, + "oid": "1.2.840.113549.2.4" + } + }, + { + "bom-ref": "f68e6d0c-bad3-4da4-9bc8-c3754037345f", + "type": "cryptographic-asset", + "name": "MD5", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.md5.go.crypto.md5.hash-usage" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/github.com/google/uuid/hash.go", + "line": 50, + "additionalContext": "scanoss:match,return NewHash(md5.New(), space, data, 3)" + }, + { + "location": "vendor-deps/github.com/Azure/go-ntlmssp/nlmp.go", + "line": 46, + "additionalContext": "scanoss:match,mac := hmac.New(md5.New, key)" + }, + { + "location": "vendor-deps/github.com/go-ldap/ldap/v3/bind.go", + "line": 375, + "additionalContext": "scanoss:match,hasher := md5.New()" + }, + { + "location": "vendor-deps/github.com/google/uuid/hash.go", + "line": 50, + "additionalContext": "scanoss:match,return NewHash(md5.New(), space, data, 3)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 72, + "additionalContext": "scanoss:match,RSAMD5: crypto.MD5, // Deprecated in RFC 6725" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/operator/resource/resourceapply/resource_cache.go", + "line": 164, + "additionalContext": "scanoss:match,h := md5.New()" + }, + { + "location": "vendor-deps/golang.org/x/tools/internal/pkgbits/encoder.go", + "line": 58, + "additionalContext": "scanoss:match,h := md5.New()" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "hash", + "parameterSetIdentifier": "128", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + }, + "oid": "1.2.840.113549.2.5" + } + }, + { + "bom-ref": "cb1abb6e-3499-4ff6-95b0-11e780c216c7", + "type": "cryptographic-asset", + "name": "OTR", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "sign,verify,keygen" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.xcrypto.algorithm.otr.go.xcrypto.otr.privatekey-sign" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.xcrypto.algorithm.otr.go.xcrypto.otr.publickey-verify" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.xcrypto.algorithm.otr.go.xcrypto.otr.privatekey-generate" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/github.com/dustin/go-humanize/comma.go", + "line": 91, + "additionalContext": "scanoss:match,if b.Sign() \u003c 0 {" + }, + { + "location": "etcd-deps/github.com/dustin/go-humanize/commaf.go", + "line": 16, + "additionalContext": "scanoss:match,if v.Sign() \u003c 0 {" + }, + { + "location": "etcd-deps/github.com/fxamacker/cbor/v2/encode.go", + "line": 1685, + "additionalContext": "scanoss:match,sign := vbi.Sign()" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ecdsa.go", + "line": 83, + "additionalContext": "scanoss:match,if verifystatus := ecdsa.Verify(ecdsaKey, hasher.Sum(nil), r, s); verifystatus {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ecdsa.go", + "line": 111, + "additionalContext": "scanoss:match,if r, s, err := ecdsa.Sign(rand.Reader, ecdsaKey, hasher.Sum(nil)); err == nil {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ed25519.go", + "line": 49, + "additionalContext": "scanoss:match,if !ed25519.Verify(ed25519Key, []byte(signingString), sig) {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ed25519.go", + "line": 73, + "additionalContext": "scanoss:match,sig, err := ed25519Key.Sign(rand.Reader, []byte(signingString), crypto.Hash(0))" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/parser.go", + "line": 105, + "additionalContext": "scanoss:match,if err = token.Method.Verify(text, token.Signature, key); err == nil {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/parser.go", + "line": 110, + "additionalContext": "scanoss:match,err = token.Method.Verify(text, token.Signature, have)" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/token.go", + "line": 69, + "additionalContext": "scanoss:match,sig, err := t.Method.Sign(sstr, key)" + }, + { + "location": "etcd-deps/go.etcd.io/bbolt/bucket.go", + "line": 882, + "additionalContext": "scanoss:match,common.Verify(func() { common.Assert(pgId == 0, \"The page ID (%d) isn't 0 for an inline bucket\", pgId) })" + }, + { + "location": "etcd-deps/go.etcd.io/bbolt/internal/freelist/array.go", + "line": 73, + "additionalContext": "scanoss:match,common.Verify(func() { idsIdx := make(map[common.Pgid]struct{}) for _, id := range f.ids { // The existing f.ids shouldn't have duplicated free ID. if _, ok := idsIdx[id]; ok { panic(fmt.Sprintf(\"detected duplicated free page ID: %d in existing f.ids: %v\", id, f.ids)) } idsIdx[id] = struct{}{} } prev := common.Pgid(0) for _, id := range ids { // The ids shouldn't have duplicated free ID. Note page 0 and 1 // are reserved for meta pages, so they can never be free page IDs. if prev == id { panic(fmt.Sprintf(\"detected duplicated free ID: %d in ids: %v\", id, ids)) } prev = id // The ids shouldn't have any overlap with the existing f.ids. if _, ok := idsIdx[id]; ok { panic(fmt.Sprintf(\"detected overlapped free page ID: %d between ids: %v and existing f.ids: %v\", id, ids, f.ids)) } } })" + }, + { + "location": "etcd-deps/go.etcd.io/bbolt/internal/freelist/hashmap.go", + "line": 109, + "additionalContext": "scanoss:match,common.Verify(func() { expectedFreePageCount := f.hashmapFreeCountSlow() common.Assert(int(f.freePagesCount) == expectedFreePageCount, \"freePagesCount (%d) is out of sync with free pages map (%d)\", f.freePagesCount, expectedFreePageCount) })" + }, + { + "location": "etcd-deps/go.etcd.io/bbolt/internal/freelist/hashmap.go", + "line": 172, + "additionalContext": "scanoss:match,common.Verify(func() { ids1Freemap := f.idsFromFreemaps() ids2Forward := f.idsFromForwardMap() ids3Backward := f.idsFromBackwardMap() if !reflect.DeepEqual(ids1Freemap, ids2Forward) { panic(fmt.Sprintf(\"Detected mismatch, f.freemaps: %v, f.forwardMap: %v\", f.freemaps, f.forwardMap)) } if !reflect.DeepEqual(ids1Freemap, ids3Backward) { panic(fmt.Sprintf(\"Detected mismatch, f.freemaps: %v, f.backwardMap: %v\", f.freemaps, f.backwardMap)) } sort.Sort(ids) prev := common.Pgid(0) for _, id := range ids { // The ids shouldn't have duplicated free ID. if prev == id { panic(fmt.Sprintf(\"detected duplicated free ID: %d in ids: %v\", id, ids)) } prev = id // The ids shouldn't have any overlap with the existing f.freemaps. if _, ok := ids1Freemap[id]; ok { panic(fmt.Sprintf(\"detected overlapped free page ID: %d between ids: %v and existing f.freemaps: %v\", id, ids, f.freemaps)) } } })" + }, + { + "location": "etcd-deps/go.etcd.io/bbolt/internal/freelist/shared.go", + "line": 68, + "additionalContext": "scanoss:match,common.Verify(func() { if allocTxid == txid { panic(fmt.Sprintf(\"free: freed page (%d) was allocated by the same transaction (%d)\", p.Id(), txid)) } })" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/client/v3/client.go", + "line": 200, + "additionalContext": "scanoss:match,verify.Verify(func() { if len(eps) == 0 { panic(\"empty endpoints returned from etcd cluster\") } })" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/etcdserver/server.go", + "line": 1182, + "additionalContext": "scanoss:match,verify.Verify(func() { if cindex != snapshot.Metadata.Index { panic(fmt.Sprintf(\"consistent_index(%d) isn't equal to snapshot index (%d)\", cindex, snapshot.Metadata.Index)) } })" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/etcdserver/server.go", + "line": 1190, + "additionalContext": "scanoss:match,verify.Verify(func() { if cindex \u003c snapshot.Metadata.Index { lg.Panic(fmt.Sprintf(\"consistent_index(%d) is older than snapshot index (%d)\", cindex, snapshot.Metadata.Index)) } })" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/etcdserver/server.go", + "line": 2176, + "additionalContext": "scanoss:match,verify.Verify(func() { s.verifyV3StoreInSyncWithV2Store(shouldApplyV3) })" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/storage/backend/tx_buffer.go", + "line": 59, + "additionalContext": "scanoss:match,verify.Verify(func() { b, ok := txw.buckets[bucket.ID()] if !ok || b.used == 0 { return } existingMaxKey := b.buf[b.used-1].key if bytes.Compare(k, existingMaxKey) \u003c= 0 { panic(fmt.Sprintf(\"Broke the rule of monotonically increasing, existingMaxKey: %s, currentKey: %s\", hex.EncodeToString(existingMaxKey), hex.EncodeToString(k))) } })" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/storage/backend/verify.go", + "line": 83, + "additionalContext": "scanoss:match,verify.Verify(func() { if b == nil { return } if lg != nil { lg.Debug(\"verifyBackendConsistency\", zap.Bool(\"skipSafeRangeBucket\", skipSafeRangeBucket)) } b.BatchTx().LockOutsideApply() defer b.BatchTx().Unlock() b.ReadTx().RLock() defer b.ReadTx().RUnlock() for _, bkt := range bucket { if skipSafeRangeBucket \u0026\u0026 bkt.IsSafeRangeBucket() { continue } unsafeVerifyTxConsistency(b, bkt) } })" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/storage/mvcc/kvstore.go", + "line": 462, + "additionalContext": "scanoss:match,verify.Verify(func() { if rev.Main \u003c currentRev { panic(fmt.Errorf(\"revision %d shouldn't be less than the previous revision %d\", rev.Main, currentRev)) } })" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/storage/mvcc/watchable_store.go", + "line": 594, + "additionalContext": "scanoss:match,verify.Verify(func() { if w.startRev \u003e 0 { for _, ev := range wr.Events { if ev.Kv.ModRevision \u003c w.startRev { panic(fmt.Sprintf(\"Event.ModRevision(%d) is less than the w.startRev(%d) for watchID: %d\", ev.Kv.ModRevision, w.startRev, w.id)) } } } })" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/storage/schema/cindex.go", + "line": 79, + "additionalContext": "scanoss:match,verify.Verify(func() { previousIndex, _ := UnsafeReadConsistentIndex(tx) if index \u003c previousIndex { panic(fmt.Errorf(\"update of consistent index not advancing: previous: %v new: %v\", previousIndex, index)) } })" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/verify/verify.go", + "line": 143, + "additionalContext": "scanoss:match,hardstate, err := wal2.Verify(cfg.Logger, walDir, snapshot)" + }, + { + "location": "etcd-deps/gopkg.in/inf.v0/dec.go", + "line": 187, + "additionalContext": "scanoss:match,return x.UnscaledBig().Sign()" + }, + { + "location": "etcd-deps/gopkg.in/inf.v0/dec.go", + "line": 361, + "additionalContext": "scanoss:match,if dm.Sign() == 0 {" + }, + { + "location": "etcd-deps/gopkg.in/inf.v0/dec.go", + "line": 433, + "additionalContext": "scanoss:match,if scale != 0 \u0026\u0026 x.unscaled.Sign() != 0 {" + }, + { + "location": "etcd-deps/gopkg.in/inf.v0/dec.go", + "line": 438, + "additionalContext": "scanoss:match,negbit := Scale(-((x.Sign() - 1) / 2))" + }, + { + "location": "etcd-deps/gopkg.in/inf.v0/rounder.go", + "line": 78, + "additionalContext": "scanoss:match,srA, srB := rA.Sign(), rB.Sign()" + }, + { + "location": "etcd-deps/gopkg.in/inf.v0/rounder.go", + "line": 100, + "additionalContext": "scanoss:match,if rA.Sign() != 0 {" + }, + { + "location": "etcd-deps/gopkg.in/inf.v0/rounder.go", + "line": 112, + "additionalContext": "scanoss:match,if rA.Sign() != 0 {" + }, + { + "location": "etcd-deps/gopkg.in/inf.v0/rounder.go", + "line": 113, + "additionalContext": "scanoss:match,z.UnscaledBig().Add(z.UnscaledBig(), intSign[rA.Sign()*rB.Sign()+1])" + }, + { + "location": "etcd-deps/gopkg.in/inf.v0/rounder.go", + "line": 120, + "additionalContext": "scanoss:match,if rA.Sign()*rB.Sign() \u003c 0 {" + }, + { + "location": "etcd-deps/gopkg.in/inf.v0/rounder.go", + "line": 128, + "additionalContext": "scanoss:match,if rA.Sign()*rB.Sign() \u003e 0 {" + }, + { + "location": "etcd-deps/k8s.io/apimachinery/pkg/api/resource/quantity.go", + "line": 364, + "additionalContext": "scanoss:match,sign := amount.Sign()" + }, + { + "location": "etcd-deps/k8s.io/apimachinery/pkg/api/resource/quantity.go", + "line": 556, + "additionalContext": "scanoss:match,return q.d.Dec.Sign() == 0" + }, + { + "location": "etcd-deps/k8s.io/apimachinery/pkg/api/resource/quantity.go", + "line": 565, + "additionalContext": "scanoss:match,return q.d.Dec.Sign()" + }, + { + "location": "etcd-deps/k8s.io/apimachinery/pkg/api/resource/quantity.go", + "line": 567, + "additionalContext": "scanoss:match,return q.i.Sign()" + }, + { + "location": "etcd-deps/k8s.io/apimachinery/pkg/api/resource/scale_int.go", + "line": 90, + "additionalContext": "scanoss:match,if remainder.Sign() != 0 {" + }, + { + "location": "vendor-deps/github.com/coreos/go-oidc/jwks.go", + "line": 117, + "additionalContext": "scanoss:match,if payload, err := jws.Verify(\u0026key); err == nil {" + }, + { + "location": "vendor-deps/github.com/coreos/go-oidc/jwks.go", + "line": 135, + "additionalContext": "scanoss:match,if payload, err := jws.Verify(\u0026key); err == nil {" + }, + { + "location": "vendor-deps/github.com/coreos/go-oidc/verify.go", + "line": 163, + "additionalContext": "scanoss:match,token, err := verifier.Verify(ctx, string(body))" + }, + { + "location": "vendor-deps/github.com/fxamacker/cbor/v2/encode.go", + "line": 1685, + "additionalContext": "scanoss:match,sign := vbi.Sign()" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 326, + "additionalContext": "scanoss:match,signature, err := k.Sign(rand.Reader, hashed, hash)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 467, + "additionalContext": "scanoss:match,if ecdsa.Verify(pubkey, h.Sum(nil), r, s) {" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 478, + "additionalContext": "scanoss:match,if ed25519.Verify(pubkey, append(signeddata, wire...), sigbuf) {" + }, + { + "location": "vendor-deps/github.com/miekg/dns/sig0.go", + "line": 178, + "additionalContext": "scanoss:match,if ecdsa.Verify(pk, hashed, r, s) {" + }, + { + "location": "vendor-deps/github.com/miekg/dns/sig0.go", + "line": 186, + "additionalContext": "scanoss:match,if ed25519.Verify(pk, hashed, sig) {" + }, + { + "location": "vendor-deps/github.com/miekg/dns/tsig.go", + "line": 63, + "additionalContext": "scanoss:match,b, err := key.Generate(msg, t)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/tsig.go", + "line": 84, + "additionalContext": "scanoss:match,return tsigHMACProvider(key).Generate(msg, t)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/tsig.go", + "line": 92, + "additionalContext": "scanoss:match,return tsigHMACProvider(key).Verify(msg, t)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/tsig.go", + "line": 197, + "additionalContext": "scanoss:match,mac, err := provider.Generate(buf, rr)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/tsig.go", + "line": 243, + "additionalContext": "scanoss:match,if err := provider.Verify(buf, tsig); err != nil {" + }, + { + "location": "vendor-deps/github.com/openshift/apiserver-library-go/pkg/securitycontextconstraints/sccmatching/provider.go", + "line": 108, + "additionalContext": "scanoss:match,supGroups, err := s.supplementalGroupStrategy.Generate(pod)" + }, + { + "location": "vendor-deps/github.com/openshift/apiserver-library-go/pkg/securitycontextconstraints/sccmatching/provider.go", + "line": 124, + "additionalContext": "scanoss:match,seLinux, err := s.seLinuxStrategy.Generate(pod, nil)" + }, + { + "location": "vendor-deps/github.com/openshift/apiserver-library-go/pkg/securitycontextconstraints/sccmatching/provider.go", + "line": 133, + "additionalContext": "scanoss:match,seccompProfile, err := s.seccompStrategy.Generate(pod.Annotations, pod)" + }, + { + "location": "vendor-deps/github.com/openshift/apiserver-library-go/pkg/securitycontextconstraints/sccmatching/provider.go", + "line": 157, + "additionalContext": "scanoss:match,uid, err := s.runAsUserStrategy.Generate(pod, container)" + }, + { + "location": "vendor-deps/github.com/openshift/apiserver-library-go/pkg/securitycontextconstraints/sccmatching/provider.go", + "line": 165, + "additionalContext": "scanoss:match,seLinux, err := s.seLinuxStrategy.Generate(pod, container)" + }, + { + "location": "vendor-deps/github.com/openshift/apiserver-library-go/pkg/securitycontextconstraints/sccmatching/provider.go", + "line": 195, + "additionalContext": "scanoss:match,caps, err := s.capabilitiesStrategy.Generate(pod, container)" + }, + { + "location": "vendor-deps/github.com/ovn-kubernetes/libovsdb/client/api.go", + "line": 428, + "additionalContext": "scanoss:match,conditions, err := a.cond.Generate()" + }, + { + "location": "vendor-deps/github.com/ovn-kubernetes/libovsdb/client/api.go", + "line": 505, + "additionalContext": "scanoss:match,conditions, err := a.cond.Generate()" + }, + { + "location": "vendor-deps/github.com/ovn-kubernetes/libovsdb/client/api.go", + "line": 527, + "additionalContext": "scanoss:match,conditions, err := a.cond.Generate()" + }, + { + "location": "vendor-deps/github.com/ovn-kubernetes/libovsdb/client/api.go", + "line": 566, + "additionalContext": "scanoss:match,conditions, err := a.cond.Generate()" + }, + { + "location": "vendor-deps/github.com/ovn-kubernetes/libovsdb/client/api.go", + "line": 704, + "additionalContext": "scanoss:match,ovsdbConditionsList, err = a.cond.Generate()" + }, + { + "location": "vendor-deps/go.etcd.io/etcd/client/v3/client.go", + "line": 200, + "additionalContext": "scanoss:match,verify.Verify(func() { if len(eps) == 0 { panic(\"empty endpoints returned from etcd cluster\") } })" + }, + { + "location": "vendor-deps/golang.org/x/crypto/cryptobyte/asn1.go", + "line": 73, + "additionalContext": "scanoss:match,if n.Sign() \u003c 0 {" + }, + { + "location": "vendor-deps/golang.org/x/crypto/cryptobyte/asn1.go", + "line": 88, + "additionalContext": "scanoss:match,} else if n.Sign() == 0 {" + }, + { + "location": "vendor-deps/golang.org/x/crypto/ed25519/ed25519.go", + "line": 65, + "additionalContext": "scanoss:match,return ed25519.Sign(privateKey, message)" + }, + { + "location": "vendor-deps/golang.org/x/crypto/ed25519/ed25519.go", + "line": 71, + "additionalContext": "scanoss:match,return ed25519.Verify(publicKey, message, sig)" + }, + { + "location": "vendor-deps/golang.org/x/crypto/nacl/secretbox/secretbox.go", + "line": 145, + "additionalContext": "scanoss:match,if !poly1305.Verify(\u0026tag, box[poly1305.TagSize:], \u0026poly1305Key) {" + }, + { + "location": "vendor-deps/golang.org/x/tools/internal/gcimporter/iexport.go", + "line": 1406, + "additionalContext": "scanoss:match,negative := x.Sign() \u003c 0" + }, + { + "location": "vendor-deps/golang.org/x/tools/internal/gcimporter/iexport.go", + "line": 1485, + "additionalContext": "scanoss:match,if manti.Sign() != 0 {" + }, + { + "location": "vendor-deps/golang.org/x/tools/internal/gcimporter/iimport.go", + "line": 796, + "additionalContext": "scanoss:match,if f.Sign() != 0 {" + }, + { + "location": "vendor-deps/golang.org/x/tools/internal/pkgbits/encoder.go", + "line": 383, + "additionalContext": "scanoss:match,w.Bool(v.Sign() \u003c 0)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 478, + "additionalContext": "scanoss:match,sig, err := ctx.privateKey.Sign(RandReader, payload, crypto.Hash(0))" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 493, + "additionalContext": "scanoss:match,ok := ed25519.Verify(ctx.publicKey, payload, signature)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 528, + "additionalContext": "scanoss:match,r, s, err := ecdsa.Sign(RandReader, ctx.privateKey, hashed)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 589, + "additionalContext": "scanoss:match,match := ecdsa.Verify(ctx.publicKey, hashed, r, s)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/jwt/builder.go", + "line": 225, + "additionalContext": "scanoss:match,return b.sig.Sign(p)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/jwt/builder.go", + "line": 323, + "additionalContext": "scanoss:match,sig, err := b.sig.Sign(p)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/shared.go", + "line": 208, + "additionalContext": "scanoss:match,return leaf.Verify(opts)" + }, + { + "location": "vendor-deps/gopkg.in/inf.v0/dec.go", + "line": 187, + "additionalContext": "scanoss:match,return x.UnscaledBig().Sign()" + }, + { + "location": "vendor-deps/gopkg.in/inf.v0/dec.go", + "line": 361, + "additionalContext": "scanoss:match,if dm.Sign() == 0 {" + }, + { + "location": "vendor-deps/gopkg.in/inf.v0/dec.go", + "line": 433, + "additionalContext": "scanoss:match,if scale != 0 \u0026\u0026 x.unscaled.Sign() != 0 {" + }, + { + "location": "vendor-deps/gopkg.in/inf.v0/dec.go", + "line": 438, + "additionalContext": "scanoss:match,negbit := Scale(-((x.Sign() - 1) / 2))" + }, + { + "location": "vendor-deps/gopkg.in/inf.v0/rounder.go", + "line": 78, + "additionalContext": "scanoss:match,srA, srB := rA.Sign(), rB.Sign()" + }, + { + "location": "vendor-deps/gopkg.in/inf.v0/rounder.go", + "line": 100, + "additionalContext": "scanoss:match,if rA.Sign() != 0 {" + }, + { + "location": "vendor-deps/gopkg.in/inf.v0/rounder.go", + "line": 112, + "additionalContext": "scanoss:match,if rA.Sign() != 0 {" + }, + { + "location": "vendor-deps/gopkg.in/inf.v0/rounder.go", + "line": 113, + "additionalContext": "scanoss:match,z.UnscaledBig().Add(z.UnscaledBig(), intSign[rA.Sign()*rB.Sign()+1])" + }, + { + "location": "vendor-deps/gopkg.in/inf.v0/rounder.go", + "line": 120, + "additionalContext": "scanoss:match,if rA.Sign()*rB.Sign() \u003c 0 {" + }, + { + "location": "vendor-deps/gopkg.in/inf.v0/rounder.go", + "line": 128, + "additionalContext": "scanoss:match,if rA.Sign()*rB.Sign() \u003e 0 {" + }, + { + "location": "vendor-deps/k8s.io/apimachinery/pkg/api/resource/quantity.go", + "line": 364, + "additionalContext": "scanoss:match,sign := amount.Sign()" + }, + { + "location": "vendor-deps/k8s.io/apimachinery/pkg/api/resource/quantity.go", + "line": 556, + "additionalContext": "scanoss:match,return q.d.Dec.Sign() == 0" + }, + { + "location": "vendor-deps/k8s.io/apimachinery/pkg/api/resource/quantity.go", + "line": 565, + "additionalContext": "scanoss:match,return q.d.Dec.Sign()" + }, + { + "location": "vendor-deps/k8s.io/apimachinery/pkg/api/resource/quantity.go", + "line": 567, + "additionalContext": "scanoss:match,return q.i.Sign()" + }, + { + "location": "vendor-deps/k8s.io/apimachinery/pkg/api/resource/scale_int.go", + "line": 90, + "additionalContext": "scanoss:match,if remainder.Sign() != 0 {" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/admission/plugin/resourcequota/controller.go", + "line": 374, + "additionalContext": "scanoss:match,if v.Sign() == 1 {" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/authentication/request/x509/x509.go", + "line": 185, + "additionalContext": "scanoss:match,chains, err := req.TLS.PeerCertificates[0].Verify(optsCopy)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/authentication/request/x509/x509.go", + "line": 248, + "additionalContext": "scanoss:match,if _, err := req.TLS.PeerCertificates[0].Verify(optsCopy); err != nil {" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/cel/library/quantity.go", + "line": 267, + "additionalContext": "scanoss:match,return types.Int(q.Sign())" + }, + { + "location": "vendor-deps/k8s.io/apiserver/plugin/pkg/authenticator/token/oidc/oidc.go", + "line": 813, + "additionalContext": "scanoss:match,t, err := v.Verify(ctx, jwt)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/plugin/pkg/authenticator/token/oidc/oidc.go", + "line": 830, + "additionalContext": "scanoss:match,t, err := v.verifier.Verify(ctx, rawIDToken)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/plugin/pkg/authenticator/token/oidc/oidc.go", + "line": 870, + "additionalContext": "scanoss:match,idToken, err := verifier.Verify(ctx, token)" + }, + { + "location": "vendor-deps/k8s.io/cluster-bootstrap/token/jws/jws.go", + "line": 49, + "additionalContext": "scanoss:match,jws, err := signer.Sign([]byte(content))" + }, + { + "location": "vendor-deps/k8s.io/externaljwt/apis/v1/api_grpc.pb.go", + "line": 194, + "additionalContext": "scanoss:match,return srv.(ExternalJWTSignerServer).Sign(ctx, in)" + }, + { + "location": "vendor-deps/k8s.io/externaljwt/apis/v1/api_grpc.pb.go", + "line": 201, + "additionalContext": "scanoss:match,return srv.(ExternalJWTSignerServer).Sign(ctx, req.(*SignJWTRequest))" + }, + { + "location": "vendor-deps/k8s.io/kubectl/pkg/util/qos/qos.go", + "line": 46, + "additionalContext": "scanoss:match,if quantity.Sign() == 1 {" + }, + { + "location": "vendor-deps/k8s.io/kubectl/pkg/util/qos/qos.go", + "line": 67, + "additionalContext": "scanoss:match,if quantity.Sign() == 1 {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/cmd/kubelet/app/server.go", + "line": 1375, + "additionalContext": "scanoss:match,if q.Sign() == -1 {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/apis/autoscaling/validation/validation.go", + "line": 456, + "additionalContext": "scanoss:match,if mt.Value != nil \u0026\u0026 mt.Value.Sign() != 1 {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/apis/autoscaling/validation/validation.go", + "line": 460, + "additionalContext": "scanoss:match,if mt.AverageValue != nil \u0026\u0026 mt.AverageValue.Sign() != 1 {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/apis/certificates/validation/validation.go", + "line": 694, + "additionalContext": "scanoss:match,if !ed25519.Verify(pub, []byte(req.Spec.PodUID), req.Spec.ProofOfPossession) {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/apis/core/helper/helpers.go", + "line": 49, + "additionalContext": "scanoss:match,if pageSize.Sign() \u003c= 0 || pageSize.MilliValue()%int64(1000) != int64(0) {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/apis/core/v1/helper/qos/qos.go", + "line": 52, + "additionalContext": "scanoss:match,if quantity.Sign() == 1 {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/apis/core/v1/helper/qos/qos.go", + "line": 73, + "additionalContext": "scanoss:match,if quantity.Sign() == 1 {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/apis/core/v1/helper/qos/qos.go", + "line": 118, + "additionalContext": "scanoss:match,if quantity.Sign() == 1 {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/apis/core/v1/helper/qos/qos.go", + "line": 134, + "additionalContext": "scanoss:match,if quantity.Sign() == 1 {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/apis/resource/validation/validation.go", + "line": 912, + "additionalContext": "scanoss:match,if mapping.AllocationMultiplier.Sign() \u003c= 0 {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/controller/certificates/signer/signer.go", + "line": 206, + "additionalContext": "scanoss:match,der, err := currCA.Sign(x509cr.Raw, authority.PermissiveSigningPolicy{ TTL: s.duration(expirationSeconds), Usages: usages, Backdate: 5 * time.Minute, // this must always be less than the minimum TTL requested by a user (see sanity check requestedDuration below) Short: 8 * time.Hour, // 5 minutes of backdating is roughly 1% of 8 hours Now: now, })" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/allocation/state/checkpoint.go", + "line": 68, + "additionalContext": "scanoss:match,return cp.Checksum.Verify(cp.Data)" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/cm/cpumanager/state/checkpoint.go", + "line": 177, + "additionalContext": "scanoss:match,err := ck.Verify(cp)" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/cm/cpumanager/state/checkpoint.go", + "line": 206, + "additionalContext": "scanoss:match,err := ck.Verify(cp)" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/cm/devicemanager/checkpoint/checkpoint.go", + "line": 102, + "additionalContext": "scanoss:match,return cp.Checksum.Verify(cp.Data)" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/cm/memorymanager/state/checkpoint.go", + "line": 125, + "additionalContext": "scanoss:match,err := ck.Verify(mp)" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/cm/memorymanager/state/checkpoint.go", + "line": 155, + "additionalContext": "scanoss:match,err := ck.Verify(mp)" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/cm/node_container_manager_linux.go", + "line": 262, + "additionalContext": "scanoss:match,if value.Sign() \u003c 0 {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/cm/node_container_manager_linux.go", + "line": 313, + "additionalContext": "scanoss:match,if value.Sign() \u003c 0 {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/eviction/eviction_manager.go", + "line": 544, + "additionalContext": "scanoss:match,if used != nil \u0026\u0026 size != nil \u0026\u0026 size.Sign() == 1 \u0026\u0026 used.Cmp(*size) \u003e 0 {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/eviction/helpers.go", + "line": 414, + "additionalContext": "scanoss:match,if quantity.Sign() \u003c 0 || quantity.IsZero() {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/eviction/helpers.go", + "line": 486, + "additionalContext": "scanoss:match,if quantity.Sign() \u003c 0 {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/nodestatus/setters.go", + "line": 311, + "additionalContext": "scanoss:match,if value.Sign() \u003c 0 {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/nodestatus/setters.go", + "line": 330, + "additionalContext": "scanoss:match,if allocatableMemory.Sign() \u003c 0 {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/serviceaccount/externaljwt/plugin/plugin.go", + "line": 125, + "additionalContext": "scanoss:match,response, err := p.client.Sign(ctx, request)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "signature", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "sign", + "verify", + "keygen" + ] + } + } + }, + { + "bom-ref": "4e47e6e5-fd24-46c7-999c-b43d58ac7178", + "type": "cryptographic-asset", + "name": "PBKDF2---", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "keyderive" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.pbkdf2.go.crypto.pbkdf2.key-derivation" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.xcrypto.algorithm.pbkdf2.go.xcrypto.pbkdf2.key-derivation" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/golang.org/x/crypto/pbkdf2/pbkdf2.go", + "line": 24, + "additionalContext": "scanoss:match,out, err := pbkdf2.Key(h, string(password), salt, iter, keyLen)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/symmetric.go", + "line": 321, + "additionalContext": "scanoss:match,key := pbkdf2.Key(ctx.key, salt, ctx.p2c, keyLen, h)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/symmetric.go", + "line": 321, + "additionalContext": "scanoss:match,key := pbkdf2.Key(ctx.key, salt, ctx.p2c, keyLen, h)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/symmetric.go", + "line": 417, + "additionalContext": "scanoss:match,key := pbkdf2.Key(ctx.key, salt, p2c, keyLen, h)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/symmetric.go", + "line": 417, + "additionalContext": "scanoss:match,key := pbkdf2.Key(ctx.key, salt, p2c, keyLen, h)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "kdf", + "parameterSetIdentifier": "-", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "keyderive" + ] + }, + "oid": "1.2.840.113549.1.5.12" + } + }, + { + "bom-ref": "1d0b6d56-2228-4489-844f-e5f152136399", + "type": "cryptographic-asset", + "name": "RSA", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "keygen,verify,sign" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.key-type" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.verify" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.key-type" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.sign" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.verify" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.sign" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.x509.go.crypto.x509.parse-pkcs1-key" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.key-generation" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.x509.go.crypto.x509.parse-pkcs1-key" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa.go", + "line": 50, + "additionalContext": "scanoss:match,var rsaKey *rsa.PublicKey" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa.go", + "line": 65, + "additionalContext": "scanoss:match,return rsa.VerifyPKCS1v15(rsaKey, m.Hash, hasher.Sum(nil), sig)" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa.go", + "line": 71, + "additionalContext": "scanoss:match,var rsaKey *rsa.PrivateKey" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa.go", + "line": 88, + "additionalContext": "scanoss:match,if sigBytes, err := rsa.SignPKCS1v15(rand.Reader, rsaKey, m.Hash, hasher.Sum(nil)); err == nil {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_pss.go", + "line": 83, + "additionalContext": "scanoss:match,var rsaKey *rsa.PublicKey" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_pss.go", + "line": 103, + "additionalContext": "scanoss:match,return rsa.VerifyPSS(rsaKey, m.Hash, hasher.Sum(nil), sig, opts)" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_pss.go", + "line": 109, + "additionalContext": "scanoss:match,var rsaKey *rsa.PrivateKey" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_pss.go", + "line": 127, + "additionalContext": "scanoss:match,if sigBytes, err := rsa.SignPSS(rand.Reader, rsaKey, m.Hash, hasher.Sum(nil), m.Options); err == nil {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_utils.go", + "line": 27, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKCS1PrivateKey(block.Bytes); err != nil {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_utils.go", + "line": 33, + "additionalContext": "scanoss:match,var pkey *rsa.PrivateKey" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_utils.go", + "line": 63, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKCS1PrivateKey(blockDecrypted); err != nil {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_utils.go", + "line": 69, + "additionalContext": "scanoss:match,var pkey *rsa.PrivateKey" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_utils.go", + "line": 94, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKCS1PublicKey(block.Bytes); err != nil {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_utils.go", + "line": 100, + "additionalContext": "scanoss:match,var pkey *rsa.PublicKey" + }, + { + "location": "etcd-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 1036, + "additionalContext": "scanoss:match,privateKey, err := rsa.GenerateKey(rand.Reader, keyBits)" + }, + { + "location": "etcd-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 1227, + "additionalContext": "scanoss:match,if err := pem.Encode(\u0026b, \u0026pem.Block{Type: \"RSA PRIVATE KEY\", Bytes: x509.MarshalPKCS1PrivateKey(key)}); err != nil {" + }, + { + "location": "etcd-deps/github.com/openshift/library-go/pkg/crypto/keygen.go", + "line": 47, + "additionalContext": "scanoss:match,privateKey, err := rsa.GenerateKey(rand.Reader, bits)" + }, + { + "location": "etcd-deps/github.com/openshift/microshift/pkg/util/cert.go", + "line": 44, + "additionalContext": "scanoss:match,rsaKey, err := rsa.GenerateKey(rand.Reader, keySize)" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/auth/options.go", + "line": 121, + "additionalContext": "scanoss:match,priv *rsa.PrivateKey" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/auth/options.go", + "line": 122, + "additionalContext": "scanoss:match,pub *rsa.PublicKey" + }, + { + "location": "etcd-deps/golang.org/x/oauth2/internal/oauth2.go", + "line": 27, + "additionalContext": "scanoss:match,parsedKey, err = x509.ParsePKCS1PrivateKey(key)" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/cert/cert.go", + "line": 173, + "additionalContext": "scanoss:match,caKey, err := rsa.GenerateKey(cryptorand.Reader, 2048)" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/cert/cert.go", + "line": 206, + "additionalContext": "scanoss:match,priv, err := rsa.GenerateKey(cryptorand.Reader, 2048)" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/cert/cert.go", + "line": 254, + "additionalContext": "scanoss:match,if err := pem.Encode(\u0026keyBuffer, \u0026pem.Block{Type: keyutil.RSAPrivateKeyBlockType, Bytes: x509.MarshalPKCS1PrivateKey(priv)}); err != nil {" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 113, + "additionalContext": "scanoss:match,Bytes: x509.MarshalPKCS1PrivateKey(t)," + }, + { + "location": "etcd-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 176, + "additionalContext": "scanoss:match,if key, err := x509.ParsePKCS1PrivateKey(privateKeyPemBlock.Bytes); err == nil {" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 249, + "additionalContext": "scanoss:match,var pubKey *rsa.PublicKey" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 264, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKCS1PrivateKey(data); err != nil {" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 271, + "additionalContext": "scanoss:match,var privKey *rsa.PrivateKey" + }, + { + "location": "pkg/util/cert.go", + "line": 44, + "additionalContext": "scanoss:match,rsaKey, err := rsa.GenerateKey(rand.Reader, keySize)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 453, + "additionalContext": "scanoss:match,return rsa.VerifyPKCS1v15(pubkey, cryptohash, h.Sum(nil), sigbuf)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 550, + "additionalContext": "scanoss:match,pubkey := new(rsa.PublicKey)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec_keygen.go", + "line": 47, + "additionalContext": "scanoss:match,priv, err := rsa.GenerateKey(rand.Reader, bits)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec_keyscan.go", + "line": 77, + "additionalContext": "scanoss:match,p := new(rsa.PrivateKey)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/sig0.go", + "line": 171, + "additionalContext": "scanoss:match,return rsa.VerifyPKCS1v15(pk, cryptohash, hashed, sig)" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 1036, + "additionalContext": "scanoss:match,privateKey, err := rsa.GenerateKey(rand.Reader, keyBits)" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 1227, + "additionalContext": "scanoss:match,if err := pem.Encode(\u0026b, \u0026pem.Block{Type: \"RSA PRIVATE KEY\", Bytes: x509.MarshalPKCS1PrivateKey(key)}); err != nil {" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/crypto/keygen.go", + "line": 47, + "additionalContext": "scanoss:match,privateKey, err := rsa.GenerateKey(rand.Reader, bits)" + }, + { + "location": "vendor-deps/golang.org/x/oauth2/internal/oauth2.go", + "line": 27, + "additionalContext": "scanoss:match,parsedKey, err = x509.ParsePKCS1PrivateKey(key)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 291, + "additionalContext": "scanoss:match,out, err = rsa.SignPKCS1v15(RandReader, ctx.privateKey, hash, hashed)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 293, + "additionalContext": "scanoss:match,out, err = rsa.SignPSS(RandReader, ctx.privateKey, hash, hashed, \u0026rsa.PSSOptions{ SaltLength: rsa.PSSSaltLengthEqualsHash, })" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 331, + "additionalContext": "scanoss:match,return rsa.VerifyPKCS1v15(ctx.publicKey, hash, hashed, signature)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 333, + "additionalContext": "scanoss:match,return rsa.VerifyPSS(ctx.publicKey, hash, hashed, signature, nil)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/jwk.go", + "line": 611, + "additionalContext": "scanoss:match,rv := \u0026rsa.PrivateKey{ PublicKey: rsa.PublicKey{ N: key.N.bigInt(), E: key.E.toInt(), }, D: key.D.bigInt(), Primes: []*big.Int{ key.P.bigInt(), key.Q.bigInt(), }, }" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/cert/cert.go", + "line": 173, + "additionalContext": "scanoss:match,caKey, err := rsa.GenerateKey(cryptorand.Reader, 2048)" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/cert/cert.go", + "line": 206, + "additionalContext": "scanoss:match,priv, err := rsa.GenerateKey(cryptorand.Reader, 2048)" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/cert/cert.go", + "line": 254, + "additionalContext": "scanoss:match,if err := pem.Encode(\u0026keyBuffer, \u0026pem.Block{Type: keyutil.RSAPrivateKeyBlockType, Bytes: x509.MarshalPKCS1PrivateKey(priv)}); err != nil {" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 113, + "additionalContext": "scanoss:match,Bytes: x509.MarshalPKCS1PrivateKey(t)," + }, + { + "location": "vendor-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 176, + "additionalContext": "scanoss:match,if key, err := x509.ParsePKCS1PrivateKey(privateKeyPemBlock.Bytes); err == nil {" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 249, + "additionalContext": "scanoss:match,var pubKey *rsa.PublicKey" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 264, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKCS1PrivateKey(data); err != nil {" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 271, + "additionalContext": "scanoss:match,var privKey *rsa.PrivateKey" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/apis/certificates/validation/validation.go", + "line": 714, + "additionalContext": "scanoss:match,if err := rsa.VerifyPSS(pub, crypto.SHA256, hashBytes([]byte(req.Spec.PodUID)), req.Spec.ProofOfPossession, nil); err != nil {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/podcertificate/podcertificatemanager.go", + "line": 879, + "additionalContext": "scanoss:match,priv, err := rsa.GenerateKey(rand.Reader, 3072)" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/podcertificate/podcertificatemanager.go", + "line": 885, + "additionalContext": "scanoss:match,priv, err := rsa.GenerateKey(rand.Reader, 4096)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "pke", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "keygen", + "verify", + "sign" + ] + }, + "oid": "1.2.840.113549.1.1.1" + } + }, + { + "bom-ref": "71d14df5-217c-4e7a-9e5e-493649e030f7", + "type": "cryptographic-asset", + "name": "RSA-OAEP-sha1", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "encrypt,decrypt" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.encrypt-oaep" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.decrypt-oaep" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 200, + "additionalContext": "scanoss:match,return rsa.EncryptOAEP(sha1.New(), RandReader, ctx.publicKey, cek, []byte{})" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 253, + "additionalContext": "scanoss:match,return rsa.DecryptOAEP(sha1.New(), rand.Reader, ctx.privateKey, jek, []byte{})" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "pke", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "encrypt", + "decrypt" + ] + }, + "oid": "1.2.840.113549.1.1.1" + } + }, + { + "bom-ref": "c81f8b98-90af-4b1d-b1be-5ca4ee724bda", + "type": "cryptographic-asset", + "name": "RSA-OAEP-sha256", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "encrypt,decrypt" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.encrypt-oaep" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.decrypt-oaep" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 202, + "additionalContext": "scanoss:match,return rsa.EncryptOAEP(sha256.New(), RandReader, ctx.publicKey, cek, []byte{})" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 256, + "additionalContext": "scanoss:match,return rsa.DecryptOAEP(sha256.New(), rand.Reader, ctx.privateKey, jek, []byte{})" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "pke", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "encrypt", + "decrypt" + ] + }, + "oid": "1.2.840.113549.1.1.1" + } + }, + { + "bom-ref": "487d3678-2f6e-4c18-a077-832759e2b277", + "type": "cryptographic-asset", + "name": "RSA-PKCS1v15", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "encrypt,decrypt" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.encrypt-pkcs1v15" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.decrypt-pkcs1v15" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 198, + "additionalContext": "scanoss:match,return rsa.EncryptPKCS1v15(RandReader, ctx.publicKey, cek)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 248, + "additionalContext": "scanoss:match,_ = rsa.DecryptPKCS1v15SessionKey(rand.Reader, ctx.privateKey, jek, cek)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "pke", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "encrypt", + "decrypt" + ] + }, + "oid": "1.2.840.113549.1.1.1" + } + }, + { + "bom-ref": "561422d9-a15c-4876-b781-0a9dede446c9", + "type": "cryptographic-asset", + "name": "RSA-PKCS1v15-", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "verify,sign" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.verify-pkcs1v15" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.sign-pkcs1v15" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa.go", + "line": 65, + "additionalContext": "scanoss:match,return rsa.VerifyPKCS1v15(rsaKey, m.Hash, hasher.Sum(nil), sig)" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa.go", + "line": 88, + "additionalContext": "scanoss:match,if sigBytes, err := rsa.SignPKCS1v15(rand.Reader, rsaKey, m.Hash, hasher.Sum(nil)); err == nil {" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 453, + "additionalContext": "scanoss:match,return rsa.VerifyPKCS1v15(pubkey, cryptohash, h.Sum(nil), sigbuf)" + }, + { + "location": "vendor-deps/github.com/miekg/dns/sig0.go", + "line": 171, + "additionalContext": "scanoss:match,return rsa.VerifyPKCS1v15(pk, cryptohash, hashed, sig)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 291, + "additionalContext": "scanoss:match,out, err = rsa.SignPKCS1v15(RandReader, ctx.privateKey, hash, hashed)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 331, + "additionalContext": "scanoss:match,return rsa.VerifyPKCS1v15(ctx.publicKey, hash, hashed, signature)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "signature", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "verify", + "sign" + ] + }, + "oid": "1.2.840.113549.1.1.1" + } + }, + { + "bom-ref": "7854a75e-e055-4a9e-8826-6698cab47be8", + "type": "cryptographic-asset", + "name": "RSA-PSS-", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "verify,sign" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.verify-pss" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.sign-pss" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_pss.go", + "line": 103, + "additionalContext": "scanoss:match,return rsa.VerifyPSS(rsaKey, m.Hash, hasher.Sum(nil), sig, opts)" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_pss.go", + "line": 127, + "additionalContext": "scanoss:match,if sigBytes, err := rsa.SignPSS(rand.Reader, rsaKey, m.Hash, hasher.Sum(nil), m.Options); err == nil {" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 293, + "additionalContext": "scanoss:match,out, err = rsa.SignPSS(RandReader, ctx.privateKey, hash, hashed, \u0026rsa.PSSOptions{ SaltLength: rsa.PSSSaltLengthEqualsHash, })" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 333, + "additionalContext": "scanoss:match,return rsa.VerifyPSS(ctx.publicKey, hash, hashed, signature, nil)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "signature", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "verify", + "sign" + ] + }, + "oid": "1.2.840.113549.1.1.1" + } + }, + { + "bom-ref": "4f32f289-ad9d-4370-a0da-f5c2635bda19", + "type": "cryptographic-asset", + "name": "RSA-PSS-SHA256", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "verify" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.rsa.go.crypto.rsa.verify-pss" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/apis/certificates/validation/validation.go", + "line": 714, + "additionalContext": "scanoss:match,if err := rsa.VerifyPSS(pub, crypto.SHA256, hashBytes([]byte(req.Spec.PodUID)), req.Spec.ProofOfPossession, nil); err != nil {" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "signature", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "verify" + ] + }, + "oid": "1.2.840.113549.1.1.1" + } + }, + { + "bom-ref": "b6421418-9648-4192-a36d-61c5d00cebf4", + "type": "cryptographic-asset", + "name": "SHA-1", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.sha1.go.crypto.sha1.hash-usage" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/github.com/google/uuid/hash.go", + "line": 58, + "additionalContext": "scanoss:match,return NewHash(sha1.New(), space, data, 5)" + }, + { + "location": "etcd-deps/github.com/gorilla/websocket/util.go", + "line": 20, + "additionalContext": "scanoss:match,h := sha1.New()" + }, + { + "location": "etcd-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 1028, + "additionalContext": "scanoss:match,hash := sha1.New()" + }, + { + "location": "etcd-deps/github.com/squat/generic-device-plugin/deviceplugin/path.go", + "line": 98, + "additionalContext": "scanoss:match,h := sha1.New()" + }, + { + "location": "etcd-deps/github.com/squat/generic-device-plugin/deviceplugin/usb.go", + "line": 279, + "additionalContext": "scanoss:match,h := sha1.New()" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/etcdserver/api/membership/cluster.go", + "line": 238, + "additionalContext": "scanoss:match,hash := sha1.Sum(b)" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/etcdserver/api/membership/member.go", + "line": 74, + "additionalContext": "scanoss:match,hash := sha1.Sum(b)" + }, + { + "location": "vendor-deps/github.com/Microsoft/go-winio/pkg/guid/guid.go", + "line": 68, + "additionalContext": "scanoss:match,b := sha1.New() //nolint:gosec // not used for secure application" + }, + { + "location": "vendor-deps/github.com/godbus/dbus/v5/auth_sha1_windows.go", + "line": 50, + "additionalContext": "scanoss:match,hash := sha1.New()" + }, + { + "location": "vendor-deps/github.com/google/uuid/hash.go", + "line": 58, + "additionalContext": "scanoss:match,return NewHash(sha1.New(), space, data, 5)" + }, + { + "location": "vendor-deps/github.com/gorilla/websocket/util.go", + "line": 20, + "additionalContext": "scanoss:match,h := sha1.New()" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 73, + "additionalContext": "scanoss:match,DSA: crypto.SHA1," + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 74, + "additionalContext": "scanoss:match,RSASHA1: crypto.SHA1," + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 75, + "additionalContext": "scanoss:match,RSASHA1NSEC3SHA1: crypto.SHA1," + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 212, + "additionalContext": "scanoss:match,hash = crypto.SHA1" + }, + { + "location": "vendor-deps/github.com/miekg/dns/nsecx.go", + "line": 29, + "additionalContext": "scanoss:match,s := sha1.New()" + }, + { + "location": "vendor-deps/github.com/miekg/dns/tsig.go", + "line": 46, + "additionalContext": "scanoss:match,h = hmac.New(sha1.New, rawsecret)" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 1028, + "additionalContext": "scanoss:match,hash := sha1.New()" + }, + { + "location": "vendor-deps/github.com/squat/generic-device-plugin/deviceplugin/path.go", + "line": 98, + "additionalContext": "scanoss:match,h := sha1.New()" + }, + { + "location": "vendor-deps/github.com/squat/generic-device-plugin/deviceplugin/usb.go", + "line": 279, + "additionalContext": "scanoss:match,h := sha1.New()" + }, + { + "location": "vendor-deps/golang.org/x/net/websocket/hybi.go", + "line": 391, + "additionalContext": "scanoss:match,h := sha1.New()" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 200, + "additionalContext": "scanoss:match,return rsa.EncryptOAEP(sha1.New(), RandReader, ctx.publicKey, cek, []byte{})" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 253, + "additionalContext": "scanoss:match,return rsa.DecryptOAEP(sha1.New(), rand.Reader, ctx.privateKey, jek, []byte{})" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/jwk.go", + "line": 148, + "additionalContext": "scanoss:match,expectedSHA1 := sha1.Sum(k.Certificates[0].Raw)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/jwk.go", + "line": 298, + "additionalContext": "scanoss:match,sha1sum := sha1.Sum(leaf.Raw)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "hash", + "parameterSetIdentifier": "160", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + }, + "oid": "1.3.14.3.2.26" + } + }, + { + "bom-ref": "d389e591-901d-488b-840b-215ca1c33855", + "type": "cryptographic-asset", + "name": "SHA-224", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.sha256.go.crypto.sha256.hash-usage-224" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/github.com/miekg/dns/tsig.go", + "line": 48, + "additionalContext": "scanoss:match,h = hmac.New(sha256.New224, rawsecret)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "hash", + "parameterSetIdentifier": "224", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + }, + "oid": "2.16.840.1.101.3.4.2.4" + } + }, + { + "bom-ref": "fc9801bc-1c8d-4f69-943d-08979d9da273", + "type": "cryptographic-asset", + "name": "SHA-256", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.sha256.go.crypto.sha256.hash-usage-256" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ecdsa.go", + "line": 34, + "additionalContext": "scanoss:match,SigningMethodES256 = \u0026SigningMethodECDSA{\"ES256\", crypto.SHA256, 32, 256}" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/hmac.go", + "line": 26, + "additionalContext": "scanoss:match,SigningMethodHS256 = \u0026SigningMethodHMAC{\"HS256\", crypto.SHA256}" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa.go", + "line": 25, + "additionalContext": "scanoss:match,SigningMethodRS256 = \u0026SigningMethodRSA{\"RS256\", crypto.SHA256}" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_pss.go", + "line": 32, + "additionalContext": "scanoss:match,Hash: crypto.SHA256," + }, + { + "location": "etcd-deps/github.com/openshift/library-go/pkg/crypto/keygen.go", + "line": 116, + "additionalContext": "scanoss:match,hash := sha256.Sum256(rawBytes)" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/auth/store.go", + "line": 1235, + "additionalContext": "scanoss:match,sum := sha256.Sum256([]byte(token))" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/etcdserver/api/v3rpc/maintenance.go", + "line": 153, + "additionalContext": "scanoss:match,h := sha256.New()" + }, + { + "location": "etcd-deps/golang.org/x/oauth2/pkce.go", + "line": 50, + "additionalContext": "scanoss:match,sha := sha256.Sum256([]byte(verifier))" + }, + { + "location": "etcd-deps/k8s.io/client-go/discovery/cached/disk/round_tripper.go", + "line": 91, + "additionalContext": "scanoss:match,got := sha256.Sum256(response)" + }, + { + "location": "etcd-deps/k8s.io/client-go/discovery/cached/disk/round_tripper.go", + "line": 103, + "additionalContext": "scanoss:match,s := sha256.Sum256(response)" + }, + { + "location": "etcd-deps/k8s.io/client-go/discovery/cached/disk/round_tripper.go", + "line": 119, + "additionalContext": "scanoss:match,return fmt.Sprintf(\"%x\", sha256.Sum256([]byte(key)))" + }, + { + "location": "etcd-deps/sigs.k8s.io/kustomize/api/hasher/hasher.go", + "line": 53, + "additionalContext": "scanoss:match,return fmt.Sprintf(\"%x\", sha256.Sum256([]byte(data)))" + }, + { + "location": "pkg/components/render.go", + "line": 20, + "additionalContext": "scanoss:match,\"Sha256sum\": func(s string) string { return fmt.Sprintf(\"%x\", sha256.Sum256([]byte(s))) }," + }, + { + "location": "pkg/controllers/filewatcher.go", + "line": 282, + "additionalContext": "scanoss:match,hash := sha256.Sum256(content)" + }, + { + "location": "vendor-deps/github.com/coreos/go-oidc/oidc.go", + "line": 349, + "additionalContext": "scanoss:match,h = sha256.New()" + }, + { + "location": "vendor-deps/github.com/go-playground/validator/v10/baked_in.go", + "line": 769, + "additionalContext": "scanoss:match,h := sha256.New()" + }, + { + "location": "vendor-deps/github.com/go-playground/validator/v10/baked_in.go", + "line": 772, + "additionalContext": "scanoss:match,h = sha256.New()" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dane.go", + "line": 22, + "additionalContext": "scanoss:match,h := sha256.New()" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 76, + "additionalContext": "scanoss:match,RSASHA256: crypto.SHA256," + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 77, + "additionalContext": "scanoss:match,ECDSAP256SHA256: crypto.SHA256," + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 214, + "additionalContext": "scanoss:match,hash = crypto.SHA256" + }, + { + "location": "vendor-deps/github.com/miekg/dns/smimea.go", + "line": 36, + "additionalContext": "scanoss:match,hasher := sha256.New()" + }, + { + "location": "vendor-deps/github.com/miekg/dns/tsig.go", + "line": 50, + "additionalContext": "scanoss:match,h = hmac.New(sha256.New, rawsecret)" + }, + { + "location": "vendor-deps/github.com/opencontainers/go-digest/algorithm.go", + "line": 51, + "additionalContext": "scanoss:match,SHA256: crypto.SHA256," + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/controller/fileobserver/observer_polling.go", + "line": 196, + "additionalContext": "scanoss:match,hasher := sha256.New()" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/crypto/keygen.go", + "line": 116, + "additionalContext": "scanoss:match,hash := sha256.Sum256(rawBytes)" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/image/internal/digest/digester.go", + "line": 35, + "additionalContext": "scanoss:match,SHA256: crypto.SHA256," + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/operator/events/recorder.go", + "line": 252, + "additionalContext": "scanoss:match,hash := sha256.New()" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/operator/resource/resourceapply/apps.go", + "line": 65, + "additionalContext": "scanoss:match,specHash := fmt.Sprintf(\"%x\", sha256.Sum256(jsonBytes))" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/operator/resource/resourceapply/credentialsrequest.go", + "line": 36, + "additionalContext": "scanoss:match,specHash := fmt.Sprintf(\"%x\", sha256.Sum256(jsonBytes))" + }, + { + "location": "vendor-deps/github.com/ovn-kubernetes/libovsdb/cache/cache.go", + "line": 1239, + "additionalContext": "scanoss:match,h := sha256.New()" + }, + { + "location": "vendor-deps/golang.org/x/oauth2/pkce.go", + "line": 50, + "additionalContext": "scanoss:match,sha := sha256.Sum256([]byte(verifier))" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 202, + "additionalContext": "scanoss:match,return rsa.EncryptOAEP(sha256.New(), RandReader, ctx.publicKey, cek, []byte{})" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 256, + "additionalContext": "scanoss:match,return rsa.DecryptOAEP(sha256.New(), rand.Reader, ctx.privateKey, jek, []byte{})" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 268, + "additionalContext": "scanoss:match,hash = crypto.SHA256" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 314, + "additionalContext": "scanoss:match,hash = crypto.SHA256" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 508, + "additionalContext": "scanoss:match,hash = crypto.SHA256" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 565, + "additionalContext": "scanoss:match,hash = crypto.SHA256" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/cipher/cbc_hmac.go", + "line": 49, + "additionalContext": "scanoss:match,hash = sha256.New" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/cipher/ecdh_es.go", + "line": 61, + "additionalContext": "scanoss:match,reader := NewConcatKDF(crypto.SHA256, zBytes, algID, ptyUInfo, ptyVInfo, supPubInfo, []byte{})" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/jwk.go", + "line": 149, + "additionalContext": "scanoss:match,expectedSHA256 := sha256.Sum256(k.Certificates[0].Raw)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/jwk.go", + "line": 299, + "additionalContext": "scanoss:match,sha256sum := sha256.Sum256(leaf.Raw)" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/symmetric.go", + "line": 138, + "additionalContext": "scanoss:match,return 16, sha256.New" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/symmetric.go", + "line": 473, + "additionalContext": "scanoss:match,hash = sha256.New" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/admission/plugin/manifest/loader.go", + "line": 79, + "additionalContext": "scanoss:match,h := sha256.New()" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/admission/plugin/manifest/metrics/metrics.go", + "line": 160, + "additionalContext": "scanoss:match,return fmt.Sprintf(\"sha256:%x\", sha256.Sum256([]byte(data)))" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/authentication/request/x509/x509.go", + "line": 285, + "additionalContext": "scanoss:match,fp := sha256.Sum256(chain[0].Raw)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/authentication/token/cache/cached_token_authenticator.go", + "line": 122, + "additionalContext": "scanoss:match,return hmac.New(sha256.New, randomCacheKey)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/endpoints/discovery/storageversionhash.go", + "line": 30, + "additionalContext": "scanoss:match,bytes := sha256.Sum256([]byte(gvk))" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/endpoints/filters/impersonation/cache.go", + "line": 314, + "additionalContext": "scanoss:match,hashed := sha256.Sum256(c.builder) // reduce the size of the cache key to keep the overall cache size small" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/server/config.go", + "line": 447, + "additionalContext": "scanoss:match,hash := sha256.Sum256(hashData)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/server/options/authenticationconfig/metrics/metrics.go", + "line": 105, + "additionalContext": "scanoss:match,return fmt.Sprintf(\"sha256:%x\", sha256.Sum256([]byte(data)))" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/server/options/authorizationconfig/metrics/metrics.go", + "line": 76, + "additionalContext": "scanoss:match,return sha256.New()" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/server/options/encryptionconfig/config.go", + "line": 904, + "additionalContext": "scanoss:match,return fmt.Sprintf(\"sha256:%x\", sha256.Sum256(data))" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/server/options/encryptionconfig/metrics/metrics.go", + "line": 76, + "additionalContext": "scanoss:match,return sha256.New()" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/aes/aes_extended_nonce.go", + "line": 135, + "additionalContext": "scanoss:match,kdf := hkdf.Expand(sha256.New, e.seed, info)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/envelope/kmsv2/cache.go", + "line": 56, + "additionalContext": "scanoss:match,return sha256.New()" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/envelope/kmsv2/envelope.go", + "line": 557, + "additionalContext": "scanoss:match,return fmt.Sprintf(\"sha256:%x\", sha256.Sum256([]byte(data)))" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/envelope/metrics/metrics.go", + "line": 207, + "additionalContext": "scanoss:match,return sha256.New()" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/util/flowcontrol/apf_controller.go", + "line": 1132, + "additionalContext": "scanoss:match,hash := sha256.New()" + }, + { + "location": "vendor-deps/k8s.io/apiserver/plugin/pkg/authenticator/token/oidc/metrics.go", + "line": 206, + "additionalContext": "scanoss:match,return fmt.Sprintf(\"sha256:%x\", sha256.Sum256([]byte(data)))" + }, + { + "location": "vendor-deps/k8s.io/client-go/discovery/cached/disk/round_tripper.go", + "line": 91, + "additionalContext": "scanoss:match,got := sha256.Sum256(response)" + }, + { + "location": "vendor-deps/k8s.io/client-go/discovery/cached/disk/round_tripper.go", + "line": 103, + "additionalContext": "scanoss:match,s := sha256.Sum256(response)" + }, + { + "location": "vendor-deps/k8s.io/client-go/discovery/cached/disk/round_tripper.go", + "line": 119, + "additionalContext": "scanoss:match,return fmt.Sprintf(\"%x\", sha256.Sum256([]byte(key)))" + }, + { + "location": "vendor-deps/k8s.io/kube-aggregator/pkg/controllers/openapi/aggregator/aggregator.go", + "line": 184, + "additionalContext": "scanoss:match,return merged, fmt.Sprintf(\"%x\", sha256.Sum256([]byte(fmt.Sprintf(\"%#v\", etags)))), nil" + }, + { + "location": "vendor-deps/k8s.io/kubectl/pkg/cmd/apply/applyset.go", + "line": 173, + "additionalContext": "scanoss:match,hashed := sha256.Sum256([]byte(unencoded))" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/apis/certificates/validation/validation.go", + "line": 714, + "additionalContext": "scanoss:match,if err := rsa.VerifyPSS(pub, crypto.SHA256, hashBytes([]byte(req.Spec.PodUID)), req.Spec.ProofOfPossession, nil); err != nil {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/apis/certificates/validation/validation.go", + "line": 776, + "additionalContext": "scanoss:match,out := sha256.Sum256(in)" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/controller/certificates/clustertrustbundlepublisher/publisher.go", + "line": 374, + "additionalContext": "scanoss:match,bundleHash := sha256.Sum256(bundleBytes)" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/credentialprovider/keyring.go", + "line": 369, + "additionalContext": "scanoss:match,hash := sha256.New()" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/credentialprovider/plugin/config.go", + "line": 85, + "additionalContext": "scanoss:match,hasher := sha256.New()" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/credentialprovider/plugin/plugin.go", + "line": 843, + "additionalContext": "scanoss:match,return fmt.Sprintf(\"sha256:%x\", sha256.Sum256([]byte(data)))" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/images/pullmanager/fs_pullrecords.go", + "line": 273, + "additionalContext": "scanoss:match,return fmt.Sprintf(\"%s%x\", cacheFilesSHA256Prefix, sha256.Sum256([]byte(image)))" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/serviceaccount/jwt.go", + "line": 105, + "additionalContext": "scanoss:match,hasher := crypto.SHA256.New()" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/volume/csi/csi_attacher.go", + "line": 594, + "additionalContext": "scanoss:match,result := sha256.Sum256([]byte(fmt.Sprintf(\"%s%s%s\", volName, csiDriverName, nodeName)))" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/volume/csi/csi_attacher.go", + "line": 620, + "additionalContext": "scanoss:match,result := sha256.Sum256([]byte(fmt.Sprintf(\"%s\", csiSource.VolumeHandle)))" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/volume/csi/csi_mounter.go", + "line": 613, + "additionalContext": "scanoss:match,result := sha256.Sum256([]byte(fmt.Sprintf(\"%s%s\", podUID, volSourceSpecName)))" + }, + { + "location": "vendor-deps/sigs.k8s.io/kustomize/api/hasher/hasher.go", + "line": 53, + "additionalContext": "scanoss:match,return fmt.Sprintf(\"%x\", sha256.Sum256([]byte(data)))" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "hash", + "parameterSetIdentifier": "256", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + }, + "oid": "2.16.840.1.101.3.4.2.1" + } + }, + { + "bom-ref": "9332bdf3-f762-42a1-a730-a70810a7f244", + "type": "cryptographic-asset", + "name": "SHA-3-224", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.sha3.go.crypto.sha3.hash-usage" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/golang.org/x/crypto/sha3/hashes.go", + "line": 25, + "additionalContext": "scanoss:match,return sha3.New224()" + }, + { + "location": "vendor-deps/golang.org/x/crypto/sha3/hashes.go", + "line": 67, + "additionalContext": "scanoss:match,return sha3.Sum224(data)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "hash", + "parameterSetIdentifier": "224", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + }, + "oid": "2.16.840.1.101.3.4.2" + } + }, + { + "bom-ref": "4795ed65-71bb-41fc-8c0c-9c4cef248764", + "type": "cryptographic-asset", + "name": "SHA-3-256", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.sha3.go.crypto.sha3.hash-usage" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/golang.org/x/crypto/sha3/hashes.go", + "line": 36, + "additionalContext": "scanoss:match,return sha3.New256()" + }, + { + "location": "vendor-deps/golang.org/x/crypto/sha3/hashes.go", + "line": 76, + "additionalContext": "scanoss:match,return sha3.Sum256(data)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "hash", + "parameterSetIdentifier": "256", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + }, + "oid": "2.16.840.1.101.3.4.2" + } + }, + { + "bom-ref": "ed40141c-d2c5-4898-8fde-fc4161e642b1", + "type": "cryptographic-asset", + "name": "SHA-3-384", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.sha3.go.crypto.sha3.hash-usage" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/golang.org/x/crypto/sha3/hashes.go", + "line": 47, + "additionalContext": "scanoss:match,return sha3.New384()" + }, + { + "location": "vendor-deps/golang.org/x/crypto/sha3/hashes.go", + "line": 85, + "additionalContext": "scanoss:match,return sha3.Sum384(data)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "hash", + "parameterSetIdentifier": "384", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + }, + "oid": "2.16.840.1.101.3.4.2" + } + }, + { + "bom-ref": "b0b5c925-2890-4a72-b69c-ef6d7a62090c", + "type": "cryptographic-asset", + "name": "SHA-3-512", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.sha3.go.crypto.sha3.hash-usage" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/golang.org/x/crypto/sha3/hashes.go", + "line": 58, + "additionalContext": "scanoss:match,return sha3.New512()" + }, + { + "location": "vendor-deps/golang.org/x/crypto/sha3/hashes.go", + "line": 94, + "additionalContext": "scanoss:match,return sha3.Sum512(data)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "hash", + "parameterSetIdentifier": "512", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + }, + "oid": "2.16.840.1.101.3.4.2" + } + }, + { + "bom-ref": "d3a57bdb-ae7d-41e6-9234-08e00e7f8c48", + "type": "cryptographic-asset", + "name": "SHA-384", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.sha512.go.crypto.sha512.hash-usage-384" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ecdsa.go", + "line": 40, + "additionalContext": "scanoss:match,SigningMethodES384 = \u0026SigningMethodECDSA{\"ES384\", crypto.SHA384, 48, 384}" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/hmac.go", + "line": 32, + "additionalContext": "scanoss:match,SigningMethodHS384 = \u0026SigningMethodHMAC{\"HS384\", crypto.SHA384}" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa.go", + "line": 31, + "additionalContext": "scanoss:match,SigningMethodRS384 = \u0026SigningMethodRSA{\"RS384\", crypto.SHA384}" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_pss.go", + "line": 49, + "additionalContext": "scanoss:match,Hash: crypto.SHA384," + }, + { + "location": "vendor-deps/github.com/coreos/go-oidc/oidc.go", + "line": 351, + "additionalContext": "scanoss:match,h = sha512.New384()" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 78, + "additionalContext": "scanoss:match,ECDSAP384SHA384: crypto.SHA384," + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 216, + "additionalContext": "scanoss:match,hash = crypto.SHA384" + }, + { + "location": "vendor-deps/github.com/miekg/dns/tsig.go", + "line": 52, + "additionalContext": "scanoss:match,h = hmac.New(sha512.New384, rawsecret)" + }, + { + "location": "vendor-deps/github.com/opencontainers/go-digest/algorithm.go", + "line": 52, + "additionalContext": "scanoss:match,SHA384: crypto.SHA384," + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/image/internal/digest/digester.go", + "line": 36, + "additionalContext": "scanoss:match,SHA384: crypto.SHA384," + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 270, + "additionalContext": "scanoss:match,hash = crypto.SHA384" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 316, + "additionalContext": "scanoss:match,hash = crypto.SHA384" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 511, + "additionalContext": "scanoss:match,hash = crypto.SHA384" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 568, + "additionalContext": "scanoss:match,hash = crypto.SHA384" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/cipher/cbc_hmac.go", + "line": 51, + "additionalContext": "scanoss:match,hash = sha512.New384" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/symmetric.go", + "line": 140, + "additionalContext": "scanoss:match,return 24, sha512.New384" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/symmetric.go", + "line": 475, + "additionalContext": "scanoss:match,hash = sha512.New384" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "hash", + "parameterSetIdentifier": "384", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + }, + "oid": "2.16.840.1.101.3.4.2.2" + } + }, + { + "bom-ref": "222b3cc2-666f-4846-be68-10b04ab894e4", + "type": "cryptographic-asset", + "name": "SHA-512", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.sha512.go.crypto.sha512.hash-usage-512" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ecdsa.go", + "line": 46, + "additionalContext": "scanoss:match,SigningMethodES512 = \u0026SigningMethodECDSA{\"ES512\", crypto.SHA512, 66, 521}" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/hmac.go", + "line": 38, + "additionalContext": "scanoss:match,SigningMethodHS512 = \u0026SigningMethodHMAC{\"HS512\", crypto.SHA512}" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa.go", + "line": 37, + "additionalContext": "scanoss:match,SigningMethodRS512 = \u0026SigningMethodRSA{\"RS512\", crypto.SHA512}" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_pss.go", + "line": 66, + "additionalContext": "scanoss:match,Hash: crypto.SHA512," + }, + { + "location": "etcd-deps/k8s.io/kube-openapi/pkg/handler3/handler.go", + "line": 125, + "additionalContext": "scanoss:match,return fmt.Sprintf(\"%X\", sha512.Sum512(data))" + }, + { + "location": "vendor-deps/github.com/coreos/go-oidc/oidc.go", + "line": 353, + "additionalContext": "scanoss:match,h = sha512.New()" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dane.go", + "line": 32, + "additionalContext": "scanoss:match,h := sha512.New()" + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 79, + "additionalContext": "scanoss:match,RSASHA512: crypto.SHA512," + }, + { + "location": "vendor-deps/github.com/miekg/dns/dnssec.go", + "line": 218, + "additionalContext": "scanoss:match,hash = crypto.SHA512" + }, + { + "location": "vendor-deps/github.com/miekg/dns/tsig.go", + "line": 54, + "additionalContext": "scanoss:match,h = hmac.New(sha512.New, rawsecret)" + }, + { + "location": "vendor-deps/github.com/opencontainers/go-digest/algorithm.go", + "line": 53, + "additionalContext": "scanoss:match,SHA512: crypto.SHA512," + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/image/internal/digest/digester.go", + "line": 37, + "additionalContext": "scanoss:match,SHA512: crypto.SHA512," + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 272, + "additionalContext": "scanoss:match,hash = crypto.SHA512" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 318, + "additionalContext": "scanoss:match,hash = crypto.SHA512" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 514, + "additionalContext": "scanoss:match,hash = crypto.SHA512" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/asymmetric.go", + "line": 571, + "additionalContext": "scanoss:match,hash = crypto.SHA512" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/cipher/cbc_hmac.go", + "line": 53, + "additionalContext": "scanoss:match,hash = sha512.New" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/symmetric.go", + "line": 142, + "additionalContext": "scanoss:match,return 32, sha512.New" + }, + { + "location": "vendor-deps/gopkg.in/go-jose/go-jose.v2/symmetric.go", + "line": 477, + "additionalContext": "scanoss:match,hash = sha512.New" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/endpoints/discovery/aggregated/etag.go", + "line": 84, + "additionalContext": "scanoss:match,return fmt.Sprintf(\"%X\", sha512.Sum512(serialized)), nil" + }, + { + "location": "vendor-deps/k8s.io/kube-aggregator/pkg/controllers/openapi/aggregator/downloader.go", + "line": 110, + "additionalContext": "scanoss:match,return fmt.Sprintf(\"%s%X\\\"\", locallyGeneratedEtagPrefix, sha512.Sum512(data))" + }, + { + "location": "vendor-deps/k8s.io/kube-aggregator/pkg/controllers/openapiv3/aggregator/patch_aggregator.go", + "line": 245, + "additionalContext": "scanoss:match,return fmt.Sprintf(\"%X\", sha512.Sum512(data))" + }, + { + "location": "vendor-deps/k8s.io/kube-openapi/pkg/handler/handler.go", + "line": 52, + "additionalContext": "scanoss:match,return fmt.Sprintf(\"%X\", sha512.Sum512(data))" + }, + { + "location": "vendor-deps/k8s.io/kube-openapi/pkg/handler3/handler.go", + "line": 125, + "additionalContext": "scanoss:match,return fmt.Sprintf(\"%X\", sha512.Sum512(data))" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "hash", + "parameterSetIdentifier": "512", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + }, + "oid": "2.16.840.1.101.3.4.2.3" + } + }, + { + "bom-ref": "ecb16192-7453-457a-b55d-1d122228bee2", + "type": "cryptographic-asset", + "name": "SHA-512/256", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.sha512.go.crypto.sha512.hash-usage-512-256" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/certificate/bootstrap/bootstrap.go", + "line": 369, + "additionalContext": "scanoss:match,hash := sha512.New512_256()" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "hash", + "parameterSetIdentifier": "256", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + }, + "oid": "2.16.840.1.101.3.4.2" + } + }, + { + "bom-ref": "1e66ecd9-754f-47ed-b5e8-153d61d1ab46", + "type": "cryptographic-asset", + "name": "SHAKE128", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.sha3.go.crypto.sha3.shake-usage" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/golang.org/x/crypto/sha3/shake.go", + "line": 34, + "additionalContext": "scanoss:match,return \u0026shakeWrapper{sha3.NewSHAKE128(), 32, false, sha3.NewSHAKE128}" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "xof", + "parameterSetIdentifier": "128", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + }, + "oid": "2.16.840.1.101.3.4.2.11" + } + }, + { + "bom-ref": "d447bed6-5556-4676-95c0-3cb4e5c60502", + "type": "cryptographic-asset", + "name": "SHAKE256", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "digest" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.algorithm.sha3.go.crypto.sha3.shake-usage" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/golang.org/x/crypto/sha3/shake.go", + "line": 41, + "additionalContext": "scanoss:match,return \u0026shakeWrapper{sha3.NewSHAKE256(), 64, false, sha3.NewSHAKE256}" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "xof", + "parameterSetIdentifier": "256", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "digest" + ] + }, + "oid": "2.16.840.1.101.3.4.2.12" + } + }, + { + "bom-ref": "ce0351fa-e349-4e7e-8265-7ba5adeea4c7", + "type": "cryptographic-asset", + "name": "Salsa20", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "encrypt" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.xcrypto.algorithm.salsa20.go.xcrypto.salsa20.stream-cipher" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/golang.org/x/crypto/nacl/secretbox/secretbox.go", + "line": 85, + "additionalContext": "scanoss:match,salsa.XORKeyStream(firstBlock[:], firstBlock[:], \u0026counter, \u0026subKey)" + }, + { + "location": "vendor-deps/golang.org/x/crypto/nacl/secretbox/secretbox.go", + "line": 113, + "additionalContext": "scanoss:match,salsa.XORKeyStream(out, message, \u0026counter, \u0026subKey)" + }, + { + "location": "vendor-deps/golang.org/x/crypto/nacl/secretbox/secretbox.go", + "line": 138, + "additionalContext": "scanoss:match,salsa.XORKeyStream(firstBlock[:], firstBlock[:], \u0026counter, \u0026subKey)" + }, + { + "location": "vendor-deps/golang.org/x/crypto/nacl/secretbox/secretbox.go", + "line": 170, + "additionalContext": "scanoss:match,salsa.XORKeyStream(out, box, \u0026counter, \u0026subKey)" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "stream-cipher", + "parameterSetIdentifier": "256", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "encrypt" + ] + } + } + }, + { + "bom-ref": "89fa563f-304d-4113-9884-e258f14b635e", + "type": "cryptographic-asset", + "name": "XSalsa20-Poly1305", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "encrypt,decrypt" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.xcrypto.algorithm.nacl.go.xcrypto.nacl.secretbox.encrypt" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.xcrypto.algorithm.nacl.go.xcrypto.nacl.secretbox.open" + } + ] + } + ], + "occurrences": [ + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/secretbox/secretbox.go", + "line": 46, + "additionalContext": "scanoss:match,if len(data) \u003c (secretbox.Overhead + nonceSize) {" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/secretbox/secretbox.go", + "line": 52, + "additionalContext": "scanoss:match,out := make([]byte, 0, len(data)-secretbox.Overhead)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/secretbox/secretbox.go", + "line": 53, + "additionalContext": "scanoss:match,result, ok := secretbox.Open(out, data, \u0026nonce, \u0026t.key)" + }, + { + "location": "vendor-deps/k8s.io/apiserver/pkg/storage/value/encrypt/secretbox/secretbox.go", + "line": 69, + "additionalContext": "scanoss:match,return secretbox.Seal(nonce[:], data, \u0026nonce, \u0026t.key), nil" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "ae", + "parameterSetIdentifier": "256", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "encrypt", + "decrypt" + ] + } + } + }, + { + "bom-ref": "3541ad20-90ac-432e-9ac2-e02d25bff0be", + "type": "cryptographic-asset", + "name": "bcrypt", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "verify,keyderive" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.xcrypto.algorithm.bcrypt.go.xcrypto.bcrypt.password-verify" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.xcrypto.algorithm.bcrypt.go.xcrypto.bcrypt.password-hash" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/auth/store.go", + "line": 389, + "additionalContext": "scanoss:match,if bcrypt.CompareHashAndPassword(user.Password, []byte(password)) != nil {" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/auth/store.go", + "line": 418, + "additionalContext": "scanoss:match,return bcrypt.GenerateFromPassword([]byte(password), as.bcryptCost)" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/etcdserver/v3_server.go", + "line": 667, + "additionalContext": "scanoss:match,hashedPassword, err := bcrypt.GenerateFromPassword([]byte(r.Password), s.authStore.BcryptCost())" + }, + { + "location": "etcd-deps/go.etcd.io/etcd/server/v3/etcdserver/v3_server.go", + "line": 692, + "additionalContext": "scanoss:match,hashedPassword, err := bcrypt.GenerateFromPassword([]byte(r.Password), s.authStore.BcryptCost())" + } + ] + }, + "cryptoProperties": { + "assetType": "algorithm", + "algorithmProperties": { + "primitive": "kdf", + "executionEnvironment": "software-plain-ram", + "implementationPlatform": "x86_64", + "cryptoFunctions": [ + "verify", + "keyderive" + ] + } + } + }, + { + "bom-ref": "faee3ccd-6de9-4b02-b7ca-ffb2633a52a7", + "type": "cryptographic-asset", + "name": "private-key", + "description": "Cryptographic private-key", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "keygen" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.related-crypto-material.x509.go.crypto.x509.parse-pkcs8-private-key" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.related-crypto-material.x509.go.crypto.x509.pem-block" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.related-crypto-material.x509.go.crypto.x509.parse-pkcs8-private-key" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ecdsa_utils.go", + "line": 28, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKCS8PrivateKey(block.Bytes); err != nil {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ed25519_utils.go", + "line": 28, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKCS8PrivateKey(block.Bytes); err != nil {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_utils.go", + "line": 28, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKCS8PrivateKey(block.Bytes); err != nil {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_utils.go", + "line": 59, + "additionalContext": "scanoss:match,if blockDecrypted, err = x509.DecryptPEMBlock(block, []byte(password)); err != nil {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_utils.go", + "line": 64, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKCS8PrivateKey(blockDecrypted); err != nil {" + }, + { + "location": "etcd-deps/golang.org/x/oauth2/internal/oauth2.go", + "line": 25, + "additionalContext": "scanoss:match,parsedKey, err := x509.ParsePKCS8PrivateKey(key)" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 181, + "additionalContext": "scanoss:match,if key, err := x509.ParsePKCS8PrivateKey(privateKeyPemBlock.Bytes); err == nil {" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 265, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKCS8PrivateKey(data); err != nil {" + }, + { + "location": "vendor-deps/golang.org/x/oauth2/internal/oauth2.go", + "line": 25, + "additionalContext": "scanoss:match,parsedKey, err := x509.ParsePKCS8PrivateKey(key)" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 181, + "additionalContext": "scanoss:match,if key, err := x509.ParsePKCS8PrivateKey(privateKeyPemBlock.Bytes); err == nil {" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 265, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKCS8PrivateKey(data); err != nil {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/podcertificate/podcertificatemanager.go", + "line": 928, + "additionalContext": "scanoss:match,keyDER, err := x509.MarshalPKCS8PrivateKey(key)" + } + ] + }, + "cryptoProperties": { + "assetType": "related-crypto-material", + "relatedCryptoMaterialProperties": { + "type": "private-key" + } + } + }, + { + "bom-ref": "4249c9a4-ac81-4e2b-8548-db8cbe14117d", + "type": "cryptographic-asset", + "name": "public-key", + "description": "Cryptographic public-key", + "properties": [ + { + "name": "scanoss:cryptoFunction", + "value": "keygen" + } + ], + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.related-crypto-material.x509.go.crypto.x509.pkix-public-key" + } + ] + }, + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.crypto.related-crypto-material.x509.go.crypto.x509.pkix-public-key" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ecdsa_utils.go", + "line": 54, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKIXPublicKey(block.Bytes); err != nil {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/ed25519_utils.go", + "line": 53, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKIXPublicKey(block.Bytes); err != nil {" + }, + { + "location": "etcd-deps/github.com/golang-jwt/jwt/v5/rsa_utils.go", + "line": 90, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKIXPublicKey(block.Bytes); err != nil {" + }, + { + "location": "etcd-deps/github.com/openshift/microshift/pkg/util/cert.go", + "line": 72, + "additionalContext": "scanoss:match,keyInBytes, err := x509.MarshalPKIXPublicKey(key)" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 240, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKIXPublicKey(data); err != nil {" + }, + { + "location": "etcd-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 286, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKIXPublicKey(data); err != nil {" + }, + { + "location": "pkg/util/cert.go", + "line": 72, + "additionalContext": "scanoss:match,keyInBytes, err := x509.MarshalPKIXPublicKey(key)" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 240, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKIXPublicKey(data); err != nil {" + }, + { + "location": "vendor-deps/k8s.io/client-go/util/keyutil/key.go", + "line": 286, + "additionalContext": "scanoss:match,if parsedKey, err = x509.ParsePKIXPublicKey(data); err != nil {" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/apis/certificates/validation/validation.go", + "line": 684, + "additionalContext": "scanoss:match,pubAny, err := x509.ParsePKIXPublicKey(req.Spec.PKIXPublicKey)" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/apis/certificates/validation/validation.go", + "line": 914, + "additionalContext": "scanoss:match,wantPKAny, err = x509.ParsePKIXPublicKey(oldReq.Spec.PKIXPublicKey)" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/kubelet/certificate/bootstrap/bootstrap.go", + "line": 383, + "additionalContext": "scanoss:match,publicKeyData, err := x509.MarshalPKIXPublicKey(publicKey)" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/serviceaccount/externaljwt/plugin/keycache.go", + "line": 233, + "additionalContext": "scanoss:match,parsedPublicKey, err := x509.ParsePKIXPublicKey(protoKey.Key)" + }, + { + "location": "vendor-deps/k8s.io/kubernetes/pkg/serviceaccount/jwt.go", + "line": 100, + "additionalContext": "scanoss:match,publicKeyDERBytes, err := x509.MarshalPKIXPublicKey(publicKey)" + } + ] + }, + "cryptoProperties": { + "assetType": "related-crypto-material", + "relatedCryptoMaterialProperties": { + "type": "public-key" + } + } + }, + { + "bom-ref": "1c26abaa-f11d-444e-80bc-8f89fd8422f9", + "type": "cryptographic-asset", + "name": "signature", + "description": "Cryptographic signature", + "evidence": { + "identity": [ + { + "field": "name", + "confidence": 1, + "methods": [ + { + "technique": "source-code-analysis", + "confidence": 1, + "value": "scanoss:ruleid,crypto-rules.go.library-go.related-crypto-material.go.crypto.library-go.sign-certificate" + } + ] + } + ], + "occurrences": [ + { + "location": "etcd-deps/github.com/openshift/library-go/pkg/crypto/cert_config.go", + "line": 53, + "additionalContext": "scanoss:match,cert, err := o.signer.SignCertificate(template, publicKey)" + }, + { + "location": "etcd-deps/github.com/openshift/library-go/pkg/crypto/cert_config.go", + "line": 119, + "additionalContext": "scanoss:match,cert, err := ca.SignCertificate(template, publicKey)" + }, + { + "location": "etcd-deps/github.com/openshift/library-go/pkg/crypto/cert_config.go", + "line": 157, + "additionalContext": "scanoss:match,cert, err := ca.SignCertificate(template, publicKey)" + }, + { + "location": "etcd-deps/github.com/openshift/library-go/pkg/crypto/cert_config.go", + "line": 216, + "additionalContext": "scanoss:match,cert, err := ca.SignCertificate(template, publicKey)" + }, + { + "location": "etcd-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 731, + "additionalContext": "scanoss:match,signerCert, err := issuer.SignCertificate(signerTemplate, signerPublicKey)" + }, + { + "location": "etcd-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 847, + "additionalContext": "scanoss:match,serverCrt, err := ca.SignCertificate(serverTemplate, serverPublicKey)" + }, + { + "location": "etcd-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 868, + "additionalContext": "scanoss:match,serverCrt, err := ca.SignCertificate(serverTemplate, serverPublicKey)" + }, + { + "location": "etcd-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 923, + "additionalContext": "scanoss:match,clientCrt, err := ca.SignCertificate(clientTemplate, clientPublicKey)" + }, + { + "location": "etcd-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 950, + "additionalContext": "scanoss:match,clientCrt, err := ca.SignCertificate(clientTemplate, clientPublicKey)" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/crypto/cert_config.go", + "line": 53, + "additionalContext": "scanoss:match,cert, err := o.signer.SignCertificate(template, publicKey)" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/crypto/cert_config.go", + "line": 119, + "additionalContext": "scanoss:match,cert, err := ca.SignCertificate(template, publicKey)" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/crypto/cert_config.go", + "line": 157, + "additionalContext": "scanoss:match,cert, err := ca.SignCertificate(template, publicKey)" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/crypto/cert_config.go", + "line": 216, + "additionalContext": "scanoss:match,cert, err := ca.SignCertificate(template, publicKey)" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 731, + "additionalContext": "scanoss:match,signerCert, err := issuer.SignCertificate(signerTemplate, signerPublicKey)" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 847, + "additionalContext": "scanoss:match,serverCrt, err := ca.SignCertificate(serverTemplate, serverPublicKey)" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 868, + "additionalContext": "scanoss:match,serverCrt, err := ca.SignCertificate(serverTemplate, serverPublicKey)" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 923, + "additionalContext": "scanoss:match,clientCrt, err := ca.SignCertificate(clientTemplate, clientPublicKey)" + }, + { + "location": "vendor-deps/github.com/openshift/library-go/pkg/crypto/crypto.go", + "line": 950, + "additionalContext": "scanoss:match,clientCrt, err := ca.SignCertificate(clientTemplate, clientPublicKey)" + } + ] + }, + "cryptoProperties": { + "assetType": "related-crypto-material", + "relatedCryptoMaterialProperties": { + "type": "signature" + } + } + } + ] +} diff --git a/deps/github.com/openshift/kubernetes/.go-version b/deps/github.com/openshift/kubernetes/.go-version index ea0928cedf..8fe00a57fe 100644 --- a/deps/github.com/openshift/kubernetes/.go-version +++ b/deps/github.com/openshift/kubernetes/.go-version @@ -1 +1 @@ -1.26.4 +1.26.5 diff --git a/deps/github.com/openshift/kubernetes/CHANGELOG/CHANGELOG-1.36.md b/deps/github.com/openshift/kubernetes/CHANGELOG/CHANGELOG-1.36.md index dd1dc99b77..032ae4e005 100644 --- a/deps/github.com/openshift/kubernetes/CHANGELOG/CHANGELOG-1.36.md +++ b/deps/github.com/openshift/kubernetes/CHANGELOG/CHANGELOG-1.36.md @@ -1,139 +1,260 @@ -- [v1.36.1](#v1361) - - [Downloads for v1.36.1](#downloads-for-v1361) +- [v1.36.2](#v1362) + - [Downloads for v1.36.2](#downloads-for-v1362) - [Source Code](#source-code) - [Client Binaries](#client-binaries) - [Server Binaries](#server-binaries) - [Node Binaries](#node-binaries) - [Container Images](#container-images) - - [Changelog since v1.36.0](#changelog-since-v1360) + - [Changelog since v1.36.1](#changelog-since-v1361) - [Changes by Kind](#changes-by-kind) + - [Feature](#feature) - [Bug or Regression](#bug-or-regression) - [Dependencies](#dependencies) - [Added](#added) - [Changed](#changed) - [Removed](#removed) -- [v1.36.0](#v1360) - - [Downloads for v1.36.0](#downloads-for-v1360) +- [v1.36.1](#v1361) + - [Downloads for v1.36.1](#downloads-for-v1361) - [Source Code](#source-code-1) - [Client Binaries](#client-binaries-1) - [Server Binaries](#server-binaries-1) - [Node Binaries](#node-binaries-1) - [Container Images](#container-images-1) - - [Changelog since v1.35.0](#changelog-since-v1350) - - [Urgent Upgrade Notes](#urgent-upgrade-notes) - - [(No, really, you MUST read this before you upgrade)](#no-really-you-must-read-this-before-you-upgrade) + - [Changelog since v1.36.0](#changelog-since-v1360) - [Changes by Kind](#changes-by-kind-1) - - [Dependency](#dependency) - - [Deprecation](#deprecation) - - [API Change](#api-change) - - [Feature](#feature) - - [Documentation](#documentation) - - [Failing Test](#failing-test) - [Bug or Regression](#bug-or-regression-1) - - [Other (Cleanup or Flake)](#other-cleanup-or-flake) - [Dependencies](#dependencies-1) - [Added](#added-1) - [Changed](#changed-1) - [Removed](#removed-1) -- [v1.36.0-rc.1](#v1360-rc1) - - [Downloads for v1.36.0-rc.1](#downloads-for-v1360-rc1) +- [v1.36.0](#v1360) + - [Downloads for v1.36.0](#downloads-for-v1360) - [Source Code](#source-code-2) - [Client Binaries](#client-binaries-2) - [Server Binaries](#server-binaries-2) - [Node Binaries](#node-binaries-2) - [Container Images](#container-images-2) - - [Changelog since v1.36.0-rc.0](#changelog-since-v1360-rc0) + - [Changelog since v1.35.0](#changelog-since-v1350) + - [Urgent Upgrade Notes](#urgent-upgrade-notes) + - [(No, really, you MUST read this before you upgrade)](#no-really-you-must-read-this-before-you-upgrade) + - [Changes by Kind](#changes-by-kind-2) + - [Dependency](#dependency) + - [Deprecation](#deprecation) + - [API Change](#api-change) + - [Feature](#feature-1) + - [Documentation](#documentation) + - [Failing Test](#failing-test) + - [Bug or Regression](#bug-or-regression-2) + - [Other (Cleanup or Flake)](#other-cleanup-or-flake) - [Dependencies](#dependencies-2) - [Added](#added-2) - [Changed](#changed-2) - [Removed](#removed-2) -- [v1.36.0-rc.0](#v1360-rc0) - - [Downloads for v1.36.0-rc.0](#downloads-for-v1360-rc0) +- [v1.36.0-rc.1](#v1360-rc1) + - [Downloads for v1.36.0-rc.1](#downloads-for-v1360-rc1) - [Source Code](#source-code-3) - [Client Binaries](#client-binaries-3) - [Server Binaries](#server-binaries-3) - [Node Binaries](#node-binaries-3) - [Container Images](#container-images-3) - - [Changelog since v1.36.0-beta.0](#changelog-since-v1360-beta0) - - [Changes by Kind](#changes-by-kind-2) - - [API Change](#api-change-1) - - [Feature](#feature-1) - - [Bug or Regression](#bug-or-regression-2) - - [Other (Cleanup or Flake)](#other-cleanup-or-flake-1) + - [Changelog since v1.36.0-rc.0](#changelog-since-v1360-rc0) - [Dependencies](#dependencies-3) - [Added](#added-3) - [Changed](#changed-3) - [Removed](#removed-3) -- [v1.36.0-beta.0](#v1360-beta0) - - [Downloads for v1.36.0-beta.0](#downloads-for-v1360-beta0) +- [v1.36.0-rc.0](#v1360-rc0) + - [Downloads for v1.36.0-rc.0](#downloads-for-v1360-rc0) - [Source Code](#source-code-4) - [Client Binaries](#client-binaries-4) - [Server Binaries](#server-binaries-4) - [Node Binaries](#node-binaries-4) - [Container Images](#container-images-4) - - [Changelog since v1.36.0-alpha.2](#changelog-since-v1360-alpha2) - - [Urgent Upgrade Notes](#urgent-upgrade-notes-1) - - [(No, really, you MUST read this before you upgrade)](#no-really-you-must-read-this-before-you-upgrade-1) + - [Changelog since v1.36.0-beta.0](#changelog-since-v1360-beta0) - [Changes by Kind](#changes-by-kind-3) - - [Deprecation](#deprecation-1) - - [API Change](#api-change-2) + - [API Change](#api-change-1) - [Feature](#feature-2) - - [Documentation](#documentation-1) - - [Failing Test](#failing-test-1) - [Bug or Regression](#bug-or-regression-3) - - [Other (Cleanup or Flake)](#other-cleanup-or-flake-2) + - [Other (Cleanup or Flake)](#other-cleanup-or-flake-1) - [Dependencies](#dependencies-4) - [Added](#added-4) - [Changed](#changed-4) - [Removed](#removed-4) -- [v1.36.0-alpha.2](#v1360-alpha2) - - [Downloads for v1.36.0-alpha.2](#downloads-for-v1360-alpha2) +- [v1.36.0-beta.0](#v1360-beta0) + - [Downloads for v1.36.0-beta.0](#downloads-for-v1360-beta0) - [Source Code](#source-code-5) - [Client Binaries](#client-binaries-5) - [Server Binaries](#server-binaries-5) - [Node Binaries](#node-binaries-5) - [Container Images](#container-images-5) - - [Changelog since v1.36.0-alpha.1](#changelog-since-v1360-alpha1) - - [Urgent Upgrade Notes](#urgent-upgrade-notes-2) - - [(No, really, you MUST read this before you upgrade)](#no-really-you-must-read-this-before-you-upgrade-2) + - [Changelog since v1.36.0-alpha.2](#changelog-since-v1360-alpha2) + - [Urgent Upgrade Notes](#urgent-upgrade-notes-1) + - [(No, really, you MUST read this before you upgrade)](#no-really-you-must-read-this-before-you-upgrade-1) - [Changes by Kind](#changes-by-kind-4) - - [Dependency](#dependency-1) - - [Deprecation](#deprecation-2) - - [API Change](#api-change-3) + - [Deprecation](#deprecation-1) + - [API Change](#api-change-2) - [Feature](#feature-3) - - [Failing Test](#failing-test-2) + - [Documentation](#documentation-1) + - [Failing Test](#failing-test-1) - [Bug or Regression](#bug-or-regression-4) - - [Other (Cleanup or Flake)](#other-cleanup-or-flake-3) + - [Other (Cleanup or Flake)](#other-cleanup-or-flake-2) - [Dependencies](#dependencies-5) - [Added](#added-5) - [Changed](#changed-5) - [Removed](#removed-5) -- [v1.36.0-alpha.1](#v1360-alpha1) - - [Downloads for v1.36.0-alpha.1](#downloads-for-v1360-alpha1) +- [v1.36.0-alpha.2](#v1360-alpha2) + - [Downloads for v1.36.0-alpha.2](#downloads-for-v1360-alpha2) - [Source Code](#source-code-6) - [Client Binaries](#client-binaries-6) - [Server Binaries](#server-binaries-6) - [Node Binaries](#node-binaries-6) - [Container Images](#container-images-6) - - [Changelog since v1.35.0](#changelog-since-v1350-1) - - [Urgent Upgrade Notes](#urgent-upgrade-notes-3) - - [(No, really, you MUST read this before you upgrade)](#no-really-you-must-read-this-before-you-upgrade-3) + - [Changelog since v1.36.0-alpha.1](#changelog-since-v1360-alpha1) + - [Urgent Upgrade Notes](#urgent-upgrade-notes-2) + - [(No, really, you MUST read this before you upgrade)](#no-really-you-must-read-this-before-you-upgrade-2) - [Changes by Kind](#changes-by-kind-5) - - [Dependency](#dependency-2) - - [API Change](#api-change-4) + - [Dependency](#dependency-1) + - [Deprecation](#deprecation-2) + - [API Change](#api-change-3) - [Feature](#feature-4) - - [Failing Test](#failing-test-3) + - [Failing Test](#failing-test-2) - [Bug or Regression](#bug-or-regression-5) - - [Other (Cleanup or Flake)](#other-cleanup-or-flake-4) + - [Other (Cleanup or Flake)](#other-cleanup-or-flake-3) - [Dependencies](#dependencies-6) - [Added](#added-6) - [Changed](#changed-6) - [Removed](#removed-6) +- [v1.36.0-alpha.1](#v1360-alpha1) + - [Downloads for v1.36.0-alpha.1](#downloads-for-v1360-alpha1) + - [Source Code](#source-code-7) + - [Client Binaries](#client-binaries-7) + - [Server Binaries](#server-binaries-7) + - [Node Binaries](#node-binaries-7) + - [Container Images](#container-images-7) + - [Changelog since v1.35.0](#changelog-since-v1350-1) + - [Urgent Upgrade Notes](#urgent-upgrade-notes-3) + - [(No, really, you MUST read this before you upgrade)](#no-really-you-must-read-this-before-you-upgrade-3) + - [Changes by Kind](#changes-by-kind-6) + - [Dependency](#dependency-2) + - [API Change](#api-change-4) + - [Feature](#feature-5) + - [Failing Test](#failing-test-3) + - [Bug or Regression](#bug-or-regression-6) + - [Other (Cleanup or Flake)](#other-cleanup-or-flake-4) + - [Dependencies](#dependencies-7) + - [Added](#added-7) + - [Changed](#changed-7) + - [Removed](#removed-7) +# v1.36.2 + + +## Downloads for v1.36.2 + + + +### Source Code + +filename | sha512 hash +-------- | ----------- +[kubernetes.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes.tar.gz) | aef47a1cdd9a8aad387ee3aaeb3d681affe6af1231b72c67d73264d177bb63a5bbcf050fc0562a8310e6ed64be5fb0672e638e104dc630e6b6a82e15acc5ff66 +[kubernetes-src.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-src.tar.gz) | fad7f78605f87a93199316f7fb3f586e4531c41476c53fedee92fdd5bd641a9128c5cde45b6859e07eb2ab254873f1845236c0a33934cba918ff5b97d0cf571d + +### Client Binaries + +filename | sha512 hash +-------- | ----------- +[kubernetes-client-darwin-amd64.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-client-darwin-amd64.tar.gz) | 71ad2179e6cfbfc85b162da58b3ad7143ed94eba62185b23f4b02445b664b155db590aae4c56c5be04d9b9a1d460db2b5779536d9a1f0ff00b00b285fe141259 +[kubernetes-client-darwin-arm64.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-client-darwin-arm64.tar.gz) | 9cdf5cb41032a632ec9434f5b1ce11be71c4648860d658dc78e55837956f7df080f8d47b81f5c901eb4599722c2f5f967ef04922aad51e3a027a76731604b5d5 +[kubernetes-client-linux-386.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-client-linux-386.tar.gz) | 7b18df02a37ab4ae8a5fbc363baa1032204c3d532cc8f0be1f762f0e9f950ba2b7be99f1ec197b1ce28a89c09c5e77f088107b588d25eed61ad33ad1a24b0198 +[kubernetes-client-linux-amd64.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-client-linux-amd64.tar.gz) | bf3fa2fe065af663b944acdef42ab61a0062e01d325d60d756aaab22bb412addc2ffa77fdcb39de47560c5613a9bcd68e67ea83417626aefbe52db9cc76fde7d +[kubernetes-client-linux-arm.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-client-linux-arm.tar.gz) | c4fe54b27ab0cb342967d0911e0f695cc1226ed3f4f0fc84080d547fa8c92b343d75054cbc1e51e9af5c066f475b5b4463f029a7e883c83d986e5142cc2464df +[kubernetes-client-linux-arm64.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-client-linux-arm64.tar.gz) | ef798cdab3538164ecd6b3c1987c69e4094c14d3e88a31811964cd0b57536a4b488b0b9f37a4ad7139d25f1b73c019d2791f9e58017cce929bc0e8262484496d +[kubernetes-client-linux-ppc64le.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-client-linux-ppc64le.tar.gz) | 9f0474cbce05b41674a1e49fe5dc7c4f88cfe7db18c6c60d6b93a1ccff4ec1ee6c23633b45ea1b1715f2c00191eee0a2dbec6fbba3297e80279b1b648c8b7fd7 +[kubernetes-client-linux-s390x.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-client-linux-s390x.tar.gz) | 4e39e5c5160cd2a1379749f055a0555ba682fec6a924a271a5b45a185995a95093ca6e76bc1ad9ba2863b7ae0ea38368e9b15aa1282775263d0ccecf735052f5 +[kubernetes-client-windows-386.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-client-windows-386.tar.gz) | 23218ac82fcb2ec98e3af1e1a11cee6b20eb7bc610366dfb7aafbb82e9ab2c890a71256f7f52d3c68f8d4e8abf21672ef142735a3463fc89498ecdd6973b1a4d +[kubernetes-client-windows-amd64.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-client-windows-amd64.tar.gz) | 853ee9d8783f16236285fc4b37bbf972719c8061ff99a4b61c2a7c680441ac98886885723b31a9b418b3236ee0d5876268efb42de1e4b5355facd5305bfd7802 +[kubernetes-client-windows-arm64.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-client-windows-arm64.tar.gz) | a036865e990eb797dd2eef91983fb518712c76c640c66d3c5b80a41a89c283feb61a16b0869209229be0d38392b9d0c316c45836790f4934ba3dcaf065e6910f + +### Server Binaries + +filename | sha512 hash +-------- | ----------- +[kubernetes-server-linux-amd64.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-server-linux-amd64.tar.gz) | 0c617cb74f6a8ddc142afd453b3ece4b39268d78febdbe9df91faf3a01031d364e9347bf8dfdc336e9ed0fe64ad82ce0209ef9fc0340e7d2f784d37bfa7e0d18 +[kubernetes-server-linux-arm64.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-server-linux-arm64.tar.gz) | 7226d91204980892f593307f06acefd5579337ec5758c8615a0e46541a990083c6be9809b01fb9e06da7e9b6d7208a673fd5129b7145436c3fe6e726d1fa469d +[kubernetes-server-linux-ppc64le.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-server-linux-ppc64le.tar.gz) | 791c496395c6834554d05a0bbba11e5ab99dc8a2639f1adb53ccbc91919b6760339378a02d05bbc9543e3d018440f258426ed5c2625ddc56cc613e5c952c2c2f +[kubernetes-server-linux-s390x.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-server-linux-s390x.tar.gz) | b2f24c710a4e1124a0b352c85f2d3316cac9d711e879cd081ad3ea1d646c034ceecc7f892364646516fafec61efe20621bfb0eb3f5c94052cf2d6c92da091c1d + +### Node Binaries + +filename | sha512 hash +-------- | ----------- +[kubernetes-node-linux-amd64.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-node-linux-amd64.tar.gz) | 24b95198259d96990d1aa4a625c15017348affe2ef7964225968e58b30d622c6dabfaf1c7abe12d1103b3879f0e887bf956259ee160eab3bcb24d7d3f5a72dab +[kubernetes-node-linux-arm64.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-node-linux-arm64.tar.gz) | 2dc8926b5f5d08e7f3133e7ca9a50365e6f424f40a6c6931c57b64e0f93440430bf628ac31579d3b9a9d8dbf519e5b7d76e044b7198011e519eeb96e8545e6c2 +[kubernetes-node-linux-ppc64le.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-node-linux-ppc64le.tar.gz) | f69d6b1e29bd978085376f014023a792e2571865950794bf6cbde9dc65440ce3a3c0a47f1ffc2a8a8bfa0bc546d32980954d4b7adb71589fbeaeec8081cbe284 +[kubernetes-node-linux-s390x.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-node-linux-s390x.tar.gz) | cc0d4198955e55cca46de24548ccbd398f96e9e6b3dcc381d3b68706847b1e39e6992757a8927a4fce968399d9459cd26465e02d9be0f3e707507459c1e5aad9 +[kubernetes-node-windows-amd64.tar.gz](https://dl.k8s.io/v1.36.2/kubernetes-node-windows-amd64.tar.gz) | aaa965f855ef9eede65b3101b6885555661d355a1805ebf351cfb66c6e9219489f982f63d40c1aa241df827d5646fb8f06bab398deadac9724a85b791f7ecedb + +### Container Images + +All container images are available as manifest lists and support the described +architectures. It is also possible to pull a specific architecture directly by +adding the "-$ARCH" suffix to the container image name. + +name | architectures +---- | ------------- +[registry.k8s.io/conformance:v1.36.2](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/conformance) | [amd64](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/conformance-amd64), [arm64](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/conformance-arm64), [ppc64le](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/conformance-ppc64le), [s390x](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/conformance-s390x) +[registry.k8s.io/kube-apiserver:v1.36.2](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-apiserver) | [amd64](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-apiserver-amd64), [arm64](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-apiserver-arm64), [ppc64le](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-apiserver-ppc64le), [s390x](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-apiserver-s390x) +[registry.k8s.io/kube-controller-manager:v1.36.2](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-controller-manager) | [amd64](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-controller-manager-amd64), [arm64](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-controller-manager-arm64), [ppc64le](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-controller-manager-ppc64le), [s390x](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-controller-manager-s390x) +[registry.k8s.io/kube-proxy:v1.36.2](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-proxy) | [amd64](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-proxy-amd64), [arm64](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-proxy-arm64), [ppc64le](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-proxy-ppc64le), [s390x](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-proxy-s390x) +[registry.k8s.io/kube-scheduler:v1.36.2](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-scheduler) | [amd64](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-scheduler-amd64), [arm64](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-scheduler-arm64), [ppc64le](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-scheduler-ppc64le), [s390x](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kube-scheduler-s390x) +[registry.k8s.io/kubectl:v1.36.2](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kubectl) | [amd64](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kubectl-amd64), [arm64](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kubectl-arm64), [ppc64le](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kubectl-ppc64le), [s390x](https://console.cloud.google.com/artifacts/docker/k8s-artifacts-prod/southamerica-east1/images/kubectl-s390x) + +## Changelog since v1.36.1 + +## Changes by Kind + +### Feature + +- Kubernetes is now built using Go 1.26.4 ([#139585](https://github.com/kubernetes/kubernetes/pull/139585), [@cpanato](https://github.com/cpanato)) [SIG Release and Testing] +- Kubernetes is now built with Go 1.26.4 ([#138871](https://github.com/kubernetes/kubernetes/pull/138871), [@BenTheElder](https://github.com/BenTheElder)) [SIG Release] + +### Bug or Regression + +- Avoid costly comparisons during selinux metric emission. ([#139136](https://github.com/kubernetes/kubernetes/pull/139136), [@gnufied](https://github.com/gnufied)) [SIG Apps and Storage] +- Fixed a Dynamic Resource Allocation scheduler bug that could assign mutually exclusive + device partitions to multiple Pods. This affected DRA drivers using `SharedCounters` + (`DRAPartitionableDevices`) together with multi-allocatable devices (`DRAConsumableCapacity`). + Depending on the device and driver, the incorrect double-allocation could cause workload failures, + device conflicts, crashes, or data loss. ([#139211](https://github.com/kubernetes/kubernetes/pull/139211), [@ashvindeodhar](https://github.com/ashvindeodhar)) [SIG Node] +- Fixed a bug where Pods that share multi-node claims and also have per-node claims can get stuck in Pending. ([#139363](https://github.com/kubernetes/kubernetes/pull/139363), [@nojnhuh](https://github.com/nojnhuh)) [SIG Node and Scheduling] +- Fixed a kube-scheduler panic when a DRA ResourceClaim using `allocationMode: All` selects a device that consumes shared counters. ([#138988](https://github.com/kubernetes/kubernetes/pull/138988), [@pohly](https://github.com/pohly)) [SIG Node] +- Fixed a panic in the endpoint controller when processing services with empty IPFamilies field (pre-dual-stack services that were never spec-updated). ([#139233](https://github.com/kubernetes/kubernetes/pull/139233), [@rahulbabu95](https://github.com/rahulbabu95)) [SIG Apps and Network] +- Fixed a regression in 1.36 where modifications to scheduling directives (nodeSelector, tolerations, node affinity) on suspended Jobs were rejected if the JobSuspended condition had not yet been set by the job controller. ([#139329](https://github.com/kubernetes/kubernetes/pull/139329), [@kannon92](https://github.com/kannon92)) [SIG Apps and Testing] +- Fixed an issue where kubelet would delete the CSI mount directory when + a periodic NodePublishVolume call (triggered by + CSIDriver.spec.requiresRepublish=true) returned an error, leaving the + pod with stale volume contents that subsequent successful republishes + could not repair. ([#139228](https://github.com/kubernetes/kubernetes/pull/139228), [@aramase](https://github.com/aramase)) [SIG Storage] +- Fixes a 1.34+ regression handling containers with environment values set from Secret API objects containing binary non-utf8 data. ([#139192](https://github.com/kubernetes/kubernetes/pull/139192), [@liggitt](https://github.com/liggitt)) [SIG Node] +- Kubeadm: fixed kubeadm init phase certs --dry-run to correctly copy existing CA files. ([#139445](https://github.com/kubernetes/kubernetes/pull/139445), [@HirazawaUi](https://github.com/HirazawaUi)) [SIG Cluster Lifecycle] + +## Dependencies + +### Added +_Nothing has changed._ + +### Changed +_Nothing has changed._ + +### Removed +_Nothing has changed._ + + + # v1.36.1 diff --git a/deps/github.com/openshift/kubernetes/REBASE.openshift.md b/deps/github.com/openshift/kubernetes/REBASE.openshift.md index 1d6d616f8e..a800ceecc4 100644 --- a/deps/github.com/openshift/kubernetes/REBASE.openshift.md +++ b/deps/github.com/openshift/kubernetes/REBASE.openshift.md @@ -360,9 +360,8 @@ The following repositories have been already bumped as well: -Followup work has been assigned to appropriate teams -through bugzillas linked in the code. Please treat -them as the highest priority after landing the bump. +A Jira ticket has been opened for the rebase process. +It has been linked to the pull request. Finally, this means we are blocking ALL PRs to our kubernetes fork. @@ -404,10 +403,55 @@ them as the highest priority and release blockers for your team: 1. Update cluster-kube-apiserver-operator `pre-release-lifecycle` alert's `removed_release` version similarly to https://github.com/openshift/cluster-kube-apiserver-operator/pull/1382. -## Updating with `git merge` +## Updating with `redhat-chai-bot` *This is the preferred way to update to patch releases of kubernetes* +[chai-bot](slack://app?team=T027F3GAJ&id=A0AJUKWDUR1&tab=messages) (ship-help-bot) is an internal tool has been given instructions to +periodically check for upstream patch releases and complete the rebase autonomously. The steps taken are outlined below: + + +1. Fetch upstream tags over the past 31 days: +``` +git fetch --tags upstream && git tag --sort=-creatordate | grep -E 'v[0-9]+\.[0-9]+\.[0-9]+$' | awk -v cutoff="$(date -d '31 days ago' +%s)" '$2 >= cutoff {print $1}' +``` +where `upstream` points at https://github.com/kubernetes/kubernetes/ + +2. Determine whether any patch release have occurred that have not yet been rebased and merged. If such patch releases exist, + the corresponding openshift branches are found and marked to be rebased. Otherwise, chai-bot reports that there is no rebase necessary. + - *Branches tracking master are skipped.* + +3. Output a mapping table of upstream release to openshift version, as well as whether that branch needs to be rebased, to the appropriate team: +``` +*Kubernetes patch rebase check* + +Upstream Release OCP Branch Current k8s Status Notes +───────────────── ────────────── ──────────── ───────── ────────────────────────── +v1.35.6 master 1.35.3 REBASE Patch 3 → 6 +v1.35.6 release-5.1 1.35.3 SKIP Points at openshift/master +v1.35.6 release-4.22 1.35.5 REBASE Patch 5 → 6 +v1.34.9 release-4.21 1.34.8 REBASE Patch 8 → 9 +``` + +4. For each branch requiring a rebase, chai-bot runs [rebase.sh](https://github.com/openshift/kubernetes/blob/master/openshift-hack/rebase.sh) (see usage below) with + the appropriate parameters of `kubernetes_tag` and `openshift_release`. + +5. After each successful rebase, a message is posted to the appropriate team: +``` +*:white_check_mark: Rebase of openshift/kubernetes:{openshift_release} → {kubernetes_tag} complete* + +Branch pushed: :{branch_name} +• Kubernetes version: {old_version} → {kubernetes_tag} +• Merge conflicts: {list of files or "None"} + +_Open a PR against `openshift/kubernetes:{openshift_release}` when ready._ +``` +On rebase failure, a message containing failure details is posted instead and the next branch is rebased. + +6. A final summary is posted and permission to open a pull request for each rebase is requested. + +## Updating with `git merge` + After the initial bump as described above it is possible to update to newer released version using `git merge`. To do that follow these steps: @@ -512,26 +556,24 @@ etcd version 3.5.6 or greater required Grab newer version of etcd from https://github.com/etcd-io/etcd/releases/ and place it in `/usr/local/bin/etcd`. -## Updating with `rebase.sh` (experimental) +## Updating with `rebase.sh` -The above steps are available as a script that will merge and rebase along the happy path without automatic conflict -resolution and at the end will create a PR for you. +In the event that chai-bot fails to rebase, [rebase.sh](https://github.com/openshift/kubernetes/blob/master/openshift-hack/rebase.sh) can also be run manually. Here are the steps: -1. Create a new BugZilla with the respective OpenShift version to rebase (Target Release stays ---), - Prio&Severity to High with a proper description of the change logs. - See [BZ2021468](https://bugzilla.redhat.com/show_bug.cgi?id=2021468) as an example. +1. Create a new Jira ticket under OCPBUGS with the respective OpenShift version to rebase, + Target Backport Version to the previous minor version + .z 2. It's best to start off with a fresh fork of [openshift/kubernetes](https://github.com/openshift/kubernetes/). Stay on the master branch. -3. This script requires `jq`, `git`, `podman` and `bash`, `gh` is optional. +3. This script requires `git`, `podman` and `bash`, and optionally uses `gh` to create a pull request. 4. In the root dir of that fork run: ``` -openshift-hack/rebase.sh --k8s-tag=v1.25.2 --openshift-release=release-4.12 --bugzilla-id=2003027 +openshift-hack/rebase.sh --k8s-tag=v1.25.2 --openshift-release=release-4.12 --jira-id=OCPBUGS-90150 ``` where `k8s-tag` is the [kubernetes/kubernetes](https://github.com/kubernetes/kubernetes/) release tag, the `openshift-release` -is the OpenShift release branch in [openshift/kubernetes](https://github.com/openshift/kubernetes/) and the `bugzilla-id` is the -BugZilla ID created in step (1). +is the OpenShift release branch in [openshift/kubernetes](https://github.com/openshift/kubernetes/) and the `jira-id` is the +Jira ticket number created in step (1). 5. In case of conflicts, it will ask you to step into another shell to resolve those. The script will continue by committing the resolution with `UPSTREAM: `. 6. At the end, there will be a "rebase-$VERSION" branch pushed to your fork. -7. If you have `gh` installed and are logged in, it will attempt to create a PR for you by opening a web browser. +7. A pull request will be created with the title `$jira_id: Rebase $k8s_tag in $openshift_release` against the corresponding openshift branch. diff --git a/deps/github.com/openshift/kubernetes/build/build-image/cross/VERSION b/deps/github.com/openshift/kubernetes/build/build-image/cross/VERSION index eaff4eee63..8d181a62ca 100644 --- a/deps/github.com/openshift/kubernetes/build/build-image/cross/VERSION +++ b/deps/github.com/openshift/kubernetes/build/build-image/cross/VERSION @@ -1 +1 @@ -v1.36.0-go1.26.4-bullseye.0 \ No newline at end of file +v1.36.0-go1.26.5-bullseye.0 diff --git a/deps/github.com/openshift/kubernetes/build/common.sh b/deps/github.com/openshift/kubernetes/build/common.sh index 4e6a5307b6..718f549036 100755 --- a/deps/github.com/openshift/kubernetes/build/common.sh +++ b/deps/github.com/openshift/kubernetes/build/common.sh @@ -77,8 +77,8 @@ readonly REMOTE_OUTPUT_BINPATH="${REMOTE_OUTPUT_SUBPATH}/bin" readonly REMOTE_OUTPUT_GOPATH="${REMOTE_OUTPUT_SUBPATH}/go" # These are the default versions (image tags) for their respective base images. -readonly __default_distroless_iptables_version=v0.9.3 -readonly __default_go_runner_version=v2.4.0-go1.26.4-bookworm.0 +readonly __default_distroless_iptables_version=v0.9.6 +readonly __default_go_runner_version=v2.4.0-go1.26.5-bookworm.0 readonly __default_setcap_version=bookworm-v1.0.6 # The default image for all binaries which are dynamically linked. diff --git a/deps/github.com/openshift/kubernetes/build/dependencies.yaml b/deps/github.com/openshift/kubernetes/build/dependencies.yaml index ba2532f5de..2096e578db 100644 --- a/deps/github.com/openshift/kubernetes/build/dependencies.yaml +++ b/deps/github.com/openshift/kubernetes/build/dependencies.yaml @@ -137,7 +137,7 @@ dependencies: # should also be updated, but go-runner is much harder to exploit and has # far less relevancy to go updates for Kubernetes more generally. - name: "registry.k8s.io/kube-cross: dependents" - version: v1.36.0-go1.26.4-bullseye.0 + version: v1.36.0-go1.26.5-bullseye.0 refPaths: - path: build/build-image/cross/VERSION @@ -175,7 +175,7 @@ dependencies: match: registry\.k8s\.io\/build-image\/debian-base:[a-zA-Z]+\-v((([0-9]+)\.([0-9]+)\.([0-9]+)(?:-([0-9a-zA-Z-]+(?:\.[0-9a-zA-Z-]+)*))?)(?:\+([0-9a-zA-Z-]+(?:\.[0-9a-zA-Z-]+)*))?) - name: "registry.k8s.io/distroless-iptables: dependents" - version: v0.9.3 + version: v0.9.6 refPaths: - path: build/common.sh match: __default_distroless_iptables_version= @@ -183,7 +183,7 @@ dependencies: match: configs\[DistrolessIptables\] = Config{list\.BuildImageRegistry, "distroless-iptables", "v([0-9]+)\.([0-9]+)\.([0-9]+)"} - name: "registry.k8s.io/go-runner: dependents" - version: v2.4.0-go1.26.4-bookworm.0 + version: v2.4.0-go1.26.5-bookworm.0 refPaths: - path: build/common.sh match: __default_go_runner_version= diff --git a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/certs.go b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/certs.go index 1e5115a558..0579d02107 100644 --- a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/certs.go +++ b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/certs.go @@ -350,7 +350,7 @@ func getInternalCfg(cfgPath string, client kubernetes.Interface, cfg kubeadmapiv getNodeRegistration := true getAPIEndpoint := staticpodutil.IsControlPlaneNode() getComponentConfigs := true - internalcfg, err := configutil.FetchInitConfigurationFromCluster(client, printer, logPrefix, getNodeRegistration, getAPIEndpoint, getComponentConfigs) + internalcfg, err := configutil.FetchInitConfigurationFromCluster(client, printer, logPrefix, getNodeRegistration, getAPIEndpoint, getComponentConfigs, true) if err == nil { printer.Println() // add empty line to separate the FetchInitConfigurationFromCluster output from the command output // certificate renewal or expiration checking doesn't depend on a running cluster, which means the CertificatesDir diff --git a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/join.go b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/join.go index 20920abe6e..a64b45a045 100644 --- a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/join.go +++ b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/join.go @@ -715,7 +715,7 @@ func fetchInitConfiguration(client clientset.Interface) (*kubeadmapi.InitConfigu getNodeRegistration := false getAPIEndpoint := false getComponentConfigs := true - initConfiguration, err := configutil.FetchInitConfigurationFromCluster(client, nil, "preflight", getNodeRegistration, getAPIEndpoint, getComponentConfigs) + initConfiguration, err := configutil.FetchInitConfigurationFromCluster(client, nil, "preflight", getNodeRegistration, getAPIEndpoint, getComponentConfigs, false) if err != nil { return nil, errors.Wrap(err, "unable to fetch the kubeadm-config ConfigMap") } diff --git a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/reset.go b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/reset.go index 66a64e2cdf..1aeff6fbcc 100644 --- a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/reset.go +++ b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/reset.go @@ -136,7 +136,7 @@ func newResetData(cmd *cobra.Command, opts *resetOptions, in io.Reader, out io.W getNodeRegistration := true getAPIEndpoint := staticpodutil.IsControlPlaneNode() getComponentConfigs := true - initCfg, err = configutil.FetchInitConfigurationFromCluster(client, nil, "reset", getNodeRegistration, getAPIEndpoint, getComponentConfigs) + initCfg, err = configutil.FetchInitConfigurationFromCluster(client, nil, "reset", getNodeRegistration, getAPIEndpoint, getComponentConfigs, true) if err != nil { klog.Warningf("[reset] Unable to fetch the kubeadm-config ConfigMap from cluster: %v", err) } diff --git a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/apply.go b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/apply.go index f940639844..90b6fefd86 100644 --- a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/apply.go +++ b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/apply.go @@ -241,7 +241,7 @@ func newApplyData(cmd *cobra.Command, args []string, applyFlags *applyFlags) (*a getNodeRegistration := true isControlPlaneNode := true getComponentConfigs := true - initCfg, err := configutil.FetchInitConfigurationFromCluster(client, nil, "upgrade", getNodeRegistration, isControlPlaneNode, getComponentConfigs) + initCfg, err := configutil.FetchInitConfigurationFromCluster(client, nil, "upgrade", getNodeRegistration, isControlPlaneNode, getComponentConfigs, false) if err != nil { if apierrors.IsNotFound(err) { _, _ = printer.Printf("[upgrade] In order to upgrade, a ConfigMap called %q in the %q namespace must exist.\n", constants.KubeadmConfigConfigMap, metav1.NamespaceSystem) diff --git a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/common.go b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/common.go index 0fee21e2ec..d853e4454c 100644 --- a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/common.go +++ b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/common.go @@ -96,7 +96,7 @@ func enforceRequirements(flagSet *pflag.FlagSet, flags *applyPlanFlags, args []s getNodeRegistration := true getAPIEndpoint := staticpodutil.IsControlPlaneNode() getComponentConfigs := true - initCfg, err := configutil.FetchInitConfigurationFromCluster(client, printer, "upgrade/config", getNodeRegistration, getAPIEndpoint, getComponentConfigs) + initCfg, err := configutil.FetchInitConfigurationFromCluster(client, printer, "upgrade/config", getNodeRegistration, getAPIEndpoint, getComponentConfigs, false) if err != nil { return nil, nil, nil, nil, errors.Wrap(err, "[upgrade/init config] FATAL") } diff --git a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/diff.go b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/diff.go index 3d5bf468e9..6fc12b222e 100644 --- a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/diff.go +++ b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/diff.go @@ -107,7 +107,7 @@ func validateManifestsPath(manifests ...string) (err error) { } // FetchInitConfigurationFunc defines the signature of the function which will fetch InitConfiguration from cluster. -type FetchInitConfigurationFunc func(client clientset.Interface, printer output.Printer, logPrefix string, getNodeRegistration, getAPIEndpoint, getComponentConfigs bool) (*kubeadmapi.InitConfiguration, error) +type FetchInitConfigurationFunc func(client clientset.Interface, printer output.Printer, logPrefix string, getNodeRegistration, getAPIEndpoint, getComponentConfigs, shortConfigMapGet bool) (*kubeadmapi.InitConfiguration, error) func runDiff(fs *pflag.FlagSet, flags *diffFlags, args []string, fetchInitConfigurationFromCluster FetchInitConfigurationFunc) error { externalCfg := &v1beta4.UpgradeConfiguration{} @@ -123,7 +123,7 @@ func runDiff(fs *pflag.FlagSet, flags *diffFlags, args []string, fetchInitConfig getNodeRegistration := true getAPIEndpoint := staticpodutil.IsControlPlaneNode() getComponentConfigs := false - initCfg, err := fetchInitConfigurationFromCluster(client, &output.TextPrinter{}, "upgrade/diff", getNodeRegistration, getAPIEndpoint, getComponentConfigs) + initCfg, err := fetchInitConfigurationFromCluster(client, &output.TextPrinter{}, "upgrade/diff", getNodeRegistration, getAPIEndpoint, getComponentConfigs, false) if err != nil { return err } diff --git a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/diff_test.go b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/diff_test.go index 7e65ee1a18..4cf16c612c 100644 --- a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/diff_test.go +++ b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/diff_test.go @@ -44,7 +44,7 @@ func createTestRunDiffFile(contents []byte) (string, error) { return file.Name(), nil } -func fakeFetchInitConfig(client clientset.Interface, printer output.Printer, logPrefix string, getNodeRegistration, getAPIEndpoint, getComponentConfigs bool) (*kubeadmapi.InitConfiguration, error) { +func fakeFetchInitConfig(client clientset.Interface, printer output.Printer, logPrefix string, getNodeRegistration, getAPIEndpoint, getComponentConfigs, shortConfigMapGet bool) (*kubeadmapi.InitConfiguration, error) { return &kubeadmapi.InitConfiguration{ ClusterConfiguration: kubeadmapi.ClusterConfiguration{ KubernetesVersion: "v1.0.1", diff --git a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/node.go b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/node.go index 1c8ad80049..36b5bc03b2 100644 --- a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/node.go +++ b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/cmd/upgrade/node.go @@ -205,7 +205,7 @@ func newNodeData(cmd *cobra.Command, nodeOptions *nodeOptions, out io.Writer) (* getNodeRegistration := true getAPIEndpoint := isControlPlaneNode getComponentConfigs := true - initCfg, err := configutil.FetchInitConfigurationFromCluster(client, nil, "upgrade", getNodeRegistration, getAPIEndpoint, getComponentConfigs) + initCfg, err := configutil.FetchInitConfigurationFromCluster(client, nil, "upgrade", getNodeRegistration, getAPIEndpoint, getComponentConfigs, false) if err != nil { return nil, errors.Wrap(err, "unable to fetch the kubeadm-config ConfigMap") } diff --git a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/util/config/cluster.go b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/util/config/cluster.go index ebdb51c2ab..7c02a40d27 100644 --- a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/util/config/cluster.go +++ b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/util/config/cluster.go @@ -27,6 +27,7 @@ import ( "time" authv1 "k8s.io/api/authentication/v1" + v1 "k8s.io/api/core/v1" metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" "k8s.io/apimachinery/pkg/runtime" "k8s.io/apimachinery/pkg/util/wait" @@ -51,8 +52,10 @@ import ( kubeadmruntime "k8s.io/kubernetes/cmd/kubeadm/app/util/runtime" ) -// FetchInitConfigurationFromCluster fetches configuration from a ConfigMap in the cluster -func FetchInitConfigurationFromCluster(client clientset.Interface, printer output.Printer, logPrefix string, getNodeRegistration, getAPIEndpoint, getComponentConfigs bool) (*kubeadmapi.InitConfiguration, error) { +// FetchInitConfigurationFromCluster fetches configuration from a ConfigMap in the cluster. +// If shortConfigMapGet is true, a short retry is used when fetching the kubeadm-config ConfigMap, +// which is suitable for callers like "kubeadm reset" that don't need a long retry. +func FetchInitConfigurationFromCluster(client clientset.Interface, printer output.Printer, logPrefix string, getNodeRegistration, getAPIEndpoint, getComponentConfigs, shortConfigMapGet bool) (*kubeadmapi.InitConfiguration, error) { if printer == nil { printer = &output.TextPrinter{} } @@ -61,7 +64,7 @@ func FetchInitConfigurationFromCluster(client clientset.Interface, printer outpu _, _ = printer.Printf("[%s] Use 'kubeadm init phase upload-config kubeadm --config your-config-file' to re-upload it.\n", logPrefix) // Fetch the actual config from cluster - cfg, err := getInitConfigurationFromCluster(constants.KubernetesDir, client, getNodeRegistration, getAPIEndpoint, getComponentConfigs) + cfg, err := getInitConfigurationFromCluster(constants.KubernetesDir, client, getNodeRegistration, getAPIEndpoint, getComponentConfigs, shortConfigMapGet) if err != nil { return nil, err } @@ -78,9 +81,31 @@ func FetchInitConfigurationFromCluster(client clientset.Interface, printer outpu } // getInitConfigurationFromCluster is separate only for testing purposes, don't call it directly, use FetchInitConfigurationFromCluster instead -func getInitConfigurationFromCluster(kubeconfigDir string, client clientset.Interface, getNodeRegistration, getAPIEndpoint, getComponentConfigs bool) (*kubeadmapi.InitConfiguration, error) { +func getInitConfigurationFromCluster(kubeconfigDir string, client clientset.Interface, getNodeRegistration, getAPIEndpoint, getComponentConfigs, shortConfigMapGet bool) (*kubeadmapi.InitConfiguration, error) { // Also, the config map really should be KubeadmConfigConfigMap... - configMap, err := apiclient.GetConfigMapWithShortRetry(client, metav1.NamespaceSystem, constants.KubeadmConfigConfigMap) + var configMap *v1.ConfigMap + var err error + if shortConfigMapGet { + configMap, err = apiclient.GetConfigMapWithShortRetry(client, metav1.NamespaceSystem, constants.KubeadmConfigConfigMap) + } else { + var lastErr error + err = wait.PollUntilContextTimeout(context.Background(), + constants.KubernetesAPICallRetryInterval, + kubeadmapi.GetActiveTimeouts().KubernetesAPICall.Duration, + true, func(_ context.Context) (bool, error) { + var err error + configMap, err = client.CoreV1().ConfigMaps(metav1.NamespaceSystem).Get( + context.Background(), constants.KubeadmConfigConfigMap, metav1.GetOptions{}) + if err == nil { + return true, nil + } + lastErr = err + return false, nil + }) + if err != nil { + err = lastErr + } + } if err != nil { return nil, errors.Wrap(err, "failed to get config map") } diff --git a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/util/config/cluster_test.go b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/util/config/cluster_test.go index adaf85dbb2..728e5c877b 100644 --- a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/util/config/cluster_test.go +++ b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/util/config/cluster_test.go @@ -540,7 +540,7 @@ func TestGetInitConfigurationFromCluster(t *testing.T) { } getComponentConfigs := true - cfg, err := getInitConfigurationFromCluster(tmpdir, client, rt.getNodeRegistration, rt.getAPIEndpoint, getComponentConfigs) + cfg, err := getInitConfigurationFromCluster(tmpdir, client, rt.getNodeRegistration, rt.getAPIEndpoint, getComponentConfigs, true) if rt.expectedError != (err != nil) { t.Errorf("unexpected return err from getInitConfigurationFromCluster: %v", err) return diff --git a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/util/etcd/etcd.go b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/util/etcd/etcd.go index e3da49c0c6..e746c2012b 100644 --- a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/util/etcd/etcd.go +++ b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/util/etcd/etcd.go @@ -584,6 +584,8 @@ func (c *Client) getMemberStatus(memberID uint64) (isLearner bool, started bool, func (c *Client) MemberPromote(learnerID uint64) error { var ( lastError error + isLearner bool + isStarted bool learnerIDUint = strconv.FormatUint(learnerID, 16) ) @@ -591,7 +593,8 @@ func (c *Client) MemberPromote(learnerID uint64) error { err := wait.PollUntilContextTimeout(context.Background(), constants.EtcdAPICallRetryInterval, kubeadmapi.GetActiveTimeouts().EtcdAPICall.Duration, true, func(_ context.Context) (bool, error) { - isLearner, started, err := c.getMemberStatus(learnerID) + var err error + isLearner, isStarted, err = c.getMemberStatus(learnerID) if err != nil { lastError = errors.WithMessagef(err, "failed to get member %s status", learnerIDUint) return false, nil @@ -600,7 +603,7 @@ func (c *Client) MemberPromote(learnerID uint64) error { klog.V(1).Infof("[etcd] Member %s was already promoted.", learnerIDUint) return true, nil } - if !started { + if !isStarted { klog.V(1).Infof("[etcd] Member %s is not started yet. Waiting for it to be started.", learnerIDUint) lastError = errors.Errorf("the etcd member %s is not started", learnerIDUint) return false, nil @@ -611,6 +614,10 @@ func (c *Client) MemberPromote(learnerID uint64) error { return lastError } + if !isLearner { + return nil + } + klog.V(1).Infof("[etcd] Promoting a learner as a voting member: %s", learnerIDUint) cli, err := c.newEtcdClient(c.Endpoints) @@ -626,14 +633,39 @@ func (c *Client) MemberPromote(learnerID uint64) error { // 2. context deadline exceeded // 3. peer URLs already exists // Once the client provides a way to check if the etcd learner is ready to promote, the retry logic can be revisited. - var promoteResp *clientv3.MemberPromoteResponse + var memberList []*etcdserverpb.Member err = wait.PollUntilContextTimeout(context.Background(), constants.EtcdAPICallRetryInterval, kubeadmapi.GetActiveTimeouts().EtcdAPICall.Duration, true, func(_ context.Context) (bool, error) { + // MemberPromote can return a transient client-side error even if the + // promotion already succeeded on the etcd side. Check the current + // member state before attempting another promotion so that retries + // remain idempotent. + resp, statusErr := c.listMembersOnce() + if statusErr != nil { + klog.V(5).Infof("[etcd] Failed to list members before promoting learner %s: %v", learnerIDUint, statusErr) + lastError = statusErr + return false, nil + } + + for _, m := range resp.Members { + if m.ID != learnerID { + continue + } + + if !m.IsLearner { + klog.V(1).Infof("[etcd] Member %s is already a voting member, treating promotion as successful", learnerIDUint) + memberList = resp.Members + return true, nil + } + break + } + ctx, cancel := context.WithTimeout(context.Background(), etcdTimeout) defer cancel() - promoteResp, err = cli.MemberPromote(ctx, learnerID) + promoteResp, err := cli.MemberPromote(ctx, learnerID) if err == nil { klog.V(1).Infof("[etcd] The learner was promoted as a voting member: %s", learnerIDUint) + memberList = promoteResp.Members return true, nil } klog.V(5).Infof("[etcd] Promoting the learner %s failed: %v", learnerIDUint, err) @@ -644,7 +676,7 @@ func (c *Client) MemberPromote(learnerID uint64) error { return lastError } - for _, m := range promoteResp.Members { + for _, m := range memberList { if m.ID == learnerID { parsedPeerAddrs, err := url.Parse(m.PeerURLs[0]) if err != nil { diff --git a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/util/etcd/etcd_test.go b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/util/etcd/etcd_test.go index cbf1a97463..af4f99e0f0 100644 --- a/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/util/etcd/etcd_test.go +++ b/deps/github.com/openshift/kubernetes/cmd/kubeadm/app/util/etcd/etcd_test.go @@ -20,6 +20,7 @@ import ( "context" "fmt" "reflect" + "slices" "strconv" "testing" "time" @@ -44,6 +45,9 @@ var errNotImplemented = errors.New("not implemented") type fakeEtcdClient struct { members []*pb.Member endpoints []string + + memberListFunc func(context.Context, ...clientv3.OpOption) (*clientv3.MemberListResponse, error) + memberPromoteFunc func(context.Context, uint64) (*clientv3.MemberPromoteResponse, error) } // Close shuts down the client's etcd connections. @@ -58,7 +62,10 @@ func (f *fakeEtcdClient) Endpoints() []string { } // MemberList lists the current cluster membership. -func (f *fakeEtcdClient) MemberList(_ context.Context, _ ...clientv3.OpOption) (*clientv3.MemberListResponse, error) { +func (f *fakeEtcdClient) MemberList(ctx context.Context, opts ...clientv3.OpOption) (*clientv3.MemberListResponse, error) { + if f.memberListFunc != nil { + return f.memberListFunc(ctx, opts...) + } return &clientv3.MemberListResponse{ Members: f.members, }, nil @@ -80,7 +87,10 @@ func (f *fakeEtcdClient) MemberRemove(_ context.Context, id uint64) (*clientv3.M } // MemberPromote promotes a member from raft learner (non-voting) to raft voting member. -func (f *fakeEtcdClient) MemberPromote(_ context.Context, id uint64) (*clientv3.MemberPromoteResponse, error) { +func (f *fakeEtcdClient) MemberPromote(ctx context.Context, id uint64) (*clientv3.MemberPromoteResponse, error) { + if f.memberPromoteFunc != nil { + return f.memberPromoteFunc(ctx, id) + } return nil, errNotImplemented } @@ -965,3 +975,198 @@ func TestEvaluateClusterStatus(t *testing.T) { }) } } + +func TestMemberPromote(t *testing.T) { + learnerID := uint64(12345) + + const ( + initialEndpoint = "https://192.168.10.100:2379" + promotedEndpoint = "https://192.168.10.200:2379" + ) + + member := func(isLearner bool) *pb.Member { + return &pb.Member{ + ID: learnerID, + Name: "cp-1", + PeerURLs: []string{"https://192.168.10.200:2380"}, + ClientURLs: []string{promotedEndpoint}, + IsLearner: isLearner, + } + } + + type memberListResult struct { + members []*pb.Member + err error + } + + type memberPromoteResult struct { + resp *clientv3.MemberPromoteResponse + err error + } + + tests := []struct { + name string + memberListResults []memberListResult + memberPromoteResults []memberPromoteResult + wantErr bool + wantEndpoint string + wantPromoteCalls int + minMemberListCalls int + }{ + { + name: "successful promotion adds endpoint", + memberListResults: []memberListResult{ + {members: []*pb.Member{member(true)}}, + {members: []*pb.Member{member(true)}}, + }, + memberPromoteResults: []memberPromoteResult{ + { + resp: &clientv3.MemberPromoteResponse{ + Members: []*pb.Member{member(false)}, + }, + }, + }, + wantEndpoint: promotedEndpoint, + wantPromoteCalls: 1, + minMemberListCalls: 2, + }, + { + name: "already promoted after transient promote failure adds endpoint", + memberListResults: []memberListResult{ + {members: []*pb.Member{member(true)}}, + {members: []*pb.Member{member(true)}}, + {members: []*pb.Member{member(false)}}, + }, + memberPromoteResults: []memberPromoteResult{ + { + err: context.DeadlineExceeded, + }, + }, + wantEndpoint: promotedEndpoint, + wantPromoteCalls: 1, + minMemberListCalls: 3, + }, + { + name: "already promoted before promote attempt adds endpoint", + memberListResults: []memberListResult{ + {members: []*pb.Member{member(true)}}, + {members: []*pb.Member{member(false)}}, + }, + wantEndpoint: promotedEndpoint, + wantPromoteCalls: 0, + minMemberListCalls: 2, + }, + { + name: "member list error before promote is retried", + memberListResults: []memberListResult{ + {members: []*pb.Member{member(true)}}, + {err: errNotImplemented}, + {members: []*pb.Member{member(true)}}, + }, + memberPromoteResults: []memberPromoteResult{ + { + resp: &clientv3.MemberPromoteResponse{ + Members: []*pb.Member{member(false)}, + }, + }, + }, + wantEndpoint: promotedEndpoint, + wantPromoteCalls: 1, + minMemberListCalls: 3, + }, + { + name: "promotion keeps failing", + memberListResults: []memberListResult{ + {members: []*pb.Member{member(true)}}, + {members: []*pb.Member{member(true)}}, + }, + memberPromoteResults: []memberPromoteResult{ + { + err: context.DeadlineExceeded, + }, + }, + wantErr: true, + wantPromoteCalls: -1, + minMemberListCalls: 1, + }, + } + + oldActiveTimeout := kubeadmapi.GetActiveTimeouts() + newActiveTimeout := oldActiveTimeout.DeepCopy() + newActiveTimeout.EtcdAPICall = &metav1.Duration{ + Duration: 3 * constants.EtcdAPICallRetryInterval, + } + kubeadmapi.SetActiveTimeouts(newActiveTimeout) + defer kubeadmapi.SetActiveTimeouts(oldActiveTimeout) + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + memberListCalls := 0 + memberPromoteCalls := 0 + + fakeClient := &fakeEtcdClient{} + + fakeClient.memberListFunc = func(_ context.Context, _ ...clientv3.OpOption) (*clientv3.MemberListResponse, error) { + if len(tt.memberListResults) == 0 { + t.Fatal("MemberList called without configured results") + } + + resultIndex := memberListCalls + if resultIndex >= len(tt.memberListResults) { + resultIndex = len(tt.memberListResults) - 1 + } + result := tt.memberListResults[resultIndex] + memberListCalls++ + + if result.err != nil { + return nil, result.err + } + return &clientv3.MemberListResponse{ + Members: result.members, + }, nil + } + + fakeClient.memberPromoteFunc = func(_ context.Context, _ uint64) (*clientv3.MemberPromoteResponse, error) { + if len(tt.memberPromoteResults) == 0 { + t.Fatalf("unexpected MemberPromote call") + } + + resultIndex := memberPromoteCalls + if resultIndex >= len(tt.memberPromoteResults) { + resultIndex = len(tt.memberPromoteResults) - 1 + } + result := tt.memberPromoteResults[resultIndex] + memberPromoteCalls++ + + return result.resp, result.err + } + + c := &Client{ + Endpoints: []string{initialEndpoint}, + } + c.newEtcdClient = func(_ []string) (etcdClient, error) { + return fakeClient, nil + } + c.listMembersFunc = func(_ time.Duration) (*clientv3.MemberListResponse, error) { + return fakeClient.MemberList(context.Background()) + } + + err := c.MemberPromote(learnerID) + if (err != nil) != tt.wantErr { + t.Fatalf("MemberPromote() error = %v, wantErr %v", err, tt.wantErr) + } + + if tt.wantPromoteCalls >= 0 && memberPromoteCalls != tt.wantPromoteCalls { + t.Fatalf("MemberPromote calls = %d, want %d", memberPromoteCalls, tt.wantPromoteCalls) + } + + if memberListCalls < tt.minMemberListCalls { + t.Fatalf("MemberList calls = %d, want at least %d", memberListCalls, tt.minMemberListCalls) + } + + if tt.wantEndpoint != "" && !slices.Contains(c.Endpoints, tt.wantEndpoint) { + t.Fatalf("expected endpoint %q to be added, got %v", tt.wantEndpoint, c.Endpoints) + } + }) + } +} diff --git a/deps/github.com/openshift/kubernetes/go.mod b/deps/github.com/openshift/kubernetes/go.mod index 7c8be20ca5..b33d07e18e 100644 --- a/deps/github.com/openshift/kubernetes/go.mod +++ b/deps/github.com/openshift/kubernetes/go.mod @@ -126,7 +126,7 @@ require ( sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 sigs.k8s.io/knftables v0.0.21 sigs.k8s.io/randfill v1.0.0 - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 sigs.k8s.io/yaml v1.6.0 ) diff --git a/deps/github.com/openshift/kubernetes/go.sum b/deps/github.com/openshift/kubernetes/go.sum index 2379794f21..a627d3583d 100644 --- a/deps/github.com/openshift/kubernetes/go.sum +++ b/deps/github.com/openshift/kubernetes/go.sum @@ -604,7 +604,7 @@ sigs.k8s.io/kustomize/kyaml v0.21.1 h1:IVlbmhC076nf6foyL6Taw4BkrLuEsXUXNpsE+ScX7 sigs.k8s.io/kustomize/kyaml v0.21.1/go.mod h1:hmxADesM3yUN2vbA5z1/YTBnzLJ1dajdqpQonwBL1FQ= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/openshift-hack/cmd/k8s-tests-ext/disabled_tests.go b/deps/github.com/openshift/kubernetes/openshift-hack/cmd/k8s-tests-ext/disabled_tests.go index 14b814010a..e03ea96d80 100644 --- a/deps/github.com/openshift/kubernetes/openshift-hack/cmd/k8s-tests-ext/disabled_tests.go +++ b/deps/github.com/openshift/kubernetes/openshift-hack/cmd/k8s-tests-ext/disabled_tests.go @@ -163,9 +163,6 @@ func filterOutDisabledSpecs(specs et.ExtensionTestSpecs) et.ExtensionTestSpecs { // https://issues.redhat.com/browse/OCPBUGS-45275 "[sig-network] Connectivity Pod Lifecycle should be able to connect to other Pod from a terminating Pod", - // https://issues.redhat.com/browse/OCPBUGS-63132 - "[sig-node] [Serial] Pod InPlace Resize Container (deferred-resizes) [FeatureGate:InPlacePodVerticalScaling] pod-resize-retry-deferred-test-3", - // https://issues.redhat.com/browse/OCPBUGS-99058 "[sig-node] [DRA] [FeatureGate:DRAExtendedResource] [Beta] [Feature:DynamicResourceAllocation] must run pods with extended resource on dra nodes and device plugin nodes [Serial] [KubeletMinVersion:1.35]", }, @@ -177,9 +174,6 @@ func filterOutDisabledSpecs(specs et.ExtensionTestSpecs) et.ExtensionTestSpecs { // https://issues.redhat.com/browse/OCPBUGS-61378 "[sig-network] Conntrack should be able to cleanup conntrack entries when UDP service target port changes for a NodePort service", - // https://redhat.atlassian.net/browse/OCPBUGS-85262 - "[sig-cli] kubectl kuberc commands", - // https://redhat.atlassian.net/browse/OCPBUGS-64847 "[sig-node] [Serial] Pod InPlace Resize Container (deferred-resizes) [FeatureGate:InPlacePodVerticalScaling] pod-resize-retry-deferred-test-2", }, diff --git a/deps/github.com/openshift/kubernetes/openshift-hack/images/hyperkube/Dockerfile.rhel b/deps/github.com/openshift/kubernetes/openshift-hack/images/hyperkube/Dockerfile.rhel index ac000558bd..c306f87d1a 100644 --- a/deps/github.com/openshift/kubernetes/openshift-hack/images/hyperkube/Dockerfile.rhel +++ b/deps/github.com/openshift/kubernetes/openshift-hack/images/hyperkube/Dockerfile.rhel @@ -15,4 +15,4 @@ COPY --from=builder /tmp/build/* /usr/bin/ LABEL io.k8s.display-name="OpenShift Kubernetes Server Commands" \ io.k8s.description="OpenShift is a platform for developing, building, and deploying containerized applications." \ io.openshift.tags="openshift,hyperkube" \ - io.openshift.build.versions="kubernetes=1.36.2" + io.openshift.build.versions="kubernetes=1.36.3" diff --git a/deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh b/deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh index ed2fdbbed5..9db68e2274 100755 --- a/deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh +++ b/deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh @@ -2,7 +2,7 @@ # READ FIRST BEFORE USING THIS SCRIPT # -# This script requires jq, git, podman and bash to work properly (dependencies are checked for you). +# This script requires git, podman and bash to work properly (dependencies are checked for you). # The Github CLI "gh" is optional, but convenient to create a pull request automatically at the end. # # This script generates a git remote structure described in: @@ -11,16 +11,16 @@ # # The usage is described in /Rebase.openshift.md. -# validate input args --k8s-tag=v1.21.2 --openshift-release=release-4.8 --bugzilla-id=2003027 +# validate input args --k8s-tag=v1.21.2 --openshift-release=release-4.8 --jira-id=OCPBUGS-91759 k8s_tag="" openshift_release="" -bugzilla_id="" +jira_id="" usage() { echo "Available arguments:" echo " --k8s-tag (required) Example: --k8s-tag=v1.21.2" echo " --openshift-release (required) Example: --openshift-release=release-4.8" - echo " --bugzilla-id (optional) creates new PR against openshift/kubernetes:${openshift-release}: Example: --bugzilla-id=2003027" + echo " --jira-id (optional) Include Jira ticket in PR title: Example: --jira-id=OCPBUGS-1234" } for i in "$@"; do @@ -33,8 +33,8 @@ for i in "$@"; do openshift_release="${i#*=}" shift ;; - --bugzilla-id=*) - bugzilla_id="${i#*=}" + --jira-id=*) + jira_id="${i#*=}" shift ;; *) @@ -61,7 +61,7 @@ fi echo "Processed arguments are:" echo "--k8s_tag=${k8s_tag}" echo "--openshift_release=${openshift_release}" -echo "--bugzilla_id=${bugzilla_id}" +echo "--jira_id=${jira_id}" # prerequisites (check git, podman, ... is present) if ! command -v git &>/dev/null; then @@ -69,11 +69,6 @@ if ! command -v git &>/dev/null; then exit 1 fi -if ! command -v jq &>/dev/null; then - echo "jq not installed, exiting" - exit 1 -fi - if ! command -v podman &>/dev/null; then echo "podman not installed, exiting" exit 1 @@ -98,9 +93,13 @@ git fetch upstream --tags -f git remote add openshift git@github.com:openshift/kubernetes.git git fetch openshift -#git checkout --track "openshift/$openshift_release" +git checkout --track "openshift/$openshift_release" git pull openshift "$openshift_release" +if [ -z "$(git tag -l "$k8s_tag")" ]; then + echo "No such tag exists in upstream for: $k8s_tag" + exit 1 +fi git merge "$k8s_tag" # shellcheck disable=SC2181 if [ $? -eq 0 ]; then @@ -125,18 +124,17 @@ fi # openshift-hack/images/hyperkube/Dockerfile.rhel still has FROM pointing to old tag # we need to remove the prefix "v" from the $k8s_tag to stay compatible -sed -i -E "s/(io.openshift.build.versions=\"kubernetes=)(1.[1-9]+.[1-9]+)/\1${k8s_tag:1}/" openshift-hack/images/hyperkube/Dockerfile.rhel +podman run --rm -v "$(pwd):/workspace:Z" docker.io/library/alpine:latest \ + sed -i -E "s/(io.openshift.build.versions=\"kubernetes=)(1.[1-9]+.[1-9]+)/\1${k8s_tag:1}/" \ + /workspace/openshift-hack/images/hyperkube/Dockerfile.rhel go_mod_go_ver=$(grep -E 'go 1\.[1-9][0-9]?' go.mod | sed -E 's/go (1\.[1-9][0-9]?)/\1/' | cut -d '.' -f 1,2) # Need to handle mod versions like 1.23 and 1.23.4; our release images only have major.minor -tag="rhel-8-release-golang-${go_mod_go_ver}-openshift-${openshift_release#release-}" - -# update openshift go.mod dependencies -sed -i -E "/=>/! s/(\tgithub.com\/openshift\/[a-z|-]+) (.*)$/\1 $openshift_release/" go.mod +tag=$(grep "^ tag:" .ci-operator.yaml | head -n1 | sed -E 's/.*: (.*)/\1/') echo "> go mod tidy && hack/update-vendor.sh" -podman run -it --rm -v "$(pwd):/go/k8s.io/kubernetes:Z" \ +podman run --rm -v "$(pwd):/go/k8s.io/kubernetes:Z" \ --workdir=/go/k8s.io/kubernetes \ "registry.ci.openshift.org/openshift/release:$tag" \ - go mod tidy && hack/update-vendor.sh + /bin/bash -c "go mod tidy && hack/update-vendor.sh" # shellcheck disable=SC2181 if [ $? -ne 0 ]; then @@ -144,10 +142,26 @@ if [ $? -ne 0 ]; then exit 1 fi -podman run -it --rm -v "$(pwd):/go/k8s.io/kubernetes:Z" \ +echo "> make clean to remove stale _output directory" +podman run --rm -v "$(pwd):/go/k8s.io/kubernetes:Z" \ + --workdir=/go/k8s.io/kubernetes \ + "registry.ci.openshift.org/openshift/release:$tag" \ + make clean +# shellcheck disable=SC2181 +if [ $? -ne 0 ]; then + echo "make clean failed — check filesystem permissions on _output/" + exit 1 +fi + +podman run --rm -v "$(pwd):/go/k8s.io/kubernetes:Z" \ --workdir=/go/k8s.io/kubernetes \ "registry.ci.openshift.org/openshift/release:$tag" \ make update OS_RUN_WITHOUT_DOCKER=yes +# shellcheck disable=SC2181 +if [ $? -ne 0 ]; then + echo "make update failed" + exit 1 +fi git add -A git commit -m "UPSTREAM: : hack/update-vendor.sh, make update and update image" @@ -155,21 +169,19 @@ git commit -m "UPSTREAM: : hack/update-vendor.sh, make update and update i remote_branch="rebase-$k8s_tag" git push origin "$openshift_release:$remote_branch" -XY=$(echo "$k8s_tag" | sed -E "s/v(1\.[0-9]+)\.[0-9]+/\1/") -ver=$(echo "$k8s_tag" | sed "s/\.//g") -link="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-$XY.md#$ver" -if [ -n "${bugzilla_id}" ]; then - if command -v gh &>/dev/null; then - XY=$(echo "$k8s_tag" | sed -E "s/v(1\.[0-9]+)\.[0-9]+/\1/") - ver=$(echo "$k8s_tag" | sed "s/\.//g") - link="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-$XY.md#$ver" - - # opens a web browser, because we can't properly create PRs against remote repositories with the GH CLI (yet): - # https://github.com/cli/cli/issues/2691 - gh pr create \ - --title "Bug $bugzilla_id: Rebase $k8s_tag" \ - --body "CHANGELOG $link" \ - --web +if command -v gh &>/dev/null; then + XY=$(echo "$k8s_tag" | sed -E "s/v(1\.[0-9]+)\.[0-9]+/\1/") + ver=$(echo "$k8s_tag" | sed "s/\.//g") + link="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-$XY.md#$ver" + title="Rebase $k8s_tag in $openshift_release" + if [ -n "${jira_id}" ]; then + title="$jira_id: $title" fi + + gh pr create \ + --title "$title" \ + --body "CHANGELOG $link" \ + --base "$openshift_release" \ + --head "$remote_branch" fi diff --git a/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go b/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go index 9bf0a1f8a1..530639815a 100644 --- a/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go +++ b/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go @@ -17,7 +17,6 @@ import ( "k8s.io/apimachinery/pkg/api/errors" "k8s.io/apimachinery/pkg/api/resource" metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" - "k8s.io/apimachinery/pkg/labels" "k8s.io/apimachinery/pkg/util/validation/field" "k8s.io/apiserver/pkg/admission" "k8s.io/apiserver/pkg/admission/initializer" @@ -187,16 +186,6 @@ func (a *managementCPUsOverride) Admit(ctx context.Context, attr admission.Attri return admission.NewForbidden(attr, fmt.Errorf("%s node or namespace or infra config cache not synchronized", PluginName)) } - nodes, err := a.nodeLister.List(labels.Everything()) - if err != nil { - return admission.NewForbidden(attr, err) // can happen due to informer latency - } - - // we still need to have nodes under the cluster to decide if the management resource enabled or not - if len(nodes) == 0 { - return admission.NewForbidden(attr, fmt.Errorf("%s the cluster does not have any nodes", PluginName)) - } - clusterInfra, err := a.infraConfigLister.Get(infraClusterName) if err != nil { return admission.NewForbidden(attr, err) // can happen due to informer latency @@ -215,7 +204,7 @@ func (a *managementCPUsOverride) Admit(ctx context.Context, attr admission.Attri } // Check if we are in CPU Partitioning mode for AllNodes - if !isCPUPartitioning(clusterInfra.Status, nodes, workloadType) { + if !isCPUPartitioning(clusterInfra.Status) { return nil } @@ -284,18 +273,7 @@ func (a *managementCPUsOverride) Admit(ctx context.Context, attr admission.Attri return nil } -func isCPUPartitioning(infraStatus configv1.InfrastructureStatus, nodes []*corev1.Node, workloadType string) bool { - // If status is not for CPU partitioning and we're single node we also check nodes to support upgrade event - // TODO: This should not be needed after 4.13 as all clusters after should have this feature on at install time, or updated by migration in NTO. - if infraStatus.CPUPartitioning != configv1.CPUPartitioningAllNodes && infraStatus.ControlPlaneTopology == configv1.SingleReplicaTopologyMode { - managedResource := fmt.Sprintf("%s.%s", workloadType, containerWorkloadResourceSuffix) - for _, node := range nodes { - // We only expect a single node to exist, so we return on first hit - if _, ok := node.Status.Allocatable[corev1.ResourceName(managedResource)]; ok { - return true - } - } - } +func isCPUPartitioning(infraStatus configv1.InfrastructureStatus) bool { return infraStatus.CPUPartitioning == configv1.CPUPartitioningAllNodes } diff --git a/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission_test.go b/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission_test.go index 9564bffe39..209bea8383 100644 --- a/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission_test.go +++ b/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission_test.go @@ -87,7 +87,7 @@ func TestAdmit(t *testing.T) { pod: testManagedPodWithWorkloadAnnotation("500m", "250m", "500Mi", "250Mi", "non-existent"), expectedCpuRequest: resource.MustParse("250m"), namespace: testManagedNamespace(), - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), expectedError: fmt.Errorf("the pod namespace %q does not allow the workload type non-existent", "managed-namespace"), }, @@ -96,7 +96,7 @@ func TestAdmit(t *testing.T) { pod: testPod("500m", "250m", "500Mi", "250Mi"), expectedCpuRequest: resource.MustParse("250m"), namespace: testManagedNamespace(), - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, }, { name: "should return admission error when the pod has more than one workload annotation", @@ -112,7 +112,7 @@ func TestAdmit(t *testing.T) { ), expectedCpuRequest: resource.MustParse("250m"), namespace: testManagedNamespace(), - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), expectedError: fmt.Errorf("the pod can not have more than one workload annotations"), }, @@ -129,7 +129,7 @@ func TestAdmit(t *testing.T) { ), expectedCpuRequest: resource.MustParse("250m"), namespace: testManagedNamespace(), - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), expectedError: fmt.Errorf("the workload annotation key should have format %s", podWorkloadTargetAnnotationPrefix), }, @@ -146,7 +146,7 @@ func TestAdmit(t *testing.T) { ), expectedCpuRequest: resource.MustParse("250m"), namespace: testManagedNamespace(), - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), expectedError: fmt.Errorf(`failed to get workload annotation effect: failed to parse "{" annotation value: unexpected end of JSON input`), }, @@ -163,7 +163,7 @@ func TestAdmit(t *testing.T) { ), expectedCpuRequest: resource.MustParse("250m"), namespace: testManagedNamespace(), - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, expectedError: fmt.Errorf(`failed to get workload annotation effect: the workload annotation value map["test":"test"] does not have "effect" key`), infra: testClusterSNOInfra(), }, @@ -183,7 +183,7 @@ func TestAdmit(t *testing.T) { workloadAdmissionWarning: "skipping pod CPUs requests modifications because the namespace namespace is not annotated with workload.openshift.io/allowed to allow workload partitioning", }, namespace: testNamespace(), - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), }, { @@ -196,7 +196,7 @@ func TestAdmit(t *testing.T) { fmt.Sprintf("%s%s", containerResourcesAnnotationPrefix, "initTest"): fmt.Sprintf(`{"%s":256}`, containerResourcesAnnotationValueKeyCPUShares), fmt.Sprintf("%s%s", podWorkloadTargetAnnotationPrefix, workloadTypeManagement): fmt.Sprintf(`{"%s":"%s"}`, podWorkloadAnnotationEffect, workloadEffectPreferredDuringScheduling), }, - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), }, { @@ -209,7 +209,7 @@ func TestAdmit(t *testing.T) { fmt.Sprintf("%s%s", containerResourcesAnnotationPrefix, "initTest"): fmt.Sprintf(`{"%s": 2}`, containerResourcesAnnotationValueKeyCPUShares), fmt.Sprintf("%s%s", podWorkloadTargetAnnotationPrefix, workloadTypeManagement): fmt.Sprintf(`{"%s":"%s"}`, podWorkloadAnnotationEffect, workloadEffectPreferredDuringScheduling), }, - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), }, { @@ -221,7 +221,7 @@ func TestAdmit(t *testing.T) { fmt.Sprintf("%s%s", podWorkloadTargetAnnotationPrefix, workloadTypeManagement): fmt.Sprintf(`{"%s":"%s"}`, podWorkloadAnnotationEffect, workloadEffectPreferredDuringScheduling), kubetypes.ConfigSourceAnnotationKey: kubetypes.FileSource, }, - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), }, { @@ -232,7 +232,7 @@ func TestAdmit(t *testing.T) { expectedAnnotations: map[string]string{ workloadAdmissionWarning: "skip pod CPUs requests modifications because it has guaranteed QoS class", }, - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), }, { @@ -245,7 +245,7 @@ func TestAdmit(t *testing.T) { fmt.Sprintf("%s%s", containerResourcesAnnotationPrefix, "initTest"): fmt.Sprintf(`{"%s":256,"cpulimit":500}`, containerResourcesAnnotationValueKeyCPUShares), fmt.Sprintf("%s%s", podWorkloadTargetAnnotationPrefix, workloadTypeManagement): fmt.Sprintf(`{"%s":"%s"}`, podWorkloadAnnotationEffect, workloadEffectPreferredDuringScheduling), }, - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), }, { @@ -256,7 +256,7 @@ func TestAdmit(t *testing.T) { expectedAnnotations: map[string]string{ workloadAdmissionWarning: fmt.Sprintf("skip pod CPUs requests modifications because it will change the pod QoS class from %s to %s", corev1.PodQOSBurstable, corev1.PodQOSBestEffort), }, - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), }, { @@ -267,15 +267,6 @@ func TestAdmit(t *testing.T) { nodes: []*corev1.Node{testNode()}, infra: testClusterInfraWithoutWorkloadPartitioning(), }, - { - name: "should return admission error when the cluster does not have any nodes", - pod: testManagedPod("500m", "250m", "500Mi", "250Mi"), - expectedCpuRequest: resource.MustParse("250m"), - namespace: testManagedNamespace(), - nodes: []*corev1.Node{}, - infra: testClusterSNOInfra(), - expectedError: fmt.Errorf("the cluster does not have any nodes"), - }, } for _, test := range tests { diff --git a/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go b/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go index 9fa7770e9f..06a24fee8e 100644 --- a/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go +++ b/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go @@ -32,6 +32,19 @@ const ( // vpaOperatorNamespace is the namespace the VPA operator is expected to run in. vpaOperatorNamespace = "openshift-vertical-pod-autoscaler" + // croOperatorLabelKey / croOperatorLabelValue identify the CRO operator pod. + croOperatorLabelKey = "clusterresourceoverride.operator" + croOperatorLabelValue = "true" + // croOperatorNamespace is the namespace the CRO operator is expected to run in. + croOperatorNamespace = "openshift-cluster-resource-override" + + // cmaOperatorLabelKey / cmaOperatorLabelValue identify the CMA operator pod. + cmaOperatorLabelKey = "name" + cmaOperatorLabelValue = "custom-metrics-autoscaler-operator" + + // cmaOperatorNamespace is the namespace the CMA operator is expected to run in. + cmaOperatorNamespace = "openshift-keda" + // standaloneEnvVar is the environment variable checked at start-up. // It is injected by the downward API and reflects the namespace the // kube-apiserver pod runs in. @@ -93,16 +106,58 @@ func (p *nodeSelectorAdjuster) ValidateInitialization() error { // requiresNodeSelectorAdjustment returns true when the pod carries a label that // opts it in to control-plane node placement and lives in a namespace where that -// label is expected. Currently the VPA operator pod opts in via its well-known -// label. Future control-plane-adjacent Day 2 operators can be added here. +// label is expected. Control-plane-adjacent Day 2 operators can be added here. func requiresNodeSelectorAdjustment(pod *coreapi.Pod) bool { + // for VPA, we only want to update if the node selector is the default from + // https://github.com/openshift/vertical-pod-autoscaler-operator/blob/main/config/manager/manager.yaml if pod.Labels[vpaOperatorLabelKey] == vpaOperatorLabelValue && - pod.Namespace == vpaOperatorNamespace { + pod.Namespace == vpaOperatorNamespace && len(pod.Spec.NodeSelector) == 1 && + pod.Spec.NodeSelector["kubernetes.io/os"] == "linux" { return true } + // for CRO, we only want to update if the node selector empty + if pod.Labels[croOperatorLabelKey] == croOperatorLabelValue && + pod.Namespace == croOperatorNamespace && len(pod.Spec.NodeSelector) == 0 { + return true + } + // for CMA, we want to update if the node selector is empty + // and if it has a toleration that would tolerate the master NoSchedule taint + if pod.Labels[cmaOperatorLabelKey] == cmaOperatorLabelValue && + pod.Namespace == cmaOperatorNamespace && len(pod.Spec.NodeSelector) == 0 { + masterTaint := coreapi.Taint{ + Key: "node-role.kubernetes.io/master", + Effect: coreapi.TaintEffectNoSchedule, + } + for _, tol := range pod.Spec.Tolerations { + if toleratesTaint(tol, masterTaint) { + return true + } + } + } return false } +// toleratesTaint checks if a toleration tolerates a given taint, following the +// same rules as corev1.Toleration.ToleratesTaint: an empty effect matches all +// effects, the Exists operator matches any value, and an empty key with Exists +// matches all keys. +func toleratesTaint(tol coreapi.Toleration, taint coreapi.Taint) bool { + if len(tol.Effect) > 0 && tol.Effect != taint.Effect { + return false + } + if len(tol.Key) > 0 && tol.Key != taint.Key { + return false + } + switch tol.Operator { + case "", coreapi.TolerationOpEqual: + return tol.Value == taint.Value + case coreapi.TolerationOpExists: + return true + default: + return false + } +} + // addControlPlaneNodeSelector ensures spec.nodeSelector contains the control-plane role key. func addControlPlaneNodeSelector(pod *coreapi.Pod) { if pod.Spec.NodeSelector == nil { diff --git a/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission_test.go b/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission_test.go index 630616f343..38d5a1a360 100644 --- a/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission_test.go +++ b/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission_test.go @@ -20,29 +20,52 @@ func TestAdmit(t *testing.T) { expectedNodeSelector map[string]string }{ { - name: "VPA operator pod: control-plane node selector is added", + name: "VPA operator pod with default node selector: control-plane node selector is added", + pod: makePod( + withNamespace(vpaOperatorNamespace), + withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), + withNodeSelector(map[string]string{"kubernetes.io/os": "linux"}), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: map[string]string{ + controlPlaneRoleKey: "", + "kubernetes.io/os": "linux", + }, + }, + { + name: "VPA operator pod with no node selector: not modified", pod: makePod( withNamespace(vpaOperatorNamespace), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), ), resource: coreapi.Resource("pods").WithVersion("v1"), - expectedNodeSelector: map[string]string{controlPlaneRoleKey: ""}, + expectedNodeSelector: nil, }, { - name: "VPA operator pod: control-plane node selector added alongside existing selectors", + name: "VPA operator pod with non-default node selector: not modified", pod: makePod( withNamespace(vpaOperatorNamespace), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), withNodeSelector(map[string]string{"topology.kubernetes.io/zone": "us-east-1a"}), ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: map[string]string{"topology.kubernetes.io/zone": "us-east-1a"}, + }, + { + name: "VPA operator pod with extra node selectors: not modified", + pod: makePod( + withNamespace(vpaOperatorNamespace), + withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), + withNodeSelector(map[string]string{"kubernetes.io/os": "linux", "topology.kubernetes.io/zone": "us-east-1a"}), + ), resource: coreapi.Resource("pods").WithVersion("v1"), expectedNodeSelector: map[string]string{ - controlPlaneRoleKey: "", + "kubernetes.io/os": "linux", "topology.kubernetes.io/zone": "us-east-1a", }, }, { - name: "VPA operator pod: control-plane node selector already present is left unchanged", + name: "VPA operator pod with control-plane selector already present: not modified", pod: makePod( withNamespace(vpaOperatorNamespace), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), @@ -51,6 +74,125 @@ func TestAdmit(t *testing.T) { resource: coreapi.Resource("pods").WithVersion("v1"), expectedNodeSelector: map[string]string{controlPlaneRoleKey: ""}, }, + { + name: "CRO operator pod with no node selector: control-plane node selector is added", + pod: makePod( + withNamespace(croOperatorNamespace), + withLabels(map[string]string{croOperatorLabelKey: croOperatorLabelValue}), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: map[string]string{controlPlaneRoleKey: ""}, + }, + { + name: "CRO operator pod with existing node selector: not modified", + pod: makePod( + withNamespace(croOperatorNamespace), + withLabels(map[string]string{croOperatorLabelKey: croOperatorLabelValue}), + withNodeSelector(map[string]string{"kubernetes.io/os": "linux"}), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: map[string]string{"kubernetes.io/os": "linux"}, + }, + { + name: "CRO operator pod in wrong namespace: not modified", + pod: makePod( + withNamespace("other-namespace"), + withLabels(map[string]string{croOperatorLabelKey: croOperatorLabelValue}), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: nil, + }, + { + name: "CRO operator label with wrong value: not modified", + pod: makePod( + withNamespace(croOperatorNamespace), + withLabels(map[string]string{croOperatorLabelKey: "false"}), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: nil, + }, + { + name: "CMA operator pod with master toleration: control-plane node selector is added", + pod: makePod( + withNamespace(cmaOperatorNamespace), + withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/master", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + }), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: map[string]string{controlPlaneRoleKey: ""}, + }, + { + name: "CMA operator pod with broad tolerate-all toleration: control-plane node selector is added", + pod: makePod( + withNamespace(cmaOperatorNamespace), + withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withTolerations([]coreapi.Toleration{ + {Operator: coreapi.TolerationOpExists}, + }), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: map[string]string{controlPlaneRoleKey: ""}, + }, + { + name: "CMA operator pod without master toleration: not modified", + pod: makePod( + withNamespace(cmaOperatorNamespace), + withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: nil, + }, + { + name: "CMA operator pod with wrong toleration key: not modified", + pod: makePod( + withNamespace(cmaOperatorNamespace), + withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/control-plane", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + }), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: nil, + }, + { + name: "CMA operator pod with existing node selector: not modified", + pod: makePod( + withNamespace(cmaOperatorNamespace), + withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withNodeSelector(map[string]string{"kubernetes.io/os": "linux"}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/master", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + }), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: map[string]string{"kubernetes.io/os": "linux"}, + }, + { + name: "CMA operator pod in wrong namespace: not modified", + pod: makePod( + withNamespace("other-namespace"), + withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/master", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + }), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: nil, + }, + { + name: "CMA operator label with wrong value: not modified", + pod: makePod( + withNamespace(cmaOperatorNamespace), + withLabels(map[string]string{cmaOperatorLabelKey: "wrong-operator"}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/master", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + }), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: nil, + }, { name: "non-qualifying pod: not modified", pod: makePod( @@ -148,13 +290,102 @@ func TestRequiresNodeSelectorAdjustment(t *testing.T) { expected bool }{ { - name: "VPA operator label in correct namespace: match", + name: "VPA operator with default node selector: match", + pod: makePod(withNamespace(vpaOperatorNamespace), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), withNodeSelector(map[string]string{"kubernetes.io/os": "linux"})), + expected: true, + }, + { + name: "VPA operator with no node selector: no match", pod: makePod(withNamespace(vpaOperatorNamespace), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue})), + expected: false, + }, + { + name: "VPA operator with non-default node selector: no match", + pod: makePod(withNamespace(vpaOperatorNamespace), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), withNodeSelector(map[string]string{"topology.kubernetes.io/zone": "us-east-1a"})), + expected: false, + }, + { + name: "VPA operator with extra node selectors: no match", + pod: makePod(withNamespace(vpaOperatorNamespace), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), withNodeSelector(map[string]string{"kubernetes.io/os": "linux", "extra": "value"})), + expected: false, + }, + { + name: "VPA operator in wrong namespace: no match", + pod: makePod(withNamespace("other-namespace"), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), withNodeSelector(map[string]string{"kubernetes.io/os": "linux"})), + expected: false, + }, + { + name: "CRO operator with no node selector: match", + pod: makePod(withNamespace(croOperatorNamespace), withLabels(map[string]string{croOperatorLabelKey: croOperatorLabelValue})), + expected: true, + }, + { + name: "CRO operator with existing node selector: no match", + pod: makePod(withNamespace(croOperatorNamespace), withLabels(map[string]string{croOperatorLabelKey: croOperatorLabelValue}), withNodeSelector(map[string]string{"kubernetes.io/os": "linux"})), + expected: false, + }, + { + name: "CRO operator in wrong namespace: no match", + pod: makePod(withNamespace("other-namespace"), withLabels(map[string]string{croOperatorLabelKey: croOperatorLabelValue})), + expected: false, + }, + { + name: "CRO operator label with wrong value: no match", + pod: makePod(withNamespace(croOperatorNamespace), withLabels(map[string]string{croOperatorLabelKey: "false"})), + expected: false, + }, + { + name: "CMA operator with master toleration: match", + pod: makePod(withNamespace(cmaOperatorNamespace), withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/master", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + })), + expected: true, + }, + { + name: "CMA operator with broad tolerate-all toleration: match", + pod: makePod(withNamespace(cmaOperatorNamespace), withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withTolerations([]coreapi.Toleration{ + {Operator: coreapi.TolerationOpExists}, + })), expected: true, }, { - name: "VPA operator label in wrong namespace: no match", - pod: makePod(withNamespace("other-namespace"), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue})), + name: "CMA operator without master toleration: no match", + pod: makePod(withNamespace(cmaOperatorNamespace), withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue})), + expected: false, + }, + { + name: "CMA operator with wrong toleration key: no match", + pod: makePod(withNamespace(cmaOperatorNamespace), withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/control-plane", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + })), + expected: false, + }, + { + name: "CMA operator with existing node selector: no match", + pod: makePod(withNamespace(cmaOperatorNamespace), withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withNodeSelector(map[string]string{"kubernetes.io/os": "linux"}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/master", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + })), + expected: false, + }, + { + name: "CMA operator in wrong namespace: no match", + pod: makePod(withNamespace("other-namespace"), withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/master", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + })), + expected: false, + }, + { + name: "CMA operator label with wrong value: no match", + pod: makePod(withNamespace(cmaOperatorNamespace), withLabels(map[string]string{cmaOperatorLabelKey: "wrong-operator"}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/master", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + })), expected: false, }, { @@ -244,6 +475,12 @@ func withLabels(labels map[string]string) func(*coreapi.Pod) { } } +func withTolerations(tolerations []coreapi.Toleration) func(*coreapi.Pod) { + return func(p *coreapi.Pod) { + p.Spec.Tolerations = tolerations + } +} + func withNodeSelector(selector map[string]string) func(*coreapi.Pod) { return func(p *coreapi.Pod) { p.Spec.NodeSelector = selector diff --git a/deps/github.com/openshift/kubernetes/pkg/apis/flowcontrol/validation/validation.go b/deps/github.com/openshift/kubernetes/pkg/apis/flowcontrol/validation/validation.go index 510b5e4a17..d801f0e138 100644 --- a/deps/github.com/openshift/kubernetes/pkg/apis/flowcontrol/validation/validation.go +++ b/deps/github.com/openshift/kubernetes/pkg/apis/flowcontrol/validation/validation.go @@ -416,7 +416,11 @@ func ValidatePriorityLevelConfigurationSpec(spec *flowcontrol.PriorityLevelConfi allErrs = append(allErrs, ValidateLimitedPriorityLevelConfiguration(spec.Limited, requestGV, fldPath.Child("limited"), opts)...) } default: - allErrs = append(allErrs, field.NotSupported(fldPath.Child("type"), spec.Type, supportedPriorityLevelEnablement.List())) + if len(spec.Type) == 0 { + allErrs = append(allErrs, field.Required(fldPath.Child("type"), "").MarkCoveredByDeclarative()) + } else { + allErrs = append(allErrs, field.NotSupported(fldPath.Child("type"), spec.Type, supportedPriorityLevelEnablement.List())) + } } return allErrs } @@ -475,7 +479,11 @@ func ValidateLimitResponse(lr flowcontrol.LimitResponse, fldPath *field.Path) fi allErrs = append(allErrs, ValidatePriorityLevelQueuingConfiguration(lr.Queuing, fldPath.Child("queuing"))...) } default: - allErrs = append(allErrs, field.NotSupported(fldPath.Child("type"), lr.Type, supportedLimitResponseType.List())) + if len(lr.Type) == 0 { + allErrs = append(allErrs, field.Required(fldPath.Child("type"), "").MarkCoveredByDeclarative()) + } else { + allErrs = append(allErrs, field.NotSupported(fldPath.Child("type"), lr.Type, supportedLimitResponseType.List())) + } } return allErrs } diff --git a/deps/github.com/openshift/kubernetes/pkg/apis/flowcontrol/validation/validation_test.go b/deps/github.com/openshift/kubernetes/pkg/apis/flowcontrol/validation/validation_test.go index 01a21ec01c..9c3b2d305e 100644 --- a/deps/github.com/openshift/kubernetes/pkg/apis/flowcontrol/validation/validation_test.go +++ b/deps/github.com/openshift/kubernetes/pkg/apis/flowcontrol/validation/validation_test.go @@ -1127,6 +1127,38 @@ func TestPriorityLevelConfigurationValidation(t *testing.T) { expectedErrors: field.ErrorList{ field.Forbidden(field.NewPath("metadata").Child("annotations"), fmt.Sprintf("annotation '%s' is forbidden", flowcontrolv1beta3.PriorityLevelPreserveZeroConcurrencySharesKey)), }, + }, { + name: "spec.type empty should fail with required", + priorityLevelConfiguration: &flowcontrol.PriorityLevelConfiguration{ + ObjectMeta: metav1.ObjectMeta{ + Name: "test-empty-type", + }, + Spec: flowcontrol.PriorityLevelConfigurationSpec{ + Type: "", + }, + }, + expectedErrors: field.ErrorList{ + field.Required(field.NewPath("spec").Child("type"), "").MarkCoveredByDeclarative(), + }, + }, { + name: "spec.limited.limitResponse.type empty should fail with required", + priorityLevelConfiguration: &flowcontrol.PriorityLevelConfiguration{ + ObjectMeta: metav1.ObjectMeta{ + Name: "test-empty-lr-type", + }, + Spec: flowcontrol.PriorityLevelConfigurationSpec{ + Type: flowcontrol.PriorityLevelEnablementLimited, + Limited: &flowcontrol.LimitedPriorityLevelConfiguration{ + NominalConcurrencyShares: 42, + LimitResponse: flowcontrol.LimitResponse{ + Type: "", + }, + }, + }, + }, + expectedErrors: field.ErrorList{ + field.Required(field.NewPath("spec").Child("limited").Child("limitResponse").Child("type"), "").MarkCoveredByDeclarative(), + }, }} for _, testCase := range testCases { t.Run(testCase.name, func(t *testing.T) { diff --git a/deps/github.com/openshift/kubernetes/pkg/controller/job/job_controller.go b/deps/github.com/openshift/kubernetes/pkg/controller/job/job_controller.go index ccf9b222c7..b7884a0800 100644 --- a/deps/github.com/openshift/kubernetes/pkg/controller/job/job_controller.go +++ b/deps/github.com/openshift/kubernetes/pkg/controller/job/job_controller.go @@ -1855,7 +1855,12 @@ func (jm *Controller) manageJob(ctx context.Context, job *batch.Job, jobCtx *syn } if remainingTime > 0 { jm.enqueueSyncJobWithDelay(logger, job, remainingTime) - return 0, metrics.JobSyncActionPodsCreated, nil + // No pods were created or deleted, so return the current active + // count rather than 0. Returning 0 here would cause the status + // update to set Active=0 while Ready still reflects the running + // pods, which the API server rejects ("cannot set more ready pods + // than active"), blocking finalizer removal and status flushing. + return active, metrics.JobSyncActionPodsCreated, nil } if diff > int32(MaxPodCreateDeletePerSync) { diff = int32(MaxPodCreateDeletePerSync) @@ -1868,7 +1873,9 @@ func (jm *Controller) manageJob(ctx context.Context, job *batch.Job, jobCtx *syn indexesToAdd, remainingTime = jm.getPodCreationInfoForIndependentIndexes(logger, indexesToAdd, jobCtx.podsWithDelayedDeletionPerIndex) if remainingTime > 0 { jm.enqueueSyncJobWithDelay(logger, job, remainingTime) - return 0, metrics.JobSyncActionPodsCreated, nil + // No pods were created or deleted, so return the current + // active count rather than 0 (see comment above). + return active, metrics.JobSyncActionPodsCreated, nil } } diff = int32(len(indexesToAdd)) diff --git a/deps/github.com/openshift/kubernetes/pkg/controller/job/job_controller_test.go b/deps/github.com/openshift/kubernetes/pkg/controller/job/job_controller_test.go index 5c8797ea17..1c9597e9a2 100644 --- a/deps/github.com/openshift/kubernetes/pkg/controller/job/job_controller_test.go +++ b/deps/github.com/openshift/kubernetes/pkg/controller/job/job_controller_test.go @@ -453,6 +453,36 @@ func TestControllerSyncJob(t *testing.T) { expectedReady: ptr.To[int32](0), controllerTime: &referenceTime, }, + // Regression test for https://github.com/kubernetes/kubernetes/issues/139428. + // When replacement pods are needed but pod creation is deferred due to an + // active backoff, manageJob must report the actual active count rather than + // 0. Reporting 0 while Ready still reflects the running pods makes the status + // update fail apiserver validation ("cannot set more ready pods than active"), + // blocking finalizer removal and status flushing. + "too few active pods and active back-off with running pods": { + parallelism: 2, + completions: 2, + backoffLimit: 6, + backoffRecord: &backoffRecord{ + failuresAfterLastSuccess: 1, + lastFailureTime: &referenceTime, + }, + initialStatus: &jobInitialStatus{ + startTime: func() *time.Time { + now := time.Now() + return &now + }(), + }, + activePods: 1, + readyPods: 1, + succeededPods: 0, + expectedCreations: 0, + expectedActive: 1, + expectedSucceeded: 0, + expectedPodPatches: 0, + expectedReady: ptr.To[int32](1), + controllerTime: &referenceTime, + }, "too few active pods and no back-offs": { parallelism: 1, completions: 1, @@ -5377,6 +5407,52 @@ func TestSyncJobWithJobBackoffLimitPerIndex(t *testing.T) { FailedIndexes: ptr.To(""), }, }, + // Regression test for https://github.com/kubernetes/kubernetes/issues/139428. + // One index has a running pod while another index's replacement pod + // creation is deferred because its per-index backoff is still active. + // manageJob must report the actual active count (1) rather than 0; a + // status with active=0 while pods are still running is rejected by the + // apiserver ("cannot set more ready pods than active"), blocking + // finalizer removal and status flushing. + "replacement pod creation delayed by per-index backoff while another index runs": { + enableJobBackoffLimitPerIndex: true, + enableJobPodReplacementPolicy: true, + job: batch.Job{ + TypeMeta: metav1.TypeMeta{Kind: "Job"}, + ObjectMeta: validObjectMeta, + Spec: batch.JobSpec{ + Selector: validSelector, + Template: validTemplate, + Parallelism: ptr.To[int32](2), + Completions: ptr.To[int32](2), + BackoffLimit: ptr.To[int32](math.MaxInt32), + CompletionMode: ptr.To(batch.IndexedCompletion), + BackoffLimitPerIndex: ptr.To[int32](1), + }, + }, + pods: []v1.Pod{ + *buildPod().uid("a").index("0").phase(v1.PodRunning).indexFailureCount("0").trackingFinalizer().Pod, + *buildPod().uid("b").index("1").status(v1.PodStatus{ + Phase: v1.PodFailed, + ContainerStatuses: []v1.ContainerStatus{ + { + Name: "x", + State: v1.ContainerState{ + Terminated: &v1.ContainerStateTerminated{ + FinishedAt: metav1.NewTime(now), + }, + }, + }, + }, + }).indexFailureCount("0").trackingFinalizer().Pod, + }, + wantStatus: batch.JobStatus{ + Active: 1, + Terminating: ptr.To[int32](0), + UncountedTerminatedPods: &batch.UncountedTerminatedPods{}, + FailedIndexes: new(string), + }, + }, "single failed index due to exceeding the backoff limit per index, the job continues": { enableJobBackoffLimitPerIndex: true, enableJobPodReplacementPolicy: true, diff --git a/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go b/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go new file mode 100644 index 0000000000..d0c66ab8de --- /dev/null +++ b/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go @@ -0,0 +1,18 @@ +package cache + +type ConflictCounter interface { + GetConflictCount() int +} + +var _ ConflictCounter = &volumeCache{} + +func (c *volumeCache) GetConflictCount() int { + c.mutex.RLock() + defer c.mutex.RUnlock() + + conflictCount := 0 + for _, conflicts := range c.conflicts { + conflictCount += len(conflicts) + } + return conflictCount +} diff --git a/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go b/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go new file mode 100644 index 0000000000..39eeb9853c --- /dev/null +++ b/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go @@ -0,0 +1,102 @@ +package selinuxwarning + +import ( + "context" + "fmt" + "time" + + metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" + utilfeature "k8s.io/apiserver/pkg/util/feature" + applyconfigurationscorev1 "k8s.io/client-go/applyconfigurations/core/v1" + clientset "k8s.io/client-go/kubernetes" + "k8s.io/klog/v2" + "k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/cache" + "k8s.io/kubernetes/pkg/features" +) + +const ( + checkInterval = 30 * time.Second + configMapNamespace = "openshift-config" + configMapName = "selinux-conflicts" + fieldManager = "selinux-conflicts-reporter" +) + +type SELinuxConflictsReporterController struct { + kubeClient clientset.Interface + conflictCounter cache.ConflictCounter + previousConflicts metav1.ConditionStatus +} + +func NewSELinuxConflictsReporterController(kubeClient clientset.Interface, volumeCache cache.VolumeCache) *SELinuxConflictsReporterController { + return &SELinuxConflictsReporterController{ + kubeClient: kubeClient, + // Ugly retype to avoid more carry patches in Kubernetes code. + // We added ConflictCounter in cache/openshift_patch.go, + // therefore we know that VolumeCache implements it. + conflictCounter: volumeCache.(cache.ConflictCounter), + previousConflicts: metav1.ConditionUnknown, + } +} + +func (c *SELinuxConflictsReporterController) Run(ctx context.Context) { + logger := klog.FromContext(ctx) + if !utilfeature.DefaultFeatureGate.Enabled(features.SELinuxMountGAReadiness) { + logger.V(2).Info("SELinuxMountGAReadiness feature gate is disabled, not starting OpenShift SELinux conflicts reporter") + return + } + logger.V(2).Info("Starting OpenShift SELinux conflicts reporter") + timer := time.NewTimer(checkInterval) + defer timer.Stop() + for { + select { + case <-ctx.Done(): + return + case <-timer.C: + c.reportSELinuxConflicts(ctx) + timer.Reset(checkInterval) + } + } +} + +func (c *SELinuxConflictsReporterController) reportSELinuxConflicts(ctx context.Context) { + logger := klog.FromContext(ctx) + logger.V(4).Info("Checking for SELinux conflicts") + + currentConflicts := c.getConflicts(logger) + if currentConflicts == c.previousConflicts { + logger.V(4).Info("SELinux conflict status did not change since last check") + return + } + logger.V(4).Info("SELinux conflict status changed, updating the config map") + if err := c.applySELinuxConflictsConfigMap(ctx, currentConflicts); err != nil { + logger.Error(err, "Error saving conflicts config map") + // To keep it simple: no exponential backoff try again in the next iteration. + return + } + logger.V(2).Info("SELinux conflict updated", "Conflicts", currentConflicts) + c.previousConflicts = currentConflicts +} + +func (c *SELinuxConflictsReporterController) getConflicts(logger klog.Logger) metav1.ConditionStatus { + conflictsCount := c.conflictCounter.GetConflictCount() + if conflictsCount > 0 { + logger.V(4).Info("Found SELinux-conflicting pods", "conflictsCount", conflictsCount) + return metav1.ConditionTrue + } + logger.V(4).Info("Found no SELinux-conflicting pods") + return metav1.ConditionFalse +} + +func (c *SELinuxConflictsReporterController) applySELinuxConflictsConfigMap(ctx context.Context, conflictsPresent metav1.ConditionStatus) error { + cm := applyconfigurationscorev1.ConfigMap(configMapName, configMapNamespace). + WithData(map[string]string{ + "conflictsPresent": string(conflictsPresent), + }).WithAnnotations(map[string]string{ + "Description": "This config map is used to report presence of SELinux conflicts from kube-controller-manager to storage Upgradeable condition in OpenShift 5.0", + }) + _, err := c.kubeClient.CoreV1().ConfigMaps(configMapNamespace).Apply(ctx, cm, metav1.ApplyOptions{FieldManager: fieldManager, Force: true}) + if err != nil { + return fmt.Errorf("error applying config map %s: %w", configMapName, err) + } + return nil +} diff --git a/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller_test.go b/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller_test.go new file mode 100644 index 0000000000..c0a78104ac --- /dev/null +++ b/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller_test.go @@ -0,0 +1,336 @@ +package selinuxwarning + +import ( + "context" + "testing" + + v1 "k8s.io/api/core/v1" + apierrors "k8s.io/apimachinery/pkg/api/errors" + metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" + "k8s.io/client-go/kubernetes/fake" + "k8s.io/client-go/tools/cache" + "k8s.io/klog/v2/ktesting" + volumecache "k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/cache" +) + +var _ volumecache.ConflictCounter = &fakeVolumeCache{} + +func (f *fakeVolumeCache) GetConflictCount() int { + count := 0 + for _, conflicts := range f.conflictsToSend { + count += len(conflicts) + } + return count +} + +func TestReportSELinuxConflicts(t *testing.T) { + cmTrue := &v1.ConfigMap{ + ObjectMeta: metav1.ObjectMeta{ + Name: configMapName, + Namespace: configMapNamespace, + }, + Data: map[string]string{ + "conflictsPresent": "True", + }, + } + cmFalse := &v1.ConfigMap{ + ObjectMeta: metav1.ObjectMeta{ + Name: configMapName, + Namespace: configMapNamespace, + }, + Data: map[string]string{ + "conflictsPresent": "False", + }, + } + tests := []struct { + name string + conflicts map[cache.ObjectName][]volumecache.Conflict + initialConflict metav1.ConditionStatus + // If set, the ConfigMap already exists before the test runs. + existingConfigMap *v1.ConfigMap + + expectConfigMapData map[string]string + // If true, no ConfigMap write is expected (status didn't change). + expectNoWrite bool + }{ + { + name: "no conflicts, create the config map", + initialConflict: metav1.ConditionUnknown, + conflicts: nil, + expectConfigMapData: map[string]string{ + "conflictsPresent": "False", + }, + }, + { + name: "conflicts present, create the config map", + initialConflict: metav1.ConditionUnknown, + conflicts: map[cache.ObjectName][]volumecache.Conflict{ + {Namespace: "ns1", Name: "pod1"}: { + { + PropertyName: "SELinuxLabel", + EventReason: "SELinuxLabelConflict", + Pod: cache.ObjectName{Namespace: "ns1", Name: "pod1"}, + PropertyValue: ":::s0:c1,c2", + OtherPod: cache.ObjectName{Namespace: "ns1", Name: "pod2"}, + OtherPropertyValue: ":::s0:c98,c99", + }, + }, + }, + expectConfigMapData: map[string]string{ + "conflictsPresent": "True", + }, + }, + { + name: "no conflicts, status was already False", + conflicts: nil, + initialConflict: metav1.ConditionFalse, + existingConfigMap: cmFalse, + expectNoWrite: true, + }, + { + name: "conflicts present, status was already True", + conflicts: map[cache.ObjectName][]volumecache.Conflict{ + {Namespace: "ns1", Name: "pod1"}: { + { + PropertyName: "SELinuxLabel", + EventReason: "SELinuxLabelConflict", + }, + }, + }, + initialConflict: metav1.ConditionTrue, + existingConfigMap: cmTrue, + expectNoWrite: true, + }, + { + name: "no conflicts, status changes from True to False", + conflicts: nil, + initialConflict: metav1.ConditionTrue, + existingConfigMap: cmTrue, + expectConfigMapData: map[string]string{ + "conflictsPresent": "False", + }, + }, + { + name: "conflicts appear, status changes from False to True", + conflicts: map[cache.ObjectName][]volumecache.Conflict{ + {Namespace: "ns1", Name: "pod1"}: { + { + PropertyName: "SELinuxLabel", + EventReason: "SELinuxLabelConflict", + }, + }, + }, + initialConflict: metav1.ConditionFalse, + existingConfigMap: cmFalse, + expectConfigMapData: map[string]string{ + "conflictsPresent": "True", + }, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + _, ctx := ktesting.NewTestContext(t) + + var fakeClient *fake.Clientset + if tt.existingConfigMap != nil { + fakeClient = fake.NewClientset(tt.existingConfigMap) + } else { + fakeClient = fake.NewClientset() + } + + labelCache := &fakeVolumeCache{ + conflictsToSend: tt.conflicts, + } + + c := &SELinuxConflictsReporterController{ + kubeClient: fakeClient, + conflictCounter: labelCache, + previousConflicts: tt.initialConflict, + } + + c.reportSELinuxConflicts(ctx) + + if tt.expectNoWrite { + cm, err := fakeClient.CoreV1().ConfigMaps(configMapNamespace).Get(ctx, configMapName, metav1.GetOptions{}) + if tt.existingConfigMap != nil { + // The ConfigMap should still exist unchanged. + if err != nil { + t.Fatalf("expected ConfigMap to exist, got error: %v", err) + } + if cm.Data["conflictsPresent"] != tt.existingConfigMap.Data["conflictsPresent"] { + t.Errorf("ConfigMap data changed unexpectedly: got %v, want %v", cm.Data, tt.existingConfigMap.Data) + } + } else { + if err == nil || !apierrors.IsNotFound(err) { + t.Fatalf("expected ConfigMap to not exist, got error: %v", err) + } + } + return + } + + cm, err := fakeClient.CoreV1().ConfigMaps(configMapNamespace).Get(ctx, configMapName, metav1.GetOptions{}) + if err != nil { + t.Fatalf("failed to get ConfigMap: %v", err) + } + for key, expectedValue := range tt.expectConfigMapData { + if cm.Data[key] != expectedValue { + t.Errorf("ConfigMap data[%q] = %q, want %q", key, cm.Data[key], expectedValue) + } + } + }) + } +} + +func TestApplySELinuxConflictsConfigMap(t *testing.T) { + cmTrue := &v1.ConfigMap{ + ObjectMeta: metav1.ObjectMeta{ + Name: configMapName, + Namespace: configMapNamespace, + }, + Data: map[string]string{ + "conflictsPresent": "True", + }, + } + cmFalse := &v1.ConfigMap{ + ObjectMeta: metav1.ObjectMeta{ + Name: configMapName, + Namespace: configMapNamespace, + }, + Data: map[string]string{ + "conflictsPresent": "False", + }, + } + tests := []struct { + name string + existingConfigMap *v1.ConfigMap + conflictsPresent metav1.ConditionStatus + expectData map[string]string + }{ + { + name: "creates ConfigMap when it does not exist", + conflictsPresent: metav1.ConditionTrue, + expectData: map[string]string{ + "conflictsPresent": "True", + }, + }, + { + name: "patches ConfigMap when it already exists", + existingConfigMap: cmFalse, + conflictsPresent: metav1.ConditionTrue, + expectData: map[string]string{ + "conflictsPresent": string(metav1.ConditionTrue), + }, + }, + { + name: "patches ConfigMap from True to False", + existingConfigMap: cmTrue, + conflictsPresent: metav1.ConditionFalse, + expectData: map[string]string{ + "conflictsPresent": "False", + }, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + ctx := context.Background() + + var fakeClient *fake.Clientset + if tt.existingConfigMap != nil { + fakeClient = fake.NewClientset(tt.existingConfigMap) + } else { + fakeClient = fake.NewClientset() + } + + c := &SELinuxConflictsReporterController{ + kubeClient: fakeClient, + // the rest of the struct is not used in this test + } + + err := c.applySELinuxConflictsConfigMap(ctx, tt.conflictsPresent) + if err != nil { + t.Fatalf("unexpected error: %v", err) + } + + cm, err := fakeClient.CoreV1().ConfigMaps(configMapNamespace).Get(ctx, configMapName, metav1.GetOptions{}) + if err != nil { + t.Fatalf("failed to get ConfigMap: %v", err) + } + for key, expectedValue := range tt.expectData { + if cm.Data[key] != expectedValue { + t.Errorf("ConfigMap data[%q] = %q, want %q", key, cm.Data[key], expectedValue) + } + } + }) + } +} + +func TestGetConflicts(t *testing.T) { + tests := []struct { + name string + conflicts map[cache.ObjectName][]volumecache.Conflict + expected metav1.ConditionStatus + }{ + { + name: "no conflicts returns False", + conflicts: nil, + expected: metav1.ConditionFalse, + }, + { + name: "empty conflicts returns False", + conflicts: map[cache.ObjectName][]volumecache.Conflict{}, + expected: metav1.ConditionFalse, + }, + { + name: "one conflict returns True", + conflicts: map[cache.ObjectName][]volumecache.Conflict{ + {Namespace: "ns1", Name: "pod1"}: { + { + PropertyName: "SELinuxLabel", + EventReason: "SELinuxLabelConflict", + Pod: cache.ObjectName{Namespace: "ns1", Name: "pod1"}, + PropertyValue: ":::s0:c1,c2", + OtherPod: cache.ObjectName{Namespace: "ns1", Name: "pod2"}, + OtherPropertyValue: ":::s0:c98,c99", + }, + }, + }, + expected: metav1.ConditionTrue, + }, + { + name: "multiple conflicts returns True", + conflicts: map[cache.ObjectName][]volumecache.Conflict{ + {Namespace: "ns1", Name: "pod1"}: { + {PropertyName: "SELinuxLabel"}, + }, + {Namespace: "ns1", Name: "pod2"}: { + {PropertyName: "SELinuxLabel"}, + {PropertyName: "SELinuxChangePolicy"}, + }, + }, + expected: metav1.ConditionTrue, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + _, ctx := ktesting.NewTestContext(t) + logger := ktesting.NewLogger(t, ktesting.NewConfig()) + _ = ctx + + labelCache := &fakeVolumeCache{ + conflictsToSend: tt.conflicts, + } + + c := &SELinuxConflictsReporterController{ + conflictCounter: labelCache, + } + + got := c.getConflicts(logger) + if got != tt.expected { + t.Errorf("getConflicts() = %v, want %v", got, tt.expected) + } + }) + } +} diff --git a/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go b/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go index 53c08d1f6a..488a19161d 100644 --- a/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go +++ b/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go @@ -380,6 +380,13 @@ func (c *Controller) Run(ctx context.Context, workers int) { wait.UntilWithContext(ctx, c.runWorker, time.Second) }) } + + seLinuxConflictsReporterController := NewSELinuxConflictsReporterController(c.kubeClient, c.labelCache) + wg.Go(func() { + defer utilruntime.HandleCrash() + seLinuxConflictsReporterController.Run(ctx) + }) + <-ctx.Done() } diff --git a/deps/github.com/openshift/kubernetes/pkg/features/openshift_features.go b/deps/github.com/openshift/kubernetes/pkg/features/openshift_features.go index 434781ba97..b09d7fe484 100644 --- a/deps/github.com/openshift/kubernetes/pkg/features/openshift_features.go +++ b/deps/github.com/openshift/kubernetes/pkg/features/openshift_features.go @@ -9,6 +9,7 @@ var ( RouteExternalCertificate featuregate.Feature = "RouteExternalCertificate" MinimumKubeletVersion featuregate.Feature = "MinimumKubeletVersion" StoragePerformantSecurityPolicy featuregate.Feature = "StoragePerformantSecurityPolicy" + SELinuxMountGAReadiness featuregate.Feature = "SELinuxMountGAReadiness" ) // registerOpenshiftFeatures injects openshift-specific feature gates @@ -25,8 +26,13 @@ func registerOpenshiftFeatures() { defaultVersionedKubernetesFeatureGates[StoragePerformantSecurityPolicy] = featuregate.VersionedSpecs{ {Version: version.MustParse("1.33"), Default: false, PreRelease: featuregate.Alpha}, } + // Introduced in 5.0 + defaultVersionedKubernetesFeatureGates[SELinuxMountGAReadiness] = featuregate.VersionedSpecs{ + {Version: version.MustParse("1.35"), Default: false, PreRelease: featuregate.Alpha}, + } defaultKubernetesFeatureGateDependencies[RouteExternalCertificate] = []featuregate.Feature{} defaultKubernetesFeatureGateDependencies[MinimumKubeletVersion] = []featuregate.Feature{} defaultKubernetesFeatureGateDependencies[StoragePerformantSecurityPolicy] = []featuregate.Feature{} + defaultKubernetesFeatureGateDependencies[SELinuxMountGAReadiness] = []featuregate.Feature{} } diff --git a/deps/github.com/openshift/kubernetes/pkg/kubelet/allocation/allocation_manager.go b/deps/github.com/openshift/kubernetes/pkg/kubelet/allocation/allocation_manager.go index 9e8a61470c..6960ec70e2 100644 --- a/deps/github.com/openshift/kubernetes/pkg/kubelet/allocation/allocation_manager.go +++ b/deps/github.com/openshift/kubernetes/pkg/kubelet/allocation/allocation_manager.go @@ -110,6 +110,9 @@ type Manager interface { // RetryPendingResizes retries all pending resizes. RetryPendingResizes(trigger string) + + // HasPodAllocatedResources returns whether a pod has been allocated resources. + HasPodAllocatedResources(podUID types.UID) bool } type manager struct { @@ -483,6 +486,12 @@ func updatePodFromAllocation(pod *v1.Pod, allocated state.PodResourceInfo) (*v1. return pod, updated } +// HasPodAllocatedResources returns whether a pod has been allocated resources. +func (m *manager) HasPodAllocatedResources(podUID types.UID) bool { + _, allocated := m.allocated.GetPodResourceInfo(podUID) + return allocated +} + // SetAllocatedResources checkpoints the resources allocated to a pod's containers func (m *manager) SetAllocatedResources(pod *v1.Pod) error { // Use klog.TODO() because we currently do not have a proper logger to pass in. @@ -629,9 +638,14 @@ func (m *manager) getAllocatedPods(activePods []*v1.Pod) []*v1.Pod { return activePods } - allocatedPods := make([]*v1.Pod, len(activePods)) - for i, pod := range activePods { - allocatedPods[i], _ = m.UpdatePodFromAllocation(pod) + allocatedPods := make([]*v1.Pod, 0, len(activePods)) + for _, pod := range activePods { + // Filter out pods that don't yet have an allocation, which will filter pods that + // are potentially going to be denied at admission. + if m.HasPodAllocatedResources(pod.UID) { + allocatedPod, _ := m.UpdatePodFromAllocation(pod) + allocatedPods = append(allocatedPods, allocatedPod) + } } return allocatedPods } diff --git a/deps/github.com/openshift/kubernetes/pkg/kubelet/allocation/allocation_manager_test.go b/deps/github.com/openshift/kubernetes/pkg/kubelet/allocation/allocation_manager_test.go index c271527e65..a4cfa0ffcd 100644 --- a/deps/github.com/openshift/kubernetes/pkg/kubelet/allocation/allocation_manager_test.go +++ b/deps/github.com/openshift/kubernetes/pkg/kubelet/allocation/allocation_manager_test.go @@ -781,12 +781,19 @@ func TestRetryPendingResizes(t *testing.T) { } allocationManager := makeAllocationManager(t, &containertest.FakeRuntime{PodStatus: *podStatus}, []*v1.Pod{testPod1, testPod2, testPod3}, nil) + for _, p := range []*v1.Pod{testPod1, testPod2, testPod3} { + require.NoError(t, allocationManager.SetAllocatedResources(p)) + } if !tt.newResourcesAllocated { require.NoError(t, allocationManager.SetAllocatedResources(originalPod)) } else { require.NoError(t, allocationManager.SetAllocatedResources(newPod)) } - t.Cleanup(func() { allocationManager.RemovePod(originalPod.UID) }) + t.Cleanup(func() { + for _, p := range []*v1.Pod{testPod1, testPod2, testPod3} { + allocationManager.RemovePod(p.UID) + } + }) if tt.originalInProgress { allocationManager.(*manager).statusManager.SetPodResizeInProgressCondition(originalPod.UID, "", originalInProgressMsg, 0) @@ -2480,3 +2487,176 @@ func setContainerStatus(podStatus *kubecontainer.PodStatus, c *v1.Container, idx }, } } + +// TestNonAllocatedPodsExcludedFromCapacity_Resize verifies that a pending pod +// without an allocation does not block resize of an already-running pod. +func TestNonAllocatedPodsExcludedFromCapacity_Resize(t *testing.T) { + allocationManager, runningPod, pendingPod := setupNonAllocatedCapacityTest(t) + + cpu1500m := resource.MustParse("1500m") + mem1000M := resource.MustParse("1Gi") + + resizedPod := runningPod.DeepCopy() + resizedPod.Spec.Containers[0].Resources.Requests = v1.ResourceList{v1.ResourceCPU: cpu1500m, v1.ResourceMemory: mem1000M} + + allocationManager.(*manager).getPodByUID = func(uid types.UID) (*v1.Pod, bool) { + if uid == runningPod.UID { + return resizedPod, true + } + if uid == pendingPod.UID { + return pendingPod, true + } + return nil, false + } + + allocationManager.PushPendingResize(runningPod.UID) + allocationManager.RetryPendingResizes(TriggerReasonPodUpdated) + + // If pendingPod was incorrectly included in capacity calculations, this + // resize would be deferred (1500m + 10000m > 4000m allocatable). + resizeStatus := allocationManager.(*manager).statusManager.GetPodResizeConditions(runningPod.UID) + require.Len(t, resizeStatus, 1) + assert.Equal(t, v1.PodResizeInProgress, resizeStatus[0].Type) + assert.Equal(t, v1.ConditionTrue, resizeStatus[0].Status) + + alloc, found := allocationManager.GetContainerResourceAllocation(runningPod.UID, "c1") + require.True(t, found) + assert.Equal(t, cpu1500m, *alloc.Requests.Cpu()) + + _, foundPending := allocationManager.GetContainerResourceAllocation(pendingPod.UID, "c1") + assert.False(t, foundPending) +} + +// TestNonAllocatedPodsExcludedFromCapacity_AddPod verifies that a pending pod +// without an allocation does not block admission of a new pod. +func TestNonAllocatedPodsExcludedFromCapacity_AddPod(t *testing.T) { + allocationManager, runningPod, pendingPod := setupNonAllocatedCapacityTest(t) + + cpu500m := resource.MustParse("500m") + mem1000M := resource.MustParse("1Gi") + + newPod := &v1.Pod{ + ObjectMeta: metav1.ObjectMeta{ + UID: "new-pod", + Name: "new-pod", + Namespace: "default", + }, + Spec: v1.PodSpec{ + Containers: []v1.Container{ + { + Name: "c1", + Image: "test-image", + Resources: v1.ResourceRequirements{ + Requests: v1.ResourceList{v1.ResourceCPU: cpu500m, v1.ResourceMemory: mem1000M}, + }, + }, + }, + }, + Status: v1.PodStatus{ + Phase: v1.PodPending, + }, + } + + // If pendingPod was incorrectly included in capacity calculations, + // AddPod would fail (500m + 1000m + 10000m > 4000m allocatable). + ok, reason, message := allocationManager.AddPod([]*v1.Pod{runningPod, pendingPod}, newPod) + assert.True(t, ok, "AddPod should succeed: reason=%s message=%s", reason, message) + + newAlloc, found := allocationManager.GetContainerResourceAllocation(newPod.UID, "c1") + require.True(t, found) + assert.Equal(t, cpu500m, *newAlloc.Requests.Cpu()) + + _, foundPending := allocationManager.GetContainerResourceAllocation(pendingPod.UID, "c1") + assert.False(t, foundPending) +} + +// setupNonAllocatedCapacityTest creates a common test environment with: +// - A running pod allocated 1000m CPU and 1Gi memory +// - A pending pod requesting resources way beyond node capacity (not allocated) +// - An allocation manager with 4 CPU and 4Gi memory allocatable +// +// This setup is used to verify that the non-allocated pending pod is excluded +// from capacity calculations and doesn't block legitimate operations. +func setupNonAllocatedCapacityTest(t *testing.T) (Manager, *v1.Pod, *v1.Pod) { + t.Helper() + if goruntime.GOOS == "windows" { + t.Skip("InPlacePodVerticalScaling is not currently supported for Windows") + } + featuregatetesting.SetFeatureGateDuringTest(t, utilfeature.DefaultFeatureGate, features.InPlacePodVerticalScaling, true) + featuregatetesting.SetFeatureGateDuringTest(t, utilfeature.DefaultFeatureGate, features.NodeDeclaredFeatures, true) + + cpu1000m := resource.MustParse("1") + cpu10000m := resource.MustParse("10") + mem1000M := resource.MustParse("1Gi") + mem10000M := resource.MustParse("10Gi") + + runningPod := &v1.Pod{ + ObjectMeta: metav1.ObjectMeta{ + UID: "running-pod", + Name: "running-pod", + Namespace: "default", + }, + Spec: v1.PodSpec{ + Containers: []v1.Container{ + { + Name: "c1", + Image: "test-image", + Resources: v1.ResourceRequirements{ + Requests: v1.ResourceList{v1.ResourceCPU: cpu1000m, v1.ResourceMemory: mem1000M}, + }, + }, + }, + }, + Status: v1.PodStatus{ + Phase: v1.PodRunning, + ContainerStatuses: []v1.ContainerStatus{ + { + Name: "c1", + AllocatedResources: v1.ResourceList{v1.ResourceCPU: cpu1000m, v1.ResourceMemory: mem1000M}, + Resources: &v1.ResourceRequirements{}, + }, + }, + }, + } + + pendingPod := &v1.Pod{ + ObjectMeta: metav1.ObjectMeta{ + UID: "pending-pod", + Name: "pending-pod", + Namespace: "default", + }, + Spec: v1.PodSpec{ + Containers: []v1.Container{ + { + Name: "c1", + Image: "test-image", + Resources: v1.ResourceRequirements{ + Requests: v1.ResourceList{v1.ResourceCPU: cpu10000m, v1.ResourceMemory: mem10000M}, + }, + }, + }, + }, + Status: v1.PodStatus{ + Phase: v1.PodPending, + }, + } + + podStatus := &kubecontainer.PodStatus{ + ID: runningPod.UID, + Name: runningPod.Name, + Namespace: runningPod.Namespace, + } + podStatus.ContainerStatuses = make([]*kubecontainer.Status, len(runningPod.Spec.Containers)) + for i, c := range runningPod.Spec.Containers { + setContainerStatus(podStatus, &c, i) + } + + allocationManager := makeAllocationManager(t, &containertest.FakeRuntime{PodStatus: *podStatus}, []*v1.Pod{runningPod, pendingPod}, nil) + require.NoError(t, allocationManager.SetAllocatedResources(runningPod)) + t.Cleanup(func() { + allocationManager.RemovePod(runningPod.UID) + allocationManager.RemovePod(pendingPod.UID) + }) + + return allocationManager, runningPod, pendingPod +} diff --git a/deps/github.com/openshift/kubernetes/pkg/kubelet/kubelet.go b/deps/github.com/openshift/kubernetes/pkg/kubelet/kubelet.go index f912a7b54b..2c773dc750 100644 --- a/deps/github.com/openshift/kubernetes/pkg/kubelet/kubelet.go +++ b/deps/github.com/openshift/kubernetes/pkg/kubelet/kubelet.go @@ -2931,6 +2931,15 @@ func (kl *Kubelet) HandlePodUpdates(ctx context.Context, pods []*v1.Pod) { oldPod, _ := kl.podManager.GetPodByUID(pod.UID) kl.podManager.UpdatePod(pod) + if utilfeature.DefaultFeatureGate.Enabled(features.InPlacePodVerticalScaling) { + // Skip pods that haven't been allocated yet to avoid counting them against + // node capacity before they've been admitted. + if !kl.allocationManager.HasPodAllocatedResources(pod.UID) { + logger.V(4).Info("Skipping pod update for non-allocated pod", "pod", klog.KObj(pod), "podUID", pod.UID) + continue + } + } + pod, mirrorPod, wasMirror := kl.podManager.GetPodAndMirrorPod(pod) if wasMirror { if pod == nil { @@ -3133,6 +3142,8 @@ func (kl *Kubelet) HandlePodReconcile(ctx context.Context, pods []*v1.Pod) { if utilfeature.DefaultFeatureGate.Enabled(features.InPlacePodVerticalScaling) { if hasPendingResizes && !retryPendingResizes && oldPod != nil { // If the pod has reached a terminal phase, we retry all pending resizes. + // A terminated pod releases capacity even if its allocation has already + // been purged, so check this before the non-allocated skip below. if podutil.IsPodTerminal(pod) && !podutil.IsPodTerminal(oldPod) { retryPendingResizes = true triggerReason = allocation.TriggerReasonPodTerminated @@ -3160,6 +3171,13 @@ func (kl *Kubelet) HandlePodReconcile(ctx context.Context, pods []*v1.Pod) { triggerReason = allocation.TriggerReasonPodResized } } + + // Skip further reconciliation for pods that haven't been allocated yet. + // We still updated podManager above to keep status in sync with the API server. + if !kl.allocationManager.HasPodAllocatedResources(pod.UID) { + logger.V(4).Info("Skipping pod reconcile operations for non-allocated pod", "pod", klog.KObj(pod), "podUID", pod.UID) + continue + } } // TODO: reconcile being calculated in the config manager is questionable, and avoiding diff --git a/deps/github.com/openshift/kubernetes/pkg/kubelet/kubelet_test.go b/deps/github.com/openshift/kubernetes/pkg/kubelet/kubelet_test.go index 45cec1d48a..6983f7792f 100644 --- a/deps/github.com/openshift/kubernetes/pkg/kubelet/kubelet_test.go +++ b/deps/github.com/openshift/kubernetes/pkg/kubelet/kubelet_test.go @@ -1879,6 +1879,10 @@ func TestSyncPodsSetStatusToFailedForPodsThatRunTooLong(t *testing.T) { }}, } + // Set up allocation for the pod before HandlePodUpdates + err := kubelet.allocationManager.SetAllocatedResources(pods[0]) + require.NoError(t, err) + // Let the pod worker sets the status to fail after this sync. kubelet.HandlePodUpdates(tCtx, pods) status, found := kubelet.statusManager.GetPodStatus(pods[0].UID) @@ -1931,6 +1935,11 @@ func TestSyncPodsDoesNotSetPodsThatDidNotRunTooLongToFailed(t *testing.T) { } kubelet.podManager.SetPods(pods) + + // Set up allocation for the pod before HandlePodUpdates + err := kubelet.allocationManager.SetAllocatedResources(pods[0]) + require.NoError(t, err) + kubelet.HandlePodUpdates(tCtx, pods) status, found := kubelet.statusManager.GetPodStatus(pods[0].UID) assert.True(t, found, "expected to found status for pod %q", pods[0].UID) @@ -4848,34 +4857,49 @@ func TestHandlePodReconcile_RetryPendingResizes(t *testing.T) { }, } + terminalPodNoAllocation := makePodWithResources("terminal-pod-no-alloc", v1.ResourceList{v1.ResourceCPU: lowCPU, v1.ResourceMemory: lowMem}, v1.ResourceList{v1.ResourceCPU: lowCPU, v1.ResourceMemory: lowMem}) + terminalPodNoAllocation.Status.Phase = v1.PodFailed + testCases := []struct { name string oldPod *v1.Pod newPod *v1.Pod + setAllocation bool shouldRetryPendingResize bool }{ { name: "requests are increasing", oldPod: makePodWithResources("updated-pod", v1.ResourceList{v1.ResourceCPU: highCPU, v1.ResourceMemory: highMem}, v1.ResourceList{v1.ResourceCPU: lowCPU, v1.ResourceMemory: lowMem}), newPod: makePodWithResources("updated-pod", v1.ResourceList{v1.ResourceCPU: enormousCPU, v1.ResourceMemory: enormousMem}, v1.ResourceList{v1.ResourceCPU: highCPU, v1.ResourceMemory: highMem}), + setAllocation: true, shouldRetryPendingResize: false, }, { name: "requests are unchanged", oldPod: makePodWithResources("updated-pod", v1.ResourceList{v1.ResourceCPU: lowCPU, v1.ResourceMemory: lowMem}, v1.ResourceList{v1.ResourceCPU: lowCPU, v1.ResourceMemory: lowMem}), newPod: makePodWithResources("updated-pod", v1.ResourceList{v1.ResourceCPU: enormousCPU, v1.ResourceMemory: enormousMem}, v1.ResourceList{v1.ResourceCPU: lowCPU, v1.ResourceMemory: lowMem}), + setAllocation: true, shouldRetryPendingResize: false, }, { name: "requests are decreasing", oldPod: makePodWithResources("updated-pod", v1.ResourceList{v1.ResourceCPU: lowCPU, v1.ResourceMemory: lowMem}, v1.ResourceList{v1.ResourceCPU: highCPU, v1.ResourceMemory: highMem}), newPod: makePodWithResources("updated-pod", v1.ResourceList{v1.ResourceCPU: enormousCPU, v1.ResourceMemory: enormousMem}, v1.ResourceList{v1.ResourceCPU: lowCPU, v1.ResourceMemory: lowMem}), + setAllocation: true, shouldRetryPendingResize: true, }, { name: "pod is marked as terminal", oldPod: makePodWithResources("terminal-pod", v1.ResourceList{v1.ResourceCPU: lowCPU, v1.ResourceMemory: lowMem}, v1.ResourceList{v1.ResourceCPU: lowCPU, v1.ResourceMemory: lowMem}), newPod: terminalPod, + setAllocation: true, + shouldRetryPendingResize: true, + }, + { + name: "pod is marked as terminal with allocation already purged", + oldPod: makePodWithResources("terminal-pod-no-alloc", v1.ResourceList{v1.ResourceCPU: lowCPU, v1.ResourceMemory: lowMem}, v1.ResourceList{v1.ResourceCPU: lowCPU, v1.ResourceMemory: lowMem}), + newPod: terminalPodNoAllocation, + setAllocation: false, shouldRetryPendingResize: true, }, } @@ -4887,7 +4911,9 @@ func TestHandlePodReconcile_RetryPendingResizes(t *testing.T) { kubelet.allocationManager.AddPodAdmitHandlers(lifecycle.PodAdmitHandlers{handler}) require.NoError(t, kubelet.allocationManager.SetAllocatedResources(pendingResizeAllocated)) - require.NoError(t, kubelet.allocationManager.SetAllocatedResources(tc.oldPod)) + if tc.setAllocation { + require.NoError(t, kubelet.allocationManager.SetAllocatedResources(tc.oldPod)) + } // We only expect status resources to change in HandlePodReconcile. tc.oldPod.Spec = tc.newPod.Spec @@ -4900,6 +4926,11 @@ func TestHandlePodReconcile_RetryPendingResizes(t *testing.T) { kubelet.HandlePodReconcile(tCtx, []*v1.Pod{tc.newPod}) require.Equal(t, tc.shouldRetryPendingResize, kubelet.statusManager.IsPodResizeDeferred(pendingResizeDesired.UID)) + if !tc.setAllocation { + require.False(t, kubelet.allocationManager.HasPodAllocatedResources(tc.newPod.UID), + "non-allocated pod should not have allocation set after reconcile") + } + kubelet.allocationManager.RemovePod(pendingResizeDesired.UID) kubelet.podManager.RemovePod((pendingResizeDesired)) kubelet.podManager.RemovePod(tc.oldPod) @@ -5051,6 +5082,7 @@ func TestSyncPodNodeDeclaredFeaturesUpdate(t *testing.T) { } kubelet.statusManager.SetPodStatus(logger, tc.newPod, v1.PodStatus{Phase: v1.PodRunning}) + require.NoError(t, kubelet.allocationManager.SetAllocatedResources(tc.newPod)) kubelet.HandlePodUpdates(tCtx, []*v1.Pod{tc.newPod}) if tc.expectEvent { select { diff --git a/deps/github.com/openshift/kubernetes/pkg/kubelet/kuberuntime/labels.go b/deps/github.com/openshift/kubernetes/pkg/kubelet/kuberuntime/labels.go index cef97ec051..0a9f783131 100644 --- a/deps/github.com/openshift/kubernetes/pkg/kubelet/kuberuntime/labels.go +++ b/deps/github.com/openshift/kubernetes/pkg/kubelet/kuberuntime/labels.go @@ -201,22 +201,22 @@ func getContainerInfoFromAnnotations(ctx context.Context, annotations map[string if containerInfo.RestartCount, err = getIntValueFromLabel(logger, annotations, containerRestartCountLabel); err != nil { logger.Error(err, "Unable to get label value from annotations", "label", containerRestartCountLabel, "annotations", annotations) } - if containerInfo.PodDeletionGracePeriod, err = getInt64PointerFromLabel(logger, annotations, podDeletionGracePeriodLabel); err != nil { + if containerInfo.PodDeletionGracePeriod, err = getInt64PointerFromLabel(annotations, podDeletionGracePeriodLabel); err != nil { logger.Error(err, "Unable to get label value from annotations", "label", podDeletionGracePeriodLabel, "annotations", annotations) } - if containerInfo.PodTerminationGracePeriod, err = getInt64PointerFromLabel(logger, annotations, podTerminationGracePeriodLabel); err != nil { + if containerInfo.PodTerminationGracePeriod, err = getInt64PointerFromLabel(annotations, podTerminationGracePeriodLabel); err != nil { logger.Error(err, "Unable to get label value from annotations", "label", podTerminationGracePeriodLabel, "annotations", annotations) } preStopHandler := &v1.LifecycleHandler{} - if found, err := getJSONObjectFromLabel(logger, annotations, containerPreStopHandlerLabel, preStopHandler); err != nil { + if found, err := getJSONObjectFromLabel(annotations, containerPreStopHandlerLabel, preStopHandler); err != nil { logger.Error(err, "Unable to get label value from annotations", "label", containerPreStopHandlerLabel, "annotations", annotations) } else if found { containerInfo.PreStopHandler = preStopHandler } containerPorts := []v1.ContainerPort{} - if found, err := getJSONObjectFromLabel(logger, annotations, containerPortsLabel, &containerPorts); err != nil { + if found, err := getJSONObjectFromLabel(annotations, containerPortsLabel, &containerPorts); err != nil { logger.Error(err, "Unable to get label value from annotations", "label", containerPortsLabel, "annotations", annotations) } else if found { containerInfo.ContainerPorts = containerPorts @@ -266,7 +266,7 @@ func getUint64ValueFromLabel(ctx context.Context, labels map[string]string, labe return 0, nil } -func getInt64PointerFromLabel(logger klog.Logger, labels map[string]string, label string) (*int64, error) { +func getInt64PointerFromLabel(labels map[string]string, label string) (*int64, error) { if strValue, found := labels[label]; found { int64Value, err := strconv.ParseInt(strValue, 10, 64) if err != nil { @@ -275,17 +275,15 @@ func getInt64PointerFromLabel(logger klog.Logger, labels map[string]string, labe return &int64Value, nil } // If the label is not found, return pointer nil. - logger.V(4).Info("Label not found", "label", label) return nil, nil } // getJSONObjectFromLabel returns a bool value indicating whether an object is found. -func getJSONObjectFromLabel(logger klog.Logger, labels map[string]string, label string, value interface{}) (bool, error) { +func getJSONObjectFromLabel(labels map[string]string, label string, value interface{}) (bool, error) { if strValue, found := labels[label]; found { err := json.Unmarshal([]byte(strValue), value) return found, err } // If the label is not found, return not found. - logger.V(4).Info("Label not found", "label", label) return false, nil } diff --git a/deps/github.com/openshift/kubernetes/pkg/kubelet/pod_workers.go b/deps/github.com/openshift/kubernetes/pkg/kubelet/pod_workers.go index 0f3034e262..a71f1fbcbd 100644 --- a/deps/github.com/openshift/kubernetes/pkg/kubelet/pod_workers.go +++ b/deps/github.com/openshift/kubernetes/pkg/kubelet/pod_workers.go @@ -336,6 +336,16 @@ const ( // podSyncStatus tracks per-pod transitions through the three phases of pod // worker sync (setup, terminating, terminated). type podSyncStatus struct { + // ctx is reused across normal pod syncs. + // A new ctx is created on the next startPodSync after explicit cancellation. + // + // TODO: remove this from the struct by having the context initialized + // in startPodSync, the cancelFn used by UpdatePod, and cancellation of + // a parent context for tearing down workers (if needed) on shutdown. + // Be careful not to leak contexts (see #139823). + // Be careful that long-lived goroutines (such as prober workers) outlive + // the lifetime of a single startPodSync cancellation context. + ctx context.Context // cancelFn if set is expected to cancel the current podSyncer operation. cancelFn context.CancelFunc @@ -1152,7 +1162,11 @@ func (p *podWorkers) startPodSync(parentCtx context.Context, podUID types.UID) ( default: } - ctx, status.cancelFn = context.WithCancel(parentCtx) + if status.ctx == nil || status.ctx.Err() != nil { + // create a context with parentCtx's values, and reuse it until it is canceled + status.ctx, status.cancelFn = context.WithCancel(context.WithoutCancel(parentCtx)) + } + ctx = status.ctx // if we are already started, make our state visible to downstream components if status.IsStarted() { diff --git a/deps/github.com/openshift/kubernetes/pkg/kubelet/pod_workers_test.go b/deps/github.com/openshift/kubernetes/pkg/kubelet/pod_workers_test.go index ac446fe133..7fad7fb43a 100644 --- a/deps/github.com/openshift/kubernetes/pkg/kubelet/pod_workers_test.go +++ b/deps/github.com/openshift/kubernetes/pkg/kubelet/pod_workers_test.go @@ -602,6 +602,7 @@ func TestUpdatePod(t *testing.T) { } else { expected.cancelFn, status.cancelFn = nil, nil } + expected.ctx, status.ctx = nil, nil } if e, a := expected, status; !reflect.DeepEqual(e, a) { t.Fatalf("unexpected status: %s", cmp.Diff(e, a, cmp.AllowUnexported(podSyncStatus{}))) diff --git a/deps/github.com/openshift/kubernetes/pkg/registry/flowcontrol/prioritylevelconfiguration/declarative_validation_test.go b/deps/github.com/openshift/kubernetes/pkg/registry/flowcontrol/prioritylevelconfiguration/declarative_validation_test.go index 4a36e69981..f592972c95 100644 --- a/deps/github.com/openshift/kubernetes/pkg/registry/flowcontrol/prioritylevelconfiguration/declarative_validation_test.go +++ b/deps/github.com/openshift/kubernetes/pkg/registry/flowcontrol/prioritylevelconfiguration/declarative_validation_test.go @@ -103,6 +103,18 @@ func testDeclarativeValidate(t *testing.T, apiVersion string) { field.Forbidden(specPath.Child("limited", "limitResponse", "queuing"), "").MarkCoveredByDeclarative().MarkAlpha(), }, }, + "spec.type: empty": { + input: mkPLC(tweakSpecType(""), tweakLimited(nil)), + expectedErrs: field.ErrorList{ + field.Required(specPath.Child("type"), "").MarkCoveredByDeclarative().MarkAlpha(), + }, + }, + "limitResponse.type: empty": { + input: mkPLC(tweakLimitResponseType("")), + expectedErrs: field.ErrorList{ + field.Required(specPath.Child("limited", "limitResponse", "type"), "").MarkCoveredByDeclarative().MarkAlpha(), + }, + }, } for name, tc := range testCases { @@ -226,6 +238,13 @@ func tweakLimited(limited *flowcontrol.LimitedPriorityLevelConfiguration) func(* } } +// tweakSpecType sets the Spec.Type field directly. +func tweakSpecType(t flowcontrol.PriorityLevelEnablement) func(*flowcontrol.PriorityLevelConfiguration) { + return func(obj *flowcontrol.PriorityLevelConfiguration) { + obj.Spec.Type = t + } +} + // tweakExemptConfig sets the Exempt configuration field. func tweakExemptConfig(exempt *flowcontrol.ExemptPriorityLevelConfiguration) func(*flowcontrol.PriorityLevelConfiguration) { return func(obj *flowcontrol.PriorityLevelConfiguration) { diff --git a/deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go b/deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go index 994e716a28..ddcafd16ae 100644 --- a/deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go +++ b/deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go @@ -606,6 +606,10 @@ func buildControllerRoles() ([]rbacv1.ClusterRole, []rbacv1.ClusterRoleBinding) rbacv1helpers.NewRule("get", "list", "watch").Groups(legacyGroup).Resources("persistentvolumeclaims").RuleOrDie(), rbacv1helpers.NewRule("get", "list", "watch").Groups(legacyGroup).Resources("pods").RuleOrDie(), rbacv1helpers.NewRule("get", "list", "watch").Groups(storageGroup).Resources("csidrivers").RuleOrDie(), + // RBAC cannot restrict `create` by resourceName, so adding a generic rule to allow creation of any ConfigMap + rbacv1helpers.NewRule("create").Groups(legacyGroup).Resources("configmaps").RuleOrDie(), + // ... and allow patching only of the selinux-conflicts ConfigMap + rbacv1helpers.NewRule("patch").Groups(legacyGroup).Resources("configmaps").Names("selinux-conflicts").RuleOrDie(), }, }) } diff --git a/deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/testdata/controller-roles.yaml b/deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/testdata/controller-roles.yaml index 88459b2652..3e90cc424a 100644 --- a/deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/testdata/controller-roles.yaml +++ b/deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/testdata/controller-roles.yaml @@ -1465,6 +1465,20 @@ items: - get - list - watch + - apiGroups: + - "" + resources: + - configmaps + verbs: + - create + - apiGroups: + - "" + resourceNames: + - selinux-conflicts + resources: + - configmaps + verbs: + - patch - apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/api/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/api/go.mod index 95fe8fa6ee..1b27fabb64 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/api/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/api/go.mod @@ -31,7 +31,7 @@ require ( k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect sigs.k8s.io/yaml v1.6.0 // indirect ) diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/api/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/api/go.sum index 1f48074c65..b7f317dae7 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/api/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/api/go.sum @@ -98,7 +98,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiextensions-apiserver/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiextensions-apiserver/go.mod index 50ac35ea20..320766b601 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiextensions-apiserver/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiextensions-apiserver/go.mod @@ -38,7 +38,7 @@ require ( k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 sigs.k8s.io/randfill v1.0.0 - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 sigs.k8s.io/yaml v1.6.0 ) diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiextensions-apiserver/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiextensions-apiserver/go.sum index cf46ad8e8d..816181b954 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiextensions-apiserver/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiextensions-apiserver/go.sum @@ -405,7 +405,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh sigs.k8s.io/kube-storage-version-migrator v0.0.6-0.20230721195810-5c8923c5ff96/go.mod h1:EOBQyBowOUsd7U4CJnMHNE0ri+zCXyouGdLwC/jZU+I= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiextensions-apiserver/test/integration/apply_test.go b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiextensions-apiserver/test/integration/apply_test.go index a30703ae10..6149b7dba8 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiextensions-apiserver/test/integration/apply_test.go +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiextensions-apiserver/test/integration/apply_test.go @@ -19,12 +19,16 @@ package integration import ( "context" "fmt" + "strings" "testing" apiextensionsv1 "k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1" "k8s.io/apiextensions-apiserver/pkg/client/clientset/clientset" "k8s.io/apiextensions-apiserver/test/integration/fixtures" "k8s.io/apimachinery/pkg/api/errors" + metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" + "k8s.io/apimachinery/pkg/apis/meta/v1/unstructured" + "k8s.io/apimachinery/pkg/runtime/schema" "k8s.io/apimachinery/pkg/types" "k8s.io/client-go/dynamic" ) @@ -114,3 +118,145 @@ values: } } + +// TestApplyNullToObject ensures that when maps and slices are set to null using +// SSA, that the resulting field state is correct. +func TestApplyNullToObject(t *testing.T) { + tearDown, config, _, err := fixtures.StartDefaultServer(t) + if err != nil { + t.Fatal(err) + } + defer tearDown() + + apiExtensionClient, err := clientset.NewForConfig(config) + if err != nil { + t.Fatal(err) + } + dynamicClient, err := dynamic.NewForConfig(config) + if err != nil { + t.Fatal(err) + } + + testCases := []struct { + name string + nullable bool + required bool + subfieldRequired bool + + wantNull bool + wantErr string + }{ + // This behavior is fussy, so we test a wide range of combinations. + {name: "nullable and optional field with optional subfield", nullable: true, wantNull: true}, + {name: "nullable and required field with optional subfield", nullable: true, required: true, wantNull: true}, + {name: "nullable and optional field with required subfield", nullable: true, subfieldRequired: true, wantNull: true}, + {name: "nullable and required field with required subfield", nullable: true, subfieldRequired: true, required: true, wantNull: true}, + + // Applying null to a non-nullable field is rejected by validation. To clear + // a non-nullable field, it must be omitted from the apply request instead. + {name: "non-nullable and optional field with optional subfield", wantErr: "must be of type object"}, + {name: "non-nullable and required field with optional subfield", required: true, wantErr: "must be of type object"}, + {name: "non-nullable and optional field with required subfield", subfieldRequired: true, wantErr: "must be of type object"}, + {name: "non-nullable and required field with required subfield", subfieldRequired: true, required: true, wantErr: "must be of type object"}, + } + + group, version, kind, plural := "stable.example.com", "v1", "Widget", "widgets" + apiVersion := group + "/" + version + gvr := schema.GroupVersionResource{Group: group, Version: version, Resource: plural} + + // Way more efficient to test if we build a single CRD to handle all the test cases. + fieldName := func(i int) string { return fmt.Sprintf("field%d", i) } + specProps := map[string]apiextensionsv1.JSONSchemaProps{} + for i, tc := range testCases { + wrapper := apiextensionsv1.JSONSchemaProps{ + Type: "object", + Properties: map[string]apiextensionsv1.JSONSchemaProps{"inner": mkObjectSchema(tc.nullable, tc.subfieldRequired)}, + } + if tc.required { + wrapper.Required = []string{"inner"} + } + specProps[fieldName(i)] = wrapper + } + + crd := &apiextensionsv1.CustomResourceDefinition{ + ObjectMeta: metav1.ObjectMeta{Name: plural + "." + group}, + Spec: apiextensionsv1.CustomResourceDefinitionSpec{ + Group: group, + Versions: []apiextensionsv1.CustomResourceDefinitionVersion{{ + Name: version, + Served: true, + Storage: true, + Schema: &apiextensionsv1.CustomResourceValidation{ + OpenAPIV3Schema: &apiextensionsv1.JSONSchemaProps{ + Type: "object", + Properties: map[string]apiextensionsv1.JSONSchemaProps{"spec": {Type: "object", Properties: specProps}}, + }, + }, + }}, + Names: apiextensionsv1.CustomResourceDefinitionNames{ + Plural: plural, + Kind: kind, + ListKind: kind + "List", + }, + Scope: apiextensionsv1.ClusterScoped, + }, + } + if _, err := fixtures.CreateNewV1CustomResourceDefinition(crd, apiExtensionClient, dynamicClient); err != nil { + t.Fatal(err) + } + + apply := func(object, field string, inner interface{}) (*unstructured.Unstructured, error) { + obj := &unstructured.Unstructured{Object: map[string]interface{}{ + "apiVersion": apiVersion, + "kind": kind, + "metadata": map[string]interface{}{"name": object}, + "spec": map[string]interface{}{field: map[string]interface{}{"inner": inner}}, + }} + return dynamicClient.Resource(gvr).Apply(context.TODO(), object, obj, metav1.ApplyOptions{FieldManager: "apply_test"}) + } + + for i, tc := range testCases { + t.Run(tc.name, func(t *testing.T) { + object, field := fieldName(i), fieldName(i) + if _, err := apply(object, field, map[string]interface{}{"a": "1", "b": "2"}); err != nil { + t.Fatalf("populating apply failed: %v", err) + } + got, err := apply(object, field, nil) + if tc.wantErr != "" { + if err == nil { + t.Fatalf("want apply to be rejected with %q, but it succeeded", tc.wantErr) + } + if !strings.Contains(err.Error(), tc.wantErr) { + t.Fatalf("want apply error to contain %q, got: %v", tc.wantErr, err) + } + return + } + if err != nil { + t.Fatalf("clearing apply was rejected: %v", err) + } + + inner, _, err := unstructured.NestedFieldNoCopy(got.Object, "spec", field, "inner") + if err != nil { + t.Fatalf("reading spec.%s.inner: %v", field, err) + } + if tc.wantNull && inner != nil { + t.Errorf("want inner to be null, got %#v", inner) + } + }) + } +} + +func mkObjectSchema(nullable, subfieldRequired bool) apiextensionsv1.JSONSchemaProps { + s := apiextensionsv1.JSONSchemaProps{ + Type: "object", + Nullable: nullable, + Properties: map[string]apiextensionsv1.JSONSchemaProps{ + "a": {Type: "string"}, + "b": {Type: "string"}, + }, + } + if subfieldRequired { + s.Required = []string{"a", "b"} + } + return s +} diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apimachinery/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apimachinery/go.mod index 73b5adc748..5b4177c6e3 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apimachinery/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apimachinery/go.mod @@ -25,7 +25,7 @@ require ( k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 sigs.k8s.io/randfill v1.0.0 - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 sigs.k8s.io/yaml v1.6.0 ) diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apimachinery/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apimachinery/go.sum index c24b6dfc98..6975d925a7 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apimachinery/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apimachinery/go.sum @@ -137,7 +137,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiserver/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiserver/go.mod index e7c442b7af..c64a9a9677 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiserver/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiserver/go.mod @@ -62,7 +62,7 @@ require ( sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.34.0 sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 sigs.k8s.io/randfill v1.0.0 - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 sigs.k8s.io/yaml v1.6.0 ) diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiserver/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiserver/go.sum index e9f3aaf0d7..2734adbbc3 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiserver/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiserver/go.sum @@ -401,7 +401,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh sigs.k8s.io/kube-storage-version-migrator v0.0.6-0.20230721195810-5c8923c5ff96/go.mod h1:EOBQyBowOUsd7U4CJnMHNE0ri+zCXyouGdLwC/jZU+I= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cli-runtime/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cli-runtime/go.mod index b282ad9dae..3254d7a325 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cli-runtime/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cli-runtime/go.mod @@ -74,7 +74,7 @@ require ( gopkg.in/yaml.v3 v3.0.1 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect ) replace ( diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cli-runtime/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cli-runtime/go.sum index ca83779f6b..7eb94cc41c 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cli-runtime/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cli-runtime/go.sum @@ -180,7 +180,7 @@ sigs.k8s.io/kustomize/kyaml v0.21.1 h1:IVlbmhC076nf6foyL6Taw4BkrLuEsXUXNpsE+ScX7 sigs.k8s.io/kustomize/kyaml v0.21.1/go.mod h1:hmxADesM3yUN2vbA5z1/YTBnzLJ1dajdqpQonwBL1FQ= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/client-go/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/client-go/go.mod index 1c4725a5d5..ba3b793f93 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/client-go/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/client-go/go.mod @@ -31,7 +31,7 @@ require ( k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 sigs.k8s.io/randfill v1.0.0 - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 sigs.k8s.io/yaml v1.6.0 ) diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/client-go/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/client-go/go.sum index 385a80bc47..0fbe68755a 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/client-go/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/client-go/go.sum @@ -152,7 +152,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cloud-provider/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cloud-provider/go.mod index 029a160534..9986b0e949 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cloud-provider/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cloud-provider/go.mod @@ -119,7 +119,7 @@ require ( sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.34.0 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect sigs.k8s.io/yaml v1.6.0 // indirect ) diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cloud-provider/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cloud-provider/go.sum index c30da95fac..f3ca0ecfbd 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cloud-provider/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cloud-provider/go.sum @@ -379,7 +379,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh sigs.k8s.io/kube-storage-version-migrator v0.0.6-0.20230721195810-5c8923c5ff96/go.mod h1:EOBQyBowOUsd7U4CJnMHNE0ri+zCXyouGdLwC/jZU+I= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cluster-bootstrap/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cluster-bootstrap/go.mod index e09f0bef23..bf9b9aecaa 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cluster-bootstrap/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cluster-bootstrap/go.mod @@ -34,7 +34,7 @@ require ( k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect ) replace ( diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cluster-bootstrap/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cluster-bootstrap/go.sum index 486ee5d07d..d9fcbb75e7 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cluster-bootstrap/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cluster-bootstrap/go.sum @@ -96,7 +96,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/code-generator/examples/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/code-generator/examples/go.mod index 46bfd054da..78d86eda16 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/code-generator/examples/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/code-generator/examples/go.mod @@ -11,7 +11,7 @@ require ( k8s.io/apimachinery v0.36.2 k8s.io/client-go v0.0.0 k8s.io/kube-openapi v0.0.0-20260519202549-bbf5c5577288 - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 ) require ( diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/code-generator/examples/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/code-generator/examples/go.sum index fe753e2734..01af4d2e60 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/code-generator/examples/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/code-generator/examples/go.sum @@ -131,7 +131,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/code-generator/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/code-generator/go.mod index 7ce4295c91..17cec6315c 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/code-generator/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/code-generator/go.mod @@ -53,7 +53,7 @@ require ( google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af // indirect gopkg.in/inf.v0 v0.9.1 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect ) replace ( diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/code-generator/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/code-generator/go.sum index 9cd7d1ffd2..572e5450ef 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/code-generator/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/code-generator/go.sum @@ -169,7 +169,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-base/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-base/go.mod index 315040bf79..e6e389d960 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-base/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-base/go.mod @@ -90,7 +90,7 @@ require ( k8s.io/api v0.0.0 // indirect k8s.io/kube-openapi v0.0.0-20260519202549-bbf5c5577288 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect sigs.k8s.io/yaml v1.6.0 // indirect ) diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-base/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-base/go.sum index b3e726a440..57c138f67f 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-base/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-base/go.sum @@ -243,7 +243,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-helpers/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-helpers/go.mod index bd27bab31f..ff6f76bc95 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-helpers/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-helpers/go.mod @@ -55,7 +55,7 @@ require ( k8s.io/kube-openapi v0.0.0-20260519202549-bbf5c5577288 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect sigs.k8s.io/yaml v1.6.0 // indirect ) diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-helpers/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-helpers/go.sum index 8b4b405db6..40b37add79 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-helpers/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-helpers/go.sum @@ -146,7 +146,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/controller-manager/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/controller-manager/go.mod index e3c7e97dda..6eee272918 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/controller-manager/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/controller-manager/go.mod @@ -110,7 +110,7 @@ require ( sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.34.0 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect sigs.k8s.io/yaml v1.6.0 // indirect ) diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/controller-manager/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/controller-manager/go.sum index 63e630dd6c..3ed9ec6ea2 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/controller-manager/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/controller-manager/go.sum @@ -337,7 +337,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-api/pkg/apis/runtime/v1/api_json.go b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-api/pkg/apis/runtime/v1/api_json.go new file mode 100644 index 0000000000..2e0b6dc2fd --- /dev/null +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-api/pkg/apis/runtime/v1/api_json.go @@ -0,0 +1,47 @@ +/* +Copyright The Kubernetes Authors. + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. +*/ + +package v1 + +import "encoding/json" + +// MarshalJSON() preserves pre-1.34 JSON encoding of value as a string (not base64), +// stomping non-utf-8 data with the utf8 replacement character. +func (k *KeyValue) MarshalJSON() ([]byte, error) { + return json.Marshal(stringKeyValue{ + Key: k.GetKey(), + Value: string(k.GetValue()), + }) +} + +// UnmarshalJSON preserves pre-1.34 JSON decoding of value as a string (not base64), +// stomping non-utf-8 data with the utf8 replacement character. +func (k *KeyValue) UnmarshalJSON(data []byte) error { + v := stringKeyValue{} + if err := json.Unmarshal(data, &v); err != nil { + return err + } + k.Key = v.Key + k.Value = []byte(v.Value) + return nil +} + +// stringKeyValue matches the structure used to json-encode pre-1.34. +// Non-UTF-8 characters in Value are coerced to the replacement character on encode/decode. +type stringKeyValue struct { + Key string `json:"key,omitempty"` + Value string `json:"value,omitempty"` +} diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-api/pkg/apis/runtime/v1/api_json_126_test.go b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-api/pkg/apis/runtime/v1/api_json_126_test.go new file mode 100644 index 0000000000..a0a7d908d6 --- /dev/null +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-api/pkg/apis/runtime/v1/api_json_126_test.go @@ -0,0 +1,22 @@ +//go:build !go1.27 + +/* +Copyright The Kubernetes Authors. + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. +*/ + +package v1 + +// 1.26 marshals a \u-escaped replacement char +const stdlibSerializedReplacementChar = "\\ufffd" diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-api/pkg/apis/runtime/v1/api_json_127_test.go b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-api/pkg/apis/runtime/v1/api_json_127_test.go new file mode 100644 index 0000000000..e9cf35cc97 --- /dev/null +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-api/pkg/apis/runtime/v1/api_json_127_test.go @@ -0,0 +1,22 @@ +//go:build go1.27 + +/* +Copyright The Kubernetes Authors. + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. +*/ + +package v1 + +// 1.27 marshals the replacement char without escaping +const stdlibSerializedReplacementChar = "\ufffd" diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-api/pkg/apis/runtime/v1/api_json_test.go b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-api/pkg/apis/runtime/v1/api_json_test.go new file mode 100644 index 0000000000..182f9d72f2 --- /dev/null +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-api/pkg/apis/runtime/v1/api_json_test.go @@ -0,0 +1,115 @@ +/* +Copyright The Kubernetes Authors. + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. +*/ + +package v1 + +import ( + "bytes" + "encoding/json" + "testing" +) + +func TestKeyValueCompat(t *testing.T) { + testcases := []struct { + name string + envs []*KeyValue + variantJSON string + expectedJSON string + expectedRoundTripped []*KeyValue + }{ + { + name: "null", + envs: nil, + expectedJSON: `null`, + expectedRoundTripped: nil, + }, + { + name: "zero-length list", + envs: []*KeyValue{}, + expectedJSON: `[]`, + expectedRoundTripped: []*KeyValue{}, + }, + { + name: "zero-value env", + envs: []*KeyValue{{}}, + expectedJSON: `[{}]`, + expectedRoundTripped: []*KeyValue{{}}, + }, + { + name: "ascii env", + envs: []*KeyValue{{Key: "key", Value: []byte("value")}}, + expectedJSON: `[{"key":"key","value":"value"}]`, + expectedRoundTripped: []*KeyValue{{Key: "key", Value: []byte("value")}}, + }, + { + name: "utf8 env", + envs: []*KeyValue{{Key: "key", Value: []byte("Iñtërnâtiônàlizætiøn🐹")}}, + expectedJSON: `[{"key":"key","value":"Iñtërnâtiônàlizætiøn🐹"}]`, + expectedRoundTripped: []*KeyValue{{Key: "key", Value: []byte("Iñtërnâtiônàlizætiøn🐹")}}, + }, + { + name: "non-utf8 env", + envs: []*KeyValue{{Key: "key", Value: []byte{'A', 0x80, 'Z'}}}, // invalid utf8 continuation byte (0x80) + variantJSON: `[{"key":"key","value":"A` + "\x80" + `Z"}]`, // an alternate JSON input containing the invalid utf8 byte that should coerce to the same result + expectedJSON: `[{"key":"key","value":"A` + stdlibSerializedReplacementChar + `Z"}]`, // coerced to utf8 replacement character (\ufffd) on marshal + expectedRoundTripped: []*KeyValue{{Key: "key", Value: []byte("A\ufffdZ")}}, // round-trips to replacement character (\ufffd) on unmarshal + }, + } + + for _, tc := range testcases { + t.Run(tc.name, func(t *testing.T) { + data, err := json.Marshal(tc.envs) + if err != nil { + t.Fatal(err) + } + + if string(data) != tc.expectedJSON { + t.Fatalf("json differed:\nwant: %s\ngot: %s", tc.expectedJSON, string(data)) + } + + verifyJSON(t, data, tc.expectedRoundTripped) + if len(tc.variantJSON) > 0 { + verifyJSON(t, []byte(tc.variantJSON), tc.expectedRoundTripped) + } + }) + } +} + +func verifyJSON(t *testing.T, data []byte, expectedRoundTripped []*KeyValue) { + t.Helper() + + var rt []*KeyValue + if err := json.Unmarshal(data, &rt); err != nil { + t.Fatal(err) + } + if (rt == nil) != (expectedRoundTripped == nil) { + t.Fatalf("expected value (%#v) does not match actual round-tripped value (%#v) for nil", expectedRoundTripped, rt) + } + if rt == nil { + return + } + if len(rt) != len(expectedRoundTripped) { + t.Fatalf("length of expected value (%#v) does not match length of actual round-tripped value (%#v)", expectedRoundTripped, rt) + } + for i := range expectedRoundTripped { + if want, got := expectedRoundTripped[i].Key, rt[i].Key; want != got { + t.Fatalf("item[%d].key does not match: %s vs %s", i, want, got) + } + if want, got := expectedRoundTripped[i].Value, rt[i].Value; !bytes.Equal(want, got) { + t.Fatalf("item[%d].value does not match: %v vs %v", i, want, got) + } + } +} diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-client/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-client/go.sum index d502c60d9a..bde8df958f 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-client/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-client/go.sum @@ -140,5 +140,5 @@ k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 h1:jVkFFVfXdXP74B/zbO3hM3hpSFD0x k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3/go.mod h1:M2s5JB1lIYP3jzZdorPLHXIPJzt9vv2muW5a6L9DtNM= sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/csi-translation-lib/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/csi-translation-lib/go.mod index c7ae250b6a..59b182ffb8 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/csi-translation-lib/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/csi-translation-lib/go.mod @@ -33,7 +33,7 @@ require ( k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect ) replace ( diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/csi-translation-lib/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/csi-translation-lib/go.sum index 1133a3346e..7730d1d002 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/csi-translation-lib/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/csi-translation-lib/go.sum @@ -94,7 +94,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/go.mod index c0adab5c75..7c11397d85 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/go.mod @@ -87,7 +87,7 @@ require ( k8s.io/component-base v0.36.2 // indirect k8s.io/kube-openapi v0.0.0-20260519202549-bbf5c5577288 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect sigs.k8s.io/yaml v1.6.0 // indirect ) diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/go.sum index fa57b5d0dc..aa1ea686ba 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/go.sum @@ -277,7 +277,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/resourceslice/tracker/tracker.go b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/resourceslice/tracker/tracker.go index 9941a38c3f..e86ac3ddca 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/resourceslice/tracker/tracker.go +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/resourceslice/tracker/tracker.go @@ -25,7 +25,7 @@ import ( v1 "k8s.io/api/core/v1" resourceapi "k8s.io/api/resource/v1" - resourcealphaapi "k8s.io/api/resource/v1alpha3" + resourcebetaapi "k8s.io/api/resource/v1beta2" labels "k8s.io/apimachinery/pkg/labels" "k8s.io/apimachinery/pkg/util/diff" utilruntime "k8s.io/apimachinery/pkg/util/runtime" @@ -395,15 +395,15 @@ func sliceDriverPoolDeviceIndexFunc(obj any) ([]string, error) { return indexValues, nil } -func driverPoolDeviceIndexPatchKey(patch *resourcealphaapi.DeviceTaintRule) string { - deviceSelector := ptr.Deref(patch.Spec.DeviceSelector, resourcealphaapi.DeviceTaintSelector{}) +func driverPoolDeviceIndexPatchKey(patch *resourcebetaapi.DeviceTaintRule) string { + deviceSelector := ptr.Deref(patch.Spec.DeviceSelector, resourcebetaapi.DeviceTaintSelector{}) driverKey := ptr.Deref(deviceSelector.Driver, anyDriver) poolKey := ptr.Deref(deviceSelector.Pool, anyPool) deviceKey := ptr.Deref(deviceSelector.Device, anyDevice) return deviceID(driverKey, poolKey, deviceKey) } -func (t *Tracker) sliceNamesForPatch(ctx context.Context, patch *resourcealphaapi.DeviceTaintRule) []string { +func (t *Tracker) sliceNamesForPatch(ctx context.Context, patch *resourcebetaapi.DeviceTaintRule) []string { patchKey := driverPoolDeviceIndexPatchKey(patch) sliceNames, err := t.resourceSlices.GetIndexer().IndexKeys(driverPoolDeviceIndexName, patchKey) if err != nil { @@ -469,7 +469,7 @@ func (t *Tracker) resourceSliceDelete(ctx context.Context) func(obj any) { func (t *Tracker) deviceTaintAdd(ctx context.Context) func(obj any) { logger := klog.FromContext(ctx) return func(obj any) { - rule, ok := obj.(*resourcealphaapi.DeviceTaintRule) + rule, ok := obj.(*resourcebetaapi.DeviceTaintRule) if !ok { return } @@ -487,11 +487,11 @@ func (t *Tracker) deviceTaintAdd(ctx context.Context) func(obj any) { func (t *Tracker) deviceTaintUpdate(ctx context.Context) func(oldObj, newObj any) { logger := klog.FromContext(ctx) return func(oldObj, newObj any) { - oldRule, ok := oldObj.(*resourcealphaapi.DeviceTaintRule) + oldRule, ok := oldObj.(*resourcebetaapi.DeviceTaintRule) if !ok { return } - newRule, ok := newObj.(*resourcealphaapi.DeviceTaintRule) + newRule, ok := newObj.(*resourcebetaapi.DeviceTaintRule) if !ok { return } @@ -519,7 +519,7 @@ func (t *Tracker) deviceTaintDelete(ctx context.Context) func(obj any) { if tombstone, ok := obj.(cache.DeletedFinalStateUnknown); ok { obj = tombstone.Obj } - patch, ok := obj.(*resourcealphaapi.DeviceTaintRule) + patch, ok := obj.(*resourcebetaapi.DeviceTaintRule) if !ok { return } @@ -631,7 +631,7 @@ func (t *Tracker) syncSlice(ctx context.Context, name string, sendEvent bool) { return } - patches := typedSlice[*resourcealphaapi.DeviceTaintRule](t.deviceTaints.GetIndexer().List()) + patches := typedSlice[*resourcebetaapi.DeviceTaintRule](t.deviceTaints.GetIndexer().List()) patchedSlice, err := t.applyPatches(ctx, slice, patches) if err != nil { t.handleError(ctx, err, "failed to apply patches to ResourceSlice", "resourceslice", klog.KObj(slice)) @@ -666,7 +666,7 @@ func (t *Tracker) syncSlice(ctx context.Context, name string, sendEvent bool) { } } -func (t *Tracker) applyPatches(ctx context.Context, slice *resourceapi.ResourceSlice, taintRules []*resourcealphaapi.DeviceTaintRule) (*resourceapi.ResourceSlice, error) { +func (t *Tracker) applyPatches(ctx context.Context, slice *resourceapi.ResourceSlice, taintRules []*resourcebetaapi.DeviceTaintRule) (*resourceapi.ResourceSlice, error) { logger := klog.FromContext(ctx) // slice will be DeepCopied just-in-time, only when necessary. diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/resourceslice/tracker/tracker_test.go b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/resourceslice/tracker/tracker_test.go index 8a5221eacb..572c7a251c 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/resourceslice/tracker/tracker_test.go +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/resourceslice/tracker/tracker_test.go @@ -30,7 +30,7 @@ import ( "github.com/stretchr/testify/require" v1 "k8s.io/api/core/v1" resourceapi "k8s.io/api/resource/v1" - resourcealphaapi "k8s.io/api/resource/v1alpha3" + resourcebetaapi "k8s.io/api/resource/v1beta2" metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" "k8s.io/client-go/informers" "k8s.io/client-go/kubernetes/fake" @@ -116,7 +116,7 @@ func applyEventPair(tCtx *testContext, event any) { require.NoError(tCtx, err) tCtx.resourceSliceAdd(tCtx.Context)(pair[1]) } - case [2]*resourcealphaapi.DeviceTaintRule: + case [2]*resourcebetaapi.DeviceTaintRule: store := tCtx.deviceTaints.GetStore() switch { case pair[0] != nil && pair[1] != nil: @@ -279,39 +279,39 @@ var ( slice2 = sliceWithDevices(slice2NoDevices, devices2) slice2Tainted = sliceWithDevices(slice2, taintedDevices2) - alphaDeviceTaint = func(taint resourceapi.DeviceTaint) resourcealphaapi.DeviceTaint { - return resourcealphaapi.DeviceTaint{ + alphaDeviceTaint = func(taint resourceapi.DeviceTaint) resourcebetaapi.DeviceTaint { + return resourcebetaapi.DeviceTaint{ Key: taint.Key, Value: taint.Value, - Effect: resourcealphaapi.DeviceTaintEffect(taint.Effect), + Effect: resourcebetaapi.DeviceTaintEffect(taint.Effect), TimeAdded: taint.TimeAdded, } } - taintAllDevicesRule = &resourcealphaapi.DeviceTaintRule{ + taintAllDevicesRule = &resourcebetaapi.DeviceTaintRule{ ObjectMeta: metav1.ObjectMeta{ Name: "rule", }, - Spec: resourcealphaapi.DeviceTaintRuleSpec{ + Spec: resourcebetaapi.DeviceTaintRuleSpec{ Taint: alphaDeviceTaint(deviceTaint1), }, } - taintPoolDevicesRule = func(rule *resourcealphaapi.DeviceTaintRule, pool string) *resourcealphaapi.DeviceTaintRule { + taintPoolDevicesRule = func(rule *resourcebetaapi.DeviceTaintRule, pool string) *resourcebetaapi.DeviceTaintRule { rule = rule.DeepCopy() - rule.Spec.DeviceSelector = &resourcealphaapi.DeviceTaintSelector{ + rule.Spec.DeviceSelector = &resourcebetaapi.DeviceTaintSelector{ Pool: &pool, } return rule } - taintDriverDevicesRule = func(rule *resourcealphaapi.DeviceTaintRule, driver string) *resourcealphaapi.DeviceTaintRule { + taintDriverDevicesRule = func(rule *resourcebetaapi.DeviceTaintRule, driver string) *resourcebetaapi.DeviceTaintRule { rule = rule.DeepCopy() - rule.Spec.DeviceSelector = &resourcealphaapi.DeviceTaintSelector{ + rule.Spec.DeviceSelector = &resourcebetaapi.DeviceTaintSelector{ Driver: &driver, } return rule } - taintNamedDevicesRule = func(rule *resourcealphaapi.DeviceTaintRule, name string) *resourcealphaapi.DeviceTaintRule { + taintNamedDevicesRule = func(rule *resourcebetaapi.DeviceTaintRule, name string) *resourcebetaapi.DeviceTaintRule { rule = rule.DeepCopy() - rule.Spec.DeviceSelector = &resourcealphaapi.DeviceTaintSelector{ + rule.Spec.DeviceSelector = &resourcebetaapi.DeviceTaintSelector{ Device: &name, } return rule @@ -720,8 +720,8 @@ func BenchmarkEventHandlers(b *testing.B) { now := time.Now() benchmarks := map[string]struct { resourceSlices []*resourceapi.ResourceSlice - taintRules []*resourcealphaapi.DeviceTaintRule - loop func(ctx context.Context, b *testing.B, tracker *Tracker, resourceSlices []*resourceapi.ResourceSlice, taintRules []*resourcealphaapi.DeviceTaintRule, i int) + taintRules []*resourcebetaapi.DeviceTaintRule + loop func(ctx context.Context, b *testing.B, tracker *Tracker, resourceSlices []*resourceapi.ResourceSlice, taintRules []*resourcebetaapi.DeviceTaintRule, i int) }{ "resource-slice-add-no-taint-rules": { resourceSlices: func() []*resourceapi.ResourceSlice { @@ -738,7 +738,7 @@ func BenchmarkEventHandlers(b *testing.B) { } return resourceSlices }(), - loop: func(ctx context.Context, b *testing.B, tracker *Tracker, resourceSlices []*resourceapi.ResourceSlice, _ []*resourcealphaapi.DeviceTaintRule, i int) { + loop: func(ctx context.Context, b *testing.B, tracker *Tracker, resourceSlices []*resourceapi.ResourceSlice, _ []*resourcebetaapi.DeviceTaintRule, i int) { tracker.resourceSliceAdd(ctx)(resourceSlices[i%len(resourceSlices)]) }, }, @@ -757,23 +757,23 @@ func BenchmarkEventHandlers(b *testing.B) { } return resourceSlices }(), - taintRules: []*resourcealphaapi.DeviceTaintRule{ + taintRules: []*resourcebetaapi.DeviceTaintRule{ { ObjectMeta: metav1.ObjectMeta{ Name: "taintRule", }, - Spec: resourcealphaapi.DeviceTaintRuleSpec{ + Spec: resourcebetaapi.DeviceTaintRuleSpec{ DeviceSelector: nil, // all slices - Taint: resourcealphaapi.DeviceTaint{ + Taint: resourcebetaapi.DeviceTaint{ Key: "example.com/taint", Value: "tainted", - Effect: resourcealphaapi.DeviceTaintEffectNoExecute, + Effect: resourcebetaapi.DeviceTaintEffectNoExecute, TimeAdded: &metav1.Time{Time: now}, }, }, }, }, - loop: func(ctx context.Context, b *testing.B, tracker *Tracker, resourceSlices []*resourceapi.ResourceSlice, taintRules []*resourcealphaapi.DeviceTaintRule, i int) { + loop: func(ctx context.Context, b *testing.B, tracker *Tracker, resourceSlices []*resourceapi.ResourceSlice, taintRules []*resourcebetaapi.DeviceTaintRule, i int) { tracker.deviceTaintAdd(ctx)(taintRules[i%len(taintRules)]) }, }, @@ -792,23 +792,23 @@ func BenchmarkEventHandlers(b *testing.B) { } return resourceSlices }(), - taintRules: []*resourcealphaapi.DeviceTaintRule{ + taintRules: []*resourcebetaapi.DeviceTaintRule{ { ObjectMeta: metav1.ObjectMeta{ Name: "taintRule", }, - Spec: resourcealphaapi.DeviceTaintRuleSpec{ + Spec: resourcebetaapi.DeviceTaintRuleSpec{ DeviceSelector: nil, // all slices - Taint: resourcealphaapi.DeviceTaint{ + Taint: resourcebetaapi.DeviceTaint{ Key: "example.com/taint", Value: "tainted", - Effect: resourcealphaapi.DeviceTaintEffectNoExecute, + Effect: resourcebetaapi.DeviceTaintEffectNoExecute, TimeAdded: &metav1.Time{Time: now}, }, }, }, }, - loop: func(ctx context.Context, b *testing.B, tracker *Tracker, resourceSlices []*resourceapi.ResourceSlice, _ []*resourcealphaapi.DeviceTaintRule, i int) { + loop: func(ctx context.Context, b *testing.B, tracker *Tracker, resourceSlices []*resourceapi.ResourceSlice, _ []*resourcebetaapi.DeviceTaintRule, i int) { tracker.resourceSliceAdd(ctx)(resourceSlices[i%len(resourceSlices)]) }, }, @@ -841,25 +841,25 @@ func BenchmarkEventHandlers(b *testing.B) { resourceSlices[nSlices/2].Spec.Devices[nDevices/2].Name = "patchme" return resourceSlices }(), - taintRules: []*resourcealphaapi.DeviceTaintRule{ + taintRules: []*resourcebetaapi.DeviceTaintRule{ { ObjectMeta: metav1.ObjectMeta{ Name: "taintRule", }, - Spec: resourcealphaapi.DeviceTaintRuleSpec{ - DeviceSelector: &resourcealphaapi.DeviceTaintSelector{ + Spec: resourcebetaapi.DeviceTaintRuleSpec{ + DeviceSelector: &resourcebetaapi.DeviceTaintSelector{ Device: ptr.To("patchme"), }, - Taint: resourcealphaapi.DeviceTaint{ + Taint: resourcebetaapi.DeviceTaint{ Key: "example.com/taint", Value: "tainted", - Effect: resourcealphaapi.DeviceTaintEffectNoExecute, + Effect: resourcebetaapi.DeviceTaintEffectNoExecute, TimeAdded: &metav1.Time{Time: now}, }, }, }, }, - loop: func(ctx context.Context, b *testing.B, tracker *Tracker, resourceSlices []*resourceapi.ResourceSlice, taintRules []*resourcealphaapi.DeviceTaintRule, i int) { + loop: func(ctx context.Context, b *testing.B, tracker *Tracker, resourceSlices []*resourceapi.ResourceSlice, taintRules []*resourcebetaapi.DeviceTaintRule, i int) { tracker.deviceTaintAdd(ctx)(taintRules[i%len(taintRules)]) }, }, @@ -886,26 +886,26 @@ func BenchmarkEventHandlers(b *testing.B) { } return resourceSlices }(), - taintRules: []*resourcealphaapi.DeviceTaintRule{ + taintRules: []*resourcebetaapi.DeviceTaintRule{ { ObjectMeta: metav1.ObjectMeta{ Name: "patch", }, - Spec: resourcealphaapi.DeviceTaintRuleSpec{ - DeviceSelector: &resourcealphaapi.DeviceTaintSelector{ + Spec: resourcebetaapi.DeviceTaintRuleSpec{ + DeviceSelector: &resourcebetaapi.DeviceTaintSelector{ Pool: ptr.To("pool-250"), Device: ptr.To("patchme"), }, - Taint: resourcealphaapi.DeviceTaint{ + Taint: resourcebetaapi.DeviceTaint{ Key: "example.com/taint", Value: "tainted", - Effect: resourcealphaapi.DeviceTaintEffectNoExecute, + Effect: resourcebetaapi.DeviceTaintEffectNoExecute, TimeAdded: &metav1.Time{Time: now}, }, }, }, }, - loop: func(ctx context.Context, b *testing.B, tracker *Tracker, resourceSlices []*resourceapi.ResourceSlice, patches []*resourcealphaapi.DeviceTaintRule, i int) { + loop: func(ctx context.Context, b *testing.B, tracker *Tracker, resourceSlices []*resourceapi.ResourceSlice, patches []*resourcebetaapi.DeviceTaintRule, i int) { tracker.resourceSliceAdd(ctx)(resourceSlices[250]) // the slice affected by the patch }, }, @@ -927,21 +927,21 @@ func BenchmarkEventHandlers(b *testing.B) { } return resourceSlices }(), - taintRules: func() []*resourcealphaapi.DeviceTaintRule { - patches := make([]*resourcealphaapi.DeviceTaintRule, 500) + taintRules: func() []*resourcebetaapi.DeviceTaintRule { + patches := make([]*resourcebetaapi.DeviceTaintRule, 500) for i := range patches { - patches[i] = &resourcealphaapi.DeviceTaintRule{ + patches[i] = &resourcebetaapi.DeviceTaintRule{ ObjectMeta: metav1.ObjectMeta{ Name: "taint-rule-" + strconv.Itoa(i), }, - Spec: resourcealphaapi.DeviceTaintRuleSpec{ - DeviceSelector: &resourcealphaapi.DeviceTaintSelector{ + Spec: resourcebetaapi.DeviceTaintRuleSpec{ + DeviceSelector: &resourcebetaapi.DeviceTaintSelector{ Pool: ptr.To("pool-" + strconv.Itoa(i)), }, - Taint: resourcealphaapi.DeviceTaint{ + Taint: resourcebetaapi.DeviceTaint{ Key: "example.com/taint", Value: "tainted", - Effect: resourcealphaapi.DeviceTaintEffectNoExecute, + Effect: resourcebetaapi.DeviceTaintEffectNoExecute, TimeAdded: &metav1.Time{Time: now}, }, }, @@ -949,7 +949,7 @@ func BenchmarkEventHandlers(b *testing.B) { } return patches }(), - loop: func(ctx context.Context, b *testing.B, tracker *Tracker, resourceSlices []*resourceapi.ResourceSlice, taintRules []*resourcealphaapi.DeviceTaintRule, i int) { + loop: func(ctx context.Context, b *testing.B, tracker *Tracker, resourceSlices []*resourceapi.ResourceSlice, taintRules []*resourcebetaapi.DeviceTaintRule, i int) { tracker.deviceTaintAdd(ctx)(taintRules[i%len(taintRules)]) }, }, diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/structured/internal/allocatortesting/allocator_testing.go b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/structured/internal/allocatortesting/allocator_testing.go index c6a68c2043..593d766235 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/structured/internal/allocatortesting/allocator_testing.go +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/structured/internal/allocatortesting/allocator_testing.go @@ -2006,6 +2006,51 @@ func TestAllocator(t *testing.T, expectError: gomega.MatchError(gomega.ContainSubstring("claim claim-0, request req-0: cannot add device driver-a/pool-1/device-2 because a claim constraint would not be satisfied")), }, + "partitionable-all-mode-constraint-must-error-with-reserved-counter": { + // Covers allocateDevice's must=true error path when the rejected device + // has already reserved a shared counter. An all-mode request over two + // devices with mismatched constraint attributes fails on the second + // device, which consumes the counter, so rollbackDevice runs with a + // reserved counter before the must-error is returned. The error aborts the + // whole allocation, so this asserts the error contract and exercises the + // counter-release branch; the released counter is not separately + // observable through the allocation result. + features: Features{ + PartitionableDevices: true, + }, + claimsToAllocate: objects( + func() wrapResourceClaim { + claim := claimWithRequests( + claim0, + []resourceapi.DeviceConstraint{{MatchAttribute: &intAttribute}}, + request(req0, classA, 0), + ) + claim.Spec.Devices.Requests[0].Exactly.AllocationMode = resourceapi.DeviceAllocationModeAll + return claim + }(), + ), + classes: objects(class(classA, driverA)), + slices: unwrapResourceSlices( + sliceWithDevices(slice1, node1, resourcePool(pool1, 2), driverA, + device(device1, nil, map[resourceapi.QualifiedName]resourceapi.DeviceAttribute{ + "numa": {IntValue: new(int64(1))}, + }), + // device2 mismatches the constraint and consumes the single + // counter, so it reserves the counter first and then fails the + // constraint, reaching the must-error path with state to undo. + device(device2, nil, map[resourceapi.QualifiedName]resourceapi.DeviceAttribute{ + "numa": {IntValue: new(int64(2))}, + }).withDeviceCounterConsumption( + deviceCounterConsumption(counterSet1, map[string]resource.Quantity{"c": resource.MustParse("1")}), + ), + ), + sliceWithCounterSets(slice2, node1, resourcePool(pool1, 2), driverA, + counterSet(counterSet1, map[string]resource.Quantity{"c": resource.MustParse("1")}), + ), + ), + node: node(node1, region1), + expectError: gomega.MatchError(gomega.ContainSubstring("claim claim-0, request req-0: cannot add device driver-a/pool-1/device-2 because a claim constraint would not be satisfied")), + }, "with-constraint-not-matching-string-attribute": { claimsToAllocate: objects(claimWithRequests( claim0, @@ -2858,6 +2903,275 @@ func TestAllocator(t *testing.T, deviceAllocationResult(req0, driverA, pool1, device1, false), )}, }, + "partitionable-devices-taint-releases-counter": { + features: Features{ + PartitionableDevices: true, + DeviceTaints: true, + }, + claimsToAllocate: objects( + claimWithRequests(claim0, nil, request(req0, classA, 1)), + ), + classes: objects(class(classA, driverA)), + slices: unwrapResourceSlices( + sliceWithDevices(slice1, node1, resourcePool(pool1, 2), driverA, + device(device1, nil, nil).withTaints(taintNoSchedule).withDeviceCounterConsumption( + deviceCounterConsumption(counterSet1, map[string]resource.Quantity{"c": resource.MustParse("1")}), + ), + device(device2, nil, nil).withDeviceCounterConsumption( + deviceCounterConsumption(counterSet1, map[string]resource.Quantity{"c": resource.MustParse("1")}), + ), + ), + sliceWithCounterSets(slice2, node1, resourcePool(pool1, 2), driverA, + counterSet(counterSet1, map[string]resource.Quantity{"c": resource.MustParse("1")}), + ), + ), + node: node(node1, region1), + // device1 is rejected by its NoSchedule taint after its counter is + // reserved. Releasing that reservation lets the clean device2 allocate. + expectResults: []any{allocationResult( + localNodeSelector(node1), + deviceAllocationResult(req0, driverA, pool1, device2, false), + )}, + }, + "partitionable-devices-constraint-releases-counter": { + features: Features{ + PartitionableDevices: true, + }, + claimsToAllocate: objects( + claimWithRequests(claim0, + []resourceapi.DeviceConstraint{{MatchAttribute: &stringAttribute}}, + request(req0, classA, 2), + ), + ), + classes: objects(class(classA, driverA)), + slices: unwrapResourceSlices( + sliceWithDevices(slice1, node1, resourcePool(pool1, 2), driverA, + device(device1, nil, map[resourceapi.QualifiedName]resourceapi.DeviceAttribute{ + "stringAttribute": {StringValue: new("red")}, + }).withDeviceCounterConsumption( + deviceCounterConsumption(counterSet1, map[string]resource.Quantity{"c": resource.MustParse("1")}), + ), + device(device2, nil, map[resourceapi.QualifiedName]resourceapi.DeviceAttribute{ + "stringAttribute": {StringValue: new("blue")}, + }).withDeviceCounterConsumption( + deviceCounterConsumption(counterSet1, map[string]resource.Quantity{"c": resource.MustParse("1")}), + ), + device(device3, nil, map[resourceapi.QualifiedName]resourceapi.DeviceAttribute{ + "stringAttribute": {StringValue: new("blue")}, + }).withDeviceCounterConsumption( + deviceCounterConsumption(counterSet1, map[string]resource.Quantity{"c": resource.MustParse("1")}), + ), + ), + sliceWithCounterSets(slice2, node1, resourcePool(pool1, 2), driverA, + counterSet(counterSet1, map[string]resource.Quantity{"c": resource.MustParse("2")}), + ), + ), + node: node(node1, region1), + // device1 (red) is accepted first; the blue candidates are rejected by + // the match-attribute constraint after their counters are reserved. + // Releasing those reservations lets the two blue devices allocate. + expectResults: []any{allocationResult( + localNodeSelector(node1), + deviceAllocationResult(req0, driverA, pool1, device2, false), + deviceAllocationResult(req0, driverA, pool1, device3, false), + )}, + }, + "partitionable-consumable-capacity-backtrack-releases-counter": { + features: Features{ + PartitionableDevices: true, + ConsumableCapacity: true, + }, + claimsToAllocate: objects( + claimWithRequests(claim0, nil, + request(req0, classA, 1, resourceapi.DeviceSelector{ + CEL: &resourceapi.CELDeviceSelector{ + Expression: fmt.Sprintf(`device.attributes["%s"].kind == "shared"`, driverA), + }}), + request(req1, classA, 1, resourceapi.DeviceSelector{ + CEL: &resourceapi.CELDeviceSelector{ + Expression: fmt.Sprintf(`device.attributes["%s"].kind == "counteronly"`, driverA), + }}), + ), + ), + classes: objects(class(classA, driverA)), + slices: unwrapResourceSlices( + sliceWithDevices(slice1, node1, resourcePool(pool1, 2), driverA, + // device1 allows multiple allocations and consumes the single + // shared counter. It is listed first, so req0 reserves its counter + // on the first try. + device(device1, nil, map[resourceapi.QualifiedName]resourceapi.DeviceAttribute{ + "kind": {StringValue: new("shared")}, + }).withAllowMultipleAllocations().withDeviceCounterConsumption( + deviceCounterConsumption(counterSet1, map[string]resource.Quantity{"c": resource.MustParse("1")}), + ), + // device2 consumes no counter and is the correct choice for req0 + // once device1 has been backtracked. + device(device2, nil, map[resourceapi.QualifiedName]resourceapi.DeviceAttribute{ + "kind": {StringValue: new("shared")}, + }), + // device3 is the only device that satisfies req1 and needs the same + // counter device1 reserved. + device(device3, nil, map[resourceapi.QualifiedName]resourceapi.DeviceAttribute{ + "kind": {StringValue: new("counteronly")}, + }).withDeviceCounterConsumption( + deviceCounterConsumption(counterSet1, map[string]resource.Quantity{"c": resource.MustParse("1")}), + ), + ), + sliceWithCounterSets(slice2, node1, resourcePool(pool1, 2), driverA, + counterSet(counterSet1, map[string]resource.Quantity{"c": resource.MustParse("1")}), + ), + ), + node: node(node1, region1), + // device1 allows multiple allocations and reserves the single shared + // counter when req0 tries it first. req1 can only use device3, which needs + // that same counter, so the search must backtrack device1. The backtracking + // undo has to release device1's counter reservation; otherwise req0 cannot + // fall back to device2 and req1 cannot take device3. + expectResults: []any{allocationResult( + localNodeSelector(node1), + deviceAllocationResult(req0, driverA, pool1, device2, false), + deviceAllocationResult(req1, driverA, pool1, device3, false), + )}, + }, + "consumable-capacity-rejection-rolls-back-constraints": { + features: Features{ + ConsumableCapacity: true, + PrioritizedList: true, + }, + claimsToAllocate: objects( + // claim0 consumes all of device1's capacity first. Its request is not + // subject to claim1's constraint, so it does not set the reference value. + claim(claim0).withRequests( + deviceRequest(req0, classA, 1). + withCapacityRequest(new(two)). + withSelectors(resourceapi.DeviceSelector{ + CEL: &resourceapi.CELDeviceSelector{ + Expression: fmt.Sprintf(`device.attributes["%s"].stringAttribute == "cap"`, driverA), + }}), + ), + // claim1 has a match-attribute constraint. Its first (all-mode) + // subrequest includes device1, which was capacity-sufficient when the + // candidate list was built but is now full, so it is rejected on the + // in-function capacity check after being added to the constraint. The + // fallback subrequest then needs device2, whose attribute differs. + claim(claim1). + withConstraints(resourceapi.DeviceConstraint{MatchAttribute: &stringAttribute}). + withRequests(requestWithPrioritizedList(req0, + subRequest(subReq0, classA, 1, resourceapi.DeviceSelector{ + CEL: &resourceapi.CELDeviceSelector{ + Expression: fmt.Sprintf(`device.attributes["%s"].stringAttribute == "cap"`, driverA), + }}). + withAllocationMode(resourceapi.DeviceAllocationModeAll). + withCapacityRequest(new(two)), + subRequest(subReq1, classA, 1, resourceapi.DeviceSelector{ + CEL: &resourceapi.CELDeviceSelector{ + Expression: fmt.Sprintf(`device.attributes["%s"].stringAttribute == "fb"`, driverA), + }}), + )), + ), + classes: objects(class(classA, driverA)), + slices: unwrapResourceSlices( + sliceWithDevices(slice1, node1, pool1, driverA, + device(device1, map[resourceapi.QualifiedName]resource.Quantity{capacity0: two}, + map[resourceapi.QualifiedName]resourceapi.DeviceAttribute{ + "stringAttribute": {StringValue: new("cap")}, + }).withAllowMultipleAllocations(), + device(device2, nil, + map[resourceapi.QualifiedName]resourceapi.DeviceAttribute{ + "stringAttribute": {StringValue: new("fb")}, + }), + ), + ), + node: node(node1, region1), + // claim1's all-mode subReq0 adds device1 to the match constraint and is then + // rejected because claim0 already consumed device1's capacity. Rolling back + // that rejected candidate's constraint entry is what lets the fallback + // subReq1 take device2; otherwise device1's leaked attribute value blocks it. + expectResults: []any{ + allocationResult(localNodeSelector(node1), + deviceRequestAllocationResult(req0, driverA, pool1, device1). + withConsumedCapacity(&fixedShareID, map[resourceapi.QualifiedName]resource.Quantity{capacity0: two})), + allocationResult(localNodeSelector(node1), + deviceAllocationResult(req0SubReq1, driverA, pool1, device2, false)), + }, + }, + "partitionable-empty-capacity-multiple-share-backtrack-keeps-counter-ownership": { + features: Features{ + PartitionableDevices: true, + ConsumableCapacity: true, + }, + claimsToAllocate: objects( + // claim0 pins device1 as the first share and reserves its single + // shared counter. + claimWithRequests(claim0, nil, + request(req0, classA, 1, resourceapi.DeviceSelector{ + CEL: &resourceapi.CELDeviceSelector{ + Expression: fmt.Sprintf(`device.attributes["%s"].kind == "shared"`, driverA), + }}), + ), + // claim1's req1 first tries device1 as a second share (skipping the + // counter, since claim0 already reserved it), but the match-attribute + // constraint with req2 forces it to backtrack onto device2. req3 then + // shares device1 again, after req1 has already left it. + claimWithRequests(claim1, + []resourceapi.DeviceConstraint{ + {MatchAttribute: &stringAttribute, Requests: []string{req1, req2}}, + }, + request(req1, classA, 1, resourceapi.DeviceSelector{ + CEL: &resourceapi.CELDeviceSelector{ + Expression: fmt.Sprintf(`device.attributes["%s"].kind == "shared" || device.attributes["%s"].kind == "fallback"`, driverA, driverA), + }}), + request(req2, classA, 1, resourceapi.DeviceSelector{ + CEL: &resourceapi.CELDeviceSelector{ + Expression: fmt.Sprintf(`device.attributes["%s"].kind == "gate"`, driverA), + }}), + request(req3, classA, 1, resourceapi.DeviceSelector{ + CEL: &resourceapi.CELDeviceSelector{ + Expression: fmt.Sprintf(`device.attributes["%s"].kind == "shared"`, driverA), + }}), + ), + ), + classes: objects(class(classA, driverA)), + slices: unwrapResourceSlices( + sliceWithDevices(slice1, node1, resourcePool(pool1, 2), driverA, + // device1: allow-multiple, no capacity, consumes the single counter. + // kind steers the selectors; stringAttribute steers the constraint. + device(device1, nil, map[resourceapi.QualifiedName]resourceapi.DeviceAttribute{ + "kind": {StringValue: new("shared")}, + "stringAttribute": {StringValue: new("red")}, + }).withAllowMultipleAllocations().withDeviceCounterConsumption( + deviceCounterConsumption(counterSet1, map[string]resource.Quantity{"c": resource.MustParse("1")}), + ), + // device2: the fallback for req1, matching req2's stringAttribute. + device(device2, nil, map[resourceapi.QualifiedName]resourceapi.DeviceAttribute{ + "kind": {StringValue: new("fallback")}, + "stringAttribute": {StringValue: new("blue")}, + }), + // device3: the only device req2 can take. + device(device3, nil, map[resourceapi.QualifiedName]resourceapi.DeviceAttribute{ + "kind": {StringValue: new("gate")}, + "stringAttribute": {StringValue: new("blue")}, + }), + ), + sliceWithCounterSets(slice2, node1, resourcePool(pool1, 2), driverA, + counterSet(counterSet1, map[string]resource.Quantity{"c": resource.MustParse("1")}), + ), + ), + node: node(node1, region1), + // claim0 reserves device1's counter as the first share. claim1's req1 tries + // device1 as a second share, skips the counter, then backtracks onto device2 + // because of the constraint with req2. Rolling back that empty-capacity share + // must not drop device1's shared marker, because claim0's share still holds + // the counter. req3 then shares device1 again without recharging the counter. + expectResults: []any{ + allocationResult(localNodeSelector(node1), + deviceRequestAllocationResult(req0, driverA, pool1, device1).withConsumedCapacity(&fixedShareID, nil)), + allocationResult(localNodeSelector(node1), + deviceAllocationResult(req1, driverA, pool1, device2, false), + deviceAllocationResult(req2, driverA, pool1, device3, false), + deviceRequestAllocationResult(req3, driverA, pool1, device1).withConsumedCapacity(&fixedShareID, nil)), + }, + }, "partitionable-devices-prioritized-list": { features: Features{ PrioritizedList: true, diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/structured/internal/experimental/allocator_experimental.go b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/structured/internal/experimental/allocator_experimental.go index d2a2ecb92a..51a2999426 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/structured/internal/experimental/allocator_experimental.go +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/structured/internal/experimental/allocator_experimental.go @@ -1463,6 +1463,10 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus skipCounterCheck := allowMultipleAllocations && alloc.deviceCapacityInUse(device.id) // The API validation logic has checked the ConsumesCounters referred should exist inside SharedCounters. + // countersReserved records whether checkAvailableCounters actually reserved + // this device's counters. It is not the same as len(device.ConsumesCounters) > 0, + // because skipCounterCheck can bypass the reservation. + countersReserved := false if !skipCounterCheck && len(device.ConsumesCounters) > 0 { // If a device consumes counters from a counter set, verify that // there is sufficient counters available. @@ -1474,6 +1478,7 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus alloc.logger.V(7).Info("Insufficient counters", "device", device.id) return false, nil, nil } + countersReserved = true } var parentRequestName string @@ -1487,39 +1492,48 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus subRequestName = requestData.request.name() } + // state records the mutations this call makes so rollbackDevice can undo + // them. Every rejection path after a successful counter reservation calls + // rollbackDevice synchronously, and the success path returns a closure that + // calls the same helper during backtracking, so both undo routes stay + // identical. Passing the state by value to rollbackDevice keeps it (and the flags) on the + // stack for the rejection paths; only the success closure escapes. + state := deviceRollbackState{ + countersReserved: countersReserved, + previousNumResults: len(alloc.result[r.claimIndex].devices), + } + // Might be tainted, in which case the taint has to be tolerated. // The check is skipped if the feature is disabled. if alloc.features.DeviceTaints && taintPreventsAllocation(device.Device, request) { + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) return false, nil, nil } // It's available. Now check constraints. - for i, constraint := range alloc.constraints[r.claimIndex] { - added := constraint.add(baseRequestName, subRequestName, device.Device, device.id) - if !added { + for _, constraint := range alloc.constraints[r.claimIndex] { + if !constraint.add(baseRequestName, subRequestName, device.Device, device.id) { + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) if must { // It does not make sense to declare a claim where a constraint prevents getting // all devices. Treat this as an error. return false, nil, fmt.Errorf("claim %s, request %s: cannot add device %s because a claim constraint would not be satisfied", klog.KObj(claim), request.name(), device.id) } - - // Roll back for all previous constraints before we return. - for e := 0; e < i; e++ { - alloc.constraints[r.claimIndex][e].remove(baseRequestName, subRequestName, device.Device, device.id) - } return false, nil, nil } + state.constraintsAdded++ } // All constraints satisfied. Mark as in use (unless we do admin access or allow multiple allocations) // and record the result. alloc.logger.V(7).Info("Device allocated", "device", device.id) - if alloc.allocatingDevices[device.id] == nil { - alloc.allocatingDevices[device.id] = make(sets.Set[int]) - } if !allowMultipleAllocations { + if alloc.allocatingDevices[device.id] == nil { + alloc.allocatingDevices[device.id] = make(sets.Set[int]) + } alloc.allocatingDevices[device.id].Insert(r.claimIndex) + state.deviceMarked = true } consumedCapacity := make(map[resourceapi.QualifiedName]resource.Quantity, 0) @@ -1531,10 +1545,12 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus if err != nil { alloc.logger.V(7).Info("Failed to compare device capacity request on allocateDevice", "device", device, "request", requestData.request.name(), "err", err) + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) return false, nil, nil } if !success { alloc.logger.V(7).Info("Device capacity not enough", "device", device) + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) return false, nil, nil } @@ -1543,7 +1559,14 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus shareID = GenerateNewShareID() alloc.logger.V(7).Info("Device capacity allocated", "device", device.id, "consumed capacity", klog.Format(consumedCapacity)) + // A prior share of this device may already hold the capacity entry. + // That entry doubles as the "already shared" marker that lets a later + // share skip the counter check, so record whether it predated this + // share; rollback must not delete it while another share still needs it. + _, state.capacityEntryExisted = alloc.allocatingCapacity[device.id] alloc.allocatingCapacity.Insert(NewDeviceConsumedCapacity(device.id, consumedCapacity)) + state.capacityInserted = true + state.consumedCapacity = consumedCapacity } } @@ -1561,29 +1584,64 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus if len(consumedCapacity) > 0 { result.consumedCapacity = consumedCapacity } - previousNumResults := len(alloc.result[r.claimIndex].devices) alloc.result[r.claimIndex].devices = append(alloc.result[r.claimIndex].devices, result) + state.resultAdded = true + // Only this success path builds an escaping closure, so backtracking can undo + // a committed candidate. undo is a copy: capturing state directly would move it + // and its flags to the heap on the rejection paths too, which never escape. + undo := state return true, func() { - for _, constraint := range alloc.constraints[r.claimIndex] { - constraint.remove(baseRequestName, subRequestName, device.Device, device.id) - } - alloc.allocatingDevices[device.id].Delete(r.claimIndex) - if allowMultipleAllocations { - requestedResource := alloc.result[r.claimIndex].devices[previousNumResults].consumedCapacity - if requestedResource != nil { - alloc.allocatingCapacity.Remove(NewDeviceConsumedCapacity(device.id, requestedResource)) - } - } else { - alloc.allocatingDevices[device.id].Delete(r.claimIndex) - if alloc.features.PartitionableDevices && len(device.ConsumesCounters) > 0 { - alloc.deallocateCountersForDevice(device) + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, undo) + }, nil +} + +// deviceRollbackState records the mutations allocateDevice makes for a single +// candidate so rollbackDevice can undo them, both when the candidate is rejected +// and when the backtracking search abandons a previously successful candidate. +type deviceRollbackState struct { + countersReserved bool + constraintsAdded int + deviceMarked bool + capacityInserted bool + capacityEntryExisted bool + resultAdded bool + previousNumResults int + consumedCapacity map[resourceapi.QualifiedName]resource.Quantity +} + +// rollbackDevice reverses the mutations recorded in state, in the opposite order +// they were applied. It is called synchronously on the rejection paths and, via +// the closure returned on success, during backtracking. +func (alloc *allocator) rollbackDevice(r deviceIndices, device deviceWithID, baseRequestName, subRequestName string, state deviceRollbackState) { + if state.resultAdded { + alloc.result[r.claimIndex].devices = alloc.result[r.claimIndex].devices[:state.previousNumResults] + } + if state.capacityInserted { + alloc.allocatingCapacity.Remove(NewDeviceConsumedCapacity(device.id, state.consumedCapacity)) + if state.capacityEntryExisted { + // Remove drops the entry once it becomes empty, which also erases the + // shared marker that the earlier share still relies on. Restore an empty + // entry in that case so the earlier share stays accounted as shared. + if _, found := alloc.allocatingCapacity[device.id]; !found { + alloc.allocatingCapacity[device.id] = NewConsumedCapacity() } } - // Truncate, but keep the underlying slice. - alloc.result[r.claimIndex].devices = alloc.result[r.claimIndex].devices[:previousNumResults] + } + if state.deviceMarked { + alloc.allocatingDevices[device.id].Delete(r.claimIndex) + } + for i := state.constraintsAdded - 1; i >= 0; i-- { + alloc.constraints[r.claimIndex][i].remove(baseRequestName, subRequestName, device.Device, device.id) + } + if state.countersReserved { + alloc.deallocateCountersForDevice(device) + } + if state.resultAdded { + // Only a fully allocated candidate recorded a result, so this is a real + // deallocation during backtracking, not a rejection rollback. alloc.logger.V(7).Info("Device deallocated", "device", device.id) - }, nil + } } func taintPreventsAllocation(device *draapi.Device, request requestAccessor) bool { diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/structured/internal/incubating/allocator_incubating.go b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/structured/internal/incubating/allocator_incubating.go index a77feed54c..335dca2a8e 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/structured/internal/incubating/allocator_incubating.go +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/structured/internal/incubating/allocator_incubating.go @@ -1335,6 +1335,10 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus skipCounterCheck := allowMultipleAllocations && alloc.deviceCapacityInUse(device.id) // The API validation logic has checked the ConsumesCounters referred should exist inside SharedCounters. + // countersReserved records whether checkAvailableCounters actually reserved + // this device's counters. It is not the same as len(device.ConsumesCounters) > 0, + // because skipCounterCheck can bypass the reservation. + countersReserved := false if !skipCounterCheck && len(device.ConsumesCounters) > 0 { // If a device consumes counters from a counter set, verify that // there is sufficient counters available. @@ -1346,6 +1350,7 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus alloc.logger.V(7).Info("Insufficient counters", "device", device.id) return false, nil, nil } + countersReserved = true } var parentRequestName string @@ -1359,39 +1364,48 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus subRequestName = requestData.request.name() } + // state records the mutations this call makes so rollbackDevice can undo + // them. Every rejection path after a successful counter reservation calls + // rollbackDevice synchronously, and the success path returns a closure that + // calls the same helper during backtracking, so both undo routes stay + // identical. Passing the state by value to rollbackDevice keeps it (and the flags) on the + // stack for the rejection paths; only the success closure escapes. + state := deviceRollbackState{ + countersReserved: countersReserved, + previousNumResults: len(alloc.result[r.claimIndex].devices), + } + // Might be tainted, in which case the taint has to be tolerated. // The check is skipped if the feature is disabled. if alloc.features.DeviceTaints && taintPreventsAllocation(device.Device, request) { + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) return false, nil, nil } // It's available. Now check constraints. - for i, constraint := range alloc.constraints[r.claimIndex] { - added := constraint.add(baseRequestName, subRequestName, device.Device, device.id) - if !added { + for _, constraint := range alloc.constraints[r.claimIndex] { + if !constraint.add(baseRequestName, subRequestName, device.Device, device.id) { + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) if must { // It does not make sense to declare a claim where a constraint prevents getting // all devices. Treat this as an error. return false, nil, fmt.Errorf("claim %s, request %s: cannot add device %s because a claim constraint would not be satisfied", klog.KObj(claim), request.name(), device.id) } - - // Roll back for all previous constraints before we return. - for e := 0; e < i; e++ { - alloc.constraints[r.claimIndex][e].remove(baseRequestName, subRequestName, device.Device, device.id) - } return false, nil, nil } + state.constraintsAdded++ } // All constraints satisfied. Mark as in use (unless we do admin access or allow multiple allocations) // and record the result. alloc.logger.V(7).Info("Device allocated", "device", device.id) - if alloc.allocatingDevices[device.id] == nil { - alloc.allocatingDevices[device.id] = make(sets.Set[int]) - } if !allowMultipleAllocations { + if alloc.allocatingDevices[device.id] == nil { + alloc.allocatingDevices[device.id] = make(sets.Set[int]) + } alloc.allocatingDevices[device.id].Insert(r.claimIndex) + state.deviceMarked = true } consumedCapacity := make(map[resourceapi.QualifiedName]resource.Quantity, 0) @@ -1403,10 +1417,12 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus if err != nil { alloc.logger.V(7).Info("Failed to compare device capacity request on allocateDevice", "device", device, "request", requestData.request.name(), "err", err) + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) return false, nil, nil } if !success { alloc.logger.V(7).Info("Device capacity not enough", "device", device) + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) return false, nil, nil } @@ -1415,7 +1431,14 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus shareID = GenerateNewShareID() alloc.logger.V(7).Info("Device capacity allocated", "device", device.id, "consumed capacity", klog.Format(consumedCapacity)) + // A prior share of this device may already hold the capacity entry. + // That entry doubles as the "already shared" marker that lets a later + // share skip the counter check, so record whether it predated this + // share; rollback must not delete it while another share still needs it. + _, state.capacityEntryExisted = alloc.allocatingCapacity[device.id] alloc.allocatingCapacity.Insert(NewDeviceConsumedCapacity(device.id, consumedCapacity)) + state.capacityInserted = true + state.consumedCapacity = consumedCapacity } } @@ -1433,29 +1456,64 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus if len(consumedCapacity) > 0 { result.consumedCapacity = consumedCapacity } - previousNumResults := len(alloc.result[r.claimIndex].devices) alloc.result[r.claimIndex].devices = append(alloc.result[r.claimIndex].devices, result) + state.resultAdded = true + // Only this success path builds an escaping closure, so backtracking can undo + // a committed candidate. undo is a copy: capturing state directly would move it + // and its flags to the heap on the rejection paths too, which never escape. + undo := state return true, func() { - for _, constraint := range alloc.constraints[r.claimIndex] { - constraint.remove(baseRequestName, subRequestName, device.Device, device.id) - } - alloc.allocatingDevices[device.id].Delete(r.claimIndex) - if allowMultipleAllocations { - requestedResource := alloc.result[r.claimIndex].devices[previousNumResults].consumedCapacity - if requestedResource != nil { - alloc.allocatingCapacity.Remove(NewDeviceConsumedCapacity(device.id, requestedResource)) - } - } else { - alloc.allocatingDevices[device.id].Delete(r.claimIndex) - if alloc.features.PartitionableDevices && len(device.ConsumesCounters) > 0 { - alloc.deallocateCountersForDevice(device) + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, undo) + }, nil +} + +// deviceRollbackState records the mutations allocateDevice makes for a single +// candidate so rollbackDevice can undo them, both when the candidate is rejected +// and when the backtracking search abandons a previously successful candidate. +type deviceRollbackState struct { + countersReserved bool + constraintsAdded int + deviceMarked bool + capacityInserted bool + capacityEntryExisted bool + resultAdded bool + previousNumResults int + consumedCapacity map[resourceapi.QualifiedName]resource.Quantity +} + +// rollbackDevice reverses the mutations recorded in state, in the opposite order +// they were applied. It is called synchronously on the rejection paths and, via +// the closure returned on success, during backtracking. +func (alloc *allocator) rollbackDevice(r deviceIndices, device deviceWithID, baseRequestName, subRequestName string, state deviceRollbackState) { + if state.resultAdded { + alloc.result[r.claimIndex].devices = alloc.result[r.claimIndex].devices[:state.previousNumResults] + } + if state.capacityInserted { + alloc.allocatingCapacity.Remove(NewDeviceConsumedCapacity(device.id, state.consumedCapacity)) + if state.capacityEntryExisted { + // Remove drops the entry once it becomes empty, which also erases the + // shared marker that the earlier share still relies on. Restore an empty + // entry in that case so the earlier share stays accounted as shared. + if _, found := alloc.allocatingCapacity[device.id]; !found { + alloc.allocatingCapacity[device.id] = NewConsumedCapacity() } } - // Truncate, but keep the underlying slice. - alloc.result[r.claimIndex].devices = alloc.result[r.claimIndex].devices[:previousNumResults] + } + if state.deviceMarked { + alloc.allocatingDevices[device.id].Delete(r.claimIndex) + } + for i := state.constraintsAdded - 1; i >= 0; i-- { + alloc.constraints[r.claimIndex][i].remove(baseRequestName, subRequestName, device.Device, device.id) + } + if state.countersReserved { + alloc.deallocateCountersForDevice(device) + } + if state.resultAdded { + // Only a fully allocated candidate recorded a result, so this is a real + // deallocation during backtracking, not a rejection rollback. alloc.logger.V(7).Info("Device deallocated", "device", device.id) - }, nil + } } func taintPreventsAllocation(device *draapi.Device, request requestAccessor) bool { diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/structured/internal/stable/allocator_stable.go b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/structured/internal/stable/allocator_stable.go index bb85ff5286..3b434bac95 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/structured/internal/stable/allocator_stable.go +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation/structured/internal/stable/allocator_stable.go @@ -1124,6 +1124,9 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus } // The API validation logic has checked the ConsumesCounters referred should exist inside SharedCounters. + // countersReserved records whether checkAvailableCounters actually reserved + // this device's counters, so the rollback below only releases what was taken. + countersReserved := false if len(device.ConsumesCounters) > 0 { // If a device consumes counters from a counter set, verify that // there is sufficient counters available. @@ -1135,6 +1138,7 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus alloc.logger.V(7).Info("Insufficient counters", "device", device.id) return false, nil, nil } + countersReserved = true } var parentRequestName string @@ -1148,28 +1152,36 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus subRequestName = requestData.request.name() } + // state records the mutations this call makes so rollbackDevice can undo + // them. Every rejection path after a successful counter reservation calls + // rollbackDevice synchronously, and the success path returns a closure that + // calls the same helper during backtracking, so both undo routes stay + // identical. Passing the state by value to rollbackDevice keeps it (and the flags) on the + // stack for the rejection paths; only the success closure escapes. + state := deviceRollbackState{ + countersReserved: countersReserved, + previousNumResults: len(alloc.result[r.claimIndex].devices), + } + // Might be tainted, in which case the taint has to be tolerated. // The check is skipped if the feature is disabled. if alloc.features.DeviceTaints && taintPreventsAllocation(device.Device, request) { + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) return false, nil, nil } // It's available. Now check constraints. - for i, constraint := range alloc.constraints[r.claimIndex] { - added := constraint.add(baseRequestName, subRequestName, device.Device, device.id) - if !added { + for _, constraint := range alloc.constraints[r.claimIndex] { + if !constraint.add(baseRequestName, subRequestName, device.Device, device.id) { + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) if must { // It does not make sense to declare a claim where a constraint prevents getting // all devices. Treat this as an error. return false, nil, fmt.Errorf("claim %s, request %s: cannot add device %s because a claim constraint would not be satisfied", klog.KObj(claim), request.name(), device.id) } - - // Roll back for all previous constraints before we return. - for e := 0; e < i; e++ { - alloc.constraints[r.claimIndex][e].remove(baseRequestName, subRequestName, device.Device, device.id) - } return false, nil, nil } + state.constraintsAdded++ } // All constraints satisfied. Mark as in use (unless we do admin access) @@ -1180,6 +1192,7 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus alloc.allocatingDevices[device.id] = make(sets.Set[int]) } alloc.allocatingDevices[device.id].Insert(r.claimIndex) + state.deviceMarked = true result := internalDeviceResult{ request: request.name(), @@ -1191,21 +1204,50 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus if request.adminAccess() { result.adminAccess = ptr.To(request.adminAccess()) } - previousNumResults := len(alloc.result[r.claimIndex].devices) alloc.result[r.claimIndex].devices = append(alloc.result[r.claimIndex].devices, result) + state.resultAdded = true + // Only this success path builds an escaping closure, so backtracking can undo + // a committed candidate. undo is a copy: capturing state directly would move it + // and its flags to the heap on the rejection paths too, which never escape. + undo := state return true, func() { - for _, constraint := range alloc.constraints[r.claimIndex] { - constraint.remove(baseRequestName, subRequestName, device.Device, device.id) - } + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, undo) + }, nil +} + +// deviceRollbackState records the mutations allocateDevice makes for a single +// candidate so rollbackDevice can undo them, both when the candidate is rejected +// and when the backtracking search abandons a previously successful candidate. +type deviceRollbackState struct { + countersReserved bool + constraintsAdded int + deviceMarked bool + resultAdded bool + previousNumResults int +} + +// rollbackDevice reverses the mutations recorded in state, in the opposite order +// they were applied. It is called synchronously on the rejection paths and, via +// the closure returned on success, during backtracking. +func (alloc *allocator) rollbackDevice(r deviceIndices, device deviceWithID, baseRequestName, subRequestName string, state deviceRollbackState) { + if state.resultAdded { + alloc.result[r.claimIndex].devices = alloc.result[r.claimIndex].devices[:state.previousNumResults] + } + if state.deviceMarked { alloc.allocatingDevices[device.id].Delete(r.claimIndex) - if alloc.features.PartitionableDevices && len(device.ConsumesCounters) > 0 { - alloc.deallocateCountersForDevice(device) - } - // Truncate, but keep the underlying slice. - alloc.result[r.claimIndex].devices = alloc.result[r.claimIndex].devices[:previousNumResults] + } + for i := state.constraintsAdded - 1; i >= 0; i-- { + alloc.constraints[r.claimIndex][i].remove(baseRequestName, subRequestName, device.Device, device.id) + } + if state.countersReserved { + alloc.deallocateCountersForDevice(device) + } + if state.resultAdded { + // Only a fully allocated candidate recorded a result, so this is a real + // deallocation during backtracking, not a rejection rollback. alloc.logger.V(7).Info("Device deallocated", "device", device.id) - }, nil + } } func taintPreventsAllocation(device *draapi.Device, request requestAccessor) bool { diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/endpointslice/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/endpointslice/go.mod index e0d00a9c24..5620e0080e 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/endpointslice/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/endpointslice/go.mod @@ -70,7 +70,7 @@ require ( k8s.io/kube-openapi v0.0.0-20260519202549-bbf5c5577288 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect sigs.k8s.io/yaml v1.6.0 // indirect ) diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/endpointslice/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/endpointslice/go.sum index eb6750f1b3..143767c583 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/endpointslice/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/endpointslice/go.sum @@ -196,7 +196,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-aggregator/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-aggregator/go.mod index 386625b93b..5c5b0cfeee 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-aggregator/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-aggregator/go.mod @@ -28,7 +28,7 @@ require ( k8s.io/streaming v0.36.2 k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 sigs.k8s.io/randfill v1.0.0 - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 ) require ( diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-aggregator/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-aggregator/go.sum index ae5e7bf6f8..f5f4d7344d 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-aggregator/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-aggregator/go.sum @@ -384,7 +384,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh sigs.k8s.io/kube-storage-version-migrator v0.0.6-0.20230721195810-5c8923c5ff96/go.mod h1:EOBQyBowOUsd7U4CJnMHNE0ri+zCXyouGdLwC/jZU+I= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-controller-manager/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-controller-manager/go.mod index 559cff386f..4aae28919c 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-controller-manager/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-controller-manager/go.mod @@ -31,7 +31,7 @@ require ( k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect ) replace ( diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-controller-manager/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-controller-manager/go.sum index c661870e5a..fbec2a9d5f 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-controller-manager/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-controller-manager/go.sum @@ -149,7 +149,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-proxy/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-proxy/go.mod index 7aa810e6df..352fcf01a1 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-proxy/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-proxy/go.mod @@ -45,7 +45,7 @@ require ( k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect sigs.k8s.io/yaml v1.6.0 // indirect ) diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-proxy/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-proxy/go.sum index 47069946d6..b1d2fe8e54 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-proxy/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-proxy/go.sum @@ -154,7 +154,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-scheduler/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-scheduler/go.mod index cb521cc53c..d2fa0d6395 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-scheduler/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-scheduler/go.mod @@ -81,7 +81,7 @@ require ( k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect ) replace ( diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-scheduler/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-scheduler/go.sum index fcf3907d1f..60473cc087 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-scheduler/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-scheduler/go.sum @@ -243,7 +243,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubectl/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubectl/go.mod index 65081b75ff..26c0075bd8 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubectl/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubectl/go.mod @@ -45,7 +45,7 @@ require ( sigs.k8s.io/kustomize/kustomize/v5 v5.8.1 sigs.k8s.io/kustomize/kyaml v0.21.1 sigs.k8s.io/randfill v1.0.0 - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 sigs.k8s.io/yaml v1.6.0 ) diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubectl/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubectl/go.sum index 6785ef0fc8..fc3718405d 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubectl/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubectl/go.sum @@ -272,7 +272,7 @@ sigs.k8s.io/kustomize/kyaml v0.21.1 h1:IVlbmhC076nf6foyL6Taw4BkrLuEsXUXNpsE+ScX7 sigs.k8s.io/kustomize/kyaml v0.21.1/go.mod h1:hmxADesM3yUN2vbA5z1/YTBnzLJ1dajdqpQonwBL1FQ= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubelet/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubelet/go.mod index fd76cb75ad..212ec06c86 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubelet/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubelet/go.mod @@ -51,7 +51,7 @@ require ( k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect sigs.k8s.io/yaml v1.6.0 // indirect ) diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubelet/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubelet/go.sum index 8c8c571876..a370a77e69 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubelet/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubelet/go.sum @@ -180,7 +180,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/metrics/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/metrics/go.mod index 619140277d..f3a1a2bcef 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/metrics/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/metrics/go.mod @@ -64,7 +64,7 @@ require ( k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect sigs.k8s.io/yaml v1.6.0 // indirect ) diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/metrics/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/metrics/go.sum index 1272e7b4b6..a30972780e 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/metrics/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/metrics/go.sum @@ -154,7 +154,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/pod-security-admission/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/pod-security-admission/go.mod index cacd25143e..301ce368f3 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/pod-security-admission/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/pod-security-admission/go.mod @@ -116,7 +116,7 @@ require ( sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.34.0 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect ) replace ( diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/pod-security-admission/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/pod-security-admission/go.sum index 8a421864eb..c1271c8e8c 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/pod-security-admission/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/pod-security-admission/go.sum @@ -374,7 +374,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh sigs.k8s.io/kube-storage-version-migrator v0.0.6-0.20230721195810-5c8923c5ff96/go.mod h1:EOBQyBowOUsd7U4CJnMHNE0ri+zCXyouGdLwC/jZU+I= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-apiserver/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-apiserver/go.mod index a1dae8d518..e1bba13882 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-apiserver/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-apiserver/go.mod @@ -17,7 +17,7 @@ require ( k8s.io/kube-openapi v0.0.0-20260519202549-bbf5c5577288 k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 sigs.k8s.io/randfill v1.0.0 - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 ) require ( diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-apiserver/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-apiserver/go.sum index 9786a90808..b442bae7bc 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-apiserver/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-apiserver/go.sum @@ -381,7 +381,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh sigs.k8s.io/kube-storage-version-migrator v0.0.6-0.20230721195810-5c8923c5ff96/go.mod h1:EOBQyBowOUsd7U4CJnMHNE0ri+zCXyouGdLwC/jZU+I= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-cli-plugin/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-cli-plugin/go.mod index 78e15b0e9f..6741171cba 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-cli-plugin/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-cli-plugin/go.mod @@ -70,7 +70,7 @@ require ( sigs.k8s.io/kustomize/api v0.21.1 // indirect sigs.k8s.io/kustomize/kyaml v0.21.1 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect sigs.k8s.io/yaml v1.6.0 // indirect ) diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-cli-plugin/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-cli-plugin/go.sum index ca83779f6b..7eb94cc41c 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-cli-plugin/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-cli-plugin/go.sum @@ -180,7 +180,7 @@ sigs.k8s.io/kustomize/kyaml v0.21.1 h1:IVlbmhC076nf6foyL6Taw4BkrLuEsXUXNpsE+ScX7 sigs.k8s.io/kustomize/kyaml v0.21.1/go.mod h1:hmxADesM3yUN2vbA5z1/YTBnzLJ1dajdqpQonwBL1FQ= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-controller/go.mod b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-controller/go.mod index 52166a3ab7..862d65a5cc 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-controller/go.mod +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-controller/go.mod @@ -15,7 +15,7 @@ require ( k8s.io/klog/v2 v2.140.0 k8s.io/kube-openapi v0.0.0-20260519202549-bbf5c5577288 k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 ) require ( diff --git a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-controller/go.sum b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-controller/go.sum index ecfeb6ba1f..1f3d483029 100644 --- a/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-controller/go.sum +++ b/deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-controller/go.sum @@ -155,7 +155,7 @@ sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5E sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/cmd/feature_gates.go b/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/cmd/feature_gates.go index 15aaae4bfc..f2e5bc7bc1 100644 --- a/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/cmd/feature_gates.go +++ b/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/cmd/feature_gates.go @@ -60,7 +60,10 @@ type featureSpec struct { } type featureInfo struct { - Name string `yaml:"name" json:"name"` + Name string `yaml:"name" json:"name"` + // FullName is the full name of the feature, including the package name, + // used for ensuring that features are grouped by their package prefix first, + // and then sorted alphabetically within that group. FullName string `yaml:"-" json:"-"` VersionedSpecs []featureSpec `yaml:"versionedSpecs" json:"versionedSpecs"` } @@ -438,9 +441,20 @@ func isFeatureSpecType(v ast.Expr, aliasMap map[string]string) bool { } func parseFeatureInfo(variables map[string]ast.Expr, kv *ast.KeyValueExpr) (featureInfo, error) { + name := identifierName(kv.Key, true) + fullName := identifierName(kv.Key, false) + + if id, ok := kv.Key.(*ast.Ident); ok { + if varVal, ok := variables[id.Name]; ok { + if strVal, err := basicStringLiteral(varVal); err == nil { + name = strVal + } + } + } + info := featureInfo{ - Name: identifierName(kv.Key, true), - FullName: identifierName(kv.Key, false), + Name: name, + FullName: fullName, VersionedSpecs: []featureSpec{}, } specExps := []ast.Expr{} diff --git a/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/cmd/feature_gates_test.go b/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/cmd/feature_gates_test.go index a0652852b2..9631d82d86 100644 --- a/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/cmd/feature_gates_test.go +++ b/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/cmd/feature_gates_test.go @@ -108,7 +108,7 @@ func TestVerifyOrUpdateFeatureListVersioned(t *testing.T) { lockToDefault: false preRelease: Beta version: "1.30" -- name: CPUCFSQuotaPeriod +- name: CustomCPUCFSQuotaPeriod versionedSpecs: - default: false lockToDefault: false @@ -136,6 +136,9 @@ import ( "k8s.io/apimachinery/pkg/util/version" "k8s.io/component-base/featuregate" ) + +const CPUCFSQuotaPeriod featuregate.Feature = "CustomCPUCFSQuotaPeriod" + var defaultVersionedKubernetesFeatureGates = map[featuregate.Feature]featuregate.VersionedSpecs{ AppArmorFields: { {Version: version.MajorMinor(1, 30), Default: true, PreRelease: featuregate.Beta}, @@ -166,6 +169,9 @@ import ( "k8s.io/apimachinery/pkg/util/version" "k8s.io/component-base/featuregate" ) + +const CPUCFSQuotaPeriod featuregate.Feature = "CustomCPUCFSQuotaPeriod" + var defaultVersionedKubernetesFeatureGates = map[featuregate.Feature]featuregate.VersionedSpecs{ AppArmorFields: { {Version: version.MajorMinor(1, 30), Default: true, PreRelease: featuregate.Beta}, @@ -196,7 +202,7 @@ var otherFeatureGates = map[featuregate.Feature]featuregate.VersionedSpecs{ lockToDefault: false preRelease: Beta version: "1.30" -- name: CPUCFSQuotaPeriod +- name: CustomCPUCFSQuotaPeriod versionedSpecs: - default: false lockToDefault: false @@ -276,6 +282,9 @@ import ( "k8s.io/apimachinery/pkg/util/version" "k8s.io/component-base/featuregate" ) + +const CPUCFSQuotaPeriod featuregate.Feature = "CustomCPUCFSQuotaPeriod" + var defaultVersionedKubernetesFeatureGates = map[featuregate.Feature]featuregate.VersionedSpecs{ AppArmorFields: { {Version: version.MajorMinor(1, 30), Default: true, PreRelease: featuregate.Beta}, @@ -312,7 +321,7 @@ var defaultVersionedKubernetesFeatureGates = map[featuregate.Feature]featuregate lockToDefault: false preRelease: Beta version: "1.30" -- name: CPUCFSQuotaPeriod +- name: CustomCPUCFSQuotaPeriod versionedSpecs: - default: false lockToDefault: false @@ -333,6 +342,9 @@ import ( "k8s.io/apimachinery/pkg/util/version" "k8s.io/component-base/featuregate" ) + +const CPUCFSQuotaPeriod featuregate.Feature = "CustomCPUCFSQuotaPeriod" + var defaultVersionedKubernetesFeatureGates = map[featuregate.Feature]featuregate.VersionedSpecs{ CPUCFSQuotaPeriod: { {Version: version.MustParse("1.30"), Default: false, PreRelease: featuregate.Alpha}, @@ -373,6 +385,9 @@ import ( "k8s.io/apimachinery/pkg/util/version" "k8s.io/component-base/featuregate" ) + +const CPUCFSQuotaPeriod featuregate.Feature = "CustomCPUCFSQuotaPeriod" + var defaultVersionedKubernetesFeatureGates = map[featuregate.Feature]featuregate.VersionedSpecs{ AppArmorFields: { {Version: version.MajorMinor(1, 30), Default: true, PreRelease: featuregate.Beta}, @@ -401,7 +416,7 @@ var defaultVersionedKubernetesFeatureGates = map[featuregate.Feature]featuregate lockToDefault: false preRelease: Beta version: "1.30" -- name: CPUCFSQuotaPeriod +- name: CustomCPUCFSQuotaPeriod versionedSpecs: - default: false lockToDefault: false diff --git a/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/feature_list.md b/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/feature_list.md index 73e3761674..2605dbd3dd 100644 --- a/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/feature_list.md +++ b/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/feature_list.md @@ -184,6 +184,7 @@ | RuntimeClassInImageCriApi | | | 1.29– | | | | | [code](https://cs.k8s.io/?q=%5CbRuntimeClassInImageCriApi%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/kubernetes) [KEPs](https://cs.k8s.io/?q=%5CbRuntimeClassInImageCriApi%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/enhancements) | | SELinuxChangePolicy | :ballot_box_with_check: 1.33+ | :closed_lock_with_key: 1.36+ | 1.32 | 1.33–1.35 | 1.36– | | | [code](https://cs.k8s.io/?q=%5CbSELinuxChangePolicy%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/kubernetes) [KEPs](https://cs.k8s.io/?q=%5CbSELinuxChangePolicy%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/enhancements) | | SELinuxMount | | | 1.30–1.32 | 1.33– | | | | [code](https://cs.k8s.io/?q=%5CbSELinuxMount%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/kubernetes) [KEPs](https://cs.k8s.io/?q=%5CbSELinuxMount%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/enhancements) | +| SELinuxMountGAReadiness | | | 1.35– | | | | | [code](https://cs.k8s.io/?q=%5CbSELinuxMountGAReadiness%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/kubernetes) [KEPs](https://cs.k8s.io/?q=%5CbSELinuxMountGAReadiness%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/enhancements) | | SELinuxMountReadWriteOncePod | :ballot_box_with_check: 1.28+ | :closed_lock_with_key: 1.36+ | 1.25–1.26 | 1.27–1.35 | 1.36– | | | [code](https://cs.k8s.io/?q=%5CbSELinuxMountReadWriteOncePod%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/kubernetes) [KEPs](https://cs.k8s.io/?q=%5CbSELinuxMountReadWriteOncePod%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/enhancements) | | SchedulerAsyncAPICalls | | | | 1.34– | | | | [code](https://cs.k8s.io/?q=%5CbSchedulerAsyncAPICalls%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/kubernetes) [KEPs](https://cs.k8s.io/?q=%5CbSchedulerAsyncAPICalls%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/enhancements) | | SchedulerAsyncPreemption | :ballot_box_with_check: 1.33+ | | 1.32 | 1.33– | | | | [code](https://cs.k8s.io/?q=%5CbSchedulerAsyncPreemption%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/kubernetes) [KEPs](https://cs.k8s.io/?q=%5CbSchedulerAsyncPreemption%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/enhancements) | diff --git a/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/versioned_feature_list.yaml b/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/versioned_feature_list.yaml index 68d94d3943..c352aa51e7 100644 --- a/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/versioned_feature_list.yaml +++ b/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/versioned_feature_list.yaml @@ -339,16 +339,6 @@ lockToDefault: false preRelease: Beta version: "1.33" -- name: CPUCFSQuotaPeriod - versionedSpecs: - - default: false - lockToDefault: false - preRelease: Alpha - version: "1.12" - - default: true - lockToDefault: false - preRelease: GA - version: "1.36" - name: CPUManagerPolicyAlphaOptions versionedSpecs: - default: false @@ -427,6 +417,16 @@ lockToDefault: false preRelease: Alpha version: "1.21" +- name: CustomCPUCFSQuotaPeriod + versionedSpecs: + - default: false + lockToDefault: false + preRelease: Alpha + version: "1.12" + - default: true + lockToDefault: false + preRelease: GA + version: "1.36" - name: CustomResourceFieldSelectors versionedSpecs: - default: false @@ -1739,7 +1739,7 @@ lockToDefault: false preRelease: Beta version: "1.12" -- name: RuntimeClassInImageCriAPI +- name: RuntimeClassInImageCriApi versionedSpecs: - default: false lockToDefault: false diff --git a/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshot-metadata.go b/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshot-metadata.go index ca6e0ce7f2..b864ba13dc 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshot-metadata.go +++ b/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshot-metadata.go @@ -266,7 +266,7 @@ func (s *snapshotMetadataTestSuite) DefineTests(driver storageframework.TestDriv targetDeviceName string ) - f := framework.NewDefaultFramework("snapshotmetadata") + f := framework.NewFrameworkWithCustomTimeouts("snapshotmetadata", storageframework.GetDriverTimeouts(driver)) f.NamespacePodSecurityLevel = admissionapi.LevelPrivileged createBackupClientPod := func(ctx context.Context, source, target *v1.PersistentVolumeClaim) *v1.Pod { diff --git a/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable.go b/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable.go index c8fe3cc585..331adbc02c 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable.go +++ b/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable.go @@ -108,7 +108,7 @@ func (s *snapshottableTestSuite) DefineTests(driver storageframework.TestDriver, // Beware that it also registers an AfterEach which renders f unusable. Any code using // f must run inside an It or Context callback. - f := framework.NewDefaultFramework("snapshotting") + f := framework.NewFrameworkWithCustomTimeouts("snapshotting", storageframework.GetDriverTimeouts(driver)) f.NamespacePodSecurityLevel = admissionapi.LevelPrivileged ginkgo.Describe("volume snapshot controller", func() { diff --git a/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable_stress.go b/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable_stress.go index b381e67c48..289c826d18 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable_stress.go +++ b/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable_stress.go @@ -120,7 +120,7 @@ func (t *snapshottableStressTestSuite) DefineTests(driver storageframework.TestD // Beware that it also registers an AfterEach which renders f unusable. Any code using // f must run inside an It or Context callback. - f := framework.NewDefaultFramework("snapshottable-stress") + f := framework.NewFrameworkWithCustomTimeouts("snapshottable-stress", storageframework.GetDriverTimeouts(driver)) f.NamespacePodSecurityLevel = admissionapi.LevelPrivileged init := func(ctx context.Context) { diff --git a/deps/github.com/openshift/kubernetes/test/e2e/storage/utils/volume_group_snapshot.go b/deps/github.com/openshift/kubernetes/test/e2e/storage/utils/volume_group_snapshot.go index a3ed602030..6c464cb382 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/storage/utils/volume_group_snapshot.go +++ b/deps/github.com/openshift/kubernetes/test/e2e/storage/utils/volume_group_snapshot.go @@ -33,16 +33,16 @@ const ( // VolumeGroupSnapshot is the group snapshot api VolumeGroupSnapshotAPIGroup = "groupsnapshot.storage.k8s.io" // VolumeGroupSnapshotAPIVersion is the group snapshot api version - VolumeGroupSnapshotAPIVersion = "groupsnapshot.storage.k8s.io/v1beta2" + VolumeGroupSnapshotAPIVersion = "groupsnapshot.storage.k8s.io/v1" ) var ( // VolumeGroupSnapshotGVR is GroupVersionResource for volumegroupsnapshots - VolumeGroupSnapshotGVR = schema.GroupVersionResource{Group: VolumeGroupSnapshotAPIGroup, Version: "v1beta2", Resource: "volumegroupsnapshots"} + VolumeGroupSnapshotGVR = schema.GroupVersionResource{Group: VolumeGroupSnapshotAPIGroup, Version: "v1", Resource: "volumegroupsnapshots"} // VolumeGroupSnapshotClassGVR is GroupVersionResource for volumegroupsnapshotsclasses - VolumeGroupSnapshotClassGVR = schema.GroupVersionResource{Group: VolumeGroupSnapshotAPIGroup, Version: "v1beta2", Resource: "volumegroupsnapshotclasses"} - VolumeGroupSnapshotContentGVR = schema.GroupVersionResource{Group: VolumeGroupSnapshotAPIGroup, Version: "v1beta2", Resource: "volumegroupsnapshotcontents"} + VolumeGroupSnapshotClassGVR = schema.GroupVersionResource{Group: VolumeGroupSnapshotAPIGroup, Version: "v1", Resource: "volumegroupsnapshotclasses"} + VolumeGroupSnapshotContentGVR = schema.GroupVersionResource{Group: VolumeGroupSnapshotAPIGroup, Version: "v1", Resource: "volumegroupsnapshotcontents"} ) // WaitForVolumeGroupSnapshotReady waits for a VolumeGroupSnapshot to be ready to use or until timeout occurs, whichever comes first. diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotclasses.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotclasses.yaml index 81299d5ecf..25ecd53595 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotclasses.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotclasses.yaml @@ -174,5 +174,88 @@ spec: - driver type: object served: true + storage: false + subresources: {} + - additionalPrinterColumns: + - jsonPath: .driver + name: Driver + type: string + - description: Determines whether a VolumeGroupSnapshotContent created through + the VolumeGroupSnapshotClass should be deleted when its bound VolumeGroupSnapshot + is deleted. + jsonPath: .deletionPolicy + name: DeletionPolicy + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1 + schema: + openAPIV3Schema: + description: |- + VolumeGroupSnapshotClass specifies parameters that a underlying storage system + uses when creating a volume group snapshot. A specific VolumeGroupSnapshotClass + is used by specifying its name in a VolumeGroupSnapshot object. + VolumeGroupSnapshotClasses are non-namespaced. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + deletionPolicy: + description: |- + DeletionPolicy determines whether a VolumeGroupSnapshotContent created + through the VolumeGroupSnapshotClass should be deleted when its bound + VolumeGroupSnapshot is deleted. + Supported values are "Retain" and "Delete". + "Retain" means that the VolumeGroupSnapshotContent and its physical group + snapshot on underlying storage system are kept. + "Delete" means that the VolumeGroupSnapshotContent and its physical group + snapshot on underlying storage system are deleted. + Required. + enum: + - Delete + - Retain + type: string + x-kubernetes-validations: + - message: deletionPolicy is immutable once set + rule: self == oldSelf + driver: + description: |- + Driver is the name of the storage driver expected to handle this VolumeGroupSnapshotClass. + Required. + type: string + x-kubernetes-validations: + - message: driver is immutable once set + rule: self == oldSelf + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + parameters: + additionalProperties: + type: string + description: |- + Parameters is a key-value map with storage driver specific parameters for + creating group snapshots. + These values are opaque to Kubernetes and are passed directly to the driver. + type: object + x-kubernetes-validations: + - message: parameters are immutable once set + rule: self == oldSelf + required: + - deletionPolicy + - driver + type: object + served: true storage: true subresources: {} diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotcontents.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotcontents.yaml index 235198ac49..09b9ffee83 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotcontents.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotcontents.yaml @@ -656,6 +656,333 @@ spec: - spec type: object served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: Indicates if all the individual snapshots in the group are ready + to be used to restore a group of volumes. + jsonPath: .status.readyToUse + name: ReadyToUse + type: boolean + - description: Determines whether this VolumeGroupSnapshotContent and its physical + group snapshot on the underlying storage system should be deleted when its + bound VolumeGroupSnapshot is deleted. + jsonPath: .spec.deletionPolicy + name: DeletionPolicy + type: string + - description: Name of the CSI driver used to create the physical group snapshot + on the underlying storage system. + jsonPath: .spec.driver + name: Driver + type: string + - description: Name of the VolumeGroupSnapshotClass from which this group snapshot + was (or will be) created. + jsonPath: .spec.volumeGroupSnapshotClassName + name: VolumeGroupSnapshotClass + type: string + - description: Namespace of the VolumeGroupSnapshot object to which this VolumeGroupSnapshotContent + object is bound. + jsonPath: .spec.volumeGroupSnapshotRef.namespace + name: VolumeGroupSnapshotNamespace + type: string + - description: Name of the VolumeGroupSnapshot object to which this VolumeGroupSnapshotContent + object is bound. + jsonPath: .spec.volumeGroupSnapshotRef.name + name: VolumeGroupSnapshot + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1 + schema: + openAPIV3Schema: + description: |- + VolumeGroupSnapshotContent represents the actual "on-disk" group snapshot object + in the underlying storage system + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: |- + Spec defines properties of a VolumeGroupSnapshotContent created by the underlying storage system. + Required. + properties: + deletionPolicy: + description: |- + DeletionPolicy determines whether this VolumeGroupSnapshotContent and the + physical group snapshot on the underlying storage system should be deleted + when the bound VolumeGroupSnapshot is deleted. + Supported values are "Retain" and "Delete". + "Retain" means that the VolumeGroupSnapshotContent and its physical group + snapshot on underlying storage system are kept. + "Delete" means that the VolumeGroupSnapshotContent and its physical group + snapshot on underlying storage system are deleted. + For dynamically provisioned group snapshots, this field will automatically + be filled in by the CSI snapshotter sidecar with the "DeletionPolicy" field + defined in the corresponding VolumeGroupSnapshotClass. + For pre-existing snapshots, users MUST specify this field when creating the + VolumeGroupSnapshotContent object. + Required. + enum: + - Delete + - Retain + type: string + driver: + description: |- + Driver is the name of the CSI driver used to create the physical group snapshot on + the underlying storage system. + This MUST be the same as the name returned by the CSI GetPluginName() call for + that driver. + Required. + type: string + x-kubernetes-validations: + - message: driver is immutable once set + rule: self == oldSelf + source: + description: |- + Source specifies whether the snapshot is (or should be) dynamically provisioned + or already exists, and just requires a Kubernetes object representation. + This field is immutable after creation. + Required. + properties: + groupSnapshotHandles: + description: |- + GroupSnapshotHandles specifies the CSI "group_snapshot_id" of a pre-existing + group snapshot and a list of CSI "snapshot_id" of pre-existing snapshots + on the underlying storage system for which a Kubernetes object + representation was (or should be) created. + This field is immutable. + properties: + volumeGroupSnapshotHandle: + description: |- + VolumeGroupSnapshotHandle specifies the CSI "group_snapshot_id" of a pre-existing + group snapshot on the underlying storage system for which a Kubernetes object + representation was (or should be) created. + This field is immutable. + Required. + type: string + volumeSnapshotHandles: + description: |- + VolumeSnapshotHandles is a list of CSI "snapshot_id" of pre-existing + snapshots on the underlying storage system for which Kubernetes objects + representation were (or should be) created. + This field is immutable. + Required. + items: + type: string + type: array + required: + - volumeGroupSnapshotHandle + - volumeSnapshotHandles + type: object + x-kubernetes-validations: + - message: groupSnapshotHandles is immutable + rule: self == oldSelf + volumeHandles: + description: |- + VolumeHandles is a list of volume handles on the backend to be snapshotted + together. It is specified for dynamic provisioning of the VolumeGroupSnapshot. + This field is immutable. + items: + type: string + type: array + x-kubernetes-validations: + - message: volumeHandles is immutable + rule: self == oldSelf + type: object + x-kubernetes-validations: + - message: volumeHandles is required once set + rule: '!has(oldSelf.volumeHandles) || has(self.volumeHandles)' + - message: groupSnapshotHandles is required once set + rule: '!has(oldSelf.groupSnapshotHandles) || has(self.groupSnapshotHandles)' + - message: exactly one of volumeHandles and groupSnapshotHandles must + be set + rule: (has(self.volumeHandles) && !has(self.groupSnapshotHandles)) + || (!has(self.volumeHandles) && has(self.groupSnapshotHandles)) + volumeGroupSnapshotClassName: + description: |- + VolumeGroupSnapshotClassName is the name of the VolumeGroupSnapshotClass from + which this group snapshot was (or will be) created. + Note that after provisioning, the VolumeGroupSnapshotClass may be deleted or + recreated with different set of values, and as such, should not be referenced + post-snapshot creation. + For dynamic provisioning, this field must be set. + This field may be unset for pre-provisioned snapshots. + type: string + x-kubernetes-validations: + - message: volumeGroupSnapshotClassName is immutable once set + rule: self == oldSelf + volumeGroupSnapshotRef: + description: |- + VolumeGroupSnapshotRef specifies the VolumeGroupSnapshot object to which this + VolumeGroupSnapshotContent object is bound. + VolumeGroupSnapshot.Spec.VolumeGroupSnapshotContentName field must reference to + this VolumeGroupSnapshotContent's name for the bidirectional binding to be valid. + For a pre-existing VolumeGroupSnapshotContent object, name and namespace of the + VolumeGroupSnapshot object MUST be provided for binding to happen. + This field is immutable after creation. + Required. + properties: + apiVersion: + description: API version of the referent. + type: string + fieldPath: + description: |- + If referring to a piece of an object instead of an entire object, this string + should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2]. + For example, if the object reference is to a container within a pod, this would take on a value like: + "spec.containers{name}" (where "name" refers to the name of the container that triggered + the event) or if no container name is specified "spec.containers[2]" (container with + index 2 in this pod). This syntax is chosen only to have some well-defined way of + referencing a part of an object. + TODO: this design is not final and this field is subject to change in the future. + type: string + kind: + description: |- + Kind of the referent. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + name: + description: |- + Name of the referent. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + type: string + namespace: + description: |- + Namespace of the referent. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/ + type: string + resourceVersion: + description: |- + Specific resourceVersion to which this reference is made, if any. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency + type: string + uid: + description: |- + UID of the referent. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids + type: string + type: object + x-kubernetes-map-type: atomic + x-kubernetes-validations: + - message: both volumeGroupSnapshotRef.name and volumeGroupSnapshotRef.namespace + must be set + rule: has(self.name) && has(self.__namespace__) + - message: volumeGroupSnapshotRef.name and volumeGroupSnapshotRef.namespace + are immutable + rule: self.name == oldSelf.name && self.__namespace__ == oldSelf.__namespace__ + - message: volumeGroupSnapshotRef.uid is immutable once set + rule: '!has(oldSelf.uid) || (has(self.uid) && self.uid == oldSelf.uid)' + required: + - deletionPolicy + - driver + - source + - volumeGroupSnapshotRef + type: object + status: + description: status represents the current information of a group snapshot. + properties: + creationTime: + description: |- + CreationTime is the timestamp when the point-in-time group snapshot is taken + by the underlying storage system. + If not specified, it indicates the creation time is unknown. + If not specified, it means the readiness of a group snapshot is unknown. + This field is the source for the CreationTime field in VolumeGroupSnapshotStatus + format: date-time + type: string + error: + description: |- + Error is the last observed error during group snapshot creation, if any. + Upon success after retry, this error field will be cleared. + properties: + message: + description: |- + message is a string detailing the encountered error during snapshot + creation if specified. + NOTE: message may be logged, and it should not contain sensitive + information. + type: string + time: + description: time is the timestamp when the error was encountered. + format: date-time + type: string + type: object + readyToUse: + description: |- + ReadyToUse indicates if all the individual snapshots in the group are ready to be + used to restore a group of volumes. + ReadyToUse becomes true when ReadyToUse of all individual snapshots become true. + type: boolean + volumeGroupSnapshotHandle: + description: |- + VolumeGroupSnapshotHandle is a unique id returned by the CSI driver + to identify the VolumeGroupSnapshot on the storage system. + If a storage system does not provide such an id, the + CSI driver can choose to return the VolumeGroupSnapshot name. + type: string + x-kubernetes-validations: + - message: volumeGroupSnapshotHandle is immutable once set + rule: self == oldSelf + volumeSnapshotInfoList: + description: |- + This field is introduced in v1beta2 + It is replacing VolumeSnapshotHandlePairList + VolumeSnapshotInfoList is a list of snapshot information returned by + by the CSI driver to identify snapshots on the storage system. + items: + description: |- + The VolumeSnapshotInfo struct is added in v1beta2 + VolumeSnapshotInfo contains information for a snapshot + properties: + creationTime: + description: |- + creationTime is the timestamp when the point-in-time snapshot is taken + by the underlying storage system. + format: int64 + type: integer + readyToUse: + description: ReadyToUse indicates if the snapshot is ready to + be used to restore a volume. + type: boolean + restoreSize: + description: |- + RestoreSize represents the minimum size of volume required to create a volume + from this snapshot. + format: int64 + type: integer + snapshotHandle: + description: SnapshotHandle is the CSI "snapshot_id" of this + snapshot on the underlying storage system. + type: string + volumeHandle: + description: |- + VolumeHandle specifies the CSI "volume_id" of the volume from which this snapshot + was taken from. + type: string + type: object + type: array + type: object + required: + - spec + type: object + served: true storage: true subresources: status: {} diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshots.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshots.yaml index 3f8c4909aa..9e7315dfde 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshots.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshots.yaml @@ -455,6 +455,226 @@ spec: - spec type: object served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: Indicates if all the individual snapshots in the group are ready + to be used to restore a group of volumes. + jsonPath: .status.readyToUse + name: ReadyToUse + type: boolean + - description: The name of the VolumeGroupSnapshotClass requested by the VolumeGroupSnapshot. + jsonPath: .spec.volumeGroupSnapshotClassName + name: VolumeGroupSnapshotClass + type: string + - description: Name of the VolumeGroupSnapshotContent object to which the VolumeGroupSnapshot + object intends to bind to. Please note that verification of binding actually + requires checking both VolumeGroupSnapshot and VolumeGroupSnapshotContent + to ensure both are pointing at each other. Binding MUST be verified prior + to usage of this object. + jsonPath: .status.boundVolumeGroupSnapshotContentName + name: VolumeGroupSnapshotContent + type: string + - description: Timestamp when the point-in-time group snapshot was taken by the + underlying storage system. + jsonPath: .status.creationTime + name: CreationTime + type: date + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1 + schema: + openAPIV3Schema: + description: |- + VolumeGroupSnapshot is a user's request for creating either a point-in-time + group snapshot or binding to a pre-existing group snapshot. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: |- + Spec defines the desired characteristics of a group snapshot requested by a user. + Required. + properties: + source: + description: |- + Source specifies where a group snapshot will be created from. + This field is immutable after creation. + Required. + properties: + selector: + description: |- + Selector is a label query over persistent volume claims that are to be + grouped together for snapshotting. + This labelSelector will be used to match the label added to a PVC. + If the label is added or removed to a volume after a group snapshot + is created, the existing group snapshots won't be modified. + Once a VolumeGroupSnapshotContent is created and the sidecar starts to process + it, the volume list will not change with retries. + properties: + matchExpressions: + description: matchExpressions is a list of label selector + requirements. The requirements are ANDed. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key that the selector + applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + matchLabels: + additionalProperties: + type: string + description: |- + matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, whose key field is "key", the + operator is "In", and the values array contains only "value". The requirements are ANDed. + type: object + type: object + x-kubernetes-map-type: atomic + x-kubernetes-validations: + - message: selector is immutable + rule: self == oldSelf + volumeGroupSnapshotContentName: + description: |- + VolumeGroupSnapshotContentName specifies the name of a pre-existing VolumeGroupSnapshotContent + object representing an existing volume group snapshot. + This field should be set if the volume group snapshot already exists and + only needs a representation in Kubernetes. + This field is immutable. + type: string + x-kubernetes-validations: + - message: volumeGroupSnapshotContentName is immutable + rule: self == oldSelf + type: object + x-kubernetes-validations: + - message: selector is required once set + rule: '!has(oldSelf.selector) || has(self.selector)' + - message: volumeGroupSnapshotContentName is required once set + rule: '!has(oldSelf.volumeGroupSnapshotContentName) || has(self.volumeGroupSnapshotContentName)' + - message: exactly one of selector and volumeGroupSnapshotContentName + must be set + rule: (has(self.selector) && !has(self.volumeGroupSnapshotContentName)) + || (!has(self.selector) && has(self.volumeGroupSnapshotContentName)) + volumeGroupSnapshotClassName: + description: |- + VolumeGroupSnapshotClassName is the name of the VolumeGroupSnapshotClass + requested by the VolumeGroupSnapshot. + VolumeGroupSnapshotClassName may be left nil to indicate that the default + class will be used. + Empty string is not allowed for this field. + type: string + x-kubernetes-validations: + - message: volumeGroupSnapshotClassName must not be the empty string + when set + rule: size(self) > 0 + required: + - source + type: object + status: + description: |- + Status represents the current information of a group snapshot. + Consumers must verify binding between VolumeGroupSnapshot and + VolumeGroupSnapshotContent objects is successful (by validating that both + VolumeGroupSnapshot and VolumeGroupSnapshotContent point to each other) before + using this object. + properties: + boundVolumeGroupSnapshotContentName: + description: |- + BoundVolumeGroupSnapshotContentName is the name of the VolumeGroupSnapshotContent + object to which this VolumeGroupSnapshot object intends to bind to. + If not specified, it indicates that the VolumeGroupSnapshot object has not + been successfully bound to a VolumeGroupSnapshotContent object yet. + NOTE: To avoid possible security issues, consumers must verify binding between + VolumeGroupSnapshot and VolumeGroupSnapshotContent objects is successful + (by validating that both VolumeGroupSnapshot and VolumeGroupSnapshotContent + point at each other) before using this object. + type: string + x-kubernetes-validations: + - message: boundVolumeGroupSnapshotContentName is immutable once set + rule: self == oldSelf + creationTime: + description: |- + CreationTime is the timestamp when the point-in-time group snapshot is taken + by the underlying storage system. + If not specified, it may indicate that the creation time of the group snapshot + is unknown. + This field is updated based on the CreationTime field in VolumeGroupSnapshotContentStatus + format: date-time + type: string + error: + description: |- + Error is the last observed error during group snapshot creation, if any. + This field could be helpful to upper level controllers (i.e., application + controller) to decide whether they should continue on waiting for the group + snapshot to be created based on the type of error reported. + The snapshot controller will keep retrying when an error occurs during the + group snapshot creation. Upon success, this error field will be cleared. + properties: + message: + description: |- + message is a string detailing the encountered error during snapshot + creation if specified. + NOTE: message may be logged, and it should not contain sensitive + information. + type: string + time: + description: time is the timestamp when the error was encountered. + format: date-time + type: string + type: object + readyToUse: + description: |- + ReadyToUse indicates if all the individual snapshots in the group are ready + to be used to restore a group of volumes. + ReadyToUse becomes true when ReadyToUse of all individual snapshots become true. + If not specified, it means the readiness of a group snapshot is unknown. + type: boolean + type: object + required: + - spec + type: object + served: true storage: true subresources: status: {} diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/csi-hostpath-plugin.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/csi-hostpath-plugin.yaml index 4a50349cd4..c8e54f3a53 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/csi-hostpath-plugin.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/csi-hostpath-plugin.yaml @@ -262,7 +262,7 @@ spec: name: dev-dir - name: csi-external-health-monitor-controller - image: registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.17.0 + image: registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.18.0 args: - "--v=5" - "--csi-address=$(ADDRESS)" @@ -276,11 +276,12 @@ spec: mountPath: /csi - name: node-driver-registrar - image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0 + image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0 args: - --v=5 - --csi-address=/csi/csi.sock - --kubelet-registration-path=/var/lib/kubelet/plugins/csi-hostpath/csi.sock + - --http-endpoint=:9809 securityContext: # This is necessary only for systems with SELinux, where # non-privileged sidecar containers cannot access unix domain socket @@ -292,6 +293,18 @@ spec: fieldRef: apiVersion: v1 fieldPath: spec.nodeName + ports: + - containerPort: 9809 + name: healthz + protocol: TCP + livenessProbe: + httpGet: + path: /healthz + port: healthz + initialDelaySeconds: 30 + timeoutSeconds: 15 + periodSeconds: 10 + failureThreshold: 3 volumeMounts: - mountPath: /csi name: socket-dir @@ -304,13 +317,13 @@ spec: volumeMounts: - mountPath: /csi name: socket-dir - image: registry.k8s.io/sig-storage/livenessprobe:v2.18.0 + image: registry.k8s.io/sig-storage/livenessprobe:v2.19.0 args: - --csi-address=/csi/csi.sock - --health-port=9898 - name: csi-attacher - image: registry.k8s.io/sig-storage/csi-attacher:v4.11.0 + image: registry.k8s.io/sig-storage/csi-attacher:v4.12.0 args: - --v=5 - --csi-address=/csi/csi.sock @@ -324,7 +337,7 @@ spec: name: socket-dir - name: csi-provisioner - image: registry.k8s.io/sig-storage/csi-provisioner:v6.1.1 + image: registry.k8s.io/sig-storage/csi-provisioner:v6.3.0 args: - -v=5 - --csi-address=/csi/csi.sock @@ -340,7 +353,7 @@ spec: name: socket-dir - name: csi-resizer - image: registry.k8s.io/sig-storage/csi-resizer:v2.1.0 + image: registry.k8s.io/sig-storage/csi-resizer:v2.2.0 args: - -v=5 - -csi-address=/csi/csi.sock @@ -354,7 +367,7 @@ spec: name: socket-dir - name: csi-snapshotter - image: registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0 + image: registry.k8s.io/sig-storage/csi-snapshotter:v8.6.0 args: - -v=5 - --csi-address=/csi/csi.sock diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/run_group_snapshot_e2e.sh b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/run_group_snapshot_e2e.sh index 8d39c1ba44..40f0586dc9 100755 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/run_group_snapshot_e2e.sh +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/run_group_snapshot_e2e.sh @@ -244,7 +244,7 @@ run_tests() { export KUBE_CONTAINER_RUNTIME=remote export KUBE_CONTAINER_RUNTIME_ENDPOINT=unix:///run/containerd/containerd.sock export KUBE_CONTAINER_RUNTIME_NAME=containerd - export SNAPSHOTTER_VERSION="${SNAPSHOTTER_VERSION:-v8.4.0}" + export SNAPSHOTTER_VERSION="${SNAPSHOTTER_VERSION:-v8.6.0}" echo "SNAPSHOTTER_VERSION is $SNAPSHOTTER_VERSION" # Enable VolumeGroupSnapshot tests in csi-driver-hostpath diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/controller_ss.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/controller_ss.yaml index 9f7809b08b..6d7cbbf131 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/controller_ss.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/controller_ss.yaml @@ -21,7 +21,7 @@ spec: serviceAccountName: csi-gce-pd-controller-sa containers: - name: csi-snapshotter - image: registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0 + image: registry.k8s.io/sig-storage/csi-snapshotter:v8.6.0 args: - "--v=5" - "--csi-address=/csi/csi.sock" @@ -39,7 +39,7 @@ spec: - name: socket-dir mountPath: /csi - name: csi-provisioner - image: registry.k8s.io/sig-storage/csi-provisioner:v5.2.0 + image: registry.k8s.io/sig-storage/csi-provisioner:v6.3.0 args: - "--v=5" - "--csi-address=/csi/csi.sock" @@ -73,7 +73,7 @@ spec: - name: socket-dir mountPath: /csi - name: csi-attacher - image: registry.k8s.io/sig-storage/csi-attacher:v4.8.1 + image: registry.k8s.io/sig-storage/csi-attacher:v4.12.0 args: - "--v=5" - "--csi-address=/csi/csi.sock" @@ -102,7 +102,7 @@ spec: - name: socket-dir mountPath: /csi - name: csi-resizer - image: registry.k8s.io/sig-storage/csi-resizer:v1.13.1 + image: registry.k8s.io/sig-storage/csi-resizer:v2.2.0 args: - "--v=5" - "--csi-address=/csi/csi.sock" diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/node_ds.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/node_ds.yaml index 99d9f9ce2a..36c6e6ef12 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/node_ds.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/node_ds.yaml @@ -13,7 +13,7 @@ spec: spec: containers: - name: csi-driver-registrar - image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0 + image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0 args: - "--v=5" - "--csi-address=/csi/csi.sock" diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/hostpath/hostpath/csi-hostpath-plugin.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/hostpath/hostpath/csi-hostpath-plugin.yaml index 2fe67ffb71..1dd8d161b4 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/hostpath/hostpath/csi-hostpath-plugin.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/hostpath/hostpath/csi-hostpath-plugin.yaml @@ -281,7 +281,7 @@ spec: name: dev-dir - name: csi-external-health-monitor-controller - image: registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.17.0 + image: registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.18.0 args: - "--v=5" - "--csi-address=$(ADDRESS)" @@ -295,11 +295,12 @@ spec: mountPath: /csi - name: node-driver-registrar - image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0 + image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0 args: - --v=5 - --csi-address=/csi/csi.sock - --kubelet-registration-path=/var/lib/kubelet/plugins/csi-hostpath/csi.sock + - --http-endpoint=:9809 securityContext: # This is necessary only for systems with SELinux, where # non-privileged sidecar containers cannot access unix domain socket @@ -311,6 +312,18 @@ spec: fieldRef: apiVersion: v1 fieldPath: spec.nodeName + ports: + - containerPort: 9809 + name: healthz + protocol: TCP + livenessProbe: + httpGet: + path: /healthz + port: healthz + initialDelaySeconds: 30 + timeoutSeconds: 15 + periodSeconds: 10 + failureThreshold: 3 volumeMounts: - mountPath: /csi name: socket-dir @@ -323,13 +336,13 @@ spec: volumeMounts: - mountPath: /csi name: socket-dir - image: registry.k8s.io/sig-storage/livenessprobe:v2.18.0 + image: registry.k8s.io/sig-storage/livenessprobe:v2.19.0 args: - --csi-address=/csi/csi.sock - --health-port=9898 - name: csi-attacher - image: registry.k8s.io/sig-storage/csi-attacher:v4.11.0 + image: registry.k8s.io/sig-storage/csi-attacher:v4.12.0 args: - --v=5 - --csi-address=/csi/csi.sock @@ -343,7 +356,7 @@ spec: name: socket-dir - name: csi-provisioner - image: registry.k8s.io/sig-storage/csi-provisioner:v6.1.1 + image: registry.k8s.io/sig-storage/csi-provisioner:v6.3.0 args: - -v=5 - --csi-address=/csi/csi.sock @@ -359,7 +372,7 @@ spec: name: socket-dir - name: csi-resizer - image: registry.k8s.io/sig-storage/csi-resizer:v2.1.0 + image: registry.k8s.io/sig-storage/csi-resizer:v2.2.0 args: - -v=5 - -csi-address=/csi/csi.sock @@ -373,7 +386,7 @@ spec: name: socket-dir - name: csi-snapshotter - image: registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0 + image: registry.k8s.io/sig-storage/csi-snapshotter:v8.6.0 args: - -v=5 - --csi-address=/csi/csi.sock @@ -387,7 +400,7 @@ spec: name: socket-dir - name: csi-snapshot-metadata - image: registry.k8s.io/sig-storage/csi-snapshot-metadata:v0.2.0 + image: registry.k8s.io/sig-storage/csi-snapshot-metadata:v1.0.0 imagePullPolicy: IfNotPresent args: - --csi-address=/csi/csi.sock diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-attacher.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-attacher.yaml index 40a2a58587..84210e1a22 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-attacher.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-attacher.yaml @@ -15,7 +15,7 @@ spec: serviceAccountName: csi-mock containers: - name: csi-attacher - image: registry.k8s.io/sig-storage/csi-attacher:v4.11.0 + image: registry.k8s.io/sig-storage/csi-attacher:v4.12.0 args: - --v=5 - --csi-address=$(ADDRESS) diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-resizer.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-resizer.yaml index 7415c5eade..b87541894f 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-resizer.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-resizer.yaml @@ -15,7 +15,7 @@ spec: serviceAccountName: csi-mock containers: - name: csi-resizer - image: registry.k8s.io/sig-storage/csi-resizer:v2.1.0 + image: registry.k8s.io/sig-storage/csi-resizer:v2.2.0 args: - "--v=5" - "--csi-address=$(ADDRESS)" diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-snapshotter.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-snapshotter.yaml index 130721db8d..9bd0a110b3 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-snapshotter.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-snapshotter.yaml @@ -15,7 +15,7 @@ spec: serviceAccountName: csi-mock containers: - name: csi-snapshotter - image: registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0 + image: registry.k8s.io/sig-storage/csi-snapshotter:v8.6.0 args: - "--v=5" - "--csi-address=$(ADDRESS)" diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver.yaml index 5f85ae7422..c2c331a552 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver.yaml @@ -15,7 +15,7 @@ spec: serviceAccountName: csi-mock containers: - name: csi-provisioner - image: registry.k8s.io/sig-storage/csi-provisioner:v6.1.1 + image: registry.k8s.io/sig-storage/csi-provisioner:v6.3.0 args: - "--csi-address=$(ADDRESS)" # Topology support is needed for the pod rescheduling test @@ -34,11 +34,12 @@ spec: - mountPath: /csi name: socket-dir - name: driver-registrar - image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0 + image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0 args: - --v=5 - --csi-address=/csi/csi.sock - --kubelet-registration-path=/var/lib/kubelet/plugins/csi-mock/csi.sock + - --http-endpoint=:9809 env: - name: KUBE_NODE_NAME valueFrom: @@ -47,6 +48,18 @@ spec: fieldPath: spec.nodeName securityContext: privileged: true + ports: + - containerPort: 9809 + name: healthz + protocol: TCP + livenessProbe: + httpGet: + path: /healthz + port: healthz + initialDelaySeconds: 30 + timeoutSeconds: 15 + periodSeconds: 10 + failureThreshold: 3 volumeMounts: - mountPath: /csi name: socket-dir diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-proxy.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-proxy.yaml index 956adbf70a..5fad68e0a3 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-proxy.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-proxy.yaml @@ -15,7 +15,7 @@ spec: serviceAccountName: csi-mock containers: - name: csi-provisioner - image: registry.k8s.io/sig-storage/csi-provisioner:v6.1.1 + image: registry.k8s.io/sig-storage/csi-provisioner:v6.3.0 args: - "--csi-address=$(ADDRESS)" # Topology support is needed for the pod rescheduling test @@ -35,18 +35,31 @@ spec: - mountPath: /csi name: socket-dir - name: driver-registrar - image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0 + image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0 args: - --v=5 - --csi-address=/csi/csi.sock - --kubelet-registration-path=/var/lib/kubelet/plugins/csi-mock/csi.sock - --timeout=1m + - --http-endpoint=:9809 env: - name: KUBE_NODE_NAME valueFrom: fieldRef: apiVersion: v1 fieldPath: spec.nodeName + ports: + - containerPort: 9809 + name: healthz + protocol: TCP + livenessProbe: + httpGet: + path: /healthz + port: healthz + initialDelaySeconds: 30 + timeoutSeconds: 15 + periodSeconds: 10 + failureThreshold: 3 volumeMounts: - mountPath: /csi name: socket-dir diff --git a/deps/github.com/openshift/kubernetes/test/integration/dra/device_taints.go b/deps/github.com/openshift/kubernetes/test/integration/dra/device_taints.go index 958d029b8a..ef52b044f8 100644 --- a/deps/github.com/openshift/kubernetes/test/integration/dra/device_taints.go +++ b/deps/github.com/openshift/kubernetes/test/integration/dra/device_taints.go @@ -37,6 +37,7 @@ import ( "k8s.io/client-go/tools/cache" "k8s.io/kubernetes/pkg/controller/devicetainteviction" "k8s.io/kubernetes/pkg/features" + st "k8s.io/kubernetes/pkg/scheduler/testing" "k8s.io/kubernetes/test/utils/ktesting" "k8s.io/utils/ptr" ) @@ -403,3 +404,94 @@ func testEvictCluster(tCtx ktesting.TContext, useRule useRuleMode) { })))) } } + +func testNoScheduleRule(tCtx ktesting.TContext, useRule useRuleMode) { + tCtx.Parallel() + + startScheduler(tCtx) + + namespace := createTestNamespace(tCtx, nil) + class, driverName := createTestClass(tCtx, namespace) + slice := st.MakeResourceSlice("worker-0", driverName).Devices(device1) + + taintKey := "testing" + ruleName := "rule-" + namespace + switch useRule { + case useV1alpha3Rule: + rule := &resourcealpha.DeviceTaintRule{ + ObjectMeta: metav1.ObjectMeta{ + Name: ruleName, + }, + Spec: resourcealpha.DeviceTaintRuleSpec{ + DeviceSelector: &resourcealpha.DeviceTaintSelector{ + Driver: &driverName, + }, + Taint: resourcealpha.DeviceTaint{ + Key: taintKey, + Effect: resourcealpha.DeviceTaintEffectNoSchedule, + }, + }, + } + _ = must(tCtx, tCtx.Client().ResourceV1alpha3().DeviceTaintRules().Create, rule, metav1.CreateOptions{}) + tCtx.CleanupCtx(func(tCtx ktesting.TContext) { + err := tCtx.Client().ResourceV1alpha3().DeviceTaintRules().Delete(tCtx, ruleName, metav1.DeleteOptions{}) + if apierrors.IsNotFound(err) { + return + } + tCtx.ExpectNoError(err) + }) + case useV1beta2Rule: + rule := &resourcebeta.DeviceTaintRule{ + ObjectMeta: metav1.ObjectMeta{ + Name: ruleName, + }, + Spec: resourcebeta.DeviceTaintRuleSpec{ + DeviceSelector: &resourcebeta.DeviceTaintSelector{ + Driver: &driverName, + }, + Taint: resourcebeta.DeviceTaint{ + Key: taintKey, + Effect: resourcebeta.DeviceTaintEffectNoSchedule, + }, + }, + } + _ = must(tCtx, tCtx.Client().ResourceV1beta2().DeviceTaintRules().Create, rule, metav1.CreateOptions{}) + tCtx.CleanupCtx(func(tCtx ktesting.TContext) { + err := tCtx.Client().ResourceV1beta2().DeviceTaintRules().Delete(tCtx, ruleName, metav1.DeleteOptions{}) + if apierrors.IsNotFound(err) { + return + } + tCtx.ExpectNoError(err) + }) + case useNoRule: + slice.Spec.Devices[0].Taints = []resourceapi.DeviceTaint{ + { + Key: taintKey, + Effect: resourceapi.DeviceTaintEffectNoSchedule, + }, + } + } + + // Creating the ResourceSlice after the DeviceTaintRule exercises additional + // code paths in the ResourceSlice tracker. + _ = createSlice(tCtx, slice.Obj()) + + pod := st.MakePod().Name(podName).Namespace(namespace). + Container("my-container"). + Obj() + + untoleratingClaim := createClaim(tCtx, namespace, "-untolerating", class, claim) + untoleratingPod := createPod(tCtx, namespace, "-untolerating", pod, untoleratingClaim) + expectPodUnschedulable(tCtx, untoleratingPod, "cannot allocate all claims") + + toleratingClaim := claim.DeepCopy() + toleratingClaim.Spec.Devices.Requests[0].Exactly.Tolerations = []resourceapi.DeviceToleration{ + { + Key: taintKey, + Effect: resourceapi.DeviceTaintEffectNoSchedule, + }, + } + _ = createClaim(tCtx, namespace, "-tolerating", class, toleratingClaim) + toleratingPod := createPod(tCtx, namespace, "-tolerating", pod) + waitForPodScheduled(tCtx, namespace, toleratingPod.Name) +} diff --git a/deps/github.com/openshift/kubernetes/test/integration/dra/dra.go b/deps/github.com/openshift/kubernetes/test/integration/dra/dra.go index e8c7d76cf7..fc3e4fd1c2 100644 --- a/deps/github.com/openshift/kubernetes/test/integration/dra/dra.go +++ b/deps/github.com/openshift/kubernetes/test/integration/dra/dra.go @@ -134,6 +134,7 @@ func run(tCtx ktesting.TContext, whatRE string) { f: func(tCtx ktesting.TContext) { runSubTest(tCtx, "Pod", func(tCtx ktesting.TContext) { testPod(tCtx, true) }) runSubTest(tCtx, "EvictClusterWithSlices", func(tCtx ktesting.TContext) { testEvictCluster(tCtx, useNoRule) }) + runSubTest(tCtx, "NoScheduleWithSlices", func(tCtx ktesting.TContext) { testNoScheduleRule(tCtx, useNoRule) }) // Number of devices per slice is chosen so that Filter takes a few seconds: // without a timeout, the test doesn't run too long, but long enough that a short timeout triggers. runSubTest(tCtx, "FilterTimeout", func(tCtx ktesting.TContext) { testFilterTimeout(tCtx, 21) }) @@ -249,6 +250,9 @@ func run(tCtx ktesting.TContext, whatRE string) { runSubTest(tCtx, "EvictClusterWithV1alpha3Rule", func(tCtx ktesting.TContext) { testEvictCluster(tCtx, useV1alpha3Rule) }) runSubTest(tCtx, "EvictClusterWithV1beta2Rule", func(tCtx ktesting.TContext) { testEvictCluster(tCtx, useV1beta2Rule) }) runSubTest(tCtx, "EvictClusterWithSlices", func(tCtx ktesting.TContext) { testEvictCluster(tCtx, useNoRule) }) + runSubTest(tCtx, "NoScheduleWithV1alpha3Rule", func(tCtx ktesting.TContext) { testNoScheduleRule(tCtx, useV1alpha3Rule) }) + runSubTest(tCtx, "NoScheduleWithV1beta2Rule", func(tCtx ktesting.TContext) { testNoScheduleRule(tCtx, useV1beta2Rule) }) + runSubTest(tCtx, "NoScheduleWithSlices", func(tCtx ktesting.TContext) { testNoScheduleRule(tCtx, useNoRule) }) runSubTest(tCtx, "InvalidResourceSlices", testInvalidResourceSlices) // Number of devices per slice is chosen so that Filter takes a few seconds: The allocator // in the experimental channel has an improvement that requires a higher number here than diff --git a/deps/github.com/openshift/kubernetes/test/utils/image/manifest.go b/deps/github.com/openshift/kubernetes/test/utils/image/manifest.go index eeb6a79de2..06682ec1de 100644 --- a/deps/github.com/openshift/kubernetes/test/utils/image/manifest.go +++ b/deps/github.com/openshift/kubernetes/test/utils/image/manifest.go @@ -214,7 +214,7 @@ func initImageConfigs(list RegistryList) (map[ImageID]Config, map[ImageID]Config configs[APIServer] = Config{list.PromoterE2eRegistry, "sample-apiserver", "1.29.2"} configs[AppArmorLoader] = Config{list.PromoterE2eRegistry, "apparmor-loader", "1.4"} configs[BusyBox] = Config{list.PromoterE2eRegistry, "busybox", "1.37.0-1"} - configs[DistrolessIptables] = Config{list.BuildImageRegistry, "distroless-iptables", "v0.9.3"} + configs[DistrolessIptables] = Config{list.BuildImageRegistry, "distroless-iptables", "v0.9.6"} configs[Etcd] = Config{list.GcEtcdRegistry, "etcd", "3.6.8-0"} configs[InvalidRegistryImage] = Config{list.InvalidRegistry, "alpine", "3.1"} configs[IpcUtils] = Config{list.PromoterE2eRegistry, "ipc-utils", "1.4"} diff --git a/deps/github.com/openshift/kubernetes/vendor/modules.txt b/deps/github.com/openshift/kubernetes/vendor/modules.txt index 3c989a7236..2d27d4f8c9 100644 --- a/deps/github.com/openshift/kubernetes/vendor/modules.txt +++ b/deps/github.com/openshift/kubernetes/vendor/modules.txt @@ -1623,7 +1623,7 @@ sigs.k8s.io/kustomize/kyaml/yaml/walk ## explicit; go 1.18 sigs.k8s.io/randfill sigs.k8s.io/randfill/bytesource -# sigs.k8s.io/structured-merge-diff/v6 v6.3.2 +# sigs.k8s.io/structured-merge-diff/v6 v6.3.3 ## explicit; go 1.23 sigs.k8s.io/structured-merge-diff/v6/fieldpath sigs.k8s.io/structured-merge-diff/v6/merge diff --git a/deps/github.com/openshift/kubernetes/vendor/sigs.k8s.io/structured-merge-diff/v6/typed/remove.go b/deps/github.com/openshift/kubernetes/vendor/sigs.k8s.io/structured-merge-diff/v6/typed/remove.go index 0db1734f94..78ba6f50d0 100644 --- a/deps/github.com/openshift/kubernetes/vendor/sigs.k8s.io/structured-merge-diff/v6/typed/remove.go +++ b/deps/github.com/openshift/kubernetes/vendor/sigs.k8s.io/structured-merge-diff/v6/typed/remove.go @@ -75,7 +75,6 @@ func (w *removingWalker) doList(t *schema.List) (errs ValidationErrors) { } var newItems []interface{} - hadMatches := false iter := l.RangeUsing(w.allocator) defer w.allocator.Free(iter) for iter.Next() { @@ -99,26 +98,12 @@ func (w *removingWalker) doList(t *schema.List) (errs ValidationErrors) { continue } if isPrefixMatch { - // Removing nested items within this list item and preserve if it becomes empty - hadMatches = true - wasMap := item.IsMap() - wasList := item.IsList() item = removeItemsWithSchema(item, w.toRemove.WithPrefix(pe), w.schema, t.ElementType, w.shouldExtract) - // If item returned null but we're removing items within the structure(not the item itself), - // preserve the empty container structure - if item.IsNull() && !w.shouldExtract { - if wasMap { - item = value.NewValueInterface(map[string]interface{}{}) - } else if wasList { - item = value.NewValueInterface([]interface{}{}) - } - } } newItems = append(newItems, item.Unstructured()) } } - // Preserve empty lists (non-nil) instead of converting to null when items were matched and removed - if len(newItems) > 0 || (hadMatches && !w.shouldExtract) { + if len(newItems) > 0 { w.out = newItems } return nil @@ -156,7 +141,6 @@ func (w *removingWalker) doMap(t *schema.Map) ValidationErrors { } newMap := map[string]interface{}{} - hadMatches := false m.Iterate(func(k string, val value.Value) bool { pe := fieldpath.PathElement{FieldName: &k} path, _ := fieldpath.MakePath(pe) @@ -174,19 +158,7 @@ func (w *removingWalker) doMap(t *schema.Map) ValidationErrors { return true } if subset := w.toRemove.WithPrefix(pe); !subset.Empty() { - hadMatches = true - wasMap := val.IsMap() - wasList := val.IsList() val = removeItemsWithSchema(val, subset, w.schema, fieldType, w.shouldExtract) - // If val returned null but we're removing items within the structure (not the field itself), - // preserve the empty container structure - if val.IsNull() && !w.shouldExtract { - if wasMap { - val = value.NewValueInterface(map[string]interface{}{}) - } else if wasList { - val = value.NewValueInterface([]interface{}{}) - } - } } else { // don't save values not on the path when we shouldExtract. if w.shouldExtract { @@ -196,8 +168,7 @@ func (w *removingWalker) doMap(t *schema.Map) ValidationErrors { newMap[k] = val.Unstructured() return true }) - // Preserve empty maps (non-nil) instead of converting to null when items were matched and removed - if len(newMap) > 0 || (hadMatches && !w.shouldExtract) { + if len(newMap) > 0 { w.out = newMap } return nil diff --git a/etcd/go.mod b/etcd/go.mod index 8651ad73c6..ac4fd56a42 100644 --- a/etcd/go.mod +++ b/etcd/go.mod @@ -11,11 +11,11 @@ require ( github.com/spf13/cobra v1.10.2 go.etcd.io/etcd/api/v3 v3.6.13 go.etcd.io/etcd/server/v3 v3.6.8 - k8s.io/apimachinery v1.36.2 - k8s.io/cli-runtime v1.36.2 - k8s.io/component-base v1.36.2 + k8s.io/apimachinery v1.36.3 + k8s.io/cli-runtime v1.36.3 + k8s.io/component-base v1.36.3 k8s.io/klog/v2 v2.140.0 - k8s.io/kubectl v1.36.2 + k8s.io/kubectl v1.36.3 sigs.k8s.io/yaml v1.6.0 ) @@ -119,7 +119,7 @@ require ( golang.org/x/net v0.56.0 // indirect golang.org/x/oauth2 v0.36.0 // indirect golang.org/x/sync v0.21.0 // indirect - golang.org/x/sys v0.46.0 // indirect + golang.org/x/sys v0.47.0 // indirect golang.org/x/term v0.44.0 // indirect golang.org/x/text v0.38.0 // indirect golang.org/x/time v0.15.0 // indirect @@ -130,11 +130,11 @@ require ( gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect gopkg.in/inf.v0 v0.9.1 // indirect gopkg.in/natefinch/lumberjack.v2 v2.2.1 // indirect - k8s.io/api v1.36.2 // indirect - k8s.io/apiserver v1.36.2 // indirect - k8s.io/client-go v1.36.2 // indirect + k8s.io/api v1.36.3 // indirect + k8s.io/apiserver v1.36.3 // indirect + k8s.io/client-go v1.36.3 // indirect k8s.io/kube-openapi v0.0.0-20260618221249-bc653b64f974 // indirect - k8s.io/kubelet v1.36.2 // indirect + k8s.io/kubelet v1.36.3 // indirect k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect sigs.k8s.io/kustomize/api v0.21.1 // indirect @@ -145,11 +145,11 @@ require ( replace ( github.com/onsi/ginkgo/v2 => github.com/openshift/onsi-ginkgo/v2 v2.6.1-0.20260424201627-4d4cc33d669d // from kubernetes - go.etcd.io/etcd/api/v3 => github.com/openshift/etcd/api/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f // from etcd - go.etcd.io/etcd/client/pkg/v3 => github.com/openshift/etcd/client/pkg/v3 v3.0.0-20260722153822-64f8851a001f // from etcd - go.etcd.io/etcd/client/v3 => github.com/openshift/etcd/client/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f // from etcd - go.etcd.io/etcd/pkg/v3 => github.com/openshift/etcd/pkg/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f // from etcd - go.etcd.io/etcd/server/v3 => github.com/openshift/etcd/server/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f // from etcd + go.etcd.io/etcd/api/v3 => github.com/openshift/etcd/api/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4 // from etcd + go.etcd.io/etcd/client/pkg/v3 => github.com/openshift/etcd/client/pkg/v3 v3.0.0-20260810103824-609b11ed8fc4 // from etcd + go.etcd.io/etcd/client/v3 => github.com/openshift/etcd/client/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4 // from etcd + go.etcd.io/etcd/pkg/v3 => github.com/openshift/etcd/pkg/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4 // from etcd + go.etcd.io/etcd/server/v3 => github.com/openshift/etcd/server/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4 // from etcd ) replace ( diff --git a/etcd/go.sum b/etcd/go.sum index 6a78b08933..19e9dbc611 100644 --- a/etcd/go.sum +++ b/etcd/go.sum @@ -154,16 +154,16 @@ github.com/openshift/api v0.0.0-20260715165912-72066cc9718b h1:gN3SihCYEwoIksD+f github.com/openshift/api v0.0.0-20260715165912-72066cc9718b/go.mod h1:k6qH5QOVa5GDln2VVm8Jz4NV3Z7R2SATHFLwGS6Wh3M= github.com/openshift/build-machinery-go v0.0.0-20260629141115-154a2b810491 h1:P/vZSEsUuAHMnf89gQ6FKIl9jsbPnNJ3gIBM43xn2Bg= github.com/openshift/build-machinery-go v0.0.0-20260629141115-154a2b810491/go.mod h1:8jcm8UPtg2mCAsxfqKil1xrmRMI3a+XU2TZ9fF8A7TE= -github.com/openshift/etcd/api/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f h1:l1BwSIIoR7S6lLOC+ootMVnzcRTN5ShiDGOYId6kBNY= -github.com/openshift/etcd/api/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f/go.mod h1:X9+3gaKwzjlOxzo6TZ2u3b7HcHBcAL+Ph7EBPjI/VWk= -github.com/openshift/etcd/client/pkg/v3 v3.0.0-20260722153822-64f8851a001f h1:QTCPX2IzZANuE2q7gLY68AghVdyZswcSSY5WsJPR0fg= -github.com/openshift/etcd/client/pkg/v3 v3.0.0-20260722153822-64f8851a001f/go.mod h1:Dn2zUBOCu/6xYcd6iAjB7LgoY16OTQjDZfWHLwvuQj4= -github.com/openshift/etcd/client/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f h1:rU3frnPQT0rCITvH9uYPvgKbPzBjlI0JxoVemzWcVpg= -github.com/openshift/etcd/client/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f/go.mod h1:rtVI3vwobljb8xlTGcp1Yhz7hBIuBWULXwB848kqJGw= -github.com/openshift/etcd/pkg/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f h1:J4C0yYvcawkjHWQOBLAom9xPMK4ia9zgOVOfPoZ5Vz0= -github.com/openshift/etcd/pkg/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f/go.mod h1:YDonhdT0PCdcd/av/IyhXLNNcZk/nVCGZ38iyYFfAHU= -github.com/openshift/etcd/server/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f h1:E4a/M5UjDa/QvwGVDQvNLB3V6OFJbdQSpXQpjKeSQyQ= -github.com/openshift/etcd/server/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f/go.mod h1:9NsHlIEPZFq27IzVfLKyU15HVF/gVAk3gEe4feD7qsk= +github.com/openshift/etcd/api/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4 h1:fDN533FsyMl9qTWaO8Up/4DqkX39E4L86ikMiRzGCcE= +github.com/openshift/etcd/api/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4/go.mod h1:X9+3gaKwzjlOxzo6TZ2u3b7HcHBcAL+Ph7EBPjI/VWk= +github.com/openshift/etcd/client/pkg/v3 v3.0.0-20260810103824-609b11ed8fc4 h1:YNDg89ABbEbY7CsaiYVbkOi3xfVzdEEgdudyGNKkXSI= +github.com/openshift/etcd/client/pkg/v3 v3.0.0-20260810103824-609b11ed8fc4/go.mod h1:Dn2zUBOCu/6xYcd6iAjB7LgoY16OTQjDZfWHLwvuQj4= +github.com/openshift/etcd/client/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4 h1:tuRzXIM0ba9WlKtHqVPi3DXD+efxpzjpqppx7/cmIoI= +github.com/openshift/etcd/client/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4/go.mod h1:rtVI3vwobljb8xlTGcp1Yhz7hBIuBWULXwB848kqJGw= +github.com/openshift/etcd/pkg/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4 h1:h8J3mMo2vZh+zyVBUspsvVHrh07lVa2HwrDau0Mbrwk= +github.com/openshift/etcd/pkg/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4/go.mod h1:YDonhdT0PCdcd/av/IyhXLNNcZk/nVCGZ38iyYFfAHU= +github.com/openshift/etcd/server/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4 h1:ZCNPh6trOtzdj8vAyfWWN8hqqmq9M3V02mGbe/G+KT4= +github.com/openshift/etcd/server/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4/go.mod h1:pJ1hUZmopVjGKRsB+f6OfOPfZzhFfJ27KIgxQoQNXCo= github.com/openshift/library-go v0.0.0-20260720185249-0595e37fe20f h1:NdSEtKB+vvHlGELA+jX/c+TALNwe8iSsJAQYvMabgHQ= github.com/openshift/library-go v0.0.0-20260720185249-0595e37fe20f/go.mod h1:iWcB6wgeOhsByZAZGhmzBtEnrLQzABL0s3aeou8AmSI= github.com/openshift/onsi-ginkgo/v2 v2.6.1-0.20260424201627-4d4cc33d669d h1:t+XyaZL4LpQx/AY2SETlMCQPLc9vd05ZZ7WXvD9doME= @@ -293,8 +293,8 @@ golang.org/x/sys v0.0.0-20210616094352-59db8d763f22/go.mod h1:oPkhp1MJrh7nUepCBc golang.org/x/sys v0.0.0-20220715151400-c0bba94af5f8/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.2.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.10.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.46.0 h1:noSf2Fq6F8DBgS+LysIkx7rIExoNHJsxOAtPp4rthXw= -golang.org/x/sys v0.46.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= +golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs= +golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo= golang.org/x/term v0.44.0 h1:0rLvDRCtNj0gZkyIXhCyOb2OAzEhLVqc4B+hrsBhrmc= golang.org/x/term v0.44.0/go.mod h1:7ze4MdzUzLXpSAoFP1H0bOI9aXDqveSvatT5vKcFh2Y= diff --git a/etcd/vendor/go.etcd.io/etcd/server/v3/config/config.go b/etcd/vendor/go.etcd.io/etcd/server/v3/config/config.go index 182dec2ae4..84bc214a64 100644 --- a/etcd/vendor/go.etcd.io/etcd/server/v3/config/config.go +++ b/etcd/vendor/go.etcd.io/etcd/server/v3/config/config.go @@ -201,6 +201,12 @@ type ServerConfig struct { // consider running defrag during bootstrap. Needs to be set to non-zero value to take effect. BootstrapDefragThresholdMegabytes uint `json:"bootstrap-defrag-threshold-megabytes"` + // DefragJournalMaxOps sets the maximum number of write operations buffered + // in the non-blocking defrag journal before backpressure is applied. Only + // effective when NonBlockingDefrag feature gate is enabled. 0 means + // unlimited (no backpressure). + DefragJournalMaxOps int `json:"defrag-journal-max-ops"` + // MaxLearners sets a limit to the number of learner members that can exist in the cluster membership. MaxLearners int `json:"max-learners"` diff --git a/etcd/vendor/go.etcd.io/etcd/server/v3/embed/config.go b/etcd/vendor/go.etcd.io/etcd/server/v3/embed/config.go index fcb282d325..ed082b5111 100644 --- a/etcd/vendor/go.etcd.io/etcd/server/v3/embed/config.go +++ b/etcd/vendor/go.etcd.io/etcd/server/v3/embed/config.go @@ -52,6 +52,7 @@ import ( "go.etcd.io/etcd/server/v3/etcdserver/api/v3compactor" "go.etcd.io/etcd/server/v3/etcdserver/api/v3discovery" "go.etcd.io/etcd/server/v3/features" + "go.etcd.io/etcd/server/v3/storage/backend" ) const ( @@ -459,6 +460,11 @@ type Config struct { ExperimentalBootstrapDefragThresholdMegabytes uint `json:"experimental-bootstrap-defrag-threshold-megabytes"` // BootstrapDefragThresholdMegabytes is the minimum number of megabytes needed to be freed for etcd server to BootstrapDefragThresholdMegabytes uint `json:"bootstrap-defrag-threshold-megabytes"` + // DefragJournalMaxOps sets the maximum number of write operations buffered + // in the defrag journal before backpressure is applied to writers. Only + // effective when the NonBlockingDefrag feature gate is enabled. 0 means + // unlimited (no backpressure). + DefragJournalMaxOps int `json:"defrag-journal-max-ops"` // WarningUnaryRequestDuration is the time duration after which a warning is generated if applying // unary request takes more time than this value. WarningUnaryRequestDuration time.Duration `json:"warning-unary-request-duration"` @@ -712,6 +718,7 @@ func NewConfig() *Config { ExperimentalMemoryMlock: false, ExperimentalStopGRPCServiceOnDefrag: false, MaxLearners: membership.DefaultMaxLearners, + DefragJournalMaxOps: backend.DefaultDefragJournalMaxOps, ExperimentalTxnModeWriteWithSharedBuffer: DefaultExperimentalTxnModeWriteWithSharedBuffer, ExperimentalDistributedTracingAddress: DefaultDistributedTracingAddress, @@ -950,6 +957,7 @@ func (cfg *Config) AddFlags(fs *flag.FlagSet) { // TODO: delete in v3.7 fs.UintVar(&cfg.ExperimentalBootstrapDefragThresholdMegabytes, "experimental-bootstrap-defrag-threshold-megabytes", 0, "Enable the defrag during etcd server bootstrap on condition that it will free at least the provided threshold of disk space. Needs to be set to non-zero value to take effect. It's deprecated, and will be decommissioned in v3.7. Use --bootstrap-defrag-threshold-megabytes instead.") fs.UintVar(&cfg.BootstrapDefragThresholdMegabytes, "bootstrap-defrag-threshold-megabytes", 0, "Enable the defrag during etcd server bootstrap on condition that it will free at least the provided threshold of disk space. Needs to be set to non-zero value to take effect.") + fs.IntVar(&cfg.DefragJournalMaxOps, "defrag-journal-max-ops", backend.DefaultDefragJournalMaxOps, "Maximum number of write operations buffered in the non-blocking defrag journal before backpressure is applied. Requires --feature-gates=NonBlockingDefrag=true. Set to 0 for unlimited.") // TODO: delete in v3.7 fs.IntVar(&cfg.MaxLearners, "max-learners", membership.DefaultMaxLearners, "Sets the maximum number of learners that can be available in the cluster membership.") fs.Uint64Var(&cfg.ExperimentalSnapshotCatchUpEntries, "experimental-snapshot-catchup-entries", cfg.ExperimentalSnapshotCatchUpEntries, "Number of entries for a slow follower to catch up after compacting the raft storage entries. Deprecated in v3.6 and will be decommissioned in v3.7. Use --snapshot-catchup-entries instead.") diff --git a/etcd/vendor/go.etcd.io/etcd/server/v3/embed/etcd.go b/etcd/vendor/go.etcd.io/etcd/server/v3/embed/etcd.go index a633212ab4..4c7718a02e 100644 --- a/etcd/vendor/go.etcd.io/etcd/server/v3/embed/etcd.go +++ b/etcd/vendor/go.etcd.io/etcd/server/v3/embed/etcd.go @@ -233,6 +233,7 @@ func StartEtcd(inCfg *Config) (e *Etcd, err error) { WarningUnaryRequestDuration: cfg.WarningUnaryRequestDuration, MemoryMlock: cfg.MemoryMlock, BootstrapDefragThresholdMegabytes: cfg.BootstrapDefragThresholdMegabytes, + DefragJournalMaxOps: cfg.DefragJournalMaxOps, MaxLearners: cfg.MaxLearners, V2Deprecation: cfg.V2DeprecationEffective(), ExperimentalLocalAddress: cfg.InferLocalAddr(), diff --git a/etcd/vendor/go.etcd.io/etcd/server/v3/etcdserver/server.go b/etcd/vendor/go.etcd.io/etcd/server/v3/etcdserver/server.go index 5338815ae9..00cafbb102 100644 --- a/etcd/vendor/go.etcd.io/etcd/server/v3/etcdserver/server.go +++ b/etcd/vendor/go.etcd.io/etcd/server/v3/etcdserver/server.go @@ -260,6 +260,7 @@ type EtcdServer struct { kv mvcc.WatchableKV lessor lease.Lessor bemu sync.RWMutex + defragMu sync.Mutex be backend.Backend beHooks *serverstorage.BackendHooks authStore auth.AuthStore @@ -975,8 +976,15 @@ func (s *EtcdServer) Cleanup() { } func (s *EtcdServer) Defragment() error { - s.bemu.Lock() - defer s.bemu.Unlock() + if s.FeatureEnabled(features.NonBlockingDefrag) { + s.defragMu.Lock() + defer s.defragMu.Unlock() + s.bemu.RLock() + defer s.bemu.RUnlock() + } else { + s.bemu.Lock() + defer s.bemu.Unlock() + } return s.be.Defrag() } diff --git a/etcd/vendor/go.etcd.io/etcd/server/v3/features/etcd_features.go b/etcd/vendor/go.etcd.io/etcd/server/v3/features/etcd_features.go index 230b37c703..a87fd8a84a 100644 --- a/etcd/vendor/go.etcd.io/etcd/server/v3/features/etcd_features.go +++ b/etcd/vendor/go.etcd.io/etcd/server/v3/features/etcd_features.go @@ -35,6 +35,14 @@ const ( // of code conflicts because changes are more likely to be scattered // across the file. + // NonBlockingDefrag enables a non-blocking defragmentation algorithm that + // allows writes to continue during the bulk data copy phase. A write journal + // captures mutations during the copy; only the journal replay and database + // swap require the write lock, reducing disruption from O(db_size) to + // O(writes_during_copy). + // owner: @dusk125 + // alpha: v3.7 + NonBlockingDefrag featuregate.Feature = "NonBlockingDefrag" // StopGRPCServiceOnDefrag enables etcd gRPC service to stop serving client requests on defragmentation. // owner: @chaochn47 // alpha: v3.6 @@ -78,6 +86,7 @@ const ( var ( DefaultEtcdServerFeatureGates = map[featuregate.Feature]featuregate.FeatureSpec{ + NonBlockingDefrag: {Default: false, PreRelease: featuregate.Alpha}, StopGRPCServiceOnDefrag: {Default: false, PreRelease: featuregate.Alpha}, InitialCorruptCheck: {Default: false, PreRelease: featuregate.Alpha}, CompactHashCheck: {Default: false, PreRelease: featuregate.Alpha}, diff --git a/etcd/vendor/go.etcd.io/etcd/server/v3/storage/backend.go b/etcd/vendor/go.etcd.io/etcd/server/v3/storage/backend.go index 7db61f9fae..e3c037f5f5 100644 --- a/etcd/vendor/go.etcd.io/etcd/server/v3/storage/backend.go +++ b/etcd/vendor/go.etcd.io/etcd/server/v3/storage/backend.go @@ -23,6 +23,7 @@ import ( "go.etcd.io/etcd/server/v3/config" "go.etcd.io/etcd/server/v3/etcdserver/api/snap" + "go.etcd.io/etcd/server/v3/features" "go.etcd.io/etcd/server/v3/storage/backend" "go.etcd.io/etcd/server/v3/storage/schema" "go.etcd.io/raft/v3/raftpb" @@ -52,6 +53,10 @@ func newBackend(cfg config.ServerConfig, hooks backend.Hooks) backend.Backend { } bcfg.Mlock = cfg.MemoryMlock bcfg.Hooks = hooks + if cfg.ServerFeatureGate != nil { + bcfg.NonBlockingDefrag = cfg.ServerFeatureGate.Enabled(features.NonBlockingDefrag) + } + bcfg.DefragJournalMaxOps = cfg.DefragJournalMaxOps return backend.New(bcfg) } diff --git a/etcd/vendor/go.etcd.io/etcd/server/v3/storage/backend/backend.go b/etcd/vendor/go.etcd.io/etcd/server/v3/storage/backend/backend.go index 275064f083..c1a8e2592b 100644 --- a/etcd/vendor/go.etcd.io/etcd/server/v3/storage/backend/backend.go +++ b/etcd/vendor/go.etcd.io/etcd/server/v3/storage/backend/backend.go @@ -15,6 +15,7 @@ package backend import ( + "errors" "fmt" "hash/crc32" "io" @@ -28,6 +29,7 @@ import ( "go.uber.org/zap" bolt "go.etcd.io/bbolt" + bolterrors "go.etcd.io/bbolt/errors" "go.etcd.io/etcd/client/pkg/v3/verify" ) @@ -127,6 +129,16 @@ type backend struct { // txPostLockInsideApplyHook is called each time right after locking the tx. txPostLockInsideApplyHook func() + // nonBlockingDefrag enables the journal-based non-blocking defrag path. + nonBlockingDefrag bool + // defragJournalMaxOps is the journal backpressure limit. + // 0 means unlimited (no backpressure). + defragJournalMaxOps int + + // nonBlockDefragCopyFailHook, if non-nil, is called instead of defragFromTx + // during the copy phase. Used by tests to simulate copy failures. + nonBlockDefragCopyFailHook func() error + lg *zap.Logger } @@ -150,6 +162,14 @@ type BackendConfig struct { // Hooks are getting executed during lifecycle of Backend's transactions. Hooks Hooks + + // NonBlockingDefrag enables the journal-based non-blocking defrag + // algorithm. When false, the legacy blocking defrag is used. + NonBlockingDefrag bool + // DefragJournalMaxOps is the backpressure threshold for the defrag + // journal. Writers block when the journal reaches this size. + // 0 means unlimited (no backpressure). + DefragJournalMaxOps int } type BackendConfigOption func(*BackendConfig) @@ -235,6 +255,9 @@ func newBackend(bcfg BackendConfig) *backend { stopc: make(chan struct{}), donec: make(chan struct{}), + nonBlockingDefrag: bcfg.NonBlockingDefrag, + defragJournalMaxOps: bcfg.DefragJournalMaxOps, + lg: bcfg.Logger, } @@ -460,6 +483,9 @@ func (b *backend) Commits() int64 { } func (b *backend) Defrag() error { + if b.nonBlockingDefrag { + return b.defragNonBlocking() + } return b.defrag() } @@ -469,7 +495,6 @@ func (b *backend) defrag() error { isDefragActive.Set(1) defer isDefragActive.Set(0) - // TODO: make this non-blocking? // lock batchTx to ensure nobody is using previous tx, and then // close previous ongoing tx. b.batchTx.LockOutsideApply() @@ -483,50 +508,12 @@ func (b *backend) defrag() error { b.readTx.Lock() defer b.readTx.Unlock() - // Create a temporary file to ensure we start with a clean slate. - // Snapshotter.cleanupSnapdir cleans up any of these that are found during startup. - dir := filepath.Dir(b.db.Path()) - temp, err := os.CreateTemp(dir, "db.tmp.*") - if err != nil { - return err - } - - options := bolt.Options{} - if boltOpenOptions != nil { - options = *boltOpenOptions - } - options.OpenFile = func(_ string, _ int, _ os.FileMode) (file *os.File, err error) { - // gofail: var defragOpenFileError string - // return nil, fmt.Errorf(defragOpenFileError) - return temp, nil - } - // Don't load tmp db into memory regardless of opening options - options.Mlock = false - tdbp := temp.Name() - tmpdb, err := bolt.Open(tdbp, 0o600, &options) + tmpdb, tdbp, err := b.defragOpenTmpDB() if err != nil { - temp.Close() - if rmErr := os.Remove(temp.Name()); rmErr != nil { - b.lg.Error( - "failed to remove temporary file", - zap.String("path", temp.Name()), - zap.Error(rmErr), - ) - } - return err } - dbp := b.db.Path() - size1, sizeInUse1 := b.Size(), b.SizeInUse() - b.lg.Info( - "defragmenting", - zap.String("path", dbp), - zap.Int64("current-db-size-bytes", size1), - zap.String("current-db-size", humanize.Bytes(uint64(size1))), - zap.Int64("current-db-size-in-use-bytes", sizeInUse1), - zap.String("current-db-size-in-use", humanize.Bytes(uint64(sizeInUse1))), - ) + dbPath, initialSize, initialSizeInUse := b.defragLogStart() defer func() { // NOTE: We should exit as soon as possible because that tx @@ -545,10 +532,7 @@ func (b *backend) defrag() error { // gofail: var defragBeforeCopy struct{} err = defragdb(b.db, tmpdb, defragLimit) if err != nil { - tmpdb.Close() - if rmErr := os.RemoveAll(tmpdb.Path()); rmErr != nil { - b.lg.Error("failed to remove db.tmp after defragmentation completed", zap.Error(rmErr)) - } + b.cleanupTmpDB(tmpdb, tdbp) // restore the bbolt transactions if defragmentation fails b.batchTx.tx = b.unsafeBegin(true) @@ -557,49 +541,59 @@ func (b *backend) defrag() error { return err } - err = b.db.Close() + b.defragSwap(tmpdb, tdbp, dbPath) + + b.defragLogFinish(dbPath, initialSize, initialSizeInUse, now) + return nil +} + +// defragNonBlocking uses a journal to capture writes during the copy +// phase, allowing writes to continue unblocked. Only the journal +// replay and database swap hold the write lock. +func (b *backend) defragNonBlocking() error { + verify.Assert(b.lg != nil, "the logger should not be nil") + now := time.Now() + isDefragActive.Set(1) + defer isDefragActive.Set(0) + + tmpdb, tdbp, err := b.defragOpenTmpDB() if err != nil { - b.lg.Fatal("failed to close database", zap.Error(err)) + return err } - err = tmpdb.Close() + + dbPath, initialSize, initialSizeInUse := b.defragLogStart() + + readTx, err := b.nonBlockDefragPrepare() if err != nil { - b.lg.Fatal("failed to close tmp database", zap.Error(err)) + b.cleanupTmpDB(tmpdb, tdbp) + return err } - // gofail: var defragBeforeRename struct{} - err = os.Rename(tdbp, dbp) - if err != nil { - b.lg.Fatal("failed to rename tmp database", zap.Error(err)) + defer b.nonBlockDefragCancelJournal() + + b.lg.Info("defrag: copying data (writes unlocked)") + + // gofail: var defragNonBlockingBeforeCopy struct{} + if b.nonBlockDefragCopyFailHook != nil { + err = b.nonBlockDefragCopyFailHook() + } else { + err = defragFromTx(readTx, tmpdb, defragLimit) } + readTx.Rollback() - b.db, err = bolt.Open(dbp, 0o600, b.bopts) if err != nil { - b.lg.Fatal("failed to open database", zap.String("path", dbp), zap.Error(err)) + b.cleanupTmpDB(tmpdb, tdbp) + return err } - b.batchTx.tx = b.unsafeBegin(true) - b.readTx.reset() - b.readTx.tx = b.unsafeBegin(false) - - size := b.readTx.tx.Size() - db := b.readTx.tx.DB() - atomic.StoreInt64(&b.size, size) - atomic.StoreInt64(&b.sizeInUse, size-(int64(db.Stats().FreePageN)*int64(db.Info().PageSize))) - - took := time.Since(now) - defragSec.Observe(took.Seconds()) + // gofail: var defragBeforeReplay struct{} + b.lg.Info("defrag: replaying journal") + err = b.nonBlockDefragReplayAndSwap(tmpdb, tdbp, dbPath) + if err != nil { + b.cleanupTmpDB(tmpdb, tdbp) + return err + } - size2, sizeInUse2 := b.Size(), b.SizeInUse() - b.lg.Info( - "finished defragmenting directory", - zap.String("path", dbp), - zap.Int64("current-db-size-bytes-diff", size2-size1), - zap.Int64("current-db-size-bytes", size2), - zap.String("current-db-size", humanize.Bytes(uint64(size2))), - zap.Int64("current-db-size-in-use-bytes-diff", sizeInUse2-sizeInUse1), - zap.Int64("current-db-size-in-use-bytes", sizeInUse2), - zap.String("current-db-size-in-use", humanize.Bytes(uint64(sizeInUse2))), - zap.Duration("took", took), - ) + b.defragLogFinish(dbPath, initialSize, initialSizeInUse, now) return nil } @@ -607,6 +601,17 @@ func defragdb(odb, tmpdb *bolt.DB, limit int) error { // gofail: var defragdbFail string // return fmt.Errorf(defragdbFail) + // open a tx on old db for read + tx, err := odb.Begin(false) + if err != nil { + return err + } + defer tx.Rollback() + + return defragFromTx(tx, tmpdb, limit) +} + +func defragFromTx(tx *bolt.Tx, tmpdb *bolt.DB, limit int) error { // open a tx on tmpdb for writes tmptx, err := tmpdb.Begin(true) if err != nil { @@ -618,13 +623,6 @@ func defragdb(odb, tmpdb *bolt.DB, limit int) error { } }() - // open a tx on old db for read - tx, err := odb.Begin(false) - if err != nil { - return err - } - defer tx.Rollback() - c := tx.Cursor() count := 0 @@ -665,6 +663,244 @@ func defragdb(odb, tmpdb *bolt.DB, limit int) error { return tmptx.Commit() } +func (b *backend) defragOpenTmpDB() (*bolt.DB, string, error) { + // Create a temporary file to ensure we start with a clean slate. + // Snapshotter.cleanupSnapdir cleans up any of these that are found during startup. + dir := filepath.Dir(b.db.Path()) + temp, err := os.CreateTemp(dir, "db.tmp.*") + if err != nil { + return nil, "", err + } + + options := bolt.Options{} + if boltOpenOptions != nil { + options = *boltOpenOptions + } + options.OpenFile = func(_ string, _ int, _ os.FileMode) (file *os.File, err error) { + // gofail: var defragOpenFileError string + // return nil, fmt.Errorf(defragOpenFileError) + return temp, nil + } + // Don't load tmp db into memory regardless of opening options + options.Mlock = false + tdbp := temp.Name() + tmpdb, err := bolt.Open(tdbp, 0o600, &options) + if err != nil { + temp.Close() + if rmErr := os.Remove(temp.Name()); rmErr != nil { + b.lg.Error( + "failed to remove temporary file", + zap.String("path", temp.Name()), + zap.Error(rmErr), + ) + } + + return nil, "", err + } + return tmpdb, tdbp, nil +} + +func (b *backend) cleanupTmpDB(tmpdb *bolt.DB, tdbp string) { + tmpdb.Close() + if rmErr := os.RemoveAll(tdbp); rmErr != nil { + b.lg.Error("failed to remove tmp database", zap.String("path", tdbp), zap.Error(rmErr)) + } +} + +func (b *backend) defragLogStart() (string, int64, int64) { + dbPath := b.db.Path() + size, sizeInUse := b.Size(), b.SizeInUse() + b.lg.Info("defragmenting", + zap.String("path", dbPath), + zap.Int64("current-db-size-bytes", size), + zap.String("current-db-size", humanize.Bytes(uint64(size))), + zap.Int64("current-db-size-in-use-bytes", sizeInUse), + zap.String("current-db-size-in-use", humanize.Bytes(uint64(sizeInUse))), + ) + return dbPath, size, sizeInUse +} + +// nonBlockDefragPrepare commits pending writes, opens a read-only bbolt +// transaction for the copy phase, and installs a journal to capture +// writes that occur during the copy. +func (b *backend) nonBlockDefragPrepare() (*bolt.Tx, error) { + b.batchTx.LockOutsideApply() + defer b.batchTx.Unlock() + + b.batchTx.commit(false) + + b.mu.RLock() + readTx, err := b.db.Begin(false) + b.mu.RUnlock() + if err != nil { + return nil, fmt.Errorf("failed to begin read tx for defrag: %w", err) + } + + b.batchTx.defragJournal.Store(newDefragJournal(b.defragJournalMaxOps)) + return readTx, nil +} + +// nonBlockDefragCancelJournal removes the journal from the batch transaction +// and closes it. Safe to call even if the journal was already +// drained or never installed. +func (b *backend) nonBlockDefragCancelJournal() { + b.batchTx.LockOutsideApply() + defer b.batchTx.Unlock() + if journal := b.batchTx.defragJournal.Swap(nil); journal != nil { + // If we reach here, we errored while defragging so we need + // to clean up the journal, so we're intentionally dropping + // the operations. + _ = journal.closeAndDrain() + } +} + +func (b *backend) nonBlockDefragReplayAndSwap(tmpdb *bolt.DB, tdbp, dbp string) error { + b.batchTx.LockOutsideApply() + defer b.batchTx.Unlock() + + journal := b.batchTx.defragJournal.Swap(nil) + ops := journal.closeAndDrain() + + if len(ops) > 0 { + b.lg.Info("defrag: replaying journal ops", zap.Int("count", len(ops))) + } + + if err := nonBlockDefragReplayJournal(tmpdb, ops, defragLimit); err != nil { + return err + } + + b.lg.Info("defrag: switching database") + + b.mu.Lock() + defer b.mu.Unlock() + b.readTx.Lock() + defer b.readTx.Unlock() + + // NOTE: We should exit as soon as possible because that tx + // might be closed. The inflight request might use invalid + // tx and then panic as well. The real panic reason might be + // shadowed by new panic. So, we should fatal here with lock. + defer func() { + if rerr := recover(); rerr != nil { + b.lg.Fatal("unexpected panic during defrag", zap.Any("panic", rerr)) + } + }() + + b.batchTx.unsafeCommit(true) + b.batchTx.tx = nil + + b.defragSwap(tmpdb, tdbp, dbp) + return nil +} + +func nonBlockDefragReplayJournal(tmpdb *bolt.DB, ops []defragJournalOp, limit int) (err error) { + if len(ops) == 0 { + return nil + } + + tx, err := tmpdb.Begin(true) + if err != nil { + return err + } + defer func() { + if err != nil { + tx.Rollback() + } + }() + + count := 0 + for _, op := range ops { + count++ + if count > limit { + if err = tx.Commit(); err != nil { + return err + } + tx, err = tmpdb.Begin(true) + if err != nil { + return err + } + count = 0 + } + + switch op.opType { + case opCreateBucket: + if _, err = tx.CreateBucketIfNotExists(op.bucketName); err != nil { + return fmt.Errorf("replay: create bucket %s: %w", op.bucketName, err) + } + case opDeleteBucket: + if delErr := tx.DeleteBucket(op.bucketName); delErr != nil && !errors.Is(delErr, bolterrors.ErrBucketNotFound) { + return fmt.Errorf("replay: delete bucket %s: %w", op.bucketName, delErr) + } + case opPut: + b := tx.Bucket(op.bucketName) + if b == nil { + return fmt.Errorf("replay: bucket %s not found for put", op.bucketName) + } + if err = b.Put(op.key, op.value); err != nil { + return fmt.Errorf("replay: put in bucket %s: %w", op.bucketName, err) + } + case opDelete: + b := tx.Bucket(op.bucketName) + if b == nil { + return fmt.Errorf("replay: bucket %s not found for delete", op.bucketName) + } + if err = b.Delete(op.key); err != nil { + return fmt.Errorf("replay: delete from bucket %s: %w", op.bucketName, err) + } + } + } + + return tx.Commit() +} + +func (b *backend) defragSwap(tmpdb *bolt.DB, tdbp, dbp string) { + var err error + err = b.db.Close() + if err != nil { + b.lg.Fatal("failed to close database", zap.Error(err)) + } + err = tmpdb.Close() + if err != nil { + b.lg.Fatal("failed to close tmp database", zap.Error(err)) + } + // gofail: var defragBeforeRename struct{} + err = os.Rename(tdbp, dbp) + if err != nil { + b.lg.Fatal("failed to rename tmp database", zap.Error(err)) + } + + b.db, err = bolt.Open(dbp, 0o600, b.bopts) + if err != nil { + b.lg.Fatal("failed to open database", zap.String("path", dbp), zap.Error(err)) + } + b.batchTx.tx = b.unsafeBegin(true) + + b.readTx.reset() + b.readTx.tx = b.unsafeBegin(false) + + size := b.readTx.tx.Size() + db := b.readTx.tx.DB() + atomic.StoreInt64(&b.size, size) + atomic.StoreInt64(&b.sizeInUse, size-(int64(db.Stats().FreePageN)*int64(db.Info().PageSize))) +} + +func (b *backend) defragLogFinish(dbPath string, initialSize, initialSizeInUse int64, start time.Time) { + took := time.Since(start) + defragSec.Observe(took.Seconds()) + + newSize, newSizeInUse := b.Size(), b.SizeInUse() + b.lg.Info("finished defragmenting directory", + zap.String("path", dbPath), + zap.Int64("current-db-size-bytes-diff", newSize-initialSize), + zap.Int64("current-db-size-bytes", newSize), + zap.String("current-db-size", humanize.Bytes(uint64(newSize))), + zap.Int64("current-db-size-in-use-bytes-diff", newSizeInUse-initialSizeInUse), + zap.Int64("current-db-size-in-use-bytes", newSizeInUse), + zap.String("current-db-size-in-use", humanize.Bytes(uint64(newSizeInUse))), + zap.Duration("took", took), + ) +} + func (b *backend) begin(write bool) *bolt.Tx { b.mu.RLock() tx := b.unsafeBegin(write) diff --git a/etcd/vendor/go.etcd.io/etcd/server/v3/storage/backend/batch_tx.go b/etcd/vendor/go.etcd.io/etcd/server/v3/storage/backend/batch_tx.go index 5af557cb42..6c3787dda5 100644 --- a/etcd/vendor/go.etcd.io/etcd/server/v3/storage/backend/batch_tx.go +++ b/etcd/vendor/go.etcd.io/etcd/server/v3/storage/backend/batch_tx.go @@ -291,6 +291,11 @@ type batchTxBuffered struct { batchTx buf txWriteBuffer pendingDeleteOperations int + // defragJournal captures write operations during the non-blocking + // defrag copy phase. Accessed atomically because LockInsideApply + // reads it before acquiring the batchTx mutex (for backpressure), + // while defragPrepare/defragReplayAndSwap set it under the mutex. + defragJournal atomic.Pointer[defragJournal] } func newBatchTxBuffered(backend *backend) *batchTxBuffered { @@ -305,6 +310,15 @@ func newBatchTxBuffered(backend *backend) *batchTxBuffered { return tx } +func (t *batchTxBuffered) LockInsideApply() { + if t.backend.nonBlockingDefrag { + if j := t.defragJournal.Load(); j != nil { + j.waitForSpace() + } + } + t.batchTx.LockInsideApply() +} + func (t *batchTxBuffered) Unlock() { if t.pending != 0 { t.backend.readTx.Lock() // blocks txReadBuffer for writing. @@ -385,22 +399,51 @@ func (t *batchTxBuffered) unsafeCommit(stop bool) { } } +func (t *batchTxBuffered) UnsafeCreateBucket(bucket Bucket) { + if t.backend.nonBlockingDefrag { + if j := t.defragJournal.Load(); j != nil { + j.appendCreateBucket(bucket.Name()) + } + } + t.batchTx.UnsafeCreateBucket(bucket) +} + func (t *batchTxBuffered) UnsafePut(bucket Bucket, key []byte, value []byte) { + if t.backend.nonBlockingDefrag { + if j := t.defragJournal.Load(); j != nil { + j.appendPut(bucket.Name(), key, value, false) + } + } t.batchTx.UnsafePut(bucket, key, value) t.buf.put(bucket, key, value) } func (t *batchTxBuffered) UnsafeSeqPut(bucket Bucket, key []byte, value []byte) { + if t.backend.nonBlockingDefrag { + if j := t.defragJournal.Load(); j != nil { + j.appendPut(bucket.Name(), key, value, true) + } + } t.batchTx.UnsafeSeqPut(bucket, key, value) t.buf.putSeq(bucket, key, value) } func (t *batchTxBuffered) UnsafeDelete(bucketType Bucket, key []byte) { + if t.backend.nonBlockingDefrag { + if j := t.defragJournal.Load(); j != nil { + j.appendDelete(bucketType.Name(), key) + } + } t.batchTx.UnsafeDelete(bucketType, key) t.pendingDeleteOperations++ } func (t *batchTxBuffered) UnsafeDeleteBucket(bucket Bucket) { + if t.backend.nonBlockingDefrag { + if j := t.defragJournal.Load(); j != nil { + j.appendDeleteBucket(bucket.Name()) + } + } t.batchTx.UnsafeDeleteBucket(bucket) t.pendingDeleteOperations++ } diff --git a/etcd/vendor/go.etcd.io/etcd/server/v3/storage/backend/defrag_journal.go b/etcd/vendor/go.etcd.io/etcd/server/v3/storage/backend/defrag_journal.go new file mode 100644 index 0000000000..021382bc33 --- /dev/null +++ b/etcd/vendor/go.etcd.io/etcd/server/v3/storage/backend/defrag_journal.go @@ -0,0 +1,122 @@ +package backend + +import "sync" + +type defragOpType uint8 + +const ( + opPut defragOpType = iota + opDelete + opCreateBucket + opDeleteBucket +) + +// DefaultDefragJournalMaxOps is the default maximum number of operations +// the journal will buffer before applying backpressure to writers. +// The CLI flag --defrag-journal-max-ops defaults to this value. +const DefaultDefragJournalMaxOps = 50_000 + +type defragJournalOp struct { + opType defragOpType + bucketName []byte + key []byte + value []byte + seq bool +} + +type defragJournal struct { + mu sync.Mutex + cond *sync.Cond + ops []defragJournalOp + closed bool + maxOps int +} + +// newDefragJournal creates a journal that buffers write operations +// during the defrag copy phase. maxOps sets the backpressure threshold: +// writers block when the journal reaches this size. A value of 0 means +// no limit. +func newDefragJournal(maxOps int) *defragJournal { + j := &defragJournal{ + ops: make([]defragJournalOp, 0, 1024), + maxOps: maxOps, + } + j.cond = sync.NewCond(&j.mu) + return j +} + +// waitForSpace blocks until the journal has room for more operations +// or is closed. Must be called BEFORE acquiring the batchTx mutex to +// avoid deadlock: writers wait here without holding the mutex, so +// the defrag goroutine can still acquire the mutex to drain the journal. +func (j *defragJournal) waitForSpace() { + j.mu.Lock() + defer j.mu.Unlock() + for j.maxOps > 0 && len(j.ops) >= j.maxOps && !j.closed { + j.cond.Wait() + } +} + +func (j *defragJournal) appendPut(bucketName, key, value []byte, seq bool) { + j.mu.Lock() + defer j.mu.Unlock() + if j.closed { + panic("defragJournal: append to closed journal") + } + j.ops = append(j.ops, defragJournalOp{ + opType: opPut, + bucketName: bucketName, + key: key, + value: value, + seq: seq, + }) +} + +func (j *defragJournal) appendDelete(bucketName, key []byte) { + j.mu.Lock() + defer j.mu.Unlock() + if j.closed { + panic("defragJournal: append to closed journal") + } + j.ops = append(j.ops, defragJournalOp{ + opType: opDelete, + bucketName: bucketName, + key: key, + }) +} + +func (j *defragJournal) appendCreateBucket(bucketName []byte) { + j.mu.Lock() + defer j.mu.Unlock() + if j.closed { + panic("defragJournal: append to closed journal") + } + j.ops = append(j.ops, defragJournalOp{ + opType: opCreateBucket, + bucketName: bucketName, + }) +} + +func (j *defragJournal) appendDeleteBucket(bucketName []byte) { + j.mu.Lock() + defer j.mu.Unlock() + if j.closed { + panic("defragJournal: append to closed journal") + } + j.ops = append(j.ops, defragJournalOp{ + opType: opDeleteBucket, + bucketName: bucketName, + }) +} + +// closeAndDrain marks the journal as closed, wakes any writers +// blocked in waitForSpace, and returns all accumulated ops. +func (j *defragJournal) closeAndDrain() []defragJournalOp { + j.mu.Lock() + defer j.mu.Unlock() + j.closed = true + ops := j.ops + j.ops = nil + j.cond.Broadcast() + return ops +} diff --git a/etcd/vendor/golang.org/x/sys/unix/syscall_linux.go b/etcd/vendor/golang.org/x/sys/unix/syscall_linux.go index ce4d7ab1ed..21e2bfa398 100644 --- a/etcd/vendor/golang.org/x/sys/unix/syscall_linux.go +++ b/etcd/vendor/golang.org/x/sys/unix/syscall_linux.go @@ -1874,6 +1874,7 @@ func Dup2(oldfd, newfd int) error { //sys Dup3(oldfd int, newfd int, flags int) (err error) //sysnb EpollCreate1(flag int) (fd int, err error) //sysnb EpollCtl(epfd int, op int, fd int, event *EpollEvent) (err error) +//sys EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) = SYS_EPOLL_PWAIT //sys Eventfd(initval uint, flags int) (fd int, err error) = SYS_EVENTFD2 //sys Exit(code int) = SYS_EXIT_GROUP //sys Fallocate(fd int, mode uint32, off int64, len int64) (err error) diff --git a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_386.go b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_386.go index 506dafa7b4..210d545c93 100644 --- a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_386.go +++ b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_386.go @@ -20,7 +20,6 @@ func setTimeval(sec, usec int64) Timeval { // 64-bit file system and 32-bit uid calls // (386 default is 32-bit file system and 16-bit uid). -//sys EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) //sys Fadvise(fd int, offset int64, length int64, advice int) (err error) = SYS_FADVISE64_64 //sys Fchown(fd int, uid int, gid int) (err error) = SYS_FCHOWN32 //sys Fstat(fd int, stat *Stat_t) (err error) = SYS_FSTAT64 diff --git a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_amd64.go b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_amd64.go index d557cf8de3..a9a52f2319 100644 --- a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_amd64.go +++ b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_amd64.go @@ -6,7 +6,6 @@ package unix -//sys EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) //sys Fadvise(fd int, offset int64, length int64, advice int) (err error) = SYS_FADVISE64 //sys Fchown(fd int, uid int, gid int) (err error) //sys Fstat(fd int, stat *Stat_t) (err error) diff --git a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_arm.go b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_arm.go index ecf92bfa2a..54474c20fe 100644 --- a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_arm.go +++ b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_arm.go @@ -44,7 +44,6 @@ func Seek(fd int, offset int64, whence int) (newoffset int64, err error) { // 64-bit file system and 32-bit uid calls // (16-bit uid calls are not always supported in newer kernels) -//sys EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) //sys Fchown(fd int, uid int, gid int) (err error) = SYS_FCHOWN32 //sys Fstat(fd int, stat *Stat_t) (err error) = SYS_FSTAT64 //sys Fstatat(dirfd int, path string, stat *Stat_t, flags int) (err error) = SYS_FSTATAT64 diff --git a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_arm64.go b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_arm64.go index 173738077b..e9f30db97d 100644 --- a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_arm64.go +++ b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_arm64.go @@ -8,7 +8,6 @@ package unix import "unsafe" -//sys EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) = SYS_EPOLL_PWAIT //sys Fadvise(fd int, offset int64, length int64, advice int) (err error) = SYS_FADVISE64 //sys Fchown(fd int, uid int, gid int) (err error) //sys Fstat(fd int, stat *Stat_t) (err error) diff --git a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_loong64.go b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_loong64.go index a3fd1d0b80..6f09ca200a 100644 --- a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_loong64.go +++ b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_loong64.go @@ -8,7 +8,6 @@ package unix import "unsafe" -//sys EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) = SYS_EPOLL_PWAIT //sys Fadvise(fd int, offset int64, length int64, advice int) (err error) = SYS_FADVISE64 //sys Fchown(fd int, uid int, gid int) (err error) //sys Fstatfs(fd int, buf *Statfs_t) (err error) diff --git a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_mips64x.go b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_mips64x.go index 70963a95ab..ca3b56597d 100644 --- a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_mips64x.go +++ b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_mips64x.go @@ -6,7 +6,6 @@ package unix -//sys EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) //sys Fadvise(fd int, offset int64, length int64, advice int) (err error) = SYS_FADVISE64 //sys Fchown(fd int, uid int, gid int) (err error) //sys Fstatfs(fd int, buf *Statfs_t) (err error) diff --git a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_mipsx.go b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_mipsx.go index c218ebd280..54ba667b1b 100644 --- a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_mipsx.go +++ b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_mipsx.go @@ -13,7 +13,6 @@ import ( func Syscall9(trap, a1, a2, a3, a4, a5, a6, a7, a8, a9 uintptr) (r1, r2 uintptr, err syscall.Errno) -//sys EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) //sys Fadvise(fd int, offset int64, length int64, advice int) (err error) = SYS_FADVISE64 //sys Fchown(fd int, uid int, gid int) (err error) //sys Ftruncate(fd int, length int64) (err error) = SYS_FTRUNCATE64 diff --git a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_ppc.go b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_ppc.go index e6c48500ca..ce46285902 100644 --- a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_ppc.go +++ b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_ppc.go @@ -11,7 +11,6 @@ import ( "unsafe" ) -//sys EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) //sys Fchown(fd int, uid int, gid int) (err error) //sys Fstat(fd int, stat *Stat_t) (err error) = SYS_FSTAT64 //sys Fstatat(dirfd int, path string, stat *Stat_t, flags int) (err error) = SYS_FSTATAT64 diff --git a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_ppc64x.go b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_ppc64x.go index 7286a9aa88..33f7af3804 100644 --- a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_ppc64x.go +++ b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_ppc64x.go @@ -6,7 +6,6 @@ package unix -//sys EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) //sys Fadvise(fd int, offset int64, length int64, advice int) (err error) = SYS_FADVISE64 //sys Fchown(fd int, uid int, gid int) (err error) //sys Fstat(fd int, stat *Stat_t) (err error) diff --git a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_riscv64.go b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_riscv64.go index fc5543c5ff..c658871e30 100644 --- a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_riscv64.go +++ b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_riscv64.go @@ -8,7 +8,6 @@ package unix import "unsafe" -//sys EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) = SYS_EPOLL_PWAIT //sys Fadvise(fd int, offset int64, length int64, advice int) (err error) = SYS_FADVISE64 //sys Fchown(fd int, uid int, gid int) (err error) //sys Fstat(fd int, stat *Stat_t) (err error) diff --git a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_s390x.go b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_s390x.go index 66f31210d0..2c8587691b 100644 --- a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_s390x.go +++ b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_s390x.go @@ -10,7 +10,6 @@ import ( "unsafe" ) -//sys EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) //sys Fadvise(fd int, offset int64, length int64, advice int) (err error) = SYS_FADVISE64 //sys Fchown(fd int, uid int, gid int) (err error) //sys Fstat(fd int, stat *Stat_t) (err error) diff --git a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_sparc64.go b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_sparc64.go index 11d1f16986..4964119af8 100644 --- a/etcd/vendor/golang.org/x/sys/unix/syscall_linux_sparc64.go +++ b/etcd/vendor/golang.org/x/sys/unix/syscall_linux_sparc64.go @@ -6,7 +6,6 @@ package unix -//sys EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) //sys Fadvise(fd int, offset int64, length int64, advice int) (err error) = SYS_FADVISE64 //sys Fchown(fd int, uid int, gid int) (err error) //sys Fstat(fd int, stat *Stat_t) (err error) diff --git a/etcd/vendor/golang.org/x/sys/unix/zerrors_linux.go b/etcd/vendor/golang.org/x/sys/unix/zerrors_linux.go index 9d72a6b73a..5bb51d7ae1 100644 --- a/etcd/vendor/golang.org/x/sys/unix/zerrors_linux.go +++ b/etcd/vendor/golang.org/x/sys/unix/zerrors_linux.go @@ -1359,6 +1359,7 @@ const ( FAN_UNLIMITED_MARKS = 0x20 FAN_UNLIMITED_QUEUE = 0x10 FD_CLOEXEC = 0x1 + FD_PIDFS_ROOT = -0x2712 FD_SETSIZE = 0x400 FF0 = 0x0 FIB_RULE_DEV_DETACHED = 0x8 @@ -1970,6 +1971,8 @@ const ( MADV_DONTNEED = 0x4 MADV_DONTNEED_LOCKED = 0x18 MADV_FREE = 0x8 + MADV_GUARD_INSTALL = 0x66 + MADV_GUARD_REMOVE = 0x67 MADV_HUGEPAGE = 0xe MADV_HWPOISON = 0x64 MADV_KEEPONFORK = 0x13 @@ -2114,7 +2117,7 @@ const ( MS_NOSEC = 0x10000000 MS_NOSUID = 0x2 MS_NOSYMFOLLOW = 0x100 - MS_NOUSER = -0x80000000 + MS_NOUSER = 0x80000000 MS_POSIXACL = 0x10000 MS_PRIVATE = 0x40000 MS_RDONLY = 0x1 @@ -3786,6 +3789,9 @@ const ( TCPOPT_TIMESTAMP = 0x8 TCPOPT_TSTAMP_HDR = 0x101080a TCPOPT_WINDOW = 0x3 + TCP_AO_KEYF_EXCLUDE_OPT = 0x2 + TCP_AO_KEYF_IFINDEX = 0x1 + TCP_AO_MAXKEYLEN = 0x50 TCP_CC_INFO = 0x1a TCP_CM_INQ = 0x24 TCP_CONGESTION = 0xd diff --git a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux.go b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux.go index 80f40e4013..5788c2a58d 100644 --- a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux.go +++ b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux.go @@ -700,6 +700,23 @@ func EpollCtl(epfd int, op int, fd int, event *EpollEvent) (err error) { // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT +func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) { + var _p0 unsafe.Pointer + if len(events) > 0 { + _p0 = unsafe.Pointer(&events[0]) + } else { + _p0 = unsafe.Pointer(&_zero) + } + r0, _, e1 := Syscall6(SYS_EPOLL_PWAIT, uintptr(epfd), uintptr(_p0), uintptr(len(events)), uintptr(msec), 0, 0) + n = int(r0) + if e1 != 0 { + err = errnoErr(e1) + } + return +} + +// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT + func Eventfd(initval uint, flags int) (fd int, err error) { r0, _, e1 := Syscall(SYS_EVENTFD2, uintptr(initval), uintptr(flags), 0) fd = int(r0) diff --git a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_386.go b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_386.go index 4def3e9fcb..254f33988f 100644 --- a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_386.go +++ b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_386.go @@ -45,23 +45,6 @@ func Tee(rfd int, wfd int, len int, flags int) (n int64, err error) { // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT -func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) { - var _p0 unsafe.Pointer - if len(events) > 0 { - _p0 = unsafe.Pointer(&events[0]) - } else { - _p0 = unsafe.Pointer(&_zero) - } - r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), uintptr(len(events)), uintptr(msec), 0, 0) - n = int(r0) - if e1 != 0 { - err = errnoErr(e1) - } - return -} - -// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT - func Fadvise(fd int, offset int64, length int64, advice int) (err error) { _, _, e1 := Syscall6(SYS_FADVISE64_64, uintptr(fd), uintptr(offset), uintptr(offset>>32), uintptr(length), uintptr(length>>32), uintptr(advice)) if e1 != 0 { diff --git a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_amd64.go b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_amd64.go index fef2bc8ba9..27c05db1ac 100644 --- a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_amd64.go +++ b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_amd64.go @@ -45,23 +45,6 @@ func Tee(rfd int, wfd int, len int, flags int) (n int64, err error) { // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT -func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) { - var _p0 unsafe.Pointer - if len(events) > 0 { - _p0 = unsafe.Pointer(&events[0]) - } else { - _p0 = unsafe.Pointer(&_zero) - } - r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), uintptr(len(events)), uintptr(msec), 0, 0) - n = int(r0) - if e1 != 0 { - err = errnoErr(e1) - } - return -} - -// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT - func Fadvise(fd int, offset int64, length int64, advice int) (err error) { _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), uintptr(length), uintptr(advice), 0, 0) if e1 != 0 { diff --git a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_arm.go b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_arm.go index a9fd76a884..840d85bfc3 100644 --- a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_arm.go +++ b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_arm.go @@ -213,23 +213,6 @@ func sendmsg(s int, msg *Msghdr, flags int) (n int, err error) { // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT -func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) { - var _p0 unsafe.Pointer - if len(events) > 0 { - _p0 = unsafe.Pointer(&events[0]) - } else { - _p0 = unsafe.Pointer(&_zero) - } - r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), uintptr(len(events)), uintptr(msec), 0, 0) - n = int(r0) - if e1 != 0 { - err = errnoErr(e1) - } - return -} - -// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT - func Fchown(fd int, uid int, gid int) (err error) { _, _, e1 := Syscall(SYS_FCHOWN32, uintptr(fd), uintptr(uid), uintptr(gid)) if e1 != 0 { diff --git a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_arm64.go b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_arm64.go index 4600650280..fe414498b4 100644 --- a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_arm64.go +++ b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_arm64.go @@ -45,23 +45,6 @@ func Tee(rfd int, wfd int, len int, flags int) (n int64, err error) { // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT -func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) { - var _p0 unsafe.Pointer - if len(events) > 0 { - _p0 = unsafe.Pointer(&events[0]) - } else { - _p0 = unsafe.Pointer(&_zero) - } - r0, _, e1 := Syscall6(SYS_EPOLL_PWAIT, uintptr(epfd), uintptr(_p0), uintptr(len(events)), uintptr(msec), 0, 0) - n = int(r0) - if e1 != 0 { - err = errnoErr(e1) - } - return -} - -// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT - func Fadvise(fd int, offset int64, length int64, advice int) (err error) { _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), uintptr(length), uintptr(advice), 0, 0) if e1 != 0 { diff --git a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_loong64.go b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_loong64.go index c8987d2646..eb358ce05a 100644 --- a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_loong64.go +++ b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_loong64.go @@ -45,23 +45,6 @@ func Tee(rfd int, wfd int, len int, flags int) (n int64, err error) { // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT -func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) { - var _p0 unsafe.Pointer - if len(events) > 0 { - _p0 = unsafe.Pointer(&events[0]) - } else { - _p0 = unsafe.Pointer(&_zero) - } - r0, _, e1 := Syscall6(SYS_EPOLL_PWAIT, uintptr(epfd), uintptr(_p0), uintptr(len(events)), uintptr(msec), 0, 0) - n = int(r0) - if e1 != 0 { - err = errnoErr(e1) - } - return -} - -// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT - func Fadvise(fd int, offset int64, length int64, advice int) (err error) { _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), uintptr(length), uintptr(advice), 0, 0) if e1 != 0 { diff --git a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_mips.go b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_mips.go index 921f430611..c437622f14 100644 --- a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_mips.go +++ b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_mips.go @@ -45,23 +45,6 @@ func Tee(rfd int, wfd int, len int, flags int) (n int64, err error) { // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT -func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) { - var _p0 unsafe.Pointer - if len(events) > 0 { - _p0 = unsafe.Pointer(&events[0]) - } else { - _p0 = unsafe.Pointer(&_zero) - } - r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), uintptr(len(events)), uintptr(msec), 0, 0) - n = int(r0) - if e1 != 0 { - err = errnoErr(e1) - } - return -} - -// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT - func Fadvise(fd int, offset int64, length int64, advice int) (err error) { _, _, e1 := Syscall9(SYS_FADVISE64, uintptr(fd), 0, uintptr(offset>>32), uintptr(offset), uintptr(length>>32), uintptr(length), uintptr(advice), 0, 0) if e1 != 0 { diff --git a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_mips64.go b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_mips64.go index 44f067829c..bc4ca25582 100644 --- a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_mips64.go +++ b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_mips64.go @@ -45,23 +45,6 @@ func Tee(rfd int, wfd int, len int, flags int) (n int64, err error) { // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT -func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) { - var _p0 unsafe.Pointer - if len(events) > 0 { - _p0 = unsafe.Pointer(&events[0]) - } else { - _p0 = unsafe.Pointer(&_zero) - } - r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), uintptr(len(events)), uintptr(msec), 0, 0) - n = int(r0) - if e1 != 0 { - err = errnoErr(e1) - } - return -} - -// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT - func Fadvise(fd int, offset int64, length int64, advice int) (err error) { _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), uintptr(length), uintptr(advice), 0, 0) if e1 != 0 { diff --git a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_mips64le.go b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_mips64le.go index e7fa0abf0d..5051435ce7 100644 --- a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_mips64le.go +++ b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_mips64le.go @@ -45,23 +45,6 @@ func Tee(rfd int, wfd int, len int, flags int) (n int64, err error) { // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT -func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) { - var _p0 unsafe.Pointer - if len(events) > 0 { - _p0 = unsafe.Pointer(&events[0]) - } else { - _p0 = unsafe.Pointer(&_zero) - } - r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), uintptr(len(events)), uintptr(msec), 0, 0) - n = int(r0) - if e1 != 0 { - err = errnoErr(e1) - } - return -} - -// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT - func Fadvise(fd int, offset int64, length int64, advice int) (err error) { _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), uintptr(length), uintptr(advice), 0, 0) if e1 != 0 { diff --git a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_mipsle.go b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_mipsle.go index 8c5125675e..33aa5418a4 100644 --- a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_mipsle.go +++ b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_mipsle.go @@ -45,23 +45,6 @@ func Tee(rfd int, wfd int, len int, flags int) (n int64, err error) { // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT -func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) { - var _p0 unsafe.Pointer - if len(events) > 0 { - _p0 = unsafe.Pointer(&events[0]) - } else { - _p0 = unsafe.Pointer(&_zero) - } - r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), uintptr(len(events)), uintptr(msec), 0, 0) - n = int(r0) - if e1 != 0 { - err = errnoErr(e1) - } - return -} - -// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT - func Fadvise(fd int, offset int64, length int64, advice int) (err error) { _, _, e1 := Syscall9(SYS_FADVISE64, uintptr(fd), 0, uintptr(offset), uintptr(offset>>32), uintptr(length), uintptr(length>>32), uintptr(advice), 0, 0) if e1 != 0 { diff --git a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc.go b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc.go index 7392fd45e4..3bef8ef1d2 100644 --- a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc.go +++ b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc.go @@ -45,23 +45,6 @@ func Tee(rfd int, wfd int, len int, flags int) (n int64, err error) { // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT -func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) { - var _p0 unsafe.Pointer - if len(events) > 0 { - _p0 = unsafe.Pointer(&events[0]) - } else { - _p0 = unsafe.Pointer(&_zero) - } - r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), uintptr(len(events)), uintptr(msec), 0, 0) - n = int(r0) - if e1 != 0 { - err = errnoErr(e1) - } - return -} - -// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT - func Fchown(fd int, uid int, gid int) (err error) { _, _, e1 := Syscall(SYS_FCHOWN, uintptr(fd), uintptr(uid), uintptr(gid)) if e1 != 0 { diff --git a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64.go b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64.go index 41180434e6..fc1bd4e2c4 100644 --- a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64.go +++ b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64.go @@ -45,23 +45,6 @@ func Tee(rfd int, wfd int, len int, flags int) (n int64, err error) { // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT -func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) { - var _p0 unsafe.Pointer - if len(events) > 0 { - _p0 = unsafe.Pointer(&events[0]) - } else { - _p0 = unsafe.Pointer(&_zero) - } - r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), uintptr(len(events)), uintptr(msec), 0, 0) - n = int(r0) - if e1 != 0 { - err = errnoErr(e1) - } - return -} - -// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT - func Fadvise(fd int, offset int64, length int64, advice int) (err error) { _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), uintptr(length), uintptr(advice), 0, 0) if e1 != 0 { diff --git a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64le.go b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64le.go index 40c6ce7ae5..d78fe7dabe 100644 --- a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64le.go +++ b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64le.go @@ -45,23 +45,6 @@ func Tee(rfd int, wfd int, len int, flags int) (n int64, err error) { // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT -func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) { - var _p0 unsafe.Pointer - if len(events) > 0 { - _p0 = unsafe.Pointer(&events[0]) - } else { - _p0 = unsafe.Pointer(&_zero) - } - r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), uintptr(len(events)), uintptr(msec), 0, 0) - n = int(r0) - if e1 != 0 { - err = errnoErr(e1) - } - return -} - -// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT - func Fadvise(fd int, offset int64, length int64, advice int) (err error) { _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), uintptr(length), uintptr(advice), 0, 0) if e1 != 0 { diff --git a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_riscv64.go b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_riscv64.go index 2cfe34adb1..76dcf87d01 100644 --- a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_riscv64.go +++ b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_riscv64.go @@ -45,23 +45,6 @@ func Tee(rfd int, wfd int, len int, flags int) (n int64, err error) { // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT -func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) { - var _p0 unsafe.Pointer - if len(events) > 0 { - _p0 = unsafe.Pointer(&events[0]) - } else { - _p0 = unsafe.Pointer(&_zero) - } - r0, _, e1 := Syscall6(SYS_EPOLL_PWAIT, uintptr(epfd), uintptr(_p0), uintptr(len(events)), uintptr(msec), 0, 0) - n = int(r0) - if e1 != 0 { - err = errnoErr(e1) - } - return -} - -// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT - func Fadvise(fd int, offset int64, length int64, advice int) (err error) { _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), uintptr(length), uintptr(advice), 0, 0) if e1 != 0 { diff --git a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_s390x.go b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_s390x.go index 61e6f07097..2cf020f2ba 100644 --- a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_s390x.go +++ b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_s390x.go @@ -45,23 +45,6 @@ func Tee(rfd int, wfd int, len int, flags int) (n int64, err error) { // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT -func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) { - var _p0 unsafe.Pointer - if len(events) > 0 { - _p0 = unsafe.Pointer(&events[0]) - } else { - _p0 = unsafe.Pointer(&_zero) - } - r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), uintptr(len(events)), uintptr(msec), 0, 0) - n = int(r0) - if e1 != 0 { - err = errnoErr(e1) - } - return -} - -// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT - func Fadvise(fd int, offset int64, length int64, advice int) (err error) { _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), uintptr(length), uintptr(advice), 0, 0) if e1 != 0 { diff --git a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_sparc64.go b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_sparc64.go index 834b842042..527637623d 100644 --- a/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_sparc64.go +++ b/etcd/vendor/golang.org/x/sys/unix/zsyscall_linux_sparc64.go @@ -45,23 +45,6 @@ func Tee(rfd int, wfd int, len int, flags int) (n int64, err error) { // THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT -func EpollWait(epfd int, events []EpollEvent, msec int) (n int, err error) { - var _p0 unsafe.Pointer - if len(events) > 0 { - _p0 = unsafe.Pointer(&events[0]) - } else { - _p0 = unsafe.Pointer(&_zero) - } - r0, _, e1 := Syscall6(SYS_EPOLL_WAIT, uintptr(epfd), uintptr(_p0), uintptr(len(events)), uintptr(msec), 0, 0) - n = int(r0) - if e1 != 0 { - err = errnoErr(e1) - } - return -} - -// THIS FILE IS GENERATED BY THE COMMAND AT THE TOP; DO NOT EDIT - func Fadvise(fd int, offset int64, length int64, advice int) (err error) { _, _, e1 := Syscall6(SYS_FADVISE64, uintptr(fd), uintptr(offset), uintptr(length), uintptr(advice), 0, 0) if e1 != 0 { diff --git a/etcd/vendor/golang.org/x/sys/windows/security_windows.go b/etcd/vendor/golang.org/x/sys/windows/security_windows.go index 6c955cea15..783621561e 100644 --- a/etcd/vendor/golang.org/x/sys/windows/security_windows.go +++ b/etcd/vendor/golang.org/x/sys/windows/security_windows.go @@ -1109,17 +1109,53 @@ const ( ) // This type is the union inside of TRUSTEE and must be created using one of the TrusteeValueFrom* functions. +// +// Go pointers stored in a TrusteeValue must be pinned using [runtime.Pinner] +// for the lifetime of the TrusteeValue. type TrusteeValue uintptr +// TrusteeValueFromString is unsafe and should not be used. +// +// It returns a uintptr containing a reference to newly-allocated memory +// which will be freed by the garbage collector. +// There is no way for the caller to safely reference this memory. +// +// To create a [TrusteeValue] from a string, use: +// +// p, err := windows.UTF16PtrFromString(s) +// if err != nil { +// // handle error +// } +// +// // Pin the string for as long as it is used. +// var pinner runtime.Pinner +// pinner.Pin(p) +// defer pinner.Unpin() +// +// tv := TrusteeValue(unsafe.Pointer(p)) +// +// Deprecated: TrusteeValueFromString is unsafe and should not be used. func TrusteeValueFromString(str string) TrusteeValue { return TrusteeValue(unsafe.Pointer(StringToUTF16Ptr(str))) } + +// TrusteeValueFromSID returns a [TrusteeValue] referencing sid. +// +// The caller must pin sid using a [runtime.Pinner] for the lifetime of the TrusteeValue. func TrusteeValueFromSID(sid *SID) TrusteeValue { return TrusteeValue(unsafe.Pointer(sid)) } + +// TrusteeValueFromObjectsAndSid returns a [TrusteeValue] referencing objectsAndSid. +// +// The caller must pin objectsAndSid using a [runtime.Pinner] for the lifetime of the TrusteeValue. func TrusteeValueFromObjectsAndSid(objectsAndSid *OBJECTS_AND_SID) TrusteeValue { return TrusteeValue(unsafe.Pointer(objectsAndSid)) } + +// TrusteeValueFromObjectsAndName returns a [TrusteeValue] referencing objectsAndName. +// +// The caller must pin objectsAndName using a [runtime.Pinner] for the lifetime of the TrusteeValue. func TrusteeValueFromObjectsAndName(objectsAndName *OBJECTS_AND_NAME) TrusteeValue { return TrusteeValue(unsafe.Pointer(objectsAndName)) } diff --git a/etcd/vendor/golang.org/x/sys/windows/syscall_windows.go b/etcd/vendor/golang.org/x/sys/windows/syscall_windows.go index 9755bca9fd..e6966b4c32 100644 --- a/etcd/vendor/golang.org/x/sys/windows/syscall_windows.go +++ b/etcd/vendor/golang.org/x/sys/windows/syscall_windows.go @@ -1728,11 +1728,15 @@ func (s *NTUnicodeString) String() string { // the more common *uint16 string type. func NewNTString(s string) (*NTString, error) { var nts NTString - s8, err := BytePtrFromString(s) + s8, err := ByteSliceFromString(s) if err != nil { return nil, err } - RtlInitString(&nts, s8) + // The source string plus its terminating NUL must fit within MAX_USHORT. + if len(s8) > MAX_USHORT { + return nil, syscall.EINVAL + } + RtlInitString(&nts, &s8[0]) return &nts, nil } diff --git a/etcd/vendor/golang.org/x/sys/windows/types_windows.go b/etcd/vendor/golang.org/x/sys/windows/types_windows.go index d2574a73ee..75a50b3165 100644 --- a/etcd/vendor/golang.org/x/sys/windows/types_windows.go +++ b/etcd/vendor/golang.org/x/sys/windows/types_windows.go @@ -169,6 +169,7 @@ const ( FORMAT_MESSAGE_ARGUMENT_ARRAY = 8192 FORMAT_MESSAGE_MAX_WIDTH_MASK = 255 + MAX_USHORT = 0xffff MAX_PATH = 260 MAX_LONG_PATH = 32768 diff --git a/etcd/vendor/modules.txt b/etcd/vendor/modules.txt index 976469b94b..657b2a2be0 100644 --- a/etcd/vendor/modules.txt +++ b/etcd/vendor/modules.txt @@ -293,7 +293,7 @@ go.etcd.io/bbolt go.etcd.io/bbolt/errors go.etcd.io/bbolt/internal/common go.etcd.io/bbolt/internal/freelist -# go.etcd.io/etcd/api/v3 v3.6.13 => github.com/openshift/etcd/api/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f +# go.etcd.io/etcd/api/v3 v3.6.13 => github.com/openshift/etcd/api/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4 ## explicit; go 1.25.0 go.etcd.io/etcd/api/v3/authpb go.etcd.io/etcd/api/v3/etcdserverpb @@ -303,7 +303,7 @@ go.etcd.io/etcd/api/v3/mvccpb go.etcd.io/etcd/api/v3/v3rpc/rpctypes go.etcd.io/etcd/api/v3/version go.etcd.io/etcd/api/v3/versionpb -# go.etcd.io/etcd/client/pkg/v3 v3.6.13 => github.com/openshift/etcd/client/pkg/v3 v3.0.0-20260722153822-64f8851a001f +# go.etcd.io/etcd/client/pkg/v3 v3.6.13 => github.com/openshift/etcd/client/pkg/v3 v3.0.0-20260810103824-609b11ed8fc4 ## explicit; go 1.25.0 go.etcd.io/etcd/client/pkg/v3/fileutil go.etcd.io/etcd/client/pkg/v3/logutil @@ -314,14 +314,14 @@ go.etcd.io/etcd/client/pkg/v3/tlsutil go.etcd.io/etcd/client/pkg/v3/transport go.etcd.io/etcd/client/pkg/v3/types go.etcd.io/etcd/client/pkg/v3/verify -# go.etcd.io/etcd/client/v3 v3.6.13 => github.com/openshift/etcd/client/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f +# go.etcd.io/etcd/client/v3 v3.6.13 => github.com/openshift/etcd/client/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4 ## explicit; go 1.25.0 go.etcd.io/etcd/client/v3 go.etcd.io/etcd/client/v3/concurrency go.etcd.io/etcd/client/v3/credentials go.etcd.io/etcd/client/v3/internal/endpoint go.etcd.io/etcd/client/v3/internal/resolver -# go.etcd.io/etcd/pkg/v3 v3.6.13 => github.com/openshift/etcd/pkg/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f +# go.etcd.io/etcd/pkg/v3 v3.6.13 => github.com/openshift/etcd/pkg/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4 ## explicit; go 1.25.0 go.etcd.io/etcd/pkg/v3/adt go.etcd.io/etcd/pkg/v3/contention @@ -340,7 +340,7 @@ go.etcd.io/etcd/pkg/v3/runtime go.etcd.io/etcd/pkg/v3/schedule go.etcd.io/etcd/pkg/v3/traceutil go.etcd.io/etcd/pkg/v3/wait -# go.etcd.io/etcd/server/v3 v3.6.8 => github.com/openshift/etcd/server/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f +# go.etcd.io/etcd/server/v3 v3.6.8 => github.com/openshift/etcd/server/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4 ## explicit; go 1.25.0 go.etcd.io/etcd/server/v3/auth go.etcd.io/etcd/server/v3/config @@ -505,7 +505,7 @@ golang.org/x/oauth2/internal # golang.org/x/sync v0.21.0 ## explicit; go 1.25.0 golang.org/x/sync/errgroup -# golang.org/x/sys v0.46.0 +# golang.org/x/sys v0.47.0 ## explicit; go 1.25.0 golang.org/x/sys/plan9 golang.org/x/sys/unix @@ -663,7 +663,7 @@ gopkg.in/inf.v0 # gopkg.in/natefinch/lumberjack.v2 v2.2.1 ## explicit; go 1.13 gopkg.in/natefinch/lumberjack.v2 -# k8s.io/api v1.36.2 => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/api +# k8s.io/api v1.36.3 => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/api ## explicit; go 1.26.0 k8s.io/api/admission/v1 k8s.io/api/admission/v1beta1 @@ -723,7 +723,7 @@ k8s.io/api/storage/v1 k8s.io/api/storage/v1alpha1 k8s.io/api/storage/v1beta1 k8s.io/api/storagemigration/v1beta1 -# k8s.io/apimachinery v1.36.2 => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/apimachinery +# k8s.io/apimachinery v1.36.3 => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/apimachinery ## explicit; go 1.26.0 k8s.io/apimachinery/pkg/api/equality k8s.io/apimachinery/pkg/api/errors @@ -781,18 +781,18 @@ k8s.io/apimachinery/pkg/version k8s.io/apimachinery/pkg/watch k8s.io/apimachinery/third_party/forked/golang/json k8s.io/apimachinery/third_party/forked/golang/reflect -# k8s.io/apiserver v1.36.2 => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiserver +# k8s.io/apiserver v1.36.3 => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiserver ## explicit; go 1.26.0 k8s.io/apiserver/pkg/apis/audit k8s.io/apiserver/pkg/apis/audit/v1 k8s.io/apiserver/pkg/authentication/user -# k8s.io/cli-runtime v1.36.2 => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/cli-runtime +# k8s.io/cli-runtime v1.36.3 => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/cli-runtime ## explicit; go 1.26.0 k8s.io/cli-runtime/pkg/genericclioptions k8s.io/cli-runtime/pkg/genericiooptions k8s.io/cli-runtime/pkg/printers k8s.io/cli-runtime/pkg/resource -# k8s.io/client-go v1.36.2 => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/client-go +# k8s.io/client-go v1.36.3 => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/client-go ## explicit; go 1.26.0 k8s.io/client-go/applyconfigurations/admissionregistration/v1 k8s.io/client-go/applyconfigurations/admissionregistration/v1alpha1 @@ -944,7 +944,7 @@ k8s.io/client-go/util/homedir k8s.io/client-go/util/jsonpath k8s.io/client-go/util/keyutil k8s.io/client-go/util/workqueue -# k8s.io/component-base v1.36.2 => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-base +# k8s.io/component-base v1.36.3 => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-base ## explicit; go 1.26.0 k8s.io/component-base/cli k8s.io/component-base/cli/flag @@ -989,7 +989,7 @@ k8s.io/kube-openapi/pkg/util k8s.io/kube-openapi/pkg/util/proto k8s.io/kube-openapi/pkg/util/proto/validation k8s.io/kube-openapi/pkg/validation/spec -# k8s.io/kubectl v1.36.2 => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubectl +# k8s.io/kubectl v1.36.3 => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubectl ## explicit; go 1.26.0 k8s.io/kubectl/pkg/cmd/util k8s.io/kubectl/pkg/scheme @@ -999,7 +999,7 @@ k8s.io/kubectl/pkg/util/openapi k8s.io/kubectl/pkg/util/templates k8s.io/kubectl/pkg/util/term k8s.io/kubectl/pkg/validation -# k8s.io/kubelet v1.36.2 => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubelet +# k8s.io/kubelet v1.36.3 => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubelet ## explicit; go 1.26.0 k8s.io/kubelet/pkg/apis/deviceplugin/v1beta1 # k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 @@ -1109,11 +1109,11 @@ sigs.k8s.io/yaml sigs.k8s.io/yaml/kyaml # github.com/openshift/microshift => ../ # github.com/onsi/ginkgo/v2 => github.com/openshift/onsi-ginkgo/v2 v2.6.1-0.20260424201627-4d4cc33d669d -# go.etcd.io/etcd/api/v3 => github.com/openshift/etcd/api/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f -# go.etcd.io/etcd/client/pkg/v3 => github.com/openshift/etcd/client/pkg/v3 v3.0.0-20260722153822-64f8851a001f -# go.etcd.io/etcd/client/v3 => github.com/openshift/etcd/client/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f -# go.etcd.io/etcd/pkg/v3 => github.com/openshift/etcd/pkg/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f -# go.etcd.io/etcd/server/v3 => github.com/openshift/etcd/server/v3 v3.5.0-alpha.0.0.20260722153822-64f8851a001f +# go.etcd.io/etcd/api/v3 => github.com/openshift/etcd/api/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4 +# go.etcd.io/etcd/client/pkg/v3 => github.com/openshift/etcd/client/pkg/v3 v3.0.0-20260810103824-609b11ed8fc4 +# go.etcd.io/etcd/client/v3 => github.com/openshift/etcd/client/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4 +# go.etcd.io/etcd/pkg/v3 => github.com/openshift/etcd/pkg/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4 +# go.etcd.io/etcd/server/v3 => github.com/openshift/etcd/server/v3 v3.5.0-alpha.0.0.20260810103824-609b11ed8fc4 # k8s.io/api => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/api # k8s.io/apiextensions-apiserver => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiextensions-apiserver # k8s.io/apimachinery => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/apimachinery diff --git a/go.mod b/go.mod index 5b63d406a4..4b695c81ef 100644 --- a/go.mod +++ b/go.mod @@ -34,24 +34,24 @@ require ( github.com/go-kit/kit v0.9.0 github.com/gogo/protobuf v1.3.2 github.com/golang/snappy v0.0.4 - github.com/openshift/cluster-policy-controller v0.0.0-20260721184556-01afc4aac71a + github.com/openshift/cluster-policy-controller v0.0.0-20260811140609-469bbf211d35 github.com/openshift/route-controller-manager v0.0.0-20260722172158-59697cf7af45 github.com/prometheus/client_model v0.6.2 github.com/prometheus/common v0.67.5 github.com/prometheus/prometheus v0.302.1 github.com/squat/generic-device-plugin v0.0.0-20251019101956-043a51e18f31 gopkg.in/yaml.v2 v2.4.0 - k8s.io/api v1.36.2 - k8s.io/apiextensions-apiserver v1.36.2 - k8s.io/apimachinery v1.36.2 - k8s.io/apiserver v1.36.2 - k8s.io/cli-runtime v1.36.2 - k8s.io/client-go v1.36.2 - k8s.io/cloud-provider v1.36.2 - k8s.io/component-base v1.36.2 - k8s.io/kube-aggregator v1.36.2 - k8s.io/kubectl v1.36.2 - k8s.io/kubelet v1.36.2 + k8s.io/api v1.36.3 + k8s.io/apiextensions-apiserver v1.36.3 + k8s.io/apimachinery v1.36.3 + k8s.io/apiserver v1.36.3 + k8s.io/cli-runtime v1.36.3 + k8s.io/client-go v1.36.3 + k8s.io/cloud-provider v1.36.3 + k8s.io/component-base v1.36.3 + k8s.io/kube-aggregator v1.36.3 + k8s.io/kubectl v1.36.3 + k8s.io/kubelet v1.36.3 k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 sigs.k8s.io/kube-storage-version-migrator v0.0.6-0.20230721195810-5c8923c5ff96 sigs.k8s.io/kustomize/api v0.21.1 @@ -177,23 +177,23 @@ require ( gopkg.in/go-jose/go-jose.v2 v2.6.3 // indirect gopkg.in/inf.v0 v0.9.1 // indirect gopkg.in/natefinch/lumberjack.v2 v2.2.1 // indirect - k8s.io/cluster-bootstrap v1.36.2 // indirect - k8s.io/component-helpers v1.36.2 // indirect - k8s.io/controller-manager v1.36.2 // indirect - k8s.io/cri-api v1.36.2 // indirect - k8s.io/cri-client v1.36.2 // indirect + k8s.io/cluster-bootstrap v1.36.3 // indirect + k8s.io/component-helpers v1.36.3 // indirect + k8s.io/controller-manager v1.36.3 // indirect + k8s.io/cri-api v1.36.3 // indirect + k8s.io/cri-client v1.36.3 // indirect k8s.io/cri-streaming v0.0.0 // indirect - k8s.io/csi-translation-lib v1.36.2 // indirect - k8s.io/dynamic-resource-allocation v1.36.2 // indirect - k8s.io/endpointslice v1.36.2 // indirect - k8s.io/externaljwt v1.36.2 // indirect - k8s.io/kms v1.36.2 // indirect - k8s.io/kube-controller-manager v1.36.2 // indirect - k8s.io/kube-proxy v1.36.2 // indirect - k8s.io/kube-scheduler v1.36.2 // indirect - k8s.io/metrics v1.36.2 // indirect - k8s.io/mount-utils v1.36.2 // indirect - k8s.io/pod-security-admission v1.36.2 // indirect + k8s.io/csi-translation-lib v1.36.3 // indirect + k8s.io/dynamic-resource-allocation v1.36.3 // indirect + k8s.io/endpointslice v1.36.3 // indirect + k8s.io/externaljwt v1.36.3 // indirect + k8s.io/kms v1.36.3 // indirect + k8s.io/kube-controller-manager v1.36.3 // indirect + k8s.io/kube-proxy v1.36.3 // indirect + k8s.io/kube-scheduler v1.36.3 // indirect + k8s.io/metrics v1.36.3 // indirect + k8s.io/mount-utils v1.36.3 // indirect + k8s.io/pod-security-admission v1.36.3 // indirect k8s.io/streaming v0.36.2 // indirect sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.34.0 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect @@ -234,7 +234,7 @@ require ( google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af // indirect k8s.io/gengo/v2 v2.0.0-20250922181213-ec3ebc5fd46b // indirect k8s.io/klog/v2 v2.140.0 - k8s.io/kubernetes v1.36.2 + k8s.io/kubernetes v1.36.3 ) replace ( diff --git a/go.sum b/go.sum index f231bd74b2..df7eef02c0 100644 --- a/go.sum +++ b/go.sum @@ -312,8 +312,8 @@ github.com/openshift/build-machinery-go v0.0.0-20260629141115-154a2b810491 h1:P/ github.com/openshift/build-machinery-go v0.0.0-20260629141115-154a2b810491/go.mod h1:8jcm8UPtg2mCAsxfqKil1xrmRMI3a+XU2TZ9fF8A7TE= github.com/openshift/client-go v0.0.0-20260715172546-dac61734e0ec h1:UDjX+mot5IVLpcChyBqLXG1oSB29s4UkqFmgNb0Xsqc= github.com/openshift/client-go v0.0.0-20260715172546-dac61734e0ec/go.mod h1:iMHec0APKVjOH8GfL/RxddX8DuiuSvPlRe+s7KDqlyA= -github.com/openshift/cluster-policy-controller v0.0.0-20260721184556-01afc4aac71a h1:fo3+OOOpwyxeH53dWfyKTv+p2GpRcS6hTIyxPTGDY2Y= -github.com/openshift/cluster-policy-controller v0.0.0-20260721184556-01afc4aac71a/go.mod h1:ujufpXCwp5BBm/OseRiag45V2v7SOhow/O6EoMrVfWg= +github.com/openshift/cluster-policy-controller v0.0.0-20260811140609-469bbf211d35 h1:ltkGdV6r1OWjvvOuJt3VXWRypjGuLnNvTEP8sCkuU8c= +github.com/openshift/cluster-policy-controller v0.0.0-20260811140609-469bbf211d35/go.mod h1:ujufpXCwp5BBm/OseRiag45V2v7SOhow/O6EoMrVfWg= github.com/openshift/kubernetes-kube-storage-version-migrator v0.0.3-0.20260304192652-72835e43c775 h1:4gZibdvRUsxsQ55Tp+HFRjVzkYh+bcRezmYqhiCMk4U= github.com/openshift/kubernetes-kube-storage-version-migrator v0.0.3-0.20260304192652-72835e43c775/go.mod h1:o5cKv/pQ+exEYKq97WapNa5cxSPxuwBezHZHNW5RNRo= github.com/openshift/library-go v0.0.0-20260720185249-0595e37fe20f h1:NdSEtKB+vvHlGELA+jX/c+TALNwe8iSsJAQYvMabgHQ= diff --git a/packaging/crio.conf.d/10-microshift_amd64.conf b/packaging/crio.conf.d/10-microshift_amd64.conf index ae8b830aa9..88eafd5095 100644 --- a/packaging/crio.conf.d/10-microshift_amd64.conf +++ b/packaging/crio.conf.d/10-microshift_amd64.conf @@ -2,6 +2,6 @@ # for community builds on top of OKD, this setting has no effect [crio.image] global_auth_file="/etc/crio/openshift-pull-secret" -pause_image = "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:046dee0e64bb32cdb9d34b43abc4c1b8f2d1700e2243e3812b759e1436677c9b" +pause_image = "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:e1c1886f95f3790e60eba2c0d9b33719c38d970382ba46f306fcc3f632776594" pause_image_auth_file = "/etc/crio/openshift-pull-secret" pause_command = "/usr/bin/pod" diff --git a/packaging/crio.conf.d/10-microshift_arm64.conf b/packaging/crio.conf.d/10-microshift_arm64.conf index 22790acdd0..5b90aa8980 100644 --- a/packaging/crio.conf.d/10-microshift_arm64.conf +++ b/packaging/crio.conf.d/10-microshift_arm64.conf @@ -2,6 +2,6 @@ # for community builds on top of OKD, this setting has no effect [crio.image] global_auth_file="/etc/crio/openshift-pull-secret" -pause_image = "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:a3aba52ab6f516a28f1423d2f71e9e3320d8486a266ca0e8430e47b77c38de9c" +pause_image = "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:b5afa3f89e706db49c48c9ec436f4865c88af28ae275c4b64501e5bac27983cc" pause_image_auth_file = "/etc/crio/openshift-pull-secret" pause_command = "/usr/bin/pod" diff --git a/sbom-microshift-crypto.spdx.json b/sbom-microshift-crypto.spdx.json new file mode 100644 index 0000000000..146928ae92 --- /dev/null +++ b/sbom-microshift-crypto.spdx.json @@ -0,0 +1,672 @@ +{ + "spdxVersion": "SPDX-2.3", + "dataLicense": "CC0-1.0", + "SPDXID": "SPDXRef-DOCUMENT", + "name": "MicroShift-CBOM", + "documentNamespace": "https://microshift.io/spdx/cbom", + "packages": [ + { + "SPDXID": "SPDXRef-Package-RootPackage", + "name": "microshift", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-AES", + "name": "AES", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"block-cipher\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"keygen\"]},\"oid\":\"2.16.840.1.101.3.4.1\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-AES-GCM", + "name": "AES-GCM", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"ae\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"mode\":\"gcm\",\"cryptoFunctions\":[\"encrypt\"]},\"oid\":\"2.16.840.1.101.3.4.1\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-Blowfish", + "name": "Blowfish", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"block-cipher\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"encrypt\",\"keygen\"]}}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-CSHAKE128", + "name": "CSHAKE128", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"xof\",\"parameterSetIdentifier\":\"128\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]},\"oid\":\"2.16.840.1.101.3.4.2\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-CSHAKE256", + "name": "CSHAKE256", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"xof\",\"parameterSetIdentifier\":\"256\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]},\"oid\":\"2.16.840.1.101.3.4.2\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-CSPRNG", + "name": "CSPRNG", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"drbg\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"other\"]}}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-ECDH-", + "name": "ECDH-", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"key-agree\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"other\"]},\"oid\":\"1.2.840.10045.2.1\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-ECDSA", + "name": "ECDSA", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"signature\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"keygen\",\"verify\",\"sign\"]},\"oid\":\"1.2.840.10045.2.1\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-ECDSA-P256", + "name": "ECDSA-P256", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"signature\",\"parameterSetIdentifier\":\"256\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"keygen\"]},\"oid\":\"1.2.840.10045.2.1\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-ECDSA-P384", + "name": "ECDSA-P384", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"signature\",\"parameterSetIdentifier\":\"384\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"keygen\"]},\"oid\":\"1.2.840.10045.2.1\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-ECDSA-P521", + "name": "ECDSA-P521", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"signature\",\"parameterSetIdentifier\":\"521\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"keygen\"]},\"oid\":\"1.2.840.10045.2.1\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-Ed25519", + "name": "Ed25519", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"signature\",\"parameterSetIdentifier\":\"Ed25519\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"verify\",\"keygen\",\"sign\"]},\"oid\":\"1.3.101.112\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-HKDF-", + "name": "HKDF-", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"kdf\",\"parameterSetIdentifier\":\"HKDF-\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"keyderive\"]}}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-HMAC", + "name": "HMAC", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"mac\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"verify\"]},\"oid\":\"1.2.840.113549.2\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-HMAC-", + "name": "HMAC-", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"mac\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"sign\"]},\"oid\":\"1.2.840.113549.2\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-HMAC-md5", + "name": "HMAC-md5", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"mac\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"sign\"]},\"oid\":\"1.2.840.113549.2.6\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-HMAC-sha1", + "name": "HMAC-sha1", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"mac\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"sign\"]},\"oid\":\"1.2.840.113549.2.7\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-HMAC-sha256", + "name": "HMAC-sha256", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"mac\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"sign\"]},\"oid\":\"1.2.840.113549.2.9\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-HMAC-sha512", + "name": "HMAC-sha512", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"mac\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"sign\"]},\"oid\":\"1.2.840.113549.2.11\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-HSalsa20", + "name": "HSalsa20", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"hash\",\"parameterSetIdentifier\":\"256\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]}}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-Keccak-256", + "name": "Keccak-256", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"hash\",\"parameterSetIdentifier\":\"256\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]},\"oid\":\"2.16.840.1.101.3.4.2\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-MD4", + "name": "MD4", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"hash\",\"parameterSetIdentifier\":\"128\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]},\"oid\":\"1.2.840.113549.2.4\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-MD5", + "name": "MD5", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"hash\",\"parameterSetIdentifier\":\"128\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]},\"oid\":\"1.2.840.113549.2.5\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-OTR", + "name": "OTR", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"signature\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"sign\",\"verify\",\"keygen\"]}}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-PBKDF2---", + "name": "PBKDF2---", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"kdf\",\"parameterSetIdentifier\":\"-\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"keyderive\"]},\"oid\":\"1.2.840.113549.1.5.12\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-RSA", + "name": "RSA", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"pke\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"keygen\",\"verify\",\"sign\"]},\"oid\":\"1.2.840.113549.1.1.1\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-RSA-OAEP-sha1", + "name": "RSA-OAEP-sha1", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"pke\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"encrypt\",\"decrypt\"]},\"oid\":\"1.2.840.113549.1.1.1\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-RSA-OAEP-sha256", + "name": "RSA-OAEP-sha256", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"pke\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"encrypt\",\"decrypt\"]},\"oid\":\"1.2.840.113549.1.1.1\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-RSA-PKCS1v15", + "name": "RSA-PKCS1v15", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"pke\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"encrypt\",\"decrypt\"]},\"oid\":\"1.2.840.113549.1.1.1\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-RSA-PKCS1v15-", + "name": "RSA-PKCS1v15-", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"signature\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"verify\",\"sign\"]},\"oid\":\"1.2.840.113549.1.1.1\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-RSA-PSS-", + "name": "RSA-PSS-", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"signature\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"verify\",\"sign\"]},\"oid\":\"1.2.840.113549.1.1.1\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-RSA-PSS-SHA256", + "name": "RSA-PSS-SHA256", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"signature\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"verify\"]},\"oid\":\"1.2.840.113549.1.1.1\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-SHA-1", + "name": "SHA-1", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"hash\",\"parameterSetIdentifier\":\"160\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]},\"oid\":\"1.3.14.3.2.26\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-SHA-224", + "name": "SHA-224", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"hash\",\"parameterSetIdentifier\":\"224\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]},\"oid\":\"2.16.840.1.101.3.4.2.4\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-SHA-256", + "name": "SHA-256", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"hash\",\"parameterSetIdentifier\":\"256\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]},\"oid\":\"2.16.840.1.101.3.4.2.1\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-SHA-3-224", + "name": "SHA-3-224", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"hash\",\"parameterSetIdentifier\":\"224\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]},\"oid\":\"2.16.840.1.101.3.4.2\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-SHA-3-256", + "name": "SHA-3-256", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"hash\",\"parameterSetIdentifier\":\"256\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]},\"oid\":\"2.16.840.1.101.3.4.2\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-SHA-3-384", + "name": "SHA-3-384", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"hash\",\"parameterSetIdentifier\":\"384\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]},\"oid\":\"2.16.840.1.101.3.4.2\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-SHA-3-512", + "name": "SHA-3-512", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"hash\",\"parameterSetIdentifier\":\"512\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]},\"oid\":\"2.16.840.1.101.3.4.2\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-SHA-384", + "name": "SHA-384", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"hash\",\"parameterSetIdentifier\":\"384\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]},\"oid\":\"2.16.840.1.101.3.4.2.2\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-SHA-512", + "name": "SHA-512", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"hash\",\"parameterSetIdentifier\":\"512\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]},\"oid\":\"2.16.840.1.101.3.4.2.3\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-SHA-512-256", + "name": "SHA-512/256", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"hash\",\"parameterSetIdentifier\":\"256\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]},\"oid\":\"2.16.840.1.101.3.4.2\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-SHAKE128", + "name": "SHAKE128", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"xof\",\"parameterSetIdentifier\":\"128\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]},\"oid\":\"2.16.840.1.101.3.4.2.11\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-SHAKE256", + "name": "SHAKE256", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"xof\",\"parameterSetIdentifier\":\"256\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"digest\"]},\"oid\":\"2.16.840.1.101.3.4.2.12\"}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-Salsa20", + "name": "Salsa20", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"stream-cipher\",\"parameterSetIdentifier\":\"256\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"encrypt\"]}}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-XSalsa20-Poly1305", + "name": "XSalsa20-Poly1305", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"ae\",\"parameterSetIdentifier\":\"256\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"encrypt\",\"decrypt\"]}}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-bcrypt", + "name": "bcrypt", + "comment": "{\"assetType\":\"algorithm\",\"algorithmProperties\":{\"primitive\":\"kdf\",\"executionEnvironment\":\"software-plain-ram\",\"implementationPlatform\":\"x86_64\",\"cryptoFunctions\":[\"verify\",\"keyderive\"]}}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-private-key", + "name": "private-key", + "comment": "{\"assetType\":\"related-crypto-material\",\"relatedCryptoMaterialProperties\":{\"type\":\"private-key\"}}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-public-key", + "name": "public-key", + "comment": "{\"assetType\":\"related-crypto-material\",\"relatedCryptoMaterialProperties\":{\"type\":\"public-key\"}}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + }, + { + "SPDXID": "SPDXRef-Package-signature", + "name": "signature", + "comment": "{\"assetType\":\"related-crypto-material\",\"relatedCryptoMaterialProperties\":{\"type\":\"signature\"}}", + "description": "Converted CBOM component from CycloneDX to SPDX", + "downloadLocation": "NOASSERTION", + "filesAnalyzed": false + } + ], + "relationships": [ + { + "spdxElementId": "SPDXRef-DOCUMENT", + "relatedSpdxElement": "SPDXRef-Package-RootPackage", + "relationshipType": "DESCRIBES" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-AES", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-AES-GCM", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-Blowfish", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-CSHAKE128", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-CSHAKE256", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-CSPRNG", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-ECDH-", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-ECDSA", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-ECDSA-P256", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-ECDSA-P384", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-ECDSA-P521", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-Ed25519", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-HKDF-", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-HMAC", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-HMAC-", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-HMAC-md5", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-HMAC-sha1", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-HMAC-sha256", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-HMAC-sha512", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-HSalsa20", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-Keccak-256", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-MD4", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-MD5", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-OTR", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-PBKDF2---", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-RSA", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-RSA-OAEP-sha1", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-RSA-OAEP-sha256", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-RSA-PKCS1v15", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-RSA-PKCS1v15-", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-RSA-PSS-", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-RSA-PSS-SHA256", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-SHA-1", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-SHA-224", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-SHA-256", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-SHA-3-224", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-SHA-3-256", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-SHA-3-384", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-SHA-3-512", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-SHA-384", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-SHA-512", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-SHA-512-256", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-SHAKE128", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-SHAKE256", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-Salsa20", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-XSalsa20-Poly1305", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-bcrypt", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-private-key", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-public-key", + "relationshipType": "CONTAINS" + }, + { + "spdxElementId": "SPDXRef-Package-RootPackage", + "relatedSpdxElement": "SPDXRef-Package-signature", + "relationshipType": "CONTAINS" + } + ] +} diff --git a/scripts/auto-rebase/changelog.txt b/scripts/auto-rebase/changelog.txt index 00dd54e0f4..9781a5ae47 100644 --- a/scripts/auto-rebase/changelog.txt +++ b/scripts/auto-rebase/changelog.txt @@ -1,7 +1,459 @@ -- oc image-arm64 994613040335f72809854babcb80b9d11a4e98d5 to a88e785e90aa96ac96da93359bacf3ea5c174733 +- api embedded-component 581cfdf7198613bd325c185eb3eac672670da633 to af5c920502e23802ac1aec0eeb47740520dcb3d6 + - 8978a020 2026-08-18T12:57:25Z Revert "CNTRLPLANE-3871: promote OSStreams feature gate to Default for Hypershift" + - 89478e4a 2026-08-13T09:18:24+02:00 feat: CNTRLPLANE-3871: promote OSStreams feature gate to Default for Hypershift + - 42ec1d00 2026-08-12T15:09:42+02:00 MON-4608: add interrupts to NodeExporterCollectorConfig CRD types + - f89b3ce1 2026-08-11T20:42:12+02:00 chore: remove AWSServiceLBNetworkSecurityGroup feature gate + - 1aba41ca 2026-08-11T12:37:46-04:00 Add system service-level GOMAXPROCS configuration support + - b580b250 2026-08-11T12:37:46-04:00 Add container-level GOMAXPROCS injection support + - 18b6a38c 2026-08-07T12:45:53+02:00 Promote SELinuxMountGAReadiness to GA + - 58e3772c 2026-08-06T14:26:44-07:00 make update-codegen-crds for Azure IL6 + - a0732710 2026-08-06T14:50:54-04:00 Move GCD to TechPreview + - d6c47b1e 2026-08-06T11:09:11-07:00 config: Azure IL6 Secret Cloud support + - 2f8ef393 2026-08-05T10:47:22-03:00 set proper api-approved PR for ingresses.operator API + - 8ffacebd 2026-08-05T10:35:14-03:00 add API do payload generation script + - 0c7ee405 2026-08-05T10:35:13-03:00 NE-2778: add generated files for ingresses.operator API + - 0acc8c9e 2026-08-05T10:35:13-03:00 NE-2778: add tests for the new ingresses.operator API + - 9dcc59c2 2026-08-05T10:35:13-03:00 NE-2778: Implement the new ingresses.operator API + - 167fd8df 2026-08-05T10:35:13-03:00 NE-2777: Implement featuregate GatewayAPIManagementMode + - a694cf31 2026-08-05T14:24:49+02:00 MON-4625: add support for the nvmesubsystem collector + - 502ebf7b 2026-08-05T11:39:50+02:00 Applied rebase. Generated crds + - 5289f854 2026-08-04T17:23:34+01:00 Authentication config must not use format validations + - eeecccec 2026-08-04T17:23:33+01:00 Ingress ComponentRoute labels should use regex instead of format CEL library + - dd74e769 2026-08-03T09:45:28-04:00 AGENT-1493: Promote NoRegistryClusterInstall Feature to Default + - 6935ef91 2026-08-03T09:45:28-04:00 Remove manual override to serve v1 of internalreleaseimages API + - e5a6b6c2 2026-07-31T14:14:48+01:00 Use regex instead of format help for KMS secret name validation + - 9a13390b 2026-07-30T18:20:16+01:00 Address review comments: improve docs and test coverage + - 09530582 2026-07-30T18:31:42+02:00 Promote VolumeGroupSnapshots to GA + - e8f898e5 2026-07-30T16:08:46+01:00 CORS-4417: Add UniverseDomain field to GCPPlatformStatus + - 5ab63aea 2026-07-30T09:32:04-03:00 remove RouteExternalCertificate feature gate + - fc7e61b7 2026-07-30T11:14:03+02:00 MON-4620: expose remote-write protocol version + - fe597b07 2026-07-30T10:58:57+02:00 MON-4558: add zoneinfo to NodeExporterCollectorConfig CRD types + - fbdc6c69 2026-07-28T11:26:19-04:00 Promote CRIOCredentialProviderConfig to default, drop v1alpha1 override + - 0c727139 2026-07-27T14:03:00-04:00 graduate etcdBackendQuota to GA + - 716553af 2026-07-27T11:26:57-04:00 Promote AWS DualStack to Default + - bc8cebd3 2026-07-27T13:14:00+02:00 MON-4616: add support for dmmultipath collector + - 217ca8ce 2026-07-27T12:59:02+02:00 Remove NewOLMPreflightPermissionChecks FeatureGate + - 5c06b67f 2026-07-24T07:53:19-04:00 Added vSphere failure domain to vcenter ratcheting tests + - db1ed9c2 2026-07-24T07:53:13-04:00 Added vSphere failure domain to vcenter check + - ffbad1d3 2026-07-24T12:14:11+01:00 Check all hypershift variants when the featuregate is not platform specific + - 833c6e73 2026-07-24T08:35:50+02:00 OCPNODE-4521: Promote AdditionalStorageConfig feature gate to Default + - bb7402c2 2026-07-23T11:59:36-03:00 Promote Multi HAProxy Versions feature to default + - f4a969be 2026-07-23T14:02:51+02:00 make update + - 62822773 2026-07-23T14:02:45+02:00 operator/v1: rename KMSPluginHealthReport fields and remove compatibility marker + - 3199351b 2026-07-22T14:28:51+02:00 machineconfiguration/v1: add BGPVIPPeersJSON to ControllerConfigSpec + - b0927431 2026-07-22T14:28:49+02:00 config/v1: add BGPBasedVIPManagement feature gate and VIPManagement field + - 5bd0b76d 2026-07-21T09:05:02-05:00 NodeUID in status to detect replaced node with same name + - 91ec72c6 2026-07-21T15:06:54+03:00 Align with latest beta API of Vault + - 34bfe5f4 2026-07-10T10:13:47+02:00 Promote ExternalOIDCWithUpstreamParity to Default feature set + - a1e80c1b 2026-07-09T10:56:50+02:00 Promote OLMLifecycleAndCompatibility feature gate to Default + +- cluster-csi-snapshot-controller-operator embedded-component ef7a4c8b7f5c5e6cba4486dcc37f50521e7bc655 to 35ec0224eb0e5219d5eae012fb703223a6f3e1f7 + - ab3ec5d 2026-07-21T15:24:21+02:00 Bump all deps for 5.0.0 + - 2267501 2026-07-09T14:20:58+02:00 Remove v1beta2 group snapshot API + +- cluster-dns-operator embedded-component 4b8ae49940eefc50fa48da5179e735dd6ccd42d9 to c0ed09e329e9001629518604a58205e3fbe8284a + - 1d4d1e8 2026-07-28T18:22:09+02:00 NE-2743: gate operator metrics TLS on tlsAdherence policy + - b2ee3f5 2026-06-23T15:35:36-04:00 OCPBUGS-86009: Add regression test for scale-up without rollout + - ee254fc 2026-05-28T14:02:33-04:00 OCPBUGS-86009: Fix dns operator reporting Progressing=True on scale up + +- cluster-ingress-operator embedded-component b4daff58712de418c51d765a8686069a5f47e764 to b1cbed2ed9af6333fd96e7411076320dbcc14f7d + - fe1b58a9 2026-08-12T14:50:17-04:00 canary-certificate: improve default IngressController lookup logging + - efe5cfde 2026-08-12T14:49:56-04:00 canary-certificate: extract isCanaryCertificate predicate helper + - 25cdbf65 2026-08-12T14:49:25-04:00 canary-certificate: watch reconciliation dependencies + - 48809e3f 2026-08-10T10:51:37+01:00 OCPBUGS-86841: Add BackendTLSPolicy and ReferenceGrant e2e test coverage helpers + - 91952e13 2026-08-05T14:04:38-04:00 Address review feedback on GatewayClass available annotation + - 48fb33cd 2026-08-05T11:35:45-03:00 OCPBUGS-104205: Cover DNS ownership edge cases from review + - a1be42a9 2026-08-05T10:56:48-03:00 OCPBUGS-104205: Align Gateway API DNS e2e with oldest-wins publishing + - b06ed1d2 2026-08-05T10:56:48-03:00 OCPBUGS-104205: Harden DNS duplicate-domain ownership checks + - e8882477 2026-08-05T08:18:07-04:00 OCPBUGS-99920: Vendor sail-operator from OSSM release-3.4.1 + - 1c5c0ff3 2026-08-03T13:32:47-04:00 Add Prometheus metric verification to ListenerSet e2e and unit tests + - b7bb9f03 2026-08-03T13:13:42-04:00 Annotate GatewayClass when istiod deployment is available + - 4b99df2f 2026-08-02T22:04:51-04:00 Fix ensureDependentControllers CRD establishment race + - 8308fd17 2026-08-02T22:04:51-04:00 Fix listenerset metric registry to use controller-runtime registry + - 068a9a16 2026-08-02T22:04:51-04:00 Set Accepted=False on ListenerSets targeting OpenShift-managed Gateways + - af69f70f 2026-08-01T13:59:22Z Revert "Merge pull request #1513 from gcs278/listenerset-upgradeable" + - d89d9ac5 2026-07-31T17:00:00-03:00 Bump API to promote Multi HAProxy Versions feature + - 546c7b6f 2026-07-30T22:28:24-04:00 Move ListenerSet field index to ensureDependentControllers + - 7a481282 2026-07-30T22:28:24-04:00 Refactor to per-ListenerSet reconciliation with GaugeVec metric + - 901ca245 2026-07-30T22:28:24-04:00 Address review comments on listenerset-status controller + - 8105ed32 2026-07-30T22:28:24-04:00 Set Accepted=False on ListenerSets targeting OpenShift-managed Gateways + - e003edd7 2026-07-30T13:04:28-04:00 OCPBUGS-63219: Use status instead of old service for desired state during auto-delete + - 460e91cc 2026-07-30T13:04:28-04:00 OCPBUGS-63219: Improve NLB hairpin risk alert description + - 847c0fbf 2026-07-30T13:04:28-04:00 OCPBUGS-63219: Address code review feedback + - 8f942a63 2026-07-30T13:04:28-04:00 OCPBUGS-63219: Use isNewIngressController instead of !alreadyAdmitted for NLB protocol defaulting + - e5ca4df6 2026-07-30T13:04:28-04:00 OCPBUGS-63219: Add NLB hairpin risk alert for existing IngressControllers + - c0cf37d7 2026-07-30T13:04:28-04:00 OCPBUGS-63219: Add E2E tests for NLB protocol and LB type transition safety + - ed2c82e0 2026-07-30T09:22:59-04:00 Clean up ListenerSet ignored e2e test + - 5fc335e9 2026-07-30T08:32:37-04:00 Disable Istio CRL configmap creation + - 87efd8fc 2026-07-30T08:31:58-04:00 Bump GWAPI CRDs to v1.5.1 and Istio y-stream to 1.30 + - 89626b79 2026-07-29T19:35:49-04:00 OCPBUGS-63219: Support NLB protocol for AWS + - be35bbce 2026-07-29T23:40:36+02:00 NE-2818: Gate operator metrics TLS on tlsAdherence + - 81aa343f 2026-07-29T23:40:36+02:00 NE-2742: Replace custom metrics server with controller-runtime built-in metrics and authentication + - de37a611 2026-07-29T23:37:11+02:00 NE-2742: Apply cluster TLS security profile to operator metrics and canary endpoints + - 7304d3c0 2026-07-29T18:11:31-03:00 NE-2796: check if Gateway infrastructure labels are replicated to pods + - 79e04dfe 2026-07-29T18:11:31-03:00 NE-2796: Set APIServer TLS on sail-library options + - 0ff67422 2026-07-29T17:34:17-03:00 Rename network policy in TestContainerLoggingMinLength + - 2ce2bfc6 2026-07-29T20:24:59Z Replace deprecated io/ioutil usage + - c8b5e959 2026-07-28T18:32:06-03:00 Use /healthz for router startup probe + - e5b605c2 2026-07-27T21:42:36-04:00 GCP: Set Universe Domain + - c781a1be 2026-07-27T21:42:30-04:00 go.mod/vendor: bump google API packages for universe domain support + - bdc58f56 2026-07-27T14:58:03-04:00 Don't publish duplicate DNS records + - 2e5310f5 2026-07-27T14:40:04+01:00 OCPBUGS-85680: Re-fetch infraConfig on every periodic loop iteration + - be257092 2026-07-27T09:44:30+01:00 OCPBUGS-86841: Add BackendTLSPolicy to Gateway API e2e CRD test coverage + - 56b39bf7 2026-07-25T22:58:36Z OCPBUGS-99775: Update TestHTTPHeaderBufferSize for HAProxy 3.2 response code change + - c1d235c5 2026-07-24T17:18:46-03:00 Add upgradeable logic for HAProxy version + - a5c99e25 2026-06-23T14:17:24+01:00 OCPBUGS-90616: Add GRPCRoute to Gateway API e2e CRD test coverage + +- cluster-kube-apiserver-operator embedded-component ea8a9c50203113ca43db98ca925ab7fcdaff7d28 to b119e394abd0379fbc1ff7313f302173c75f8c61 + - 2d852d7 2026-08-18T16:12:21+05:30 Remove old perf tests and update Makefile + - 6def40a 2026-08-14T18:10:49+05:30 use provider as env var + - 02381c1 2026-08-14T18:08:48+05:30 Migrate encryption perf cases to ote + - 66379c4 2026-08-13T15:28:20-04:00 Remove MutatingAdmissionPolicy from defaultGroupVersionsByFeatureGate + - 2ed442b 2026-08-13T12:00:36+05:30 update KMS tests changes with latest library-go bump + - 5272b9c 2026-08-12T12:40:47+03:00 Retry conflict errors on UpdateKMSEncryptionStatus function + - bef6dbf 2026-08-11T12:36:05+05:30 NO-JIRA: Update KMStoKMS scenario to multi provider + - 425b449 2026-08-06T16:40:31+02:00 bump (*) + - 3f3b8c9 2026-08-06T16:40:25+02:00 wire KMS preflight gate into encryption controllers + - 4df172e 2026-08-06T13:59:16+05:30 bump library-go api and client-go + - 511f967 2026-08-06T10:06:49+05:30 Add parallelism KMS OnOff Scenarios + - c0c59b9 2026-08-05T12:40:45+03:00 Bump library-go + - 1840df0 2026-07-29T09:32:03+03:00 Update openshift/* + - e4c2c4d 2026-07-28T10:10:34+02:00 encryptionstatusprovider/provider: creates the provider from the operator client. + - 49d6404 2026-07-28T10:10:30+02:00 bump (*) + - 00f607c 2026-07-27T10:29:28+02:00 NO-JIRA: gofmt encryption_kms_2.go + - 16f12e5 2026-07-27T09:05:10+02:00 NO-JIRA: address preflight e2e review feedback + - d5e6d37 2026-07-27T09:05:10+02:00 NO-JIRA: add KMS preflight deploy e2e to encryption-kms-2 + - 09ea0d5 2026-07-24T16:22:19+03:00 Update openshift/* + - 8dfb4f8 2026-07-24T05:27:15-04:00 pkg/operator: add KMS plugin sidecar revision readiness check + - 050afcf 2026-07-23T15:52:02+02:00 NO-JIRA: Automatic agentic rebase: Update library-go to d8f45c2 + - df010b0 2026-07-23T12:17:46+05:30 Add KMS key ID identifier + - a400ab1 2026-02-09T11:18:33+01:00 chore: add permissions on endpointslice to Prometheus Role and use serviceDiscoveryRole: EndpointSlice in ServiceMonitors + +- cluster-kube-controller-manager-operator embedded-component 4e72164b8bc505033ad565ab01d57963e7c9688e to 8db74e3fe8793043d942ef1f59cce3b0a0bcc548 + - b82f457 2026-08-11T10:46:48+02:00 Remove unnecessary namespace informers from kubeInformersForNamespaces + - 92083e0 2026-08-10T19:03:26+02:00 remove duplicate wrappings of core_getters + - b68a6a3 2026-08-10T19:09:24+05:30 Migrate openshift-test-private kcm cases to OTE + +- cluster-network-operator embedded-component 4f6fb6be829a2f6ad3e0df4ab85ecb00ef028343 to a99f189161f2f426f026998e96e168e9adb5baf5 + - 1e3aca7 2026-08-12T11:27:47-04:00 Filter unsupported cipher suites to prevent ovnkube-identity crash + - b5ea0be 2026-08-10T18:11:53+02:00 Drop github.com/pkg/errors + - 16f0b21 2026-08-07T16:45:43+02:00 go fix: use min instead of open-coding it + - 73a0538 2026-08-07T16:45:35+02:00 go fix: drop obsolete build tags + - 2f2293a 2026-08-07T16:45:16+02:00 go fix: use fmt.Appendf to format to a byte slice + - d193aca 2026-08-07T16:45:14+02:00 go fix: use new to construct pointers + - cdd31e9 2026-08-07T16:45:12+02:00 go fix: iterate over strings.SplitSeq + - c5f4ef1 2026-08-07T16:44:36+02:00 go fix: use maps and slices functions instead of manual loops + - fa4df92 2026-08-07T16:44:23+02:00 go fix: use any instead of interface{} + - d54dcbf 2026-08-07T16:43:57+02:00 go fix: use integer ranges for loops + - 3d86b75 2026-08-07T04:45:51-04:00 frr-k8s: use Recreate strategy for statuscleaner deployment + - 465b313 2026-08-03T11:51:36-05:00 Add requested unit tests + - 25dc7f4 2026-08-03T11:05:24-04:00 Use service-ca certificates for network-check-source metrics + - 471c79c 2026-07-29T19:07:13-04:00 Use TLS profile to render networking-console-plugin NGINX directives + - d654633 2026-07-29T19:07:13-04:00 Migrate check-endpoints to controller-runtime with TLS CLI args + - 0cb61fc 2026-07-27T14:26:42+02:00 Reapply "Merge pull request #2925 from OlivierCazade/day0" + - ad3dcdb 2026-07-24T10:20:52+02:00 vendor: bump github.com/openshift/api to latest master + - e538c9c 2026-07-23T15:10:03-04:00 Register PKI controller through AddToManager + - e7e9bf0 2026-07-23T14:57:58-04:00 Bound PKI informer cache sync with a timeout + - 60cedaf 2026-07-23T13:48:45-04:00 Use keyutil.ParsePrivateKeyPEM for private key decoding + - 262103b 2026-07-23T13:11:47-04:00 Enable configurable PKI for managed certificate rotation + - dfb8dd5 2026-07-23T15:40:27Z Revert "Merge pull request #2925 from OlivierCazade/day0" + - 17f08a7 2026-07-22T11:44:23-04:00 ovn-kubernetes: Move MNP from ConfigMap to CLI flags + - 8e09af9 2026-07-22T06:31:47+05:30 bump ovn-controller CPU request to 50m + - 8ba1546 2026-07-21T14:09:24-05:00 Fix connectivity check for nodes named with IP address + - 9de83fa 2026-07-20T18:36:49+02:00 Fix 'kill: not a pid' error by checking PID file before use + - 40fd88f 2026-07-20T18:36:49+02:00 Remove /usr/libexec mount and avoid GLIBC compatibility issues + - a11c2e4 2026-07-20T18:36:49+02:00 Remove /usr/sbin host directory dependency from ovn-ipsec-host pod + - 3db668e 2026-07-20T18:36:39+02:00 Consume openvswitch-ipsec systemd service for OVN IPsec deployment + - 1117c8e 2026-07-17T11:37:37-04:00 Use TLS profile to render CLI args for network-check-source + - 6ad012f 2026-07-17T08:24:24-04:00 Use TLS profile to render CLI args for HyperShift ovnkube-control-plane + - 78a0e1a 2026-07-17T08:24:24-04:00 Use TLS profile to render CLI args for FRR components + - 6d2e543 2026-07-17T08:24:24-04:00 Use TLS profile to render CLI args for network-metrics kube-rbac-proxy + - 3e6eaf3 2026-07-17T08:24:24-04:00 Use TLS profile to render CLI args for kube-proxy's kube-rbac-proxy + - 46a985c 2026-07-17T08:24:24-04:00 Use TLS profile to render CLI args for kube-rbac-proxy in OVNK + - 6dd6533 2026-07-17T08:24:24-04:00 Use shared start-rbac-proxy function in ovnkube-control-plane + - c4a3db1 2026-07-17T08:24:24-04:00 Use TLS profile to render CLI args in the multus-admission-controller + - a211f70 2026-07-17T08:24:24-04:00 Use TLS profile to render CLI args in the node identity webhook + - c617131 2026-07-17T08:24:24-04:00 Add test utility functions for component rendering tests + - 42a8434 2026-07-17T08:24:24-04:00 Convert OpenSSL cipher names to IANA and filter TLS 1.3 ciphers + - 79bbb49 2026-07-15T09:43:13Z Bump frr-k8s MAX_FDS from 1024 to 65536 + - 39df367 2026-07-14T14:00:00Z Allow per-node OVN encap IP override via env-overrides + - 9c178ed 2026-04-28T16:16:58+02:00 CORENET-6581: Add transport label to CUDN telemetry recording rule + +- cluster-openshift-controller-manager-operator embedded-component 34f95b07f4afbc47558e54e4fa2710fd692e615e to ca4d2061fba488b34c042e7a16946157db595599 + - e6e55e7 2026-07-22T13:16:28-04:00 Bump go.opentelemetry.io/otel/sdk to v1.43.0 to address CVE-2026-39883 + - 6379f14 2026-07-22T13:16:11-04:00 bump(kubernetes): go mod vendor + - 33c4269 2026-07-22T13:15:52-04:00 Bump kubernetes dependencies to v0.36.2 + - 52de0b0 2026-07-21T15:59:19-04:00 Updating ose-cluster-openshift-controller-manager-operator-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/af322abdd1a4d7d0161a69a16369a0ab1748515a/images/ose-cluster-openshift-controller-manager-operator.yml + +- cluster-policy-controller embedded-component 01afc4aac71a8e8be26383a0421bed7673391750 to 469bbf211d35eee0df4422bda7e9e600b080f0f2 + - 26f5876 2026-06-07T14:46:56Z Updating ose-cluster-policy-controller-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/af322abdd1a4d7d0161a69a16369a0ab1748515a/images/cluster-policy-controller.yml + +- csi-external-snapshotter embedded-component b5e4b73f9a761ff8a59f31b982a63e1cdbb76ed8 to a019d1a9d9e1d26ffd0b2e0d911733180fa608b2 + - b17468a 2026-07-29T11:10:15+02:00 UPSTREAM: 1460: Skip NotFound errors when deleting snapshot content objects + +- etcd embedded-component 64f8851a001f7e102d47bfe51ca0dac23951879a to 609b11ed8fc404fb95572d7c87e3243a1206cdb7 + - e66403a2 2026-08-05T22:34:50-07:00 DOWNSTREAM: : OCPBUGS-103516: Document bbolt fork maintenance in REBASE.openshift.md + - b74556a0 2026-08-05T21:20:30-07:00 DOWNSTREAM: : OCPBUGS-103516: Replace bbolt with patched fork to remove MADV_RANDOM + - 1a5620d6 2026-08-05T11:09:07-04:00 UPSTREAM: : implement not-as-blocking defrag + - 77ffb681 2026-08-04T12:00:39-04:00 UPSTREAM: : refactor defrag in preparation for non-blocking defrag + +- kubernetes embedded-component 98b35193b2ac7a23a673325f5e9b830ecd5ba406 to 7b29fb077260554429dcef8234272e9fd25fcfbd + - a9c56bc60 2026-08-13T16:07:54-04:00 UPSTREAM: : hack/update-vendor.sh, make update and update image + - 092ef64dd 2026-08-13T15:09:28-04:00 UPSTREAM: : manually resolve conflicts + - fad190424 2026-08-03T10:04:31-04:00 UPSTREAM: : run resize tests + - a6b682d65 2026-07-31T14:11:52-04:00 UPSTREAM: 139522: kubelet: fix in-place pod resize with non-admitted pods + - 5e858e982 2026-07-28T13:51:08-04:00 UPSTREAM: : Re-enable kubectl kuberc commands e2e tests + - 8d27ef98f 2026-07-27T11:14:23+02:00 UPSTREAM: 137936: csi: update CSI sidecar images in test manifests + - c8aa52947 2026-07-24T13:25:07+02:00 UPSTREAM: 138768: move VolumeGroupSnapshot to V1 + - 0f29094e5 2026-07-22T18:07:38Z Release commit for Kubernetes v1.36.3 + - 0f4503bbf 2026-07-22T11:54:16-04:00 UPSTREAM: : Update openshift-hack/rebase.sh, REBASE.openshift.md + - cc48cfba7 2026-07-20T21:23:37-06:00 UPSTREAM: : Add NodeSelectorAdjuster admission plugin for standalone clusters (part 2) + - 44a83e00e 2026-07-17T15:00:07+02:00 UPSTREAM: : hack/update-featuregates.sh + - 4da08ff19 2026-07-17T08:27:41+02:00 UPSTREAM: : Store SELinuxWarningController upgrade check as a ConfigMap + - 5874ee71e 2026-07-17T08:54:21+08:00 DRA: roll back reserved state in allocateDevice + - de396e993 2026-07-16T15:20:30-06:00 UPSTREAM: 140377: e2e: storage snapshot tests should read custom timeouts from manifest + - 2c14a99ab 2026-07-15T12:55:44+07:00 Bump images and versions to golang 1.26.5 and update distroless-iptables + - fb2467e2c 2026-07-08T22:28:00+08:00 stop logging missing optional container annotations + - 4434901e4 2026-07-07T19:00:53-04:00 Add e2e test for setting maps and slices to null via SSA + - f01529250 2026-07-07T19:00:46-04:00 Bump sigs.k8s.io/structured-merge-diff/v6 to v6.3.3 + - 13ace3c70 2026-07-02T02:25:02-04:00 UPSTREAM: : upkeep cpu partitioning admission webhook + - ccca5a96b 2026-06-28T20:03:27-04:00 kubelet startPodSync: reuse the previous context to fix memory leak regression + - ab57dc006 2026-06-24T12:00:32-04:00 Make utf8 replacement char test pass on Go 1.27 + - b86d94a7c 2026-06-23T13:48:49-04:00 Restore string JSON encoding of cri-api KeyValue + - 5acf40ff7 2026-06-22T13:27:12+01:00 kubeadm: treat already promoted learner as successful + - 24b3a259f 2026-06-17T11:31:41+02:00 kubeadm: use KubernetesAPICallTimeout for mandatory kubeadm-config fetch + - d20c60aa5 2026-06-12T11:21:30-05:00 Align DeviceTaintRule informer API version with handlers + - 903e7fc93 2026-06-11T18:21:48Z Update CHANGELOG/CHANGELOG-1.36.md for v1.36.2 + - ff173bd50 2026-06-11T14:00:35+05:30 Fix job controller reporting active=0 during pod creation backoff + - bed40bd59 2026-05-28T20:23:35Z flowcontrol: cover Required rule for spec.type and limitResponse.type + - 746956bbd 2026-05-28T20:23:35Z flowcontrol: emit Required when spec.type or limitResponse.type is empty + - 720f13b8e 2026-05-11T15:44:04-05:00 test/compatibility_lifecycle: resolve feature names from variables + - 3ddb65998 2026-04-21T10:31:45+08:00 kubeadm: skip promote call when etcd member is already a voting member + +- machine-config-operator embedded-component 067b924f19a64a209796d5be5a0a63665f53b1eb to e3eb2f73dad9b9a7c4320e65ef065cebcd057629 + - b41d5792 2026-08-19T18:00:01+02:00 OCPBUGS-112075: skip proxy for OSImageStream discovery in HyperShift + - 3ed836b5 2026-08-17T14:01:04-04:00 OCPBUGS-109739: Increase rpm-ostree rebase retry backoff and preserve error + - ddab89f0 2026-08-14T10:45:38-04:00 Review suggestions + - f64d228d 2026-08-14T10:45:38-04:00 AGENT-1570: Remove all NoRegistryClusterInstall feature gate check The InternalReleaseImage(IRI) functionality will now be always active instead of being gated behind a feature flag + - 7a874709 2026-08-11T08:58:24-04:00 vsphere: check secret before mutating template + - 815f33d9 2026-08-10T16:37:07-04:00 go mod tidy; go mod vendor + - a10013c0 2026-08-10T16:36:25-04:00 update client-go dependency + - ddd69e41 2026-08-10T16:35:38-04:00 go mod tidy; go mod vendor + - cb62a477 2026-08-10T16:34:23-04:00 AGENT-1570: update dependencies to the latest after several Feature promotions to default + - 14ce7557 2026-08-10T14:11:50-04:00 test: use per-run unique vsphere template name + - ec088424 2026-08-10T09:05:21-04:00 test/extended: reupload vsphere image before reuse + - 81cacd39 2026-08-10T09:05:21-04:00 test: match vsphere fd on datastore/pool too + - f314ab70 2026-08-10T09:05:21-04:00 vsphere: scope template lookup to folder + - 3f1c874e 2026-08-07T13:30:48-04:00 devex: add new make target for skew check + - 06071908 2026-08-07T16:17:45Z Bug 105432: fix nil pointer panic in IRI controller informer race + - 71d82dd2 2026-08-07T09:09:41Z Adapt vspehere bootimage tests to multi vcenter + - 543dfae2 2026-08-07T11:10:33+05:30 Add fix TC63866 failing in CI job + - b9b675e0 2026-08-06T10:36:53-04:00 Adding missing RBAC resources + - c19a014d 2026-08-05T19:33:36+05:30 Migrate remaining OCB long-duration test cases + - 0ffff0bb 2026-08-05T14:04:55+01:00 Add missing variant check for SCOS + - c2fceefa 2026-08-03T15:09:36-04:00 bootimage: create marketplace pkg + - 276c529b 2026-08-03T14:08:24-04:00 Add metric to track mosc count for OCL usage + - a0e4a21e 2026-08-03T14:07:00-04:00 OCL metrics alert expression, and push timing + - 4a55525c 2026-08-03T14:04:47-04:00 Add Prometheus metrics for OCL build telemetry + - b8d85fbd 2026-08-03T22:24:14+05:30 OCPNODE-4040: Use single KubeletConfigAccepted condition type with True/False status + - 6ecb77fa 2026-08-03T17:33:47+02:00 MCO-2485: Mark scale-up test as 'informing' + - 9966bcea 2026-08-03T10:29:02-04:00 test: adapt bootimage tests for CAPI migration + - c6eba28b 2026-08-01T21:29:39Z Revert "Merge pull request #6303 from isabella-janssen/disrutive-suite-stabilization" + - 96201468 2026-08-01T00:07:38Z chore: update AMIs + - f5ca014a 2026-07-31T11:35:46-04:00 bootimage: degrade when vsphere fd not found + - 227d7f0f 2026-07-31T17:00:09+02:00 Revert "MCO-2470: Disable scale-up test support for AWS and vSphere" + - eccb06f8 2026-07-31T08:34:43-04:00 tests: make ImageModeStatusReporting MCP count test more resilient on SNO + - 44cb8f47 2026-07-31T10:13:32Z OCPBUGS-92811: test MCC proxy. Refactor TC 52373 proxy test. + - 7733b4d6 2026-07-31T10:51:37+05:30 Automate TC 89090, 89095 + - 5691c568 2026-07-30T13:36:40-04:00 only watch MachineConfigNode for current node in MCD + - 02624160 2026-07-30T13:33:05-04:00 use mcnLister instead of making API requests + - 1ea662e3 2026-07-30T13:33:05-04:00 add copy-on-write behavior for LayeredNodeState + - 1d6f9106 2026-07-30T13:32:59-04:00 only look at machine-config-operator pod + - 7175df39 2026-07-30T16:55:03+02:00 MCO-2256: Drop RHEL8 support + - c82906b1 2026-07-30T10:50:28-04:00 bootimage: fix vSphere new fd reconciliation + - b5f69a57 2026-07-30T09:17:23-04:00 OCPBUGS-59197: Fix MOSB image deletion race during MOSC removal + - 6a9d4739 2026-07-30T18:21:21+05:30 Fix TC 43278 failing when release payload has no MCO commit info + - 131f0458 2026-07-30T17:12:38+05:30 Migrate 17 OCB test cases from openshift-tests-private + - 92a24cee 2026-07-30T14:30:20+05:30 Fix setArchitectureAndCheckStatus corrupting multi-label annotations + - 7ddac2a2 2026-07-29T15:54:20+02:00 MCO-2244: Update MCO dependencies to Kubernetes 1.36 + - 58a9a52e 2026-07-29T10:59:57+02:00 MCO-2468: Cache backed OSImageStreams for PIS + - 25c8da3f 2026-07-28T13:27:46-04:00 Added event recording for OCL build lifecycle + - 6b9f78ba 2026-07-28T07:48:30+02:00 NO-ISSUE: Fix incorrect OSImageStreams log + - a5384d66 2026-07-27T19:53:32+02:00 Removed no more useful SkipTestIfWorkersCannotBeScaled(oc) function for scale-up test + - ce872407 2026-07-27T19:32:17+02:00 MCO-2470: Disable scale-up test support for AWS and vSphere + - 7ee7027a 2026-07-27T16:55:35+02:00 NO-ISSUE: Use context instead of discrete signal + - c316b995 2026-07-27T14:56:17+03:00 Add --collect back to systemd-run to prevent stale units + - 0cd0458e 2026-07-27T14:26:01+03:00 Bug: fix fencing_validator ocdebug fence dispatch race condition + - 08f5b4e1 2026-07-24T11:30:29Z Thread context through syncHandler instead of storing it in Controller + - c4fb4794 2026-07-24T11:30:29Z Propagate context to InspectStreamClass for shutdown cancellation + - 92bdeffb 2026-07-24T11:30:29Z Add unit tests for validateNoRuncOnRHEL10FromOSImageURL + - 3c6b0fcd 2026-07-24T11:30:29Z Inline runcBlockedError into its callers + - a0e361e2 2026-07-24T11:30:29Z Move validateNoRuncOnRHEL10FromOSImageStream out of generateRenderedMachineConfig + - cd031001 2026-07-24T11:30:29Z Decouple validateNoRuncOnRHEL10FromOSImageURL from Controller + - 46c64391 2026-07-24T11:30:29Z Rename runc validation functions for clarity + - ec249e54 2026-07-24T11:30:29Z TBD + - b5fe45d5 2026-07-24T08:59:10Z NO-ISSUE: extended tests, restore initial maxUnavailable when modified + - 00d8a31e 2026-07-24T09:55:57+02:00 vendor: bump github.com/openshift/api to latest master + - bd1f9660 2026-07-23T16:08:26+05:30 Add TC 88940: Apply password only if changes exist + - 173915e5 2026-07-23T09:54:18Z NO-ISSUE: add AWS marketplace polarion ID test + - 75e3bbca 2026-07-22T14:46:03-04:00 Surface MOSB build status on paused MCPs, added e2e tests to test the behavior, and refined non-paused pool reporting + - 9278288f 2026-07-22T15:13:16+02:00 CNTRLPLANE-3840: Remove ExternalTopologyMode guard from OSImageStream bootstrap + - 54982a74 2026-07-21T19:36:43+05:30 Add unit tests for osImageStream label skip logic in boot image controller + - 135e4398 2026-07-19T19:45:23-04:00 Add control-plane NoSchedule taint support alongside master taint + - b68a7440 2026-07-17T08:10:43Z MCO-2184: Adapt scale extended tests to support osstreams + - 7788a2e5 2026-07-09T22:27:07-04:00 OCPBUGS-98316: Fix SHA idempotency test in nmstate-configuration.sh + - a50480ed 2026-06-05T13:42:39-04:00 machine-config-daemon-firstboot: disable ostree fsync during bootstrap + - 99395483 2026-05-15T16:35:39-04:00 OCPBUGS-83562: Bump kubensmnt dependency and service to v1.3.0 + +- operator-framework-olm embedded-component 56b3931de4636f7e0d212001f2074b9dddb45a8f to c64b9ca2026d13e8907d547b1cbe5226b0a25219 + - 72c5b0d4 2026-08-13T16:31:35Z Revert "force same arch for opm and catalogsource pod for multiarch tests" + - 86d6eabd 2026-08-11T19:58:22Z :seedling: Bump github.com/go-git/go-git/v5 from 5.19.1 to 5.19.2 (#3890) + - babcb0d0 2026-08-11T19:57:33Z fix: use native gRPC probes for CatalogSource pods (#3888) + - 07c3fdef 2026-08-11T19:57:12Z :seedling: Bump go.podman.io/image/v5 from 5.40.0 to 5.41.0 (#3886) + - 19d82404 2026-08-06T07:30:51-04:00 force same arch for opm and catalogsource pod for multiarch tests + - 64d086f7 2026-08-05T00:06:15Z :seedling: Bump google.golang.org/grpc from 1.82.1 to 1.83.0 (#3885) + - 15d67f03 2026-08-05T00:04:29Z Bump actions/stale from 10 to 11 (#3887) + - dacdc2c3 2026-07-31T15:16:56-04:00 OCPBUGS-86895: Ensure packageserver pod seccompProfile is always set + - 2050b037 2026-07-31T00:04:49Z :seedling: Bump github.com/prometheus/client_golang (#3882) + - 05e37129 2026-07-31T00:03:59Z :seedling: Bump the k8s-dependencies group with 8 updates (#3879) + - 9ac5c409 2026-07-31T00:03:36Z :seedling: Bump github.com/prometheus/common from 0.70.0 to 0.70.1 (#3880) + - abeffeb5 2026-07-31T00:03:18Z :seedling: Bump go.yaml.in/yaml/v3 from 3.0.4 to 3.0.5 (#3881) + - c6c6b0cf 2026-07-24T00:21:36Z Bump actions/setup-go from 6 to 7 (#506) + - 1f40a85d 2026-07-24T00:20:39Z Bump github.com/google/cel-go from 0.29.1 to 0.29.2 (#505) + - 3c189066 2026-07-24T00:20:22Z Bump github.com/google/cel-go from 0.28.1 to 0.29.1 (#504) + - 113c62ae 2026-07-24T00:20:04Z Bump golang.org/x/net from 0.54.0 to 0.55.0 (#503) + - 0e5f254d 2026-07-24T00:19:43Z Bump actions/cache from 5 to 6 (#502) + - 8e3576e0 2026-07-24T00:19:26Z pkg/manifests: fix dropped walk errors (#495) + - 59bced99 2026-07-24T00:19:10Z Bump actions/checkout from 6 to 7 (#501) + - e3d3ba94 2026-07-24T00:18:53Z Bump the k8s-dependencies group with 4 updates (#500) + - 136d055c 2026-07-24T00:18:37Z bump api to 0.45.0 (#2040) + - 46661c32 2026-07-24T00:18:19Z Bump github.com/moby/moby/client from v0.4.1 to v0.5.0 (#2039) + - 653c6c13 2026-07-24T00:18:02Z Reject cyclic substitutesFor chains instead of looping until OOM (#2038) + - 66852bce 2026-07-24T00:17:45Z Bump actions/setup-go from 6 to 7 (#2037) + - 4210cd0f 2026-07-24T00:17:29Z Bump github.com/docker/cli (#2036) + - faa7ac12 2026-07-24T00:17:12Z Bump google.golang.org/grpc from 1.82.0 to 1.82.1 (#2035) + - 2ee84a3a 2026-07-24T00:16:57Z Bump github.com/mattn/go-sqlite3 from 1.14.47 to 1.14.48 (#2033) + - 1f9ef03f 2026-07-24T00:16:38Z Bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 (#2032) + - 7bb36d4d 2026-07-24T00:16:12Z Bump github.com/containerd/containerd from 1.7.33 to 1.7.34 (#2031) + - c3c1a01e 2026-07-24T00:15:49Z Upgrade gopkg.in/yaml.v2 to go.yaml.in/yaml/v3 (#2023) + - ac622511 2026-07-24T00:15:27Z Bump go.podman.io/common from 0.68.0 to 0.68.1 (#2029) + - 108f9b21 2026-07-24T00:15:09Z Bump github.com/grpc-ecosystem/grpc-health-probe from 0.4.52 to 0.4.53 (#2030) + - aecb2cbc 2026-07-24T00:14:50Z Bump the golang-x-deps group with 4 updates (#2028) + - cf6a7040 2026-07-24T00:14:26Z Bump golang.org/x/text from 0.38.0 to 0.39.0 in the golang-x-deps group (#2027) + - 89a84c40 2026-07-24T00:14:08Z Bump google.golang.org/grpc from 1.81.1 to 1.82.0 (#2026) + - 5def95d3 2026-07-24T00:13:51Z Bump github.com/docker/cli (#2024) + - fd563d4f 2026-07-24T00:13:30Z empty cred check failed to fall back (#2020) + - 3be9d826 2026-07-24T00:13:13Z Bump github.com/onsi/gomega from 1.42.0 to 1.42.1 (#2022) + - a9705c4c 2026-07-24T00:12:56Z Bump github.com/joelanford/ignore from 0.1.1 to 0.1.2 (#2021) + - 94dc8f82 2026-07-24T00:12:38Z Bump github.com/onsi/ginkgo/v2 from 2.31.0 to 2.32.0 (#2019) + - 006c600c 2026-07-24T00:12:21Z Bump go.etcd.io/bbolt from 1.4.3 to 1.5.0 (#2018) + - 8b9e185b 2026-07-24T00:12:04Z Bump github.com/mattn/go-sqlite3 from 1.14.46 to 1.14.47 (#2017) + - 7dd24242 2026-07-24T00:11:46Z Bump github.com/docker/cli (#2016) + - e69eb2f5 2026-07-24T00:11:28Z Bump github.com/containerd/containerd from 1.7.32 to 1.7.33 (#2015) + - f4932e58 2026-07-24T00:11:05Z Bump actions/checkout from 6 to 7 (#2014) + - bad5f896 2026-07-24T00:10:47Z Bump github.com/mattn/go-sqlite3 from 1.14.45 to 1.14.46 (#2013) + - 64421e49 2026-07-24T00:10:26Z Bump github.com/onsi/ginkgo/v2 from 2.30.0 to 2.31.0 (#2012) + - bb561dd7 2026-07-24T00:10:11Z Bump github.com/onsi/gomega from 1.41.0 to 1.42.0 (#2011) + - 71d26236 2026-07-24T00:09:48Z Bump the k8s-dependencies group with 4 updates (#2010) + - 6e325976 2026-07-24T00:09:25Z Bump github.com/onsi/ginkgo/v2 from 2.29.0 to 2.30.0 (#2009) + - 31ebf518 2026-07-24T00:09:02Z chore: bump o-f deps (#3877) + - 2d8c7fe5 2026-07-24T00:08:38Z :seedling: Bump google.golang.org/grpc from 1.82.0 to 1.82.1 (#3875) + - f6bea1b4 2026-07-24T00:08:18Z :seedling: Bump github.com/go-logr/logr from 1.4.3 to 1.4.4 (#3874) + - 6909f0e9 2026-07-24T00:07:56Z Bump actions/setup-go from 6 to 7 (#3873) + - b995490f 2026-07-24T00:07:37Z :seedling: Bump github.com/prometheus/client_golang (#3872) + - 98c63a01 2026-07-24T00:06:58Z Migrate deprecated gopkg.in/yaml.v3 to go.yaml.in/yaml/v3 (#3865) + - bf01ccba 2026-07-24T00:06:37Z deploy/chart: add static NetworkPolicies for CatalogSource gRPC ingress and bundle unpack egress (#3863) + - 21730989 2026-07-24T00:06:12Z :seedling: Bump golang.org/x/net from 0.56.0 to 0.57.0 (#3868) + - d1efd56a 2026-07-24T00:05:36Z :seedling: Bump github.com/prometheus/common from 0.69.0 to 0.70.0 (#3869) + - 90eb2fa8 2026-07-24T00:05:02Z :seedling: Bump golang.org/x/sync from 0.21.0 to 0.22.0 (#3870) + +- service-ca-operator embedded-component 6391e070d2ab026324b032a6fa5fc7d6be0d2cb5 to ed872ba14b615ca5726ae90e987268877a0b0b20 + - 0ffd45b 2026-07-30T14:48:17+01:00 Remove unnecessary cel-go replace statement + - fde9987 2026-07-27T20:08:35+01:00 Bump go.opentelemetry.io/otel/sdk to v1.43.0 to address CVE-2026-39883 + - 7f95756 2026-07-27T20:08:35+01:00 bump(kubernetes): go mod vendor + - 7ed5392 2026-07-27T19:59:19+01:00 Bump kubernetes dependencies to v0.36.2 + - 9ad2f83 2026-07-24T17:31:07-04:00 Bump github.com/openshift/build-machinery-go + - 11a6d83 2026-07-23T13:23:29+02:00 feat: inject centralized TLS into service-ca operand + - 843f71b 2026-07-22T14:39:22+02:00 chore: sync deps + - 195ba0b 2026-06-06T22:21:50Z Updating ose-service-ca-operator-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/7691ed4dc0b6585b358f9e73fb736ace9a48a286/images/ose-service-ca-operator.yml + - 2fc2708 2026-02-09T11:24:14+01:00 chore: add permissions on endpointslice to Prometheus Role and use serviceDiscoveryRole: EndpointSlice in ServiceMonitors + +- oc image-amd64 994613040335f72809854babcb80b9d11a4e98d5 to 2902632b849a20d312215e16f2058233f1713553 + - 11e91040 2026-08-19T14:15:28+02:00 deps: Update openshift/gssapi + - 5938e4f8 2026-08-11T15:28:01-04:00 OTA-1959: oc adm upgrade recommend works with accepted risks + - 3831cbb4 2026-08-10T14:09:24+02:00 oc login: Fix polluting KUBECONFIG file + - c4a856cd 2026-08-06T15:21:59-04:00 Use cv.Status.ConditionalUpdates.RiskNames + - 15cff871 2026-08-06T15:21:59-04:00 Fix issues collection + - 9f385f32 2026-08-06T15:34:47+02:00 inspect: Redact OAuthClient secrets + - 9e9db41a 2026-08-06T12:29:03+02:00 Update docs.openshift.com base URL to point to OCP docs + - 345ffe96 2026-08-05T22:59:10Z NO-JIRA: Improve must-gather image handling and annotation checks- #2071 (#2071) + - 9f2cec7a 2026-08-05T17:02:47-04:00 test-fixtures: add new test fixture to test `oc adm upgrade recommend` correctly filters out accepted alert-sourced risks + - 2a09d90c 2026-08-01T18:24:21-04:00 Isolate OCP-42982 kubeconfig writes + - 7884f37a 2026-07-31T19:05:40-04:00 Handle accept risks with different commands + - 68ed2c1a 2026-07-31T09:01:24-04:00 OCPBUGS-99757: Set oauth2 AuthStyle to AuthStyleInParams for OIDC token endpoint + - 51c19217 2026-07-27T09:55:07-04:00 OCPBUGS-99757: Include extra scopes in OIDC token cache key - a88e785e 2026-07-23T20:40:27Z RFE-8595: must-gather: add client-side keep-alive to prevent accessTokenInactivityTimeout failures (#2288) + - 324c04c3 2026-07-22T19:10:46-04:00 Revert "TRT-2817: Revert "Merge pull request #2279 from nbottari9/1814-duplicate-warning"" -- router image-arm64 0c4063da30da6091765e2576efc684d0f020918d to 682319a1bb432f0203951c33336d0f55947e1099 +- csi-external-snapshotter image-amd64 b5e4b73f9a761ff8a59f31b982a63e1cdbb76ed8 to a019d1a9d9e1d26ffd0b2e0d911733180fa608b2 + - b17468a 2026-07-29T11:10:15+02:00 UPSTREAM: 1460: Skip NotFound errors when deleting snapshot content objects + +- router image-amd64 f5b67ebd12089170bfc47da7745fe4efb1477eb7 to 3381229146657d2e6bd94115dda0885f25cb3bed + - 54def8f 2026-08-13T11:12:28-04:00 OCPBUGS-77056: Defer per-route unlock in UpdateFunc for panic safety + - f096969 2026-08-13T09:45:39-04:00 OCPBUGS-77056: Remove dead code, use const and types.NamespacedName for route keys + - 91025fd 2026-08-09T09:24:11-04:00 Revert "OCPBUGS-77056: Raise secret handler log level to V(2) for CI diagnostics" + - 647b13d 2026-08-07T20:18:04-04:00 OCPBUGS-77056: Register route before SAR validation, add informer resync + - 25df784 2026-08-07T20:17:37-04:00 OCPBUGS-77056: Raise secret handler log level to V(2) for CI diagnostics + - b4aafbf 2026-08-06T14:12:22-04:00 OCPBUGS-77056: Fix data race in ClearAsyncSARCacheForTest + - 9f6bcd5 2026-08-06T14:12:17-04:00 OCPBUGS-77056: Remove synchronous SAR from secret UpdateFunc, add staleness guard + - a15ee84 2026-08-05T11:01:31-04:00 OCPBUGS-77056: Serialize per-route cert refresh to close update race + - f856ca4 2026-08-05T08:55:35-04:00 OCPBUGS-77056: Restore deletedSecrets guard on SARCompleted write + - b0361b8 2026-08-02T17:17:10-04:00 OCPBUGS-77056: Refresh certificate synchronously on secret update + - 6230e29 2026-08-01T10:11:29-04:00 OCPBUGS-77056: Make delayed RBAC re-check a no-op when nothing changed + - 9465a49 2026-07-31T13:02:29-04:00 OCPBUGS-77056: Keep route admitted on secret update, add delayed RBAC re-check + - 64690b1 2026-07-31T05:36:39-04:00 OCPBUGS-77056: Reject route on secret update to force full re-validation + - ad278bb 2026-07-30T19:39:14-04:00 OCPBUGS-77056: Only emit SARCompleted on registration, not re-validation + - 33a9f90 2026-07-30T09:46:28-04:00 OCPBUGS-77056: Comply with OTE Binary Stdout Contract in router_test.go + - 6566c83 2026-07-30T09:21:31-04:00 OCPBUGS-77056: Fix stale comment and tighten assertion in re-admission test + - 8bb1e1e 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Prevent SARCompleted from re-admitting a deleted-secret route + - 369cbd6 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Check error returns in race condition tests + - 5c4b560 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Update test comments to describe post-fix behavior + - 91552d3 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Reduce writerlease workers and fix gofmt + - 635041f 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Fix race conditions causing x509 ECDSA verification failure + - ee99b91 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Add tests exposing race conditions in async external cert validation + - fad4035 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Use a short, unique prefix for fake-haproxy test sockets + - d29dc72 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Update vendor to remove unused authorizationutil reference + - ccac96c 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Refine secret deletion message for semantic consistency + - 2046440 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Use t.Setenv for WatchListClient override in factory tests + - b0c1182 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Include standard SA groups in SubjectAccessReview specs + - c5900c9 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Fail-closed to ValidationFailed on secret deletion + - 7702535 2026-07-30T08:53:25-04:00 Addressing coderabbit PR comments + - 11bc0d0 2026-07-30T08:53:25-04:00 Addressed several refactor needs from PR comments + - 4abff8f 2026-07-30T08:53:25-04:00 address review comment: remove unnecessary lock from StatusAdmitter + - 203d09a 2026-07-30T08:53:25-04:00 address review comment: use types.NamespacedName for informer key + - 73ef8d9 2026-07-30T08:53:25-04:00 Remove library-go replace directive and update vendor + - ed0e5f6 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Retry on write conflicts without dropping writerlease + - d8e8d3e 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Asynchronous external certificate validation and Hybrid Informer secret monitoring + - 5c27a38 2026-07-29T15:24:08Z Revert "Merge pull request #825 from bentito/OCPBUGS-77056-async-sar-resurrect-v2" + - 64e3cbf 2026-07-28T14:19:34-04:00 OCPBUGS-77056: Check error returns in race condition tests + - 941eaf6 2026-07-27T12:43:29-04:00 OCPBUGS-77056: Update test comments to describe post-fix behavior + - fd296c1 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Reduce writerlease workers and fix gofmt + - e3418f0 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Fix race conditions causing x509 ECDSA verification failure + - 3926e45 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Add tests exposing race conditions in async external cert validation + - bff072d 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Use a short, unique prefix for fake-haproxy test sockets + - 34cbff2 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Update vendor to remove unused authorizationutil reference + - 1dcc235 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Refine secret deletion message for semantic consistency + - 2d4cf93 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Use t.Setenv for WatchListClient override in factory tests + - bc5619a 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Include standard SA groups in SubjectAccessReview specs + - cfc2726 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Fail-closed to ValidationFailed on secret deletion + - fff8566 2026-07-27T11:47:39-04:00 Addressing coderabbit PR comments + - 5a52884 2026-07-27T11:47:39-04:00 Addressed several refactor needs from PR comments + - 20fe05f 2026-07-27T11:47:39-04:00 address review comment: remove unnecessary lock from StatusAdmitter + - 463265d 2026-07-27T11:47:39-04:00 address review comment: use types.NamespacedName for informer key + - 25ccd95 2026-07-27T11:47:39-04:00 Remove library-go replace directive and update vendor + - 6c010a1 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Retry on write conflicts without dropping writerlease + - 8666c60 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Asynchronous external certificate validation and Hybrid Informer secret monitoring + - b701b2d 2026-07-27T15:37:57Z images/router/f5: Delete F5 router Dockerfile - c15a20a 2026-07-25T20:02:34Z Revert "OCPBUGS-77056: Make external cert validation asynchronous (Resurrection)" - da1c969 2026-07-23T10:29:40-04:00 OCPBUGS-77056: Use a short, unique prefix for fake-haproxy test sockets - 6f2aacc 2026-07-23T10:29:40-04:00 OCPBUGS-77056: Update vendor to remove unused authorizationutil reference @@ -16,26 +468,602 @@ - 7b4b855 2026-07-23T10:29:40-04:00 Remove library-go replace directive and update vendor - 277913c 2026-07-23T10:29:40-04:00 OCPBUGS-77056: Retry on write conflicts without dropping writerlease - bc97dba 2026-07-23T10:29:40-04:00 OCPBUGS-77056: Asynchronous external certificate validation and Hybrid Informer secret monitoring - - 74b6915 2026-07-22T11:50:03-04:00 NE-2741: Align vendored openshift/api with the master branch version - - deb1d50 2026-07-22T11:21:18-04:00 NE-2741: Address PR comments on TLS curve preference parsing - - 7f33917 2026-07-22T11:21:18-04:00 Security: fail-closed on unsupported TLS curves and parse mixed delimiters - - da031dd 2026-07-22T11:21:18-04:00 Fix: shorten fake-haproxy socket path in tests to avoid length limits - - ef67e22 2026-07-22T11:21:18-04:00 NE-2741: Implement TLS Curves Support for Metrics Endpoints + - 815e9a6 2026-07-22T01:12:49+05:30 NO-JIRA: Fix staticcheck warnings across multiple packages - 6ebff4e 2026-07-20T21:03:15-04:00 NE-2223: Bump HAProxy to 3.2.19 in the router image - 400eac8 2026-06-15T16:09:07-03:00 NO-JIRA: Add default coderabbit for the repo + - 9aef0d0 2026-01-12T14:41:46-05:00 Add AGENTS.md + - 70ecec9 2026-01-12T14:39:48-05:00 HACKING.md: Fix a typo: "dockerifle" -- ovn-kubernetes image-arm64 8e2e1542642847da592268a0ab94a207eb8d3605 to 88e9f0f146784e8525f6304a1f6f7c986eba2319 +- ovn-kubernetes image-amd64 8e2e1542642847da592268a0ab94a207eb8d3605 to 7b4de5ed3bd4381e3a17cdfddbe14be1432b9860 + - 1f6c95b8 2026-08-13T19:06:55Z sync test annotations with upstream changes + - 56159f53 2026-08-13T11:18:49-04:00 iprulemanager: refactor to use map-based rule tracking and reduce reconciles + - 75e64730 2026-08-11T20:40:09+02:00 node: skip checkPorts phys ofport with allow-no-uplink + - 12402fe5 2026-08-11T20:40:09+02:00 libovsdb/ops: match port-to-br for bridge local ports + - b2ccbfbe 2026-08-11T16:34:19+05:30 factory: trim node object fields to reduce memory footprint + - 9766d2f6 2026-08-11T09:16:13+05:30 CI: add verify-mocksgen job + - e4f93569 2026-08-10T14:35:29-04:00 networkmanager: track terminating pods until completion + - adb12528 2026-08-10T18:50:34+02:00 Fix up iptables references in names, comments, etc + - 29fb9b90 2026-08-10T18:50:34+02:00 Remove remaining iptables setup + - ccc43700 2026-08-10T18:50:34+02:00 Port `InternalTrafficPolicy: Local` services from iptables to nftables + - 14e2a711 2026-08-10T18:50:34+02:00 Port no-NodePort ExternalIP/LoadBalancer services from iptables to nftables + - 0b868c64 2026-08-10T18:50:34+02:00 Port "ordinary" ExternalIP/LoadBalancer services from iptables to nftables + - cb9d465a 2026-08-10T18:50:34+02:00 Port NodePort services from iptables to nftables + - 75c8de57 2026-08-10T18:50:34+02:00 Add framework for nftables-based service rules + - d2fb553c 2026-08-10T18:50:34+02:00 Reorganize local gateway unit tests + - 8da8155d 2026-08-10T18:50:34+02:00 Add Rule/Chain management to nodenft utils + - 3a577eca 2026-08-10T18:50:34+02:00 Refactor nftables sync handling + - 747a8be3 2026-08-10T18:50:34+02:00 Refactor nftables add/delete handling + - d0fcfebb 2026-08-10T22:17:56+05:30 Update replace block in openshift/go.mod + - f79d427f 2026-08-10T16:58:01+02:00 routeadvertisements: only reconcile affected RAs on activity changes + - 6f6575a2 2026-08-10T14:45:16+02:00 Reserve platform port tunnel IDs 1-9 to avoid northd full recomputes + - 76b53a94 2026-08-10T14:38:14+02:00 Fix race in cm setTopologyType for fresh clusters + - c0740b76 2026-08-10T14:28:32+02:00 Add static kernel neighbor entries for UDN masquerade IPs + - d4cb48ec 2026-08-10T14:28:32+02:00 e2e: verify NO_FLOOD, priority-12, and priority-11 ARP/NDP flows for CUDNs + - 32634217 2026-08-10T14:28:32+02:00 test: reset config in TestOpenFlowManagerSyncsUplinkBridgeFlows + - bae8c0fa 2026-08-10T14:28:31+02:00 Fix ARP/NDP storm and FDB learning for CUDN GRs on breth0 + - ffd4c142 2026-08-10T11:05:30+02:00 e2e: fail control-plane runs that select zero specs + - ccf69490 2026-08-10T11:05:30+02:00 e2e: cover split DPU UplinkState condition ownership and recovery + - a16889f1 2026-08-10T11:05:30+02:00 util: unify MAC validity checks on IsUsableEthernetMAC + - 10d1023f 2026-08-10T11:05:30+02:00 Uplink: reject host interfaces without a usable MAC address + - f84a810e 2026-08-10T11:05:30+02:00 Uplink: retry discovery with backoff while unresolved + - f804f573 2026-08-10T11:05:30+02:00 Uplink: one writer per UplinkState condition in split DPU mode + - 13bc66a8 2026-08-07T18:53:35+02:00 [crd] Fix APBR comment + - 7c524476 2026-08-07T16:12:15+02:00 node: tolerate ExternalIP delete OpenFlow resync + - a4482ed6 2026-08-07T16:12:15+02:00 ovn: mark no-overlay cluster SNATs with DB IDs, clean up stale ones + - 1215fc2e 2026-08-07T16:12:15+02:00 ovn: fail SNAT creation when exemption address set is missing + - 26a9862e 2026-08-07T16:12:15+02:00 ovn: sync no-overlay SNAT exemptions before gateway NATs + - 559ee8b2 2026-08-07T16:12:15+02:00 libovsdb: ignore exempted_ext_ips when matching NATs + - 223c8c13 2026-08-07T14:59:35+05:30 docs: add mike-based multi-version docs publishing + - f7c5a957 2026-08-06T07:06:32-07:00 clustermanager: test inactive L2 transit router nodes + - bb92207b 2026-08-05T14:09:42+02:00 RA controller: make config error messages deterministic + - 00434fca 2026-08-05T14:09:42+02:00 RA controller: refresh status when failure reason or message changes + - 64f55117 2026-08-04T17:57:33+02:00 coderabbit: update definition of geenrated files. + - 19c90720 2026-08-04T17:57:33+02:00 UT: add EF SSA test for the NewClientset + - 211606a8 2026-08-04T17:57:27+02:00 update-codegen: check openapi-gen errors + - e8cbfc1e 2026-08-04T17:57:27+02:00 run update-codegen + - 35ffeca0 2026-08-04T17:57:20+02:00 Update update-codegen to generate SSA-compatible fake clients + - ea33cbe4 2026-08-04T20:11:01+05:30 mocks: add follow-up mocksgen output + - 3862ea30 2026-08-04T10:03:58-04:00 OCPBUGS-83863: Remove RHEL 8 build stage and version-specific CNI directories + - b1ab6276 2026-08-04T10:10:45+02:00 Revert "Get pod from apiserver on retryable annotation patch failure" + - 400e3734 2026-08-03T17:06:30-07:00 ovn: remove deprecated gateway router join address fallback + - 1f721cd8 2026-08-03T14:00:54-07:00 clustermanager: advertise dynamic L2 with transit router + - e1a2a9be 2026-08-03T10:25:06-04:00 clustermanager: re-evaluate egress IPs when cloud egress-ipconfig annotation changes + - d632294a 2026-08-03T10:25:06-04:00 util: add CloudEgressIPConfigAnnotationChanged helper + - 0a2e4e82 2026-08-03T11:55:20+02:00 node/uplink: ignore host representors when deriving the bridge uplink + - 540db4d4 2026-08-03T11:55:20+02:00 util: treat all-zero devlink function hw_addr as unset + - 4656af94 2026-08-03T11:55:20+02:00 bridgeconfig: select DPU gateway representor by host peer MAC + - 5a6bdc29 2026-08-03T11:55:20+02:00 node/uplink: resolve DPU bridges for VF and SF host interfaces + - 17c7662f 2026-07-31T19:03:32+05:30 ci: Use lint target of Makefile in lint lane + - cf911518 2026-07-31T14:09:18+05:30 Updating ovn-kubernetes-microshift-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/af322abdd1a4d7d0161a69a16369a0ab1748515a/images/ovn-kubernetes-microshift.yml + - 3a8f25c9 2026-07-31T14:09:18+05:30 Updating ose-ovn-kubernetes-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/af322abdd1a4d7d0161a69a16369a0ab1748515a/images/ose-ovn-kubernetes.yml + - 2e16b2ab 2026-07-31T14:08:48+05:30 Updating ose-ovn-kubernetes-base-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/7e3068230c1b2ba349579903983c811993b92820/images/ovn-kubernetes-base.yml + - f0321d17 2026-07-31T14:08:21+05:30 sync test annotations with upstream changes and version bump + - 6bcaede5 2026-07-30T14:27:48+02:00 docs: add Uplink feature flag to the docs + - 5994d6cc 2026-07-30T13:42:03+02:00 Uplink: report an error on CUDN that uses Uplink when flag is disabled + - 242c552a 2026-07-30T13:42:03+02:00 Enable Uplink in UT + - 8870fa49 2026-07-30T13:42:03+02:00 Wire uplink enabling through the helm and CI + - e776c689 2026-07-30T13:41:59+02:00 Add an uplink feature flag + - 1b9fb6df 2026-07-30T11:54:14+02:00 Update isEgressIPForUDNSupported to use IsNetworkSegmentationSupportEnabled + - 44c16294 2026-07-30T10:48:40+02:00 CI: add verify-codegen job to ensure generated code is not stale. + - 9c4e9095 2026-07-30T10:48:32+02:00 crd/uplink: update-codegen + - 8f64a3c4 2026-07-30T10:48:25+02:00 update-codegen: only list directories under crd/ + - 34e95eea 2026-07-30T11:19:02+03:00 docs: fix LocalnetConfig excludeSubnet GODOC and API reference doc + - 5d9782c7 2026-07-29T10:03:36+02:00 docs: document interface-defined BGP neighbors for route advertisements + - 8f84451c 2026-07-29T10:03:36+02:00 RA controller: advertise both families to unnumbered BGP neighbors + - b32e1110 2026-07-29T10:01:52+02:00 RA controller: fix raw FRR config for unnumbered BGP neighbors + - 11feeba5 2026-07-28T12:20:22-07:00 nooverlay: emit events on the configured default NAD + - ddbfebb2 2026-07-28T12:20:22-07:00 udn: Honor MAC requests on primary layer3 networks + - c7aa9825 2026-07-28T12:20:22-07:00 config: make default network NAD configurable + - ce712a9c 2026-07-28T13:41:34-04:00 Bump golang.org/x/crypto to v0.52.0 + - 62298e9d 2026-07-28T17:43:59+02:00 e2e: fix cross-UDN same-node nodeport test expectations per gateway mode + - 6568c450 2026-07-28T17:27:13+02:00 Fix Layer2 UDN same-node nodeport: use correct transit router port prefix + - f23d1d79 2026-07-28T17:27:13+02:00 Fix UDN masquerade ARP storm on external network + - cf7b1551 2026-07-27T07:52:40+02:00 ovspinning: remove pmd-cpu-mask from affinity + - 6bf19da7 2026-07-27T07:52:39+02:00 ovspinning: Only skip PMD threads if DPDK is enabled + - 41f27e4f 2026-07-27T07:52:39+02:00 ovspinning: skip OVS PMD threads if any + - 5ba4f536 2026-07-26T17:57:00+02:00 kind: use v1.36.1 node image until v1.36.2 is published + - 86421ba8 2026-07-24T14:46:46-07:00 ovn: complete egress node setup during reconciliation + - 314cbc04 2026-07-24T10:52:40-07:00 Restore DPU route import VRFs without Uplinks + - ab615f50 2026-07-24T12:18:59-04:00 egressip: migrate iptables manager to nftables + - 1b512fe1 2026-07-24T15:56:26Z Consolidate syncUDNIsolation into a single predicate scan + - 399f3ef8 2026-07-24T15:56:26Z Refactor deleteStaleMasqueradeRouteAndMACBinding to use router-scoped ops + - fd611011 2026-07-24T15:56:26Z Add upgrade migration for switch-based drop ACL to port group + - 80e969ef 2026-07-24T15:56:25Z Move advertised network drop ACL from switches to port group + - 4f32c7a2 2026-07-24T15:56:25Z Centralize router-to-switch and switch-to-router port naming into NetInfo + - e3f56978 2026-07-24T13:42:21Z Add PortGroupAdvertisedNetwork type and create PG in ConfigureAdvertisedNetworkIsolation + - d56fb7ff 2026-07-24T13:42:20Z Add EnsureAddressSetOps to AddressSetFactory interface + - 763ce2d4 2026-07-24T13:42:20Z Refactor: extract advertised network isolation init and cleanup helpers + - abe1ae2a 2026-07-23T18:16:46-04:00 Make DPU the sole Uplink gateway status writer + - 1d40e849 2026-07-23T15:28:03+02:00 ovn: fix flaky timing in NBDB-outage node retry unit tests + - 1d8befc7 2026-07-23T18:55:00+05:30 makefile: Fix lint to run when Makefile is invoked from another directory + - ed591bf5 2026-07-23T13:00:53+05:30 lint: use documented golangci-lint installer URL + - df6b3213 2026-07-23T13:00:53+05:30 lint: satisfy govet inline analyzer + - c0b63511 2026-07-23T13:00:53+05:30 test: move VTEP mocks out of generated CRD tree + - e9c15e8c 2026-07-23T13:00:53+05:30 codegen: fix generated manifests for Kubernetes 1.36 + - 7d693c53 2026-07-23T13:00:53+05:30 kind: use kubeadm v1beta4 patches for Kubernetes 1.36 + - 3b2d1a6d 2026-07-23T13:00:53+05:30 metallb: upgrade for Kubernetes 1.36 CRD validation + - 2324d2a1 2026-07-23T13:00:53+05:30 networkqos: use int64 schema for bandwidth fields + - 88d46dd8 2026-07-23T13:00:53+05:30 kind: upgrade to v0.32.0 for Kubernetes 1.36.2 + - cdc5c211 2026-07-23T13:00:53+05:30 deps: bump Kubernetes dependencies to 1.36.2 + - 15f16271 2026-07-23T12:44:47+05:30 Removing the duplicate word from the Error message + - 19b3ab36 2026-07-22T10:42:23+02:00 Remove redundant JSON unmarshal in SecondaryNetworkPodIPs + - f1434be2 2026-07-22T10:42:21+02:00 Optimize cleanupStalePodSNATs for scale + - 6556a867 2026-07-22T09:20:32+02:00 Filter namespaces not served by network controller + - 8a0fb2a9 2026-07-22T09:20:32+02:00 Use set-based lookup in hasOnlyAddresses + - d41e4256 2026-07-21T15:31:28-07:00 udn: add VRF routes for all UDN cluster subnets + - 69b3b1e6 2026-07-21T18:17:25-04:00 ci: Add image name to the e2e job name + - baa9c191 2026-07-21T18:23:32+02:00 unidling: fail controller creation when SB client cache is nil + - 959990e0 2026-07-21T10:50:40+02:00 Fix map-order flake in DPU host representor test + - d419656e 2026-07-21T09:55:40+02:00 Stabilize CUDN count metric deletion test + - f1285a42 2026-07-20T10:01:45+05:30 Fix typos in error messages + - 9b25d569 2026-07-18T10:36:35-04:00 Stabilize RouteAdvertisements preservation test + - cfdefcbb 2026-07-17T15:33:40-04:00 Stabilize transit switch IP reallocation test + - 468e83d3 2026-07-17T14:41:11-04:00 Restore simulated DPU devices when Pod state is gone + - 6ddcae93 2026-07-17T14:41:11-04:00 Aggregate Uplink gateway readiness for active CUDNs + - 53f9829f 2026-07-17T14:41:11-04:00 Update UplinkState identity and readiness semantics + - e834d672 2026-07-17T14:41:11-04:00 Fix focused Network Segmentation E2E selection + - 40d46e86 2026-07-17T14:41:11-04:00 Allow disjoint Dynamic CUDNs to share an Uplink + - 2e9c69ff 2026-07-17T14:35:32-04:00 Reject default gateway bridge as an Uplink + - d48fd1ab 2026-07-17T14:35:32-04:00 Add Uplink feature documentation + - 74477f60 2026-07-17T14:35:32-04:00 Fix RouteAdvertisements optional feature handling + - af6ec975 2026-07-17T14:35:32-04:00 Disable bridge netfilter for KIND BGP tests + - a8aa27cf 2026-07-17T14:35:32-04:00 Add Uplink e2e coverage + - cf20ae1b 2026-07-17T14:35:32-04:00 Reject Uplink outside shared gateway mode + - 38934225 2026-07-17T14:35:32-04:00 Resolve DPU Uplink bridges from host state + - 93aa53d5 2026-07-17T14:35:32-04:00 Enslave Uplink gateway interfaces to UDN VRFs + - 79cbe159 2026-07-17T14:35:32-04:00 Use Uplink bridges for UDN gateway plumbing + - b85da74d 2026-07-17T14:35:32-04:00 Teach OpenFlow manager about Uplink bridges + - 09a9359b 2026-07-17T14:35:32-04:00 Add unmanaged Uplink bridge configuration + - e3fbeb17 2026-07-17T14:35:32-04:00 Use UplinkState for CUDN gateways + - 848f9cc7 2026-07-17T14:35:32-04:00 Add node UplinkState discovery + - 9e195884 2026-07-17T14:35:32-04:00 Add Uplink cluster-manager controller + - 3c841452 2026-07-17T14:35:32-04:00 Wire Uplink API plumbing + - 82fc4de5 2026-07-17T14:30:25-04:00 Add Uplink API types + - 51047fae 2026-07-17T20:27:56+05:30 sync test annotations with upstream changes + - b05c351c 2026-07-17T20:27:53+05:30 Adapt OTE for E2E L3 CUDN multisubnet backward compatibility fixes + - 87839345 2026-07-17T16:07:27+02:00 util: wait for the bridge to inherit the NIC MAC address in NicToBridge + - cc5d2484 2026-07-17T15:23:34+02:00 Stop allocating L2 node tunnel IDs when transit router is used + - 11a9197e 2026-07-17T15:06:24+05:30 managedbgp: refactor to use GenerateName and unified labeling + - c5353747 2026-07-17T15:06:24+05:30 no-overlay: add CUDN support for no-overlay managed routing + - 70a2009b 2026-07-17T10:23:14+02:00 e2e(kubevirt): deflake "with pre-copy fails" migration test + - 47a35e07 2026-07-16T17:30:29-04:00 docs: update VRF-Lite uplink status OKEP + - 85348ff8 2026-07-16T13:37:17-04:00 ci: run a control-plane lane with ubuntu images + - fa8e140a 2026-07-16T15:33:44+02:00 Fix traffic leak in egress IP on secondary interface + - 8bce7389 2026-07-16T10:32:40+02:00 node: use libovsdb instead of ovs-vsctl exec in checkPorts + - 7b2e6eb5 2026-07-16T00:32:34+02:00 ci: cover dynamic UDN allocation on a no-overlay shared-gateway lane + - 1b7e0ec0 2026-07-16T00:32:34+02:00 e2e: adapt advertised network isolation tests to dynamic UDN allocation + - 156b75f9 2026-07-16T00:32:34+02:00 e2e: adapt CUDN advertisement tests to dynamic UDN allocation + - 501cc079 2026-07-16T00:32:34+02:00 e2e: cover RouteAdvertisements over a dynamically allocated CUDN + - 8df86599 2026-07-16T00:32:34+02:00 routeadvertisements: advertise dynamic UDNs only from active nodes + - 6a73851e 2026-07-15T14:34:58-04:00 build(deps): bump the go_modules group across 3 directories with 1 update + - 677d6113 2026-07-15T10:03:52-07:00 clustermanager: rename node allocation controller + - 5c9606a8 2026-07-15T19:10:30+05:30 openshift: fix lint issues + - 1fcfb18f 2026-07-14T16:09:34-04:00 no-overlay: host -> pods on other nodes via mp0 + - f49764be 2026-07-14T20:50:36+02:00 docs: add AGENTS.md for go-controller/pkg and CRDs + - 4620cb6d 2026-07-14T10:29:15-07:00 licenses: refresh generated third-party licenses + - 8b0dd877 2026-07-14T10:29:15-07:00 cni: fold libovsdb and shell-out ConfigureOVS paths into one + - 0b276e27 2026-07-14T10:29:15-07:00 libovsdb/ops: consolidate ovs helper operations + - 49393a41 2026-07-14T16:52:06+01:00 docs: rename portSecurity to macSecurity in OKEP-3926 + - 7229c04d 2026-07-14T20:27:41+05:30 node: skip configureGlobalForwarding tests in CI without root access + - 40bd24a5 2026-07-13T17:27:35+02:00 zone_interconnect: add unit test for stale IC route cleanup - 3f34530b 2026-07-12T10:36:43+03:00 Update OWNERS file + - 60fcdaf5 2026-07-10T18:56:40+02:00 Use new IPv6 force_forwarding sysctl if available. + - 0e3a4e06 2026-07-10T18:56:40+02:00 Don't change FORWARD table default policy for IPv4 + - 7795aba2 2026-07-10T18:56:40+02:00 Don't override FORWARD default policy when `disable-forwarding` is not set + - 92fc5160 2026-07-10T18:56:40+02:00 Update disable-gateway unit tests + - a90d60b6 2026-07-10T18:56:40+02:00 Clarify/simplify/fix "Disable Forwarding Config" docs + - bdfd82fb 2026-07-10T17:48:35+02:00 Redo the AllocateLoadBalancerNodePorts=false test cases + - dcaf6dba 2026-07-10T12:46:42+02:00 [perf] fix netpol selection for cudn-l2 job + - d447e853 2026-07-10T11:17:19+02:00 Support update of chassis-id without re-creating the node. + - 0c9edf05 2026-07-08T12:59:20-07:00 ovnkube.sh: unify gateway option loading from OVS external_ids + - 945f64d7 2026-07-08T10:33:19-07:00 test: Use proper TLS certificate validation in metrics server tests + - 98e204fe 2026-07-08T13:36:28+02:00 coderabbit: add pre-merge checks and custom validation rules + - e36fbadc 2026-07-07T20:23:30+02:00 Get pod from apiserver on retryable annotation patch failure + - 06f453b7 2026-07-07T08:13:37+02:00 e2e(kubevirt): replace echoserver with iperf3 + - 853a72fa 2026-07-06T15:06:48-07:00 libovsdb/ops: document ovs-vsctl equivalents on read wrappers + - e3e40f10 2026-07-06T15:06:48-07:00 util, libovsdb/ops: migrate NicToBridge to libovsdb + - 497f470f 2026-07-06T15:06:48-07:00 test/e2e: pin docker while importing libovsdb + - c1c5603e 2026-07-06T15:06:48-07:00 util, node: migrate nicstobridge read paths to libovsdb + - 258eb623 2026-07-06T15:06:48-07:00 node/test: migrate DPU and gateway tests to libovsdb harness + - 1a64e7db 2026-07-06T15:06:48-07:00 cni, node: migrate ConfigureOVS and delRepPort to libovsdb + - 3785f7bd 2026-07-06T15:06:48-07:00 node: move ovsClient to BaseNodeNetworkController + - a58ead15 2026-07-06T15:06:47-07:00 libovsdb/ops: add GetOVSInterface and CreateOrUpdatePodPort + - ff6d3a79 2026-07-06T15:06:47-07:00 node, controllermanager: migrate stale-port cleanup to libovsdb + - 65e3926d 2026-07-06T15:06:47-07:00 node, libovsdb/ops: migrate port-to-br shell-outs to libovsdb + - f1a554fd 2026-07-06T15:06:47-07:00 node: migrate br-exists and del-port br-int to libovsdb + - 1e4c92c6 2026-07-06T15:06:47-07:00 util, ovn-kube-util: migrate BridgeToNic to libovsdb + - 79cb19da 2026-07-06T15:06:47-07:00 libovsdb/ops: bridge-scope DeletePortWithInterfaces + - fdc69950 2026-07-06T15:06:47-07:00 node, libovsdb/ops: migrate del-br shell-outs to libovsdb + - 25b05aa5 2026-07-06T20:15:26+02:00 Only create ACCEPT rules for bypassing our own DROP rules + - fe9bd9f8 2026-07-06T20:15:26+02:00 Simplify initLocalGateway iptables/nftables setup + - f7401aeb 2026-07-03T15:15:57+02:00 routemanager: normalize IPv6 route metric to kernel default + - 7683207e 2026-07-03T10:03:37+02:00 e2e(kubevirt): drop fedora coreos image in favor of fedora + - d9d3e374 2026-07-02T18:14:51+02:00 area-merge: prevent bot comment feedback loop + - 635a3fd7 2026-07-02T15:50:39+01:00 docs: add "future work" section to OKEP-3926 + - 69f3a5e7 2026-07-02T15:50:39+01:00 docs: simplify OKEP-3926 and add per-attachment future section + - 00e2aa81 2026-07-02T15:50:39+01:00 docs: add OKEP-3926 for disabling port security on secondary networks + - 4246d935 2026-07-02T17:56:19+08:00 docs: fix typo in OKEP 5193 CUDN spec + - e9ed7419 2026-07-01T15:50:28-07:00 OKEP-6227: Add DHCP IPAM support for localnet UDNs + - 78e42465 2026-07-01T10:34:35-04:00 config: make routing table ID start configurable + - b19a79d2 2026-06-30T10:59:13-04:00 Revert "Route DPU host no-overlay traffic through OVN" + - 6eac3a2e 2026-06-30T15:35:05+02:00 docs/e2e: clarify E2E backward compatibility requirements in OKEP template + - f5692f2b 2026-06-26T11:04:37-07:00 OTE: Remove duplicate EVPN test from tests.go + - 732ca5db 2026-06-26T11:04:37-07:00 OTE: Add test list validation tooling + - 585b72c2 2026-06-26T16:33:10+02:00 Allow networks to start while route advertisements settle -- kubernetes image-arm64 0f7d1a1b66af90eece8d46f6f9dc7537bf16d978 to 63ee93dac28329fd9d81e91b21ea8d8c43105d01 +- kubernetes image-amd64 98b35193b2ac7a23a673325f5e9b830ecd5ba406 to 7b29fb077260554429dcef8234272e9fd25fcfbd + - a9c56bc60 2026-08-13T16:07:54-04:00 UPSTREAM: : hack/update-vendor.sh, make update and update image + - 092ef64dd 2026-08-13T15:09:28-04:00 UPSTREAM: : manually resolve conflicts + - fad190424 2026-08-03T10:04:31-04:00 UPSTREAM: : run resize tests + - a6b682d65 2026-07-31T14:11:52-04:00 UPSTREAM: 139522: kubelet: fix in-place pod resize with non-admitted pods + - 5e858e982 2026-07-28T13:51:08-04:00 UPSTREAM: : Re-enable kubectl kuberc commands e2e tests + - 8d27ef98f 2026-07-27T11:14:23+02:00 UPSTREAM: 137936: csi: update CSI sidecar images in test manifests + - c8aa52947 2026-07-24T13:25:07+02:00 UPSTREAM: 138768: move VolumeGroupSnapshot to V1 + - 0f29094e5 2026-07-22T18:07:38Z Release commit for Kubernetes v1.36.3 + - 0f4503bbf 2026-07-22T11:54:16-04:00 UPSTREAM: : Update openshift-hack/rebase.sh, REBASE.openshift.md + - cc48cfba7 2026-07-20T21:23:37-06:00 UPSTREAM: : Add NodeSelectorAdjuster admission plugin for standalone clusters (part 2) - 44a83e00e 2026-07-17T15:00:07+02:00 UPSTREAM: : hack/update-featuregates.sh - 4da08ff19 2026-07-17T08:27:41+02:00 UPSTREAM: : Store SELinuxWarningController upgrade check as a ConfigMap - - d178a1dbb 2026-07-17T00:54:58+05:30 UPSTREAM: 140211: Promote regression-issue-74839 to 1.5 + - 5874ee71e 2026-07-17T08:54:21+08:00 DRA: roll back reserved state in allocateDevice + - de396e993 2026-07-16T15:20:30-06:00 UPSTREAM: 140377: e2e: storage snapshot tests should read custom timeouts from manifest + - 2c14a99ab 2026-07-15T12:55:44+07:00 Bump images and versions to golang 1.26.5 and update distroless-iptables + - fb2467e2c 2026-07-08T22:28:00+08:00 stop logging missing optional container annotations + - 4434901e4 2026-07-07T19:00:53-04:00 Add e2e test for setting maps and slices to null via SSA + - f01529250 2026-07-07T19:00:46-04:00 Bump sigs.k8s.io/structured-merge-diff/v6 to v6.3.3 - 13ace3c70 2026-07-02T02:25:02-04:00 UPSTREAM: : upkeep cpu partitioning admission webhook + - ccca5a96b 2026-06-28T20:03:27-04:00 kubelet startPodSync: reuse the previous context to fix memory leak regression + - ab57dc006 2026-06-24T12:00:32-04:00 Make utf8 replacement char test pass on Go 1.27 + - b86d94a7c 2026-06-23T13:48:49-04:00 Restore string JSON encoding of cri-api KeyValue + - 5acf40ff7 2026-06-22T13:27:12+01:00 kubeadm: treat already promoted learner as successful + - 24b3a259f 2026-06-17T11:31:41+02:00 kubeadm: use KubernetesAPICallTimeout for mandatory kubeadm-config fetch + - d20c60aa5 2026-06-12T11:21:30-05:00 Align DeviceTaintRule informer API version with handlers + - 903e7fc93 2026-06-11T18:21:48Z Update CHANGELOG/CHANGELOG-1.36.md for v1.36.2 + - ff173bd50 2026-06-11T14:00:35+05:30 Fix job controller reporting active=0 during pod creation backoff + - bed40bd59 2026-05-28T20:23:35Z flowcontrol: cover Required rule for spec.type and limitResponse.type + - 746956bbd 2026-05-28T20:23:35Z flowcontrol: emit Required when spec.type or limitResponse.type is empty + - 720f13b8e 2026-05-11T15:44:04-05:00 test/compatibility_lifecycle: resolve feature names from variables + - 3ddb65998 2026-04-21T10:31:45+08:00 kubeadm: skip promote call when etcd member is already a voting member -- service-ca-operator image-arm64 6391e070d2ab026324b032a6fa5fc7d6be0d2cb5 to e260be2b3710137012814ce9ca48f155f24f0b02 +- service-ca-operator image-amd64 6391e070d2ab026324b032a6fa5fc7d6be0d2cb5 to ed872ba14b615ca5726ae90e987268877a0b0b20 + - 0ffd45b 2026-07-30T14:48:17+01:00 Remove unnecessary cel-go replace statement + - fde9987 2026-07-27T20:08:35+01:00 Bump go.opentelemetry.io/otel/sdk to v1.43.0 to address CVE-2026-39883 + - 7f95756 2026-07-27T20:08:35+01:00 bump(kubernetes): go mod vendor + - 7ed5392 2026-07-27T19:59:19+01:00 Bump kubernetes dependencies to v0.36.2 - 9ad2f83 2026-07-24T17:31:07-04:00 Bump github.com/openshift/build-machinery-go - 11a6d83 2026-07-23T13:23:29+02:00 feat: inject centralized TLS into service-ca operand - 843f71b 2026-07-22T14:39:22+02:00 chore: sync deps - 195ba0b 2026-06-06T22:21:50Z Updating ose-service-ca-operator-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/7691ed4dc0b6585b358f9e73fb736ace9a48a286/images/ose-service-ca-operator.yml + - 2fc2708 2026-02-09T11:24:14+01:00 chore: add permissions on endpointslice to Prometheus Role and use serviceDiscoveryRole: EndpointSlice in ServiceMonitors + +- oc image-arm64 a88e785e90aa96ac96da93359bacf3ea5c174733 to 2902632b849a20d312215e16f2058233f1713553 + - 11e91040 2026-08-19T14:15:28+02:00 deps: Update openshift/gssapi + - 5938e4f8 2026-08-11T15:28:01-04:00 OTA-1959: oc adm upgrade recommend works with accepted risks + - 3831cbb4 2026-08-10T14:09:24+02:00 oc login: Fix polluting KUBECONFIG file + - c4a856cd 2026-08-06T15:21:59-04:00 Use cv.Status.ConditionalUpdates.RiskNames + - 15cff871 2026-08-06T15:21:59-04:00 Fix issues collection + - 9f385f32 2026-08-06T15:34:47+02:00 inspect: Redact OAuthClient secrets + - 9e9db41a 2026-08-06T12:29:03+02:00 Update docs.openshift.com base URL to point to OCP docs + - 345ffe96 2026-08-05T22:59:10Z NO-JIRA: Improve must-gather image handling and annotation checks- #2071 (#2071) + - 9f2cec7a 2026-08-05T17:02:47-04:00 test-fixtures: add new test fixture to test `oc adm upgrade recommend` correctly filters out accepted alert-sourced risks + - 2a09d90c 2026-08-01T18:24:21-04:00 Isolate OCP-42982 kubeconfig writes + - 7884f37a 2026-07-31T19:05:40-04:00 Handle accept risks with different commands + - 68ed2c1a 2026-07-31T09:01:24-04:00 OCPBUGS-99757: Set oauth2 AuthStyle to AuthStyleInParams for OIDC token endpoint + - 51c19217 2026-07-27T09:55:07-04:00 OCPBUGS-99757: Include extra scopes in OIDC token cache key + - 324c04c3 2026-07-22T19:10:46-04:00 Revert "TRT-2817: Revert "Merge pull request #2279 from nbottari9/1814-duplicate-warning"" + +- csi-external-snapshotter image-arm64 b5e4b73f9a761ff8a59f31b982a63e1cdbb76ed8 to a019d1a9d9e1d26ffd0b2e0d911733180fa608b2 + - b17468a 2026-07-29T11:10:15+02:00 UPSTREAM: 1460: Skip NotFound errors when deleting snapshot content objects + +- router image-arm64 682319a1bb432f0203951c33336d0f55947e1099 to 3381229146657d2e6bd94115dda0885f25cb3bed + - 54def8f 2026-08-13T11:12:28-04:00 OCPBUGS-77056: Defer per-route unlock in UpdateFunc for panic safety + - f096969 2026-08-13T09:45:39-04:00 OCPBUGS-77056: Remove dead code, use const and types.NamespacedName for route keys + - 91025fd 2026-08-09T09:24:11-04:00 Revert "OCPBUGS-77056: Raise secret handler log level to V(2) for CI diagnostics" + - 647b13d 2026-08-07T20:18:04-04:00 OCPBUGS-77056: Register route before SAR validation, add informer resync + - 25df784 2026-08-07T20:17:37-04:00 OCPBUGS-77056: Raise secret handler log level to V(2) for CI diagnostics + - b4aafbf 2026-08-06T14:12:22-04:00 OCPBUGS-77056: Fix data race in ClearAsyncSARCacheForTest + - 9f6bcd5 2026-08-06T14:12:17-04:00 OCPBUGS-77056: Remove synchronous SAR from secret UpdateFunc, add staleness guard + - a15ee84 2026-08-05T11:01:31-04:00 OCPBUGS-77056: Serialize per-route cert refresh to close update race + - f856ca4 2026-08-05T08:55:35-04:00 OCPBUGS-77056: Restore deletedSecrets guard on SARCompleted write + - b0361b8 2026-08-02T17:17:10-04:00 OCPBUGS-77056: Refresh certificate synchronously on secret update + - 6230e29 2026-08-01T10:11:29-04:00 OCPBUGS-77056: Make delayed RBAC re-check a no-op when nothing changed + - 9465a49 2026-07-31T13:02:29-04:00 OCPBUGS-77056: Keep route admitted on secret update, add delayed RBAC re-check + - 64690b1 2026-07-31T05:36:39-04:00 OCPBUGS-77056: Reject route on secret update to force full re-validation + - ad278bb 2026-07-30T19:39:14-04:00 OCPBUGS-77056: Only emit SARCompleted on registration, not re-validation + - 33a9f90 2026-07-30T09:46:28-04:00 OCPBUGS-77056: Comply with OTE Binary Stdout Contract in router_test.go + - 6566c83 2026-07-30T09:21:31-04:00 OCPBUGS-77056: Fix stale comment and tighten assertion in re-admission test + - 8bb1e1e 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Prevent SARCompleted from re-admitting a deleted-secret route + - 369cbd6 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Check error returns in race condition tests + - 5c4b560 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Update test comments to describe post-fix behavior + - 91552d3 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Reduce writerlease workers and fix gofmt + - 635041f 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Fix race conditions causing x509 ECDSA verification failure + - ee99b91 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Add tests exposing race conditions in async external cert validation + - fad4035 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Use a short, unique prefix for fake-haproxy test sockets + - d29dc72 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Update vendor to remove unused authorizationutil reference + - ccac96c 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Refine secret deletion message for semantic consistency + - 2046440 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Use t.Setenv for WatchListClient override in factory tests + - b0c1182 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Include standard SA groups in SubjectAccessReview specs + - c5900c9 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Fail-closed to ValidationFailed on secret deletion + - 7702535 2026-07-30T08:53:25-04:00 Addressing coderabbit PR comments + - 11bc0d0 2026-07-30T08:53:25-04:00 Addressed several refactor needs from PR comments + - 4abff8f 2026-07-30T08:53:25-04:00 address review comment: remove unnecessary lock from StatusAdmitter + - 203d09a 2026-07-30T08:53:25-04:00 address review comment: use types.NamespacedName for informer key + - 73ef8d9 2026-07-30T08:53:25-04:00 Remove library-go replace directive and update vendor + - ed0e5f6 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Retry on write conflicts without dropping writerlease + - d8e8d3e 2026-07-30T08:53:25-04:00 OCPBUGS-77056: Asynchronous external certificate validation and Hybrid Informer secret monitoring + - 5c27a38 2026-07-29T15:24:08Z Revert "Merge pull request #825 from bentito/OCPBUGS-77056-async-sar-resurrect-v2" + - 64e3cbf 2026-07-28T14:19:34-04:00 OCPBUGS-77056: Check error returns in race condition tests + - 941eaf6 2026-07-27T12:43:29-04:00 OCPBUGS-77056: Update test comments to describe post-fix behavior + - fd296c1 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Reduce writerlease workers and fix gofmt + - e3418f0 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Fix race conditions causing x509 ECDSA verification failure + - 3926e45 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Add tests exposing race conditions in async external cert validation + - bff072d 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Use a short, unique prefix for fake-haproxy test sockets + - 34cbff2 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Update vendor to remove unused authorizationutil reference + - 1dcc235 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Refine secret deletion message for semantic consistency + - 2d4cf93 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Use t.Setenv for WatchListClient override in factory tests + - bc5619a 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Include standard SA groups in SubjectAccessReview specs + - cfc2726 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Fail-closed to ValidationFailed on secret deletion + - fff8566 2026-07-27T11:47:39-04:00 Addressing coderabbit PR comments + - 5a52884 2026-07-27T11:47:39-04:00 Addressed several refactor needs from PR comments + - 20fe05f 2026-07-27T11:47:39-04:00 address review comment: remove unnecessary lock from StatusAdmitter + - 463265d 2026-07-27T11:47:39-04:00 address review comment: use types.NamespacedName for informer key + - 25ccd95 2026-07-27T11:47:39-04:00 Remove library-go replace directive and update vendor + - 6c010a1 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Retry on write conflicts without dropping writerlease + - 8666c60 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Asynchronous external certificate validation and Hybrid Informer secret monitoring + - b701b2d 2026-07-27T15:37:57Z images/router/f5: Delete F5 router Dockerfile + - 815e9a6 2026-07-22T01:12:49+05:30 NO-JIRA: Fix staticcheck warnings across multiple packages + - 9aef0d0 2026-01-12T14:41:46-05:00 Add AGENTS.md + - 70ecec9 2026-01-12T14:39:48-05:00 HACKING.md: Fix a typo: "dockerifle" + +- ovn-kubernetes image-arm64 88e9f0f146784e8525f6304a1f6f7c986eba2319 to 7b4de5ed3bd4381e3a17cdfddbe14be1432b9860 + - 1f6c95b8 2026-08-13T19:06:55Z sync test annotations with upstream changes + - 56159f53 2026-08-13T11:18:49-04:00 iprulemanager: refactor to use map-based rule tracking and reduce reconciles + - 75e64730 2026-08-11T20:40:09+02:00 node: skip checkPorts phys ofport with allow-no-uplink + - 12402fe5 2026-08-11T20:40:09+02:00 libovsdb/ops: match port-to-br for bridge local ports + - b2ccbfbe 2026-08-11T16:34:19+05:30 factory: trim node object fields to reduce memory footprint + - 9766d2f6 2026-08-11T09:16:13+05:30 CI: add verify-mocksgen job + - e4f93569 2026-08-10T14:35:29-04:00 networkmanager: track terminating pods until completion + - adb12528 2026-08-10T18:50:34+02:00 Fix up iptables references in names, comments, etc + - 29fb9b90 2026-08-10T18:50:34+02:00 Remove remaining iptables setup + - ccc43700 2026-08-10T18:50:34+02:00 Port `InternalTrafficPolicy: Local` services from iptables to nftables + - 14e2a711 2026-08-10T18:50:34+02:00 Port no-NodePort ExternalIP/LoadBalancer services from iptables to nftables + - 0b868c64 2026-08-10T18:50:34+02:00 Port "ordinary" ExternalIP/LoadBalancer services from iptables to nftables + - cb9d465a 2026-08-10T18:50:34+02:00 Port NodePort services from iptables to nftables + - 75c8de57 2026-08-10T18:50:34+02:00 Add framework for nftables-based service rules + - d2fb553c 2026-08-10T18:50:34+02:00 Reorganize local gateway unit tests + - 8da8155d 2026-08-10T18:50:34+02:00 Add Rule/Chain management to nodenft utils + - 3a577eca 2026-08-10T18:50:34+02:00 Refactor nftables sync handling + - 747a8be3 2026-08-10T18:50:34+02:00 Refactor nftables add/delete handling + - d0fcfebb 2026-08-10T22:17:56+05:30 Update replace block in openshift/go.mod + - f79d427f 2026-08-10T16:58:01+02:00 routeadvertisements: only reconcile affected RAs on activity changes + - 6f6575a2 2026-08-10T14:45:16+02:00 Reserve platform port tunnel IDs 1-9 to avoid northd full recomputes + - 76b53a94 2026-08-10T14:38:14+02:00 Fix race in cm setTopologyType for fresh clusters + - c0740b76 2026-08-10T14:28:32+02:00 Add static kernel neighbor entries for UDN masquerade IPs + - d4cb48ec 2026-08-10T14:28:32+02:00 e2e: verify NO_FLOOD, priority-12, and priority-11 ARP/NDP flows for CUDNs + - 32634217 2026-08-10T14:28:32+02:00 test: reset config in TestOpenFlowManagerSyncsUplinkBridgeFlows + - bae8c0fa 2026-08-10T14:28:31+02:00 Fix ARP/NDP storm and FDB learning for CUDN GRs on breth0 + - ffd4c142 2026-08-10T11:05:30+02:00 e2e: fail control-plane runs that select zero specs + - ccf69490 2026-08-10T11:05:30+02:00 e2e: cover split DPU UplinkState condition ownership and recovery + - a16889f1 2026-08-10T11:05:30+02:00 util: unify MAC validity checks on IsUsableEthernetMAC + - 10d1023f 2026-08-10T11:05:30+02:00 Uplink: reject host interfaces without a usable MAC address + - f84a810e 2026-08-10T11:05:30+02:00 Uplink: retry discovery with backoff while unresolved + - f804f573 2026-08-10T11:05:30+02:00 Uplink: one writer per UplinkState condition in split DPU mode + - 13bc66a8 2026-08-07T18:53:35+02:00 [crd] Fix APBR comment + - 7c524476 2026-08-07T16:12:15+02:00 node: tolerate ExternalIP delete OpenFlow resync + - a4482ed6 2026-08-07T16:12:15+02:00 ovn: mark no-overlay cluster SNATs with DB IDs, clean up stale ones + - 1215fc2e 2026-08-07T16:12:15+02:00 ovn: fail SNAT creation when exemption address set is missing + - 26a9862e 2026-08-07T16:12:15+02:00 ovn: sync no-overlay SNAT exemptions before gateway NATs + - 559ee8b2 2026-08-07T16:12:15+02:00 libovsdb: ignore exempted_ext_ips when matching NATs + - 223c8c13 2026-08-07T14:59:35+05:30 docs: add mike-based multi-version docs publishing + - f7c5a957 2026-08-06T07:06:32-07:00 clustermanager: test inactive L2 transit router nodes + - bb92207b 2026-08-05T14:09:42+02:00 RA controller: make config error messages deterministic + - 00434fca 2026-08-05T14:09:42+02:00 RA controller: refresh status when failure reason or message changes + - 64f55117 2026-08-04T17:57:33+02:00 coderabbit: update definition of geenrated files. + - 19c90720 2026-08-04T17:57:33+02:00 UT: add EF SSA test for the NewClientset + - 211606a8 2026-08-04T17:57:27+02:00 update-codegen: check openapi-gen errors + - e8cbfc1e 2026-08-04T17:57:27+02:00 run update-codegen + - 35ffeca0 2026-08-04T17:57:20+02:00 Update update-codegen to generate SSA-compatible fake clients + - ea33cbe4 2026-08-04T20:11:01+05:30 mocks: add follow-up mocksgen output + - 3862ea30 2026-08-04T10:03:58-04:00 OCPBUGS-83863: Remove RHEL 8 build stage and version-specific CNI directories + - b1ab6276 2026-08-04T10:10:45+02:00 Revert "Get pod from apiserver on retryable annotation patch failure" + - 400e3734 2026-08-03T17:06:30-07:00 ovn: remove deprecated gateway router join address fallback + - 1f721cd8 2026-08-03T14:00:54-07:00 clustermanager: advertise dynamic L2 with transit router + - e1a2a9be 2026-08-03T10:25:06-04:00 clustermanager: re-evaluate egress IPs when cloud egress-ipconfig annotation changes + - d632294a 2026-08-03T10:25:06-04:00 util: add CloudEgressIPConfigAnnotationChanged helper + - 0a2e4e82 2026-08-03T11:55:20+02:00 node/uplink: ignore host representors when deriving the bridge uplink + - 540db4d4 2026-08-03T11:55:20+02:00 util: treat all-zero devlink function hw_addr as unset + - 4656af94 2026-08-03T11:55:20+02:00 bridgeconfig: select DPU gateway representor by host peer MAC + - 5a6bdc29 2026-08-03T11:55:20+02:00 node/uplink: resolve DPU bridges for VF and SF host interfaces + - 17c7662f 2026-07-31T19:03:32+05:30 ci: Use lint target of Makefile in lint lane + - cf911518 2026-07-31T14:09:18+05:30 Updating ovn-kubernetes-microshift-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/af322abdd1a4d7d0161a69a16369a0ab1748515a/images/ovn-kubernetes-microshift.yml + - 3a8f25c9 2026-07-31T14:09:18+05:30 Updating ose-ovn-kubernetes-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/af322abdd1a4d7d0161a69a16369a0ab1748515a/images/ose-ovn-kubernetes.yml + - 2e16b2ab 2026-07-31T14:08:48+05:30 Updating ose-ovn-kubernetes-base-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/7e3068230c1b2ba349579903983c811993b92820/images/ovn-kubernetes-base.yml + - f0321d17 2026-07-31T14:08:21+05:30 sync test annotations with upstream changes and version bump + - 6bcaede5 2026-07-30T14:27:48+02:00 docs: add Uplink feature flag to the docs + - 5994d6cc 2026-07-30T13:42:03+02:00 Uplink: report an error on CUDN that uses Uplink when flag is disabled + - 242c552a 2026-07-30T13:42:03+02:00 Enable Uplink in UT + - 8870fa49 2026-07-30T13:42:03+02:00 Wire uplink enabling through the helm and CI + - e776c689 2026-07-30T13:41:59+02:00 Add an uplink feature flag + - 1b9fb6df 2026-07-30T11:54:14+02:00 Update isEgressIPForUDNSupported to use IsNetworkSegmentationSupportEnabled + - 44c16294 2026-07-30T10:48:40+02:00 CI: add verify-codegen job to ensure generated code is not stale. + - 9c4e9095 2026-07-30T10:48:32+02:00 crd/uplink: update-codegen + - 8f64a3c4 2026-07-30T10:48:25+02:00 update-codegen: only list directories under crd/ + - 34e95eea 2026-07-30T11:19:02+03:00 docs: fix LocalnetConfig excludeSubnet GODOC and API reference doc + - 5d9782c7 2026-07-29T10:03:36+02:00 docs: document interface-defined BGP neighbors for route advertisements + - 8f84451c 2026-07-29T10:03:36+02:00 RA controller: advertise both families to unnumbered BGP neighbors + - b32e1110 2026-07-29T10:01:52+02:00 RA controller: fix raw FRR config for unnumbered BGP neighbors + - 11feeba5 2026-07-28T12:20:22-07:00 nooverlay: emit events on the configured default NAD + - ddbfebb2 2026-07-28T12:20:22-07:00 udn: Honor MAC requests on primary layer3 networks + - c7aa9825 2026-07-28T12:20:22-07:00 config: make default network NAD configurable + - ce712a9c 2026-07-28T13:41:34-04:00 Bump golang.org/x/crypto to v0.52.0 + - 62298e9d 2026-07-28T17:43:59+02:00 e2e: fix cross-UDN same-node nodeport test expectations per gateway mode + - 6568c450 2026-07-28T17:27:13+02:00 Fix Layer2 UDN same-node nodeport: use correct transit router port prefix + - f23d1d79 2026-07-28T17:27:13+02:00 Fix UDN masquerade ARP storm on external network + - cf7b1551 2026-07-27T07:52:40+02:00 ovspinning: remove pmd-cpu-mask from affinity + - 6bf19da7 2026-07-27T07:52:39+02:00 ovspinning: Only skip PMD threads if DPDK is enabled + - 41f27e4f 2026-07-27T07:52:39+02:00 ovspinning: skip OVS PMD threads if any + - 5ba4f536 2026-07-26T17:57:00+02:00 kind: use v1.36.1 node image until v1.36.2 is published + - 86421ba8 2026-07-24T14:46:46-07:00 ovn: complete egress node setup during reconciliation + - 314cbc04 2026-07-24T10:52:40-07:00 Restore DPU route import VRFs without Uplinks + - ab615f50 2026-07-24T12:18:59-04:00 egressip: migrate iptables manager to nftables + - 1b512fe1 2026-07-24T15:56:26Z Consolidate syncUDNIsolation into a single predicate scan + - 399f3ef8 2026-07-24T15:56:26Z Refactor deleteStaleMasqueradeRouteAndMACBinding to use router-scoped ops + - fd611011 2026-07-24T15:56:26Z Add upgrade migration for switch-based drop ACL to port group + - 80e969ef 2026-07-24T15:56:25Z Move advertised network drop ACL from switches to port group + - 4f32c7a2 2026-07-24T15:56:25Z Centralize router-to-switch and switch-to-router port naming into NetInfo + - e3f56978 2026-07-24T13:42:21Z Add PortGroupAdvertisedNetwork type and create PG in ConfigureAdvertisedNetworkIsolation + - d56fb7ff 2026-07-24T13:42:20Z Add EnsureAddressSetOps to AddressSetFactory interface + - 763ce2d4 2026-07-24T13:42:20Z Refactor: extract advertised network isolation init and cleanup helpers + - abe1ae2a 2026-07-23T18:16:46-04:00 Make DPU the sole Uplink gateway status writer + - 1d40e849 2026-07-23T15:28:03+02:00 ovn: fix flaky timing in NBDB-outage node retry unit tests + - 1d8befc7 2026-07-23T18:55:00+05:30 makefile: Fix lint to run when Makefile is invoked from another directory + - ed591bf5 2026-07-23T13:00:53+05:30 lint: use documented golangci-lint installer URL + - df6b3213 2026-07-23T13:00:53+05:30 lint: satisfy govet inline analyzer + - c0b63511 2026-07-23T13:00:53+05:30 test: move VTEP mocks out of generated CRD tree + - e9c15e8c 2026-07-23T13:00:53+05:30 codegen: fix generated manifests for Kubernetes 1.36 + - 7d693c53 2026-07-23T13:00:53+05:30 kind: use kubeadm v1beta4 patches for Kubernetes 1.36 + - 3b2d1a6d 2026-07-23T13:00:53+05:30 metallb: upgrade for Kubernetes 1.36 CRD validation + - 2324d2a1 2026-07-23T13:00:53+05:30 networkqos: use int64 schema for bandwidth fields + - 88d46dd8 2026-07-23T13:00:53+05:30 kind: upgrade to v0.32.0 for Kubernetes 1.36.2 + - cdc5c211 2026-07-23T13:00:53+05:30 deps: bump Kubernetes dependencies to 1.36.2 + - 15f16271 2026-07-23T12:44:47+05:30 Removing the duplicate word from the Error message + - 19b3ab36 2026-07-22T10:42:23+02:00 Remove redundant JSON unmarshal in SecondaryNetworkPodIPs + - f1434be2 2026-07-22T10:42:21+02:00 Optimize cleanupStalePodSNATs for scale + - 6556a867 2026-07-22T09:20:32+02:00 Filter namespaces not served by network controller + - 8a0fb2a9 2026-07-22T09:20:32+02:00 Use set-based lookup in hasOnlyAddresses + - d41e4256 2026-07-21T15:31:28-07:00 udn: add VRF routes for all UDN cluster subnets + - 69b3b1e6 2026-07-21T18:17:25-04:00 ci: Add image name to the e2e job name + - baa9c191 2026-07-21T18:23:32+02:00 unidling: fail controller creation when SB client cache is nil + - 959990e0 2026-07-21T10:50:40+02:00 Fix map-order flake in DPU host representor test + - d419656e 2026-07-21T09:55:40+02:00 Stabilize CUDN count metric deletion test + - f1285a42 2026-07-20T10:01:45+05:30 Fix typos in error messages + - 9b25d569 2026-07-18T10:36:35-04:00 Stabilize RouteAdvertisements preservation test + - cfdefcbb 2026-07-17T15:33:40-04:00 Stabilize transit switch IP reallocation test + - 468e83d3 2026-07-17T14:41:11-04:00 Restore simulated DPU devices when Pod state is gone + - 6ddcae93 2026-07-17T14:41:11-04:00 Aggregate Uplink gateway readiness for active CUDNs + - 53f9829f 2026-07-17T14:41:11-04:00 Update UplinkState identity and readiness semantics + - e834d672 2026-07-17T14:41:11-04:00 Fix focused Network Segmentation E2E selection + - 40d46e86 2026-07-17T14:41:11-04:00 Allow disjoint Dynamic CUDNs to share an Uplink + - 2e9c69ff 2026-07-17T14:35:32-04:00 Reject default gateway bridge as an Uplink + - d48fd1ab 2026-07-17T14:35:32-04:00 Add Uplink feature documentation + - 74477f60 2026-07-17T14:35:32-04:00 Fix RouteAdvertisements optional feature handling + - af6ec975 2026-07-17T14:35:32-04:00 Disable bridge netfilter for KIND BGP tests + - a8aa27cf 2026-07-17T14:35:32-04:00 Add Uplink e2e coverage + - cf20ae1b 2026-07-17T14:35:32-04:00 Reject Uplink outside shared gateway mode + - 38934225 2026-07-17T14:35:32-04:00 Resolve DPU Uplink bridges from host state + - 93aa53d5 2026-07-17T14:35:32-04:00 Enslave Uplink gateway interfaces to UDN VRFs + - 79cbe159 2026-07-17T14:35:32-04:00 Use Uplink bridges for UDN gateway plumbing + - b85da74d 2026-07-17T14:35:32-04:00 Teach OpenFlow manager about Uplink bridges + - 09a9359b 2026-07-17T14:35:32-04:00 Add unmanaged Uplink bridge configuration + - e3fbeb17 2026-07-17T14:35:32-04:00 Use UplinkState for CUDN gateways + - 848f9cc7 2026-07-17T14:35:32-04:00 Add node UplinkState discovery + - 9e195884 2026-07-17T14:35:32-04:00 Add Uplink cluster-manager controller + - 3c841452 2026-07-17T14:35:32-04:00 Wire Uplink API plumbing + - 82fc4de5 2026-07-17T14:30:25-04:00 Add Uplink API types + - 51047fae 2026-07-17T20:27:56+05:30 sync test annotations with upstream changes + - b05c351c 2026-07-17T20:27:53+05:30 Adapt OTE for E2E L3 CUDN multisubnet backward compatibility fixes + - 87839345 2026-07-17T16:07:27+02:00 util: wait for the bridge to inherit the NIC MAC address in NicToBridge + - cc5d2484 2026-07-17T15:23:34+02:00 Stop allocating L2 node tunnel IDs when transit router is used + - 11a9197e 2026-07-17T15:06:24+05:30 managedbgp: refactor to use GenerateName and unified labeling + - c5353747 2026-07-17T15:06:24+05:30 no-overlay: add CUDN support for no-overlay managed routing + - 70a2009b 2026-07-17T10:23:14+02:00 e2e(kubevirt): deflake "with pre-copy fails" migration test + - 47a35e07 2026-07-16T17:30:29-04:00 docs: update VRF-Lite uplink status OKEP + - 85348ff8 2026-07-16T13:37:17-04:00 ci: run a control-plane lane with ubuntu images + - fa8e140a 2026-07-16T15:33:44+02:00 Fix traffic leak in egress IP on secondary interface + - 8bce7389 2026-07-16T10:32:40+02:00 node: use libovsdb instead of ovs-vsctl exec in checkPorts + - 7b2e6eb5 2026-07-16T00:32:34+02:00 ci: cover dynamic UDN allocation on a no-overlay shared-gateway lane + - 1b7e0ec0 2026-07-16T00:32:34+02:00 e2e: adapt advertised network isolation tests to dynamic UDN allocation + - 156b75f9 2026-07-16T00:32:34+02:00 e2e: adapt CUDN advertisement tests to dynamic UDN allocation + - 501cc079 2026-07-16T00:32:34+02:00 e2e: cover RouteAdvertisements over a dynamically allocated CUDN + - 8df86599 2026-07-16T00:32:34+02:00 routeadvertisements: advertise dynamic UDNs only from active nodes + - 6a73851e 2026-07-15T14:34:58-04:00 build(deps): bump the go_modules group across 3 directories with 1 update + - 677d6113 2026-07-15T10:03:52-07:00 clustermanager: rename node allocation controller + - 5c9606a8 2026-07-15T19:10:30+05:30 openshift: fix lint issues + - 1fcfb18f 2026-07-14T16:09:34-04:00 no-overlay: host -> pods on other nodes via mp0 + - f49764be 2026-07-14T20:50:36+02:00 docs: add AGENTS.md for go-controller/pkg and CRDs + - 4620cb6d 2026-07-14T10:29:15-07:00 licenses: refresh generated third-party licenses + - 8b0dd877 2026-07-14T10:29:15-07:00 cni: fold libovsdb and shell-out ConfigureOVS paths into one + - 0b276e27 2026-07-14T10:29:15-07:00 libovsdb/ops: consolidate ovs helper operations + - 49393a41 2026-07-14T16:52:06+01:00 docs: rename portSecurity to macSecurity in OKEP-3926 + - 7229c04d 2026-07-14T20:27:41+05:30 node: skip configureGlobalForwarding tests in CI without root access + - 40bd24a5 2026-07-13T17:27:35+02:00 zone_interconnect: add unit test for stale IC route cleanup + - 60fcdaf5 2026-07-10T18:56:40+02:00 Use new IPv6 force_forwarding sysctl if available. + - 0e3a4e06 2026-07-10T18:56:40+02:00 Don't change FORWARD table default policy for IPv4 + - 7795aba2 2026-07-10T18:56:40+02:00 Don't override FORWARD default policy when `disable-forwarding` is not set + - 92fc5160 2026-07-10T18:56:40+02:00 Update disable-gateway unit tests + - a90d60b6 2026-07-10T18:56:40+02:00 Clarify/simplify/fix "Disable Forwarding Config" docs + - bdfd82fb 2026-07-10T17:48:35+02:00 Redo the AllocateLoadBalancerNodePorts=false test cases + - dcaf6dba 2026-07-10T12:46:42+02:00 [perf] fix netpol selection for cudn-l2 job + - d447e853 2026-07-10T11:17:19+02:00 Support update of chassis-id without re-creating the node. + - 0c9edf05 2026-07-08T12:59:20-07:00 ovnkube.sh: unify gateway option loading from OVS external_ids + - 945f64d7 2026-07-08T10:33:19-07:00 test: Use proper TLS certificate validation in metrics server tests + - 98e204fe 2026-07-08T13:36:28+02:00 coderabbit: add pre-merge checks and custom validation rules + - e36fbadc 2026-07-07T20:23:30+02:00 Get pod from apiserver on retryable annotation patch failure + - 06f453b7 2026-07-07T08:13:37+02:00 e2e(kubevirt): replace echoserver with iperf3 + - 853a72fa 2026-07-06T15:06:48-07:00 libovsdb/ops: document ovs-vsctl equivalents on read wrappers + - e3e40f10 2026-07-06T15:06:48-07:00 util, libovsdb/ops: migrate NicToBridge to libovsdb + - 497f470f 2026-07-06T15:06:48-07:00 test/e2e: pin docker while importing libovsdb + - c1c5603e 2026-07-06T15:06:48-07:00 util, node: migrate nicstobridge read paths to libovsdb + - 258eb623 2026-07-06T15:06:48-07:00 node/test: migrate DPU and gateway tests to libovsdb harness + - 1a64e7db 2026-07-06T15:06:48-07:00 cni, node: migrate ConfigureOVS and delRepPort to libovsdb + - 3785f7bd 2026-07-06T15:06:48-07:00 node: move ovsClient to BaseNodeNetworkController + - a58ead15 2026-07-06T15:06:47-07:00 libovsdb/ops: add GetOVSInterface and CreateOrUpdatePodPort + - ff6d3a79 2026-07-06T15:06:47-07:00 node, controllermanager: migrate stale-port cleanup to libovsdb + - 65e3926d 2026-07-06T15:06:47-07:00 node, libovsdb/ops: migrate port-to-br shell-outs to libovsdb + - f1a554fd 2026-07-06T15:06:47-07:00 node: migrate br-exists and del-port br-int to libovsdb + - 1e4c92c6 2026-07-06T15:06:47-07:00 util, ovn-kube-util: migrate BridgeToNic to libovsdb + - 79cb19da 2026-07-06T15:06:47-07:00 libovsdb/ops: bridge-scope DeletePortWithInterfaces + - fdc69950 2026-07-06T15:06:47-07:00 node, libovsdb/ops: migrate del-br shell-outs to libovsdb + - 25b05aa5 2026-07-06T20:15:26+02:00 Only create ACCEPT rules for bypassing our own DROP rules + - fe9bd9f8 2026-07-06T20:15:26+02:00 Simplify initLocalGateway iptables/nftables setup + - f7401aeb 2026-07-03T15:15:57+02:00 routemanager: normalize IPv6 route metric to kernel default + - 7683207e 2026-07-03T10:03:37+02:00 e2e(kubevirt): drop fedora coreos image in favor of fedora + - d9d3e374 2026-07-02T18:14:51+02:00 area-merge: prevent bot comment feedback loop + - 635a3fd7 2026-07-02T15:50:39+01:00 docs: add "future work" section to OKEP-3926 + - 69f3a5e7 2026-07-02T15:50:39+01:00 docs: simplify OKEP-3926 and add per-attachment future section + - 00e2aa81 2026-07-02T15:50:39+01:00 docs: add OKEP-3926 for disabling port security on secondary networks + - 4246d935 2026-07-02T17:56:19+08:00 docs: fix typo in OKEP 5193 CUDN spec + - e9ed7419 2026-07-01T15:50:28-07:00 OKEP-6227: Add DHCP IPAM support for localnet UDNs + - 78e42465 2026-07-01T10:34:35-04:00 config: make routing table ID start configurable + - b19a79d2 2026-06-30T10:59:13-04:00 Revert "Route DPU host no-overlay traffic through OVN" + - 6eac3a2e 2026-06-30T15:35:05+02:00 docs/e2e: clarify E2E backward compatibility requirements in OKEP template + - f5692f2b 2026-06-26T11:04:37-07:00 OTE: Remove duplicate EVPN test from tests.go + - 732ca5db 2026-06-26T11:04:37-07:00 OTE: Add test list validation tooling + - 585b72c2 2026-06-26T16:33:10+02:00 Allow networks to start while route advertisements settle + +- kubernetes image-arm64 63ee93dac28329fd9d81e91b21ea8d8c43105d01 to 7b29fb077260554429dcef8234272e9fd25fcfbd + - a9c56bc60 2026-08-13T16:07:54-04:00 UPSTREAM: : hack/update-vendor.sh, make update and update image + - 092ef64dd 2026-08-13T15:09:28-04:00 UPSTREAM: : manually resolve conflicts + - fad190424 2026-08-03T10:04:31-04:00 UPSTREAM: : run resize tests + - a6b682d65 2026-07-31T14:11:52-04:00 UPSTREAM: 139522: kubelet: fix in-place pod resize with non-admitted pods + - 5e858e982 2026-07-28T13:51:08-04:00 UPSTREAM: : Re-enable kubectl kuberc commands e2e tests + - 8d27ef98f 2026-07-27T11:14:23+02:00 UPSTREAM: 137936: csi: update CSI sidecar images in test manifests + - c8aa52947 2026-07-24T13:25:07+02:00 UPSTREAM: 138768: move VolumeGroupSnapshot to V1 + - 0f29094e5 2026-07-22T18:07:38Z Release commit for Kubernetes v1.36.3 + - 0f4503bbf 2026-07-22T11:54:16-04:00 UPSTREAM: : Update openshift-hack/rebase.sh, REBASE.openshift.md + - cc48cfba7 2026-07-20T21:23:37-06:00 UPSTREAM: : Add NodeSelectorAdjuster admission plugin for standalone clusters (part 2) + - 5874ee71e 2026-07-17T08:54:21+08:00 DRA: roll back reserved state in allocateDevice + - de396e993 2026-07-16T15:20:30-06:00 UPSTREAM: 140377: e2e: storage snapshot tests should read custom timeouts from manifest + - 2c14a99ab 2026-07-15T12:55:44+07:00 Bump images and versions to golang 1.26.5 and update distroless-iptables + - fb2467e2c 2026-07-08T22:28:00+08:00 stop logging missing optional container annotations + - 4434901e4 2026-07-07T19:00:53-04:00 Add e2e test for setting maps and slices to null via SSA + - f01529250 2026-07-07T19:00:46-04:00 Bump sigs.k8s.io/structured-merge-diff/v6 to v6.3.3 + - ccca5a96b 2026-06-28T20:03:27-04:00 kubelet startPodSync: reuse the previous context to fix memory leak regression + - ab57dc006 2026-06-24T12:00:32-04:00 Make utf8 replacement char test pass on Go 1.27 + - b86d94a7c 2026-06-23T13:48:49-04:00 Restore string JSON encoding of cri-api KeyValue + - 5acf40ff7 2026-06-22T13:27:12+01:00 kubeadm: treat already promoted learner as successful + - 24b3a259f 2026-06-17T11:31:41+02:00 kubeadm: use KubernetesAPICallTimeout for mandatory kubeadm-config fetch + - d20c60aa5 2026-06-12T11:21:30-05:00 Align DeviceTaintRule informer API version with handlers + - 903e7fc93 2026-06-11T18:21:48Z Update CHANGELOG/CHANGELOG-1.36.md for v1.36.2 + - ff173bd50 2026-06-11T14:00:35+05:30 Fix job controller reporting active=0 during pod creation backoff + - bed40bd59 2026-05-28T20:23:35Z flowcontrol: cover Required rule for spec.type and limitResponse.type + - 746956bbd 2026-05-28T20:23:35Z flowcontrol: emit Required when spec.type or limitResponse.type is empty + - 720f13b8e 2026-05-11T15:44:04-05:00 test/compatibility_lifecycle: resolve feature names from variables + - 3ddb65998 2026-04-21T10:31:45+08:00 kubeadm: skip promote call when etcd member is already a voting member + +- service-ca-operator image-arm64 e260be2b3710137012814ce9ca48f155f24f0b02 to ed872ba14b615ca5726ae90e987268877a0b0b20 + - 0ffd45b 2026-07-30T14:48:17+01:00 Remove unnecessary cel-go replace statement + - fde9987 2026-07-27T20:08:35+01:00 Bump go.opentelemetry.io/otel/sdk to v1.43.0 to address CVE-2026-39883 + - 7f95756 2026-07-27T20:08:35+01:00 bump(kubernetes): go mod vendor + - 7ed5392 2026-07-27T19:59:19+01:00 Bump kubernetes dependencies to v0.36.2 + - 2fc2708 2026-02-09T11:24:14+01:00 chore: add permissions on endpointslice to Prometheus Role and use serviceDiscoveryRole: EndpointSlice in ServiceMonitors diff --git a/scripts/auto-rebase/commits.txt b/scripts/auto-rebase/commits.txt index d610a4f0c7..561998a14a 100644 --- a/scripts/auto-rebase/commits.txt +++ b/scripts/auto-rebase/commits.txt @@ -1,35 +1,35 @@ -https://github.com/openshift/api embedded-component 581cfdf7198613bd325c185eb3eac672670da633 -https://github.com/openshift/cluster-csi-snapshot-controller-operator embedded-component ef7a4c8b7f5c5e6cba4486dcc37f50521e7bc655 -https://github.com/openshift/cluster-dns-operator embedded-component 4b8ae49940eefc50fa48da5179e735dd6ccd42d9 -https://github.com/openshift/cluster-ingress-operator embedded-component b4daff58712de418c51d765a8686069a5f47e764 -https://github.com/openshift/cluster-kube-apiserver-operator embedded-component ea8a9c50203113ca43db98ca925ab7fcdaff7d28 -https://github.com/openshift/cluster-kube-controller-manager-operator embedded-component 4e72164b8bc505033ad565ab01d57963e7c9688e +https://github.com/openshift/api embedded-component af5c920502e23802ac1aec0eeb47740520dcb3d6 +https://github.com/openshift/cluster-csi-snapshot-controller-operator embedded-component 35ec0224eb0e5219d5eae012fb703223a6f3e1f7 +https://github.com/openshift/cluster-dns-operator embedded-component c0ed09e329e9001629518604a58205e3fbe8284a +https://github.com/openshift/cluster-ingress-operator embedded-component b1cbed2ed9af6333fd96e7411076320dbcc14f7d +https://github.com/openshift/cluster-kube-apiserver-operator embedded-component b119e394abd0379fbc1ff7313f302173c75f8c61 +https://github.com/openshift/cluster-kube-controller-manager-operator embedded-component 8db74e3fe8793043d942ef1f59cce3b0a0bcc548 https://github.com/openshift/cluster-kube-scheduler-operator embedded-component 56fa325466a1f2a2d41435ba3a58b2bf8fdab2f3 -https://github.com/openshift/cluster-network-operator embedded-component 4f6fb6be829a2f6ad3e0df4ab85ecb00ef028343 -https://github.com/openshift/cluster-openshift-controller-manager-operator embedded-component 34f95b07f4afbc47558e54e4fa2710fd692e615e -https://github.com/openshift/cluster-policy-controller embedded-component 01afc4aac71a8e8be26383a0421bed7673391750 -https://github.com/openshift/csi-external-snapshotter embedded-component b5e4b73f9a761ff8a59f31b982a63e1cdbb76ed8 -https://github.com/openshift/etcd embedded-component 64f8851a001f7e102d47bfe51ca0dac23951879a -https://github.com/openshift/kubernetes embedded-component 98b35193b2ac7a23a673325f5e9b830ecd5ba406 +https://github.com/openshift/cluster-network-operator embedded-component a99f189161f2f426f026998e96e168e9adb5baf5 +https://github.com/openshift/cluster-openshift-controller-manager-operator embedded-component ca4d2061fba488b34c042e7a16946157db595599 +https://github.com/openshift/cluster-policy-controller embedded-component 469bbf211d35eee0df4422bda7e9e600b080f0f2 +https://github.com/openshift/csi-external-snapshotter embedded-component a019d1a9d9e1d26ffd0b2e0d911733180fa608b2 +https://github.com/openshift/etcd embedded-component 609b11ed8fc404fb95572d7c87e3243a1206cdb7 +https://github.com/openshift/kubernetes embedded-component 7b29fb077260554429dcef8234272e9fd25fcfbd https://github.com/openshift/kubernetes-kube-storage-version-migrator embedded-component 72835e43c7754356645e41031f3a99926b4d42e6 -https://github.com/openshift/machine-config-operator embedded-component 067b924f19a64a209796d5be5a0a63665f53b1eb +https://github.com/openshift/machine-config-operator embedded-component e3eb2f73dad9b9a7c4320e65ef065cebcd057629 https://github.com/openshift/openshift-controller-manager embedded-component 5631cf493b006cbc72a8600a7435813272d71940 -https://github.com/openshift/operator-framework-olm embedded-component 56b3931de4636f7e0d212001f2074b9dddb45a8f +https://github.com/openshift/operator-framework-olm embedded-component c64b9ca2026d13e8907d547b1cbe5226b0a25219 https://github.com/openshift/route-controller-manager embedded-component 59697cf7af4517dd44e28179a57f7f35b6ea0e22 -https://github.com/openshift/service-ca-operator embedded-component 6391e070d2ab026324b032a6fa5fc7d6be0d2cb5 -https://github.com/openshift/oc image-amd64 994613040335f72809854babcb80b9d11a4e98d5 +https://github.com/openshift/service-ca-operator embedded-component ed872ba14b615ca5726ae90e987268877a0b0b20 +https://github.com/openshift/oc image-amd64 2902632b849a20d312215e16f2058233f1713553 https://github.com/openshift/coredns image-amd64 37aaba896e97f4b9a091aab6d36f2213b8854474 -https://github.com/openshift/csi-external-snapshotter image-amd64 b5e4b73f9a761ff8a59f31b982a63e1cdbb76ed8 -https://github.com/openshift/router image-amd64 f5b67ebd12089170bfc47da7745fe4efb1477eb7 +https://github.com/openshift/csi-external-snapshotter image-amd64 a019d1a9d9e1d26ffd0b2e0d911733180fa608b2 +https://github.com/openshift/router image-amd64 3381229146657d2e6bd94115dda0885f25cb3bed https://github.com/openshift/kube-rbac-proxy image-amd64 43c114bc124f59e2fc3223dea8e0a8f4cdeed18d -https://github.com/openshift/ovn-kubernetes image-amd64 8e2e1542642847da592268a0ab94a207eb8d3605 -https://github.com/openshift/kubernetes image-amd64 98b35193b2ac7a23a673325f5e9b830ecd5ba406 -https://github.com/openshift/service-ca-operator image-amd64 6391e070d2ab026324b032a6fa5fc7d6be0d2cb5 -https://github.com/openshift/oc image-arm64 a88e785e90aa96ac96da93359bacf3ea5c174733 +https://github.com/openshift/ovn-kubernetes image-amd64 7b4de5ed3bd4381e3a17cdfddbe14be1432b9860 +https://github.com/openshift/kubernetes image-amd64 7b29fb077260554429dcef8234272e9fd25fcfbd +https://github.com/openshift/service-ca-operator image-amd64 ed872ba14b615ca5726ae90e987268877a0b0b20 +https://github.com/openshift/oc image-arm64 2902632b849a20d312215e16f2058233f1713553 https://github.com/openshift/coredns image-arm64 37aaba896e97f4b9a091aab6d36f2213b8854474 -https://github.com/openshift/csi-external-snapshotter image-arm64 b5e4b73f9a761ff8a59f31b982a63e1cdbb76ed8 -https://github.com/openshift/router image-arm64 682319a1bb432f0203951c33336d0f55947e1099 +https://github.com/openshift/csi-external-snapshotter image-arm64 a019d1a9d9e1d26ffd0b2e0d911733180fa608b2 +https://github.com/openshift/router image-arm64 3381229146657d2e6bd94115dda0885f25cb3bed https://github.com/openshift/kube-rbac-proxy image-arm64 43c114bc124f59e2fc3223dea8e0a8f4cdeed18d -https://github.com/openshift/ovn-kubernetes image-arm64 88e9f0f146784e8525f6304a1f6f7c986eba2319 -https://github.com/openshift/kubernetes image-arm64 63ee93dac28329fd9d81e91b21ea8d8c43105d01 -https://github.com/openshift/service-ca-operator image-arm64 e260be2b3710137012814ce9ca48f155f24f0b02 +https://github.com/openshift/ovn-kubernetes image-arm64 7b4de5ed3bd4381e3a17cdfddbe14be1432b9860 +https://github.com/openshift/kubernetes image-arm64 7b29fb077260554429dcef8234272e9fd25fcfbd +https://github.com/openshift/service-ca-operator image-arm64 ed872ba14b615ca5726ae90e987268877a0b0b20 diff --git a/scripts/auto-rebase/last_rebase.sh b/scripts/auto-rebase/last_rebase.sh index 258fd5c26e..0678127721 100755 --- a/scripts/auto-rebase/last_rebase.sh +++ b/scripts/auto-rebase/last_rebase.sh @@ -1,2 +1,2 @@ #!/bin/bash -x -./scripts/auto-rebase/rebase.sh to "registry.ci.openshift.org/ocp/release-5:5.0.0-0.nightly-2026-07-23-224236" "registry.ci.openshift.org/ocp-arm64/release-5-arm64:5.0.0-0.nightly-arm64-2026-07-27-004356" +./scripts/auto-rebase/rebase.sh to "registry.ci.openshift.org/ocp/release-5:5.1.0-0.nightly-2026-08-20-065836" "registry.ci.openshift.org/ocp-arm64/release-5-arm64:5.1.0-0.nightly-arm64-2026-08-21-025249" diff --git a/vendor/k8s.io/cri-api/pkg/apis/runtime/v1/api_json.go b/vendor/k8s.io/cri-api/pkg/apis/runtime/v1/api_json.go new file mode 100644 index 0000000000..2e0b6dc2fd --- /dev/null +++ b/vendor/k8s.io/cri-api/pkg/apis/runtime/v1/api_json.go @@ -0,0 +1,47 @@ +/* +Copyright The Kubernetes Authors. + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. +*/ + +package v1 + +import "encoding/json" + +// MarshalJSON() preserves pre-1.34 JSON encoding of value as a string (not base64), +// stomping non-utf-8 data with the utf8 replacement character. +func (k *KeyValue) MarshalJSON() ([]byte, error) { + return json.Marshal(stringKeyValue{ + Key: k.GetKey(), + Value: string(k.GetValue()), + }) +} + +// UnmarshalJSON preserves pre-1.34 JSON decoding of value as a string (not base64), +// stomping non-utf-8 data with the utf8 replacement character. +func (k *KeyValue) UnmarshalJSON(data []byte) error { + v := stringKeyValue{} + if err := json.Unmarshal(data, &v); err != nil { + return err + } + k.Key = v.Key + k.Value = []byte(v.Value) + return nil +} + +// stringKeyValue matches the structure used to json-encode pre-1.34. +// Non-UTF-8 characters in Value are coerced to the replacement character on encode/decode. +type stringKeyValue struct { + Key string `json:"key,omitempty"` + Value string `json:"value,omitempty"` +} diff --git a/vendor/k8s.io/dynamic-resource-allocation/resourceslice/tracker/tracker.go b/vendor/k8s.io/dynamic-resource-allocation/resourceslice/tracker/tracker.go index 9941a38c3f..e86ac3ddca 100644 --- a/vendor/k8s.io/dynamic-resource-allocation/resourceslice/tracker/tracker.go +++ b/vendor/k8s.io/dynamic-resource-allocation/resourceslice/tracker/tracker.go @@ -25,7 +25,7 @@ import ( v1 "k8s.io/api/core/v1" resourceapi "k8s.io/api/resource/v1" - resourcealphaapi "k8s.io/api/resource/v1alpha3" + resourcebetaapi "k8s.io/api/resource/v1beta2" labels "k8s.io/apimachinery/pkg/labels" "k8s.io/apimachinery/pkg/util/diff" utilruntime "k8s.io/apimachinery/pkg/util/runtime" @@ -395,15 +395,15 @@ func sliceDriverPoolDeviceIndexFunc(obj any) ([]string, error) { return indexValues, nil } -func driverPoolDeviceIndexPatchKey(patch *resourcealphaapi.DeviceTaintRule) string { - deviceSelector := ptr.Deref(patch.Spec.DeviceSelector, resourcealphaapi.DeviceTaintSelector{}) +func driverPoolDeviceIndexPatchKey(patch *resourcebetaapi.DeviceTaintRule) string { + deviceSelector := ptr.Deref(patch.Spec.DeviceSelector, resourcebetaapi.DeviceTaintSelector{}) driverKey := ptr.Deref(deviceSelector.Driver, anyDriver) poolKey := ptr.Deref(deviceSelector.Pool, anyPool) deviceKey := ptr.Deref(deviceSelector.Device, anyDevice) return deviceID(driverKey, poolKey, deviceKey) } -func (t *Tracker) sliceNamesForPatch(ctx context.Context, patch *resourcealphaapi.DeviceTaintRule) []string { +func (t *Tracker) sliceNamesForPatch(ctx context.Context, patch *resourcebetaapi.DeviceTaintRule) []string { patchKey := driverPoolDeviceIndexPatchKey(patch) sliceNames, err := t.resourceSlices.GetIndexer().IndexKeys(driverPoolDeviceIndexName, patchKey) if err != nil { @@ -469,7 +469,7 @@ func (t *Tracker) resourceSliceDelete(ctx context.Context) func(obj any) { func (t *Tracker) deviceTaintAdd(ctx context.Context) func(obj any) { logger := klog.FromContext(ctx) return func(obj any) { - rule, ok := obj.(*resourcealphaapi.DeviceTaintRule) + rule, ok := obj.(*resourcebetaapi.DeviceTaintRule) if !ok { return } @@ -487,11 +487,11 @@ func (t *Tracker) deviceTaintAdd(ctx context.Context) func(obj any) { func (t *Tracker) deviceTaintUpdate(ctx context.Context) func(oldObj, newObj any) { logger := klog.FromContext(ctx) return func(oldObj, newObj any) { - oldRule, ok := oldObj.(*resourcealphaapi.DeviceTaintRule) + oldRule, ok := oldObj.(*resourcebetaapi.DeviceTaintRule) if !ok { return } - newRule, ok := newObj.(*resourcealphaapi.DeviceTaintRule) + newRule, ok := newObj.(*resourcebetaapi.DeviceTaintRule) if !ok { return } @@ -519,7 +519,7 @@ func (t *Tracker) deviceTaintDelete(ctx context.Context) func(obj any) { if tombstone, ok := obj.(cache.DeletedFinalStateUnknown); ok { obj = tombstone.Obj } - patch, ok := obj.(*resourcealphaapi.DeviceTaintRule) + patch, ok := obj.(*resourcebetaapi.DeviceTaintRule) if !ok { return } @@ -631,7 +631,7 @@ func (t *Tracker) syncSlice(ctx context.Context, name string, sendEvent bool) { return } - patches := typedSlice[*resourcealphaapi.DeviceTaintRule](t.deviceTaints.GetIndexer().List()) + patches := typedSlice[*resourcebetaapi.DeviceTaintRule](t.deviceTaints.GetIndexer().List()) patchedSlice, err := t.applyPatches(ctx, slice, patches) if err != nil { t.handleError(ctx, err, "failed to apply patches to ResourceSlice", "resourceslice", klog.KObj(slice)) @@ -666,7 +666,7 @@ func (t *Tracker) syncSlice(ctx context.Context, name string, sendEvent bool) { } } -func (t *Tracker) applyPatches(ctx context.Context, slice *resourceapi.ResourceSlice, taintRules []*resourcealphaapi.DeviceTaintRule) (*resourceapi.ResourceSlice, error) { +func (t *Tracker) applyPatches(ctx context.Context, slice *resourceapi.ResourceSlice, taintRules []*resourcebetaapi.DeviceTaintRule) (*resourceapi.ResourceSlice, error) { logger := klog.FromContext(ctx) // slice will be DeepCopied just-in-time, only when necessary. diff --git a/vendor/k8s.io/dynamic-resource-allocation/structured/internal/experimental/allocator_experimental.go b/vendor/k8s.io/dynamic-resource-allocation/structured/internal/experimental/allocator_experimental.go index d2a2ecb92a..51a2999426 100644 --- a/vendor/k8s.io/dynamic-resource-allocation/structured/internal/experimental/allocator_experimental.go +++ b/vendor/k8s.io/dynamic-resource-allocation/structured/internal/experimental/allocator_experimental.go @@ -1463,6 +1463,10 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus skipCounterCheck := allowMultipleAllocations && alloc.deviceCapacityInUse(device.id) // The API validation logic has checked the ConsumesCounters referred should exist inside SharedCounters. + // countersReserved records whether checkAvailableCounters actually reserved + // this device's counters. It is not the same as len(device.ConsumesCounters) > 0, + // because skipCounterCheck can bypass the reservation. + countersReserved := false if !skipCounterCheck && len(device.ConsumesCounters) > 0 { // If a device consumes counters from a counter set, verify that // there is sufficient counters available. @@ -1474,6 +1478,7 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus alloc.logger.V(7).Info("Insufficient counters", "device", device.id) return false, nil, nil } + countersReserved = true } var parentRequestName string @@ -1487,39 +1492,48 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus subRequestName = requestData.request.name() } + // state records the mutations this call makes so rollbackDevice can undo + // them. Every rejection path after a successful counter reservation calls + // rollbackDevice synchronously, and the success path returns a closure that + // calls the same helper during backtracking, so both undo routes stay + // identical. Passing the state by value to rollbackDevice keeps it (and the flags) on the + // stack for the rejection paths; only the success closure escapes. + state := deviceRollbackState{ + countersReserved: countersReserved, + previousNumResults: len(alloc.result[r.claimIndex].devices), + } + // Might be tainted, in which case the taint has to be tolerated. // The check is skipped if the feature is disabled. if alloc.features.DeviceTaints && taintPreventsAllocation(device.Device, request) { + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) return false, nil, nil } // It's available. Now check constraints. - for i, constraint := range alloc.constraints[r.claimIndex] { - added := constraint.add(baseRequestName, subRequestName, device.Device, device.id) - if !added { + for _, constraint := range alloc.constraints[r.claimIndex] { + if !constraint.add(baseRequestName, subRequestName, device.Device, device.id) { + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) if must { // It does not make sense to declare a claim where a constraint prevents getting // all devices. Treat this as an error. return false, nil, fmt.Errorf("claim %s, request %s: cannot add device %s because a claim constraint would not be satisfied", klog.KObj(claim), request.name(), device.id) } - - // Roll back for all previous constraints before we return. - for e := 0; e < i; e++ { - alloc.constraints[r.claimIndex][e].remove(baseRequestName, subRequestName, device.Device, device.id) - } return false, nil, nil } + state.constraintsAdded++ } // All constraints satisfied. Mark as in use (unless we do admin access or allow multiple allocations) // and record the result. alloc.logger.V(7).Info("Device allocated", "device", device.id) - if alloc.allocatingDevices[device.id] == nil { - alloc.allocatingDevices[device.id] = make(sets.Set[int]) - } if !allowMultipleAllocations { + if alloc.allocatingDevices[device.id] == nil { + alloc.allocatingDevices[device.id] = make(sets.Set[int]) + } alloc.allocatingDevices[device.id].Insert(r.claimIndex) + state.deviceMarked = true } consumedCapacity := make(map[resourceapi.QualifiedName]resource.Quantity, 0) @@ -1531,10 +1545,12 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus if err != nil { alloc.logger.V(7).Info("Failed to compare device capacity request on allocateDevice", "device", device, "request", requestData.request.name(), "err", err) + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) return false, nil, nil } if !success { alloc.logger.V(7).Info("Device capacity not enough", "device", device) + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) return false, nil, nil } @@ -1543,7 +1559,14 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus shareID = GenerateNewShareID() alloc.logger.V(7).Info("Device capacity allocated", "device", device.id, "consumed capacity", klog.Format(consumedCapacity)) + // A prior share of this device may already hold the capacity entry. + // That entry doubles as the "already shared" marker that lets a later + // share skip the counter check, so record whether it predated this + // share; rollback must not delete it while another share still needs it. + _, state.capacityEntryExisted = alloc.allocatingCapacity[device.id] alloc.allocatingCapacity.Insert(NewDeviceConsumedCapacity(device.id, consumedCapacity)) + state.capacityInserted = true + state.consumedCapacity = consumedCapacity } } @@ -1561,29 +1584,64 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus if len(consumedCapacity) > 0 { result.consumedCapacity = consumedCapacity } - previousNumResults := len(alloc.result[r.claimIndex].devices) alloc.result[r.claimIndex].devices = append(alloc.result[r.claimIndex].devices, result) + state.resultAdded = true + // Only this success path builds an escaping closure, so backtracking can undo + // a committed candidate. undo is a copy: capturing state directly would move it + // and its flags to the heap on the rejection paths too, which never escape. + undo := state return true, func() { - for _, constraint := range alloc.constraints[r.claimIndex] { - constraint.remove(baseRequestName, subRequestName, device.Device, device.id) - } - alloc.allocatingDevices[device.id].Delete(r.claimIndex) - if allowMultipleAllocations { - requestedResource := alloc.result[r.claimIndex].devices[previousNumResults].consumedCapacity - if requestedResource != nil { - alloc.allocatingCapacity.Remove(NewDeviceConsumedCapacity(device.id, requestedResource)) - } - } else { - alloc.allocatingDevices[device.id].Delete(r.claimIndex) - if alloc.features.PartitionableDevices && len(device.ConsumesCounters) > 0 { - alloc.deallocateCountersForDevice(device) + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, undo) + }, nil +} + +// deviceRollbackState records the mutations allocateDevice makes for a single +// candidate so rollbackDevice can undo them, both when the candidate is rejected +// and when the backtracking search abandons a previously successful candidate. +type deviceRollbackState struct { + countersReserved bool + constraintsAdded int + deviceMarked bool + capacityInserted bool + capacityEntryExisted bool + resultAdded bool + previousNumResults int + consumedCapacity map[resourceapi.QualifiedName]resource.Quantity +} + +// rollbackDevice reverses the mutations recorded in state, in the opposite order +// they were applied. It is called synchronously on the rejection paths and, via +// the closure returned on success, during backtracking. +func (alloc *allocator) rollbackDevice(r deviceIndices, device deviceWithID, baseRequestName, subRequestName string, state deviceRollbackState) { + if state.resultAdded { + alloc.result[r.claimIndex].devices = alloc.result[r.claimIndex].devices[:state.previousNumResults] + } + if state.capacityInserted { + alloc.allocatingCapacity.Remove(NewDeviceConsumedCapacity(device.id, state.consumedCapacity)) + if state.capacityEntryExisted { + // Remove drops the entry once it becomes empty, which also erases the + // shared marker that the earlier share still relies on. Restore an empty + // entry in that case so the earlier share stays accounted as shared. + if _, found := alloc.allocatingCapacity[device.id]; !found { + alloc.allocatingCapacity[device.id] = NewConsumedCapacity() } } - // Truncate, but keep the underlying slice. - alloc.result[r.claimIndex].devices = alloc.result[r.claimIndex].devices[:previousNumResults] + } + if state.deviceMarked { + alloc.allocatingDevices[device.id].Delete(r.claimIndex) + } + for i := state.constraintsAdded - 1; i >= 0; i-- { + alloc.constraints[r.claimIndex][i].remove(baseRequestName, subRequestName, device.Device, device.id) + } + if state.countersReserved { + alloc.deallocateCountersForDevice(device) + } + if state.resultAdded { + // Only a fully allocated candidate recorded a result, so this is a real + // deallocation during backtracking, not a rejection rollback. alloc.logger.V(7).Info("Device deallocated", "device", device.id) - }, nil + } } func taintPreventsAllocation(device *draapi.Device, request requestAccessor) bool { diff --git a/vendor/k8s.io/dynamic-resource-allocation/structured/internal/incubating/allocator_incubating.go b/vendor/k8s.io/dynamic-resource-allocation/structured/internal/incubating/allocator_incubating.go index a77feed54c..335dca2a8e 100644 --- a/vendor/k8s.io/dynamic-resource-allocation/structured/internal/incubating/allocator_incubating.go +++ b/vendor/k8s.io/dynamic-resource-allocation/structured/internal/incubating/allocator_incubating.go @@ -1335,6 +1335,10 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus skipCounterCheck := allowMultipleAllocations && alloc.deviceCapacityInUse(device.id) // The API validation logic has checked the ConsumesCounters referred should exist inside SharedCounters. + // countersReserved records whether checkAvailableCounters actually reserved + // this device's counters. It is not the same as len(device.ConsumesCounters) > 0, + // because skipCounterCheck can bypass the reservation. + countersReserved := false if !skipCounterCheck && len(device.ConsumesCounters) > 0 { // If a device consumes counters from a counter set, verify that // there is sufficient counters available. @@ -1346,6 +1350,7 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus alloc.logger.V(7).Info("Insufficient counters", "device", device.id) return false, nil, nil } + countersReserved = true } var parentRequestName string @@ -1359,39 +1364,48 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus subRequestName = requestData.request.name() } + // state records the mutations this call makes so rollbackDevice can undo + // them. Every rejection path after a successful counter reservation calls + // rollbackDevice synchronously, and the success path returns a closure that + // calls the same helper during backtracking, so both undo routes stay + // identical. Passing the state by value to rollbackDevice keeps it (and the flags) on the + // stack for the rejection paths; only the success closure escapes. + state := deviceRollbackState{ + countersReserved: countersReserved, + previousNumResults: len(alloc.result[r.claimIndex].devices), + } + // Might be tainted, in which case the taint has to be tolerated. // The check is skipped if the feature is disabled. if alloc.features.DeviceTaints && taintPreventsAllocation(device.Device, request) { + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) return false, nil, nil } // It's available. Now check constraints. - for i, constraint := range alloc.constraints[r.claimIndex] { - added := constraint.add(baseRequestName, subRequestName, device.Device, device.id) - if !added { + for _, constraint := range alloc.constraints[r.claimIndex] { + if !constraint.add(baseRequestName, subRequestName, device.Device, device.id) { + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) if must { // It does not make sense to declare a claim where a constraint prevents getting // all devices. Treat this as an error. return false, nil, fmt.Errorf("claim %s, request %s: cannot add device %s because a claim constraint would not be satisfied", klog.KObj(claim), request.name(), device.id) } - - // Roll back for all previous constraints before we return. - for e := 0; e < i; e++ { - alloc.constraints[r.claimIndex][e].remove(baseRequestName, subRequestName, device.Device, device.id) - } return false, nil, nil } + state.constraintsAdded++ } // All constraints satisfied. Mark as in use (unless we do admin access or allow multiple allocations) // and record the result. alloc.logger.V(7).Info("Device allocated", "device", device.id) - if alloc.allocatingDevices[device.id] == nil { - alloc.allocatingDevices[device.id] = make(sets.Set[int]) - } if !allowMultipleAllocations { + if alloc.allocatingDevices[device.id] == nil { + alloc.allocatingDevices[device.id] = make(sets.Set[int]) + } alloc.allocatingDevices[device.id].Insert(r.claimIndex) + state.deviceMarked = true } consumedCapacity := make(map[resourceapi.QualifiedName]resource.Quantity, 0) @@ -1403,10 +1417,12 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus if err != nil { alloc.logger.V(7).Info("Failed to compare device capacity request on allocateDevice", "device", device, "request", requestData.request.name(), "err", err) + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) return false, nil, nil } if !success { alloc.logger.V(7).Info("Device capacity not enough", "device", device) + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) return false, nil, nil } @@ -1415,7 +1431,14 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus shareID = GenerateNewShareID() alloc.logger.V(7).Info("Device capacity allocated", "device", device.id, "consumed capacity", klog.Format(consumedCapacity)) + // A prior share of this device may already hold the capacity entry. + // That entry doubles as the "already shared" marker that lets a later + // share skip the counter check, so record whether it predated this + // share; rollback must not delete it while another share still needs it. + _, state.capacityEntryExisted = alloc.allocatingCapacity[device.id] alloc.allocatingCapacity.Insert(NewDeviceConsumedCapacity(device.id, consumedCapacity)) + state.capacityInserted = true + state.consumedCapacity = consumedCapacity } } @@ -1433,29 +1456,64 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus if len(consumedCapacity) > 0 { result.consumedCapacity = consumedCapacity } - previousNumResults := len(alloc.result[r.claimIndex].devices) alloc.result[r.claimIndex].devices = append(alloc.result[r.claimIndex].devices, result) + state.resultAdded = true + // Only this success path builds an escaping closure, so backtracking can undo + // a committed candidate. undo is a copy: capturing state directly would move it + // and its flags to the heap on the rejection paths too, which never escape. + undo := state return true, func() { - for _, constraint := range alloc.constraints[r.claimIndex] { - constraint.remove(baseRequestName, subRequestName, device.Device, device.id) - } - alloc.allocatingDevices[device.id].Delete(r.claimIndex) - if allowMultipleAllocations { - requestedResource := alloc.result[r.claimIndex].devices[previousNumResults].consumedCapacity - if requestedResource != nil { - alloc.allocatingCapacity.Remove(NewDeviceConsumedCapacity(device.id, requestedResource)) - } - } else { - alloc.allocatingDevices[device.id].Delete(r.claimIndex) - if alloc.features.PartitionableDevices && len(device.ConsumesCounters) > 0 { - alloc.deallocateCountersForDevice(device) + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, undo) + }, nil +} + +// deviceRollbackState records the mutations allocateDevice makes for a single +// candidate so rollbackDevice can undo them, both when the candidate is rejected +// and when the backtracking search abandons a previously successful candidate. +type deviceRollbackState struct { + countersReserved bool + constraintsAdded int + deviceMarked bool + capacityInserted bool + capacityEntryExisted bool + resultAdded bool + previousNumResults int + consumedCapacity map[resourceapi.QualifiedName]resource.Quantity +} + +// rollbackDevice reverses the mutations recorded in state, in the opposite order +// they were applied. It is called synchronously on the rejection paths and, via +// the closure returned on success, during backtracking. +func (alloc *allocator) rollbackDevice(r deviceIndices, device deviceWithID, baseRequestName, subRequestName string, state deviceRollbackState) { + if state.resultAdded { + alloc.result[r.claimIndex].devices = alloc.result[r.claimIndex].devices[:state.previousNumResults] + } + if state.capacityInserted { + alloc.allocatingCapacity.Remove(NewDeviceConsumedCapacity(device.id, state.consumedCapacity)) + if state.capacityEntryExisted { + // Remove drops the entry once it becomes empty, which also erases the + // shared marker that the earlier share still relies on. Restore an empty + // entry in that case so the earlier share stays accounted as shared. + if _, found := alloc.allocatingCapacity[device.id]; !found { + alloc.allocatingCapacity[device.id] = NewConsumedCapacity() } } - // Truncate, but keep the underlying slice. - alloc.result[r.claimIndex].devices = alloc.result[r.claimIndex].devices[:previousNumResults] + } + if state.deviceMarked { + alloc.allocatingDevices[device.id].Delete(r.claimIndex) + } + for i := state.constraintsAdded - 1; i >= 0; i-- { + alloc.constraints[r.claimIndex][i].remove(baseRequestName, subRequestName, device.Device, device.id) + } + if state.countersReserved { + alloc.deallocateCountersForDevice(device) + } + if state.resultAdded { + // Only a fully allocated candidate recorded a result, so this is a real + // deallocation during backtracking, not a rejection rollback. alloc.logger.V(7).Info("Device deallocated", "device", device.id) - }, nil + } } func taintPreventsAllocation(device *draapi.Device, request requestAccessor) bool { diff --git a/vendor/k8s.io/dynamic-resource-allocation/structured/internal/stable/allocator_stable.go b/vendor/k8s.io/dynamic-resource-allocation/structured/internal/stable/allocator_stable.go index bb85ff5286..3b434bac95 100644 --- a/vendor/k8s.io/dynamic-resource-allocation/structured/internal/stable/allocator_stable.go +++ b/vendor/k8s.io/dynamic-resource-allocation/structured/internal/stable/allocator_stable.go @@ -1124,6 +1124,9 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus } // The API validation logic has checked the ConsumesCounters referred should exist inside SharedCounters. + // countersReserved records whether checkAvailableCounters actually reserved + // this device's counters, so the rollback below only releases what was taken. + countersReserved := false if len(device.ConsumesCounters) > 0 { // If a device consumes counters from a counter set, verify that // there is sufficient counters available. @@ -1135,6 +1138,7 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus alloc.logger.V(7).Info("Insufficient counters", "device", device.id) return false, nil, nil } + countersReserved = true } var parentRequestName string @@ -1148,28 +1152,36 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus subRequestName = requestData.request.name() } + // state records the mutations this call makes so rollbackDevice can undo + // them. Every rejection path after a successful counter reservation calls + // rollbackDevice synchronously, and the success path returns a closure that + // calls the same helper during backtracking, so both undo routes stay + // identical. Passing the state by value to rollbackDevice keeps it (and the flags) on the + // stack for the rejection paths; only the success closure escapes. + state := deviceRollbackState{ + countersReserved: countersReserved, + previousNumResults: len(alloc.result[r.claimIndex].devices), + } + // Might be tainted, in which case the taint has to be tolerated. // The check is skipped if the feature is disabled. if alloc.features.DeviceTaints && taintPreventsAllocation(device.Device, request) { + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) return false, nil, nil } // It's available. Now check constraints. - for i, constraint := range alloc.constraints[r.claimIndex] { - added := constraint.add(baseRequestName, subRequestName, device.Device, device.id) - if !added { + for _, constraint := range alloc.constraints[r.claimIndex] { + if !constraint.add(baseRequestName, subRequestName, device.Device, device.id) { + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, state) if must { // It does not make sense to declare a claim where a constraint prevents getting // all devices. Treat this as an error. return false, nil, fmt.Errorf("claim %s, request %s: cannot add device %s because a claim constraint would not be satisfied", klog.KObj(claim), request.name(), device.id) } - - // Roll back for all previous constraints before we return. - for e := 0; e < i; e++ { - alloc.constraints[r.claimIndex][e].remove(baseRequestName, subRequestName, device.Device, device.id) - } return false, nil, nil } + state.constraintsAdded++ } // All constraints satisfied. Mark as in use (unless we do admin access) @@ -1180,6 +1192,7 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus alloc.allocatingDevices[device.id] = make(sets.Set[int]) } alloc.allocatingDevices[device.id].Insert(r.claimIndex) + state.deviceMarked = true result := internalDeviceResult{ request: request.name(), @@ -1191,21 +1204,50 @@ func (alloc *allocator) allocateDevice(r deviceIndices, device deviceWithID, mus if request.adminAccess() { result.adminAccess = ptr.To(request.adminAccess()) } - previousNumResults := len(alloc.result[r.claimIndex].devices) alloc.result[r.claimIndex].devices = append(alloc.result[r.claimIndex].devices, result) + state.resultAdded = true + // Only this success path builds an escaping closure, so backtracking can undo + // a committed candidate. undo is a copy: capturing state directly would move it + // and its flags to the heap on the rejection paths too, which never escape. + undo := state return true, func() { - for _, constraint := range alloc.constraints[r.claimIndex] { - constraint.remove(baseRequestName, subRequestName, device.Device, device.id) - } + alloc.rollbackDevice(r, device, baseRequestName, subRequestName, undo) + }, nil +} + +// deviceRollbackState records the mutations allocateDevice makes for a single +// candidate so rollbackDevice can undo them, both when the candidate is rejected +// and when the backtracking search abandons a previously successful candidate. +type deviceRollbackState struct { + countersReserved bool + constraintsAdded int + deviceMarked bool + resultAdded bool + previousNumResults int +} + +// rollbackDevice reverses the mutations recorded in state, in the opposite order +// they were applied. It is called synchronously on the rejection paths and, via +// the closure returned on success, during backtracking. +func (alloc *allocator) rollbackDevice(r deviceIndices, device deviceWithID, baseRequestName, subRequestName string, state deviceRollbackState) { + if state.resultAdded { + alloc.result[r.claimIndex].devices = alloc.result[r.claimIndex].devices[:state.previousNumResults] + } + if state.deviceMarked { alloc.allocatingDevices[device.id].Delete(r.claimIndex) - if alloc.features.PartitionableDevices && len(device.ConsumesCounters) > 0 { - alloc.deallocateCountersForDevice(device) - } - // Truncate, but keep the underlying slice. - alloc.result[r.claimIndex].devices = alloc.result[r.claimIndex].devices[:previousNumResults] + } + for i := state.constraintsAdded - 1; i >= 0; i-- { + alloc.constraints[r.claimIndex][i].remove(baseRequestName, subRequestName, device.Device, device.id) + } + if state.countersReserved { + alloc.deallocateCountersForDevice(device) + } + if state.resultAdded { + // Only a fully allocated candidate recorded a result, so this is a real + // deallocation during backtracking, not a rejection rollback. alloc.logger.V(7).Info("Device deallocated", "device", device.id) - }, nil + } } func taintPreventsAllocation(device *draapi.Device, request requestAccessor) bool { diff --git a/vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go b/vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go index 9bf0a1f8a1..530639815a 100644 --- a/vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go +++ b/vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go @@ -17,7 +17,6 @@ import ( "k8s.io/apimachinery/pkg/api/errors" "k8s.io/apimachinery/pkg/api/resource" metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" - "k8s.io/apimachinery/pkg/labels" "k8s.io/apimachinery/pkg/util/validation/field" "k8s.io/apiserver/pkg/admission" "k8s.io/apiserver/pkg/admission/initializer" @@ -187,16 +186,6 @@ func (a *managementCPUsOverride) Admit(ctx context.Context, attr admission.Attri return admission.NewForbidden(attr, fmt.Errorf("%s node or namespace or infra config cache not synchronized", PluginName)) } - nodes, err := a.nodeLister.List(labels.Everything()) - if err != nil { - return admission.NewForbidden(attr, err) // can happen due to informer latency - } - - // we still need to have nodes under the cluster to decide if the management resource enabled or not - if len(nodes) == 0 { - return admission.NewForbidden(attr, fmt.Errorf("%s the cluster does not have any nodes", PluginName)) - } - clusterInfra, err := a.infraConfigLister.Get(infraClusterName) if err != nil { return admission.NewForbidden(attr, err) // can happen due to informer latency @@ -215,7 +204,7 @@ func (a *managementCPUsOverride) Admit(ctx context.Context, attr admission.Attri } // Check if we are in CPU Partitioning mode for AllNodes - if !isCPUPartitioning(clusterInfra.Status, nodes, workloadType) { + if !isCPUPartitioning(clusterInfra.Status) { return nil } @@ -284,18 +273,7 @@ func (a *managementCPUsOverride) Admit(ctx context.Context, attr admission.Attri return nil } -func isCPUPartitioning(infraStatus configv1.InfrastructureStatus, nodes []*corev1.Node, workloadType string) bool { - // If status is not for CPU partitioning and we're single node we also check nodes to support upgrade event - // TODO: This should not be needed after 4.13 as all clusters after should have this feature on at install time, or updated by migration in NTO. - if infraStatus.CPUPartitioning != configv1.CPUPartitioningAllNodes && infraStatus.ControlPlaneTopology == configv1.SingleReplicaTopologyMode { - managedResource := fmt.Sprintf("%s.%s", workloadType, containerWorkloadResourceSuffix) - for _, node := range nodes { - // We only expect a single node to exist, so we return on first hit - if _, ok := node.Status.Allocatable[corev1.ResourceName(managedResource)]; ok { - return true - } - } - } +func isCPUPartitioning(infraStatus configv1.InfrastructureStatus) bool { return infraStatus.CPUPartitioning == configv1.CPUPartitioningAllNodes } diff --git a/vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go b/vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go index 9fa7770e9f..06a24fee8e 100644 --- a/vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go +++ b/vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go @@ -32,6 +32,19 @@ const ( // vpaOperatorNamespace is the namespace the VPA operator is expected to run in. vpaOperatorNamespace = "openshift-vertical-pod-autoscaler" + // croOperatorLabelKey / croOperatorLabelValue identify the CRO operator pod. + croOperatorLabelKey = "clusterresourceoverride.operator" + croOperatorLabelValue = "true" + // croOperatorNamespace is the namespace the CRO operator is expected to run in. + croOperatorNamespace = "openshift-cluster-resource-override" + + // cmaOperatorLabelKey / cmaOperatorLabelValue identify the CMA operator pod. + cmaOperatorLabelKey = "name" + cmaOperatorLabelValue = "custom-metrics-autoscaler-operator" + + // cmaOperatorNamespace is the namespace the CMA operator is expected to run in. + cmaOperatorNamespace = "openshift-keda" + // standaloneEnvVar is the environment variable checked at start-up. // It is injected by the downward API and reflects the namespace the // kube-apiserver pod runs in. @@ -93,16 +106,58 @@ func (p *nodeSelectorAdjuster) ValidateInitialization() error { // requiresNodeSelectorAdjustment returns true when the pod carries a label that // opts it in to control-plane node placement and lives in a namespace where that -// label is expected. Currently the VPA operator pod opts in via its well-known -// label. Future control-plane-adjacent Day 2 operators can be added here. +// label is expected. Control-plane-adjacent Day 2 operators can be added here. func requiresNodeSelectorAdjustment(pod *coreapi.Pod) bool { + // for VPA, we only want to update if the node selector is the default from + // https://github.com/openshift/vertical-pod-autoscaler-operator/blob/main/config/manager/manager.yaml if pod.Labels[vpaOperatorLabelKey] == vpaOperatorLabelValue && - pod.Namespace == vpaOperatorNamespace { + pod.Namespace == vpaOperatorNamespace && len(pod.Spec.NodeSelector) == 1 && + pod.Spec.NodeSelector["kubernetes.io/os"] == "linux" { return true } + // for CRO, we only want to update if the node selector empty + if pod.Labels[croOperatorLabelKey] == croOperatorLabelValue && + pod.Namespace == croOperatorNamespace && len(pod.Spec.NodeSelector) == 0 { + return true + } + // for CMA, we want to update if the node selector is empty + // and if it has a toleration that would tolerate the master NoSchedule taint + if pod.Labels[cmaOperatorLabelKey] == cmaOperatorLabelValue && + pod.Namespace == cmaOperatorNamespace && len(pod.Spec.NodeSelector) == 0 { + masterTaint := coreapi.Taint{ + Key: "node-role.kubernetes.io/master", + Effect: coreapi.TaintEffectNoSchedule, + } + for _, tol := range pod.Spec.Tolerations { + if toleratesTaint(tol, masterTaint) { + return true + } + } + } return false } +// toleratesTaint checks if a toleration tolerates a given taint, following the +// same rules as corev1.Toleration.ToleratesTaint: an empty effect matches all +// effects, the Exists operator matches any value, and an empty key with Exists +// matches all keys. +func toleratesTaint(tol coreapi.Toleration, taint coreapi.Taint) bool { + if len(tol.Effect) > 0 && tol.Effect != taint.Effect { + return false + } + if len(tol.Key) > 0 && tol.Key != taint.Key { + return false + } + switch tol.Operator { + case "", coreapi.TolerationOpEqual: + return tol.Value == taint.Value + case coreapi.TolerationOpExists: + return true + default: + return false + } +} + // addControlPlaneNodeSelector ensures spec.nodeSelector contains the control-plane role key. func addControlPlaneNodeSelector(pod *coreapi.Pod) { if pod.Spec.NodeSelector == nil { diff --git a/vendor/k8s.io/kubernetes/pkg/apis/flowcontrol/validation/validation.go b/vendor/k8s.io/kubernetes/pkg/apis/flowcontrol/validation/validation.go index 510b5e4a17..d801f0e138 100644 --- a/vendor/k8s.io/kubernetes/pkg/apis/flowcontrol/validation/validation.go +++ b/vendor/k8s.io/kubernetes/pkg/apis/flowcontrol/validation/validation.go @@ -416,7 +416,11 @@ func ValidatePriorityLevelConfigurationSpec(spec *flowcontrol.PriorityLevelConfi allErrs = append(allErrs, ValidateLimitedPriorityLevelConfiguration(spec.Limited, requestGV, fldPath.Child("limited"), opts)...) } default: - allErrs = append(allErrs, field.NotSupported(fldPath.Child("type"), spec.Type, supportedPriorityLevelEnablement.List())) + if len(spec.Type) == 0 { + allErrs = append(allErrs, field.Required(fldPath.Child("type"), "").MarkCoveredByDeclarative()) + } else { + allErrs = append(allErrs, field.NotSupported(fldPath.Child("type"), spec.Type, supportedPriorityLevelEnablement.List())) + } } return allErrs } @@ -475,7 +479,11 @@ func ValidateLimitResponse(lr flowcontrol.LimitResponse, fldPath *field.Path) fi allErrs = append(allErrs, ValidatePriorityLevelQueuingConfiguration(lr.Queuing, fldPath.Child("queuing"))...) } default: - allErrs = append(allErrs, field.NotSupported(fldPath.Child("type"), lr.Type, supportedLimitResponseType.List())) + if len(lr.Type) == 0 { + allErrs = append(allErrs, field.Required(fldPath.Child("type"), "").MarkCoveredByDeclarative()) + } else { + allErrs = append(allErrs, field.NotSupported(fldPath.Child("type"), lr.Type, supportedLimitResponseType.List())) + } } return allErrs } diff --git a/vendor/k8s.io/kubernetes/pkg/controller/job/job_controller.go b/vendor/k8s.io/kubernetes/pkg/controller/job/job_controller.go index ccf9b222c7..b7884a0800 100644 --- a/vendor/k8s.io/kubernetes/pkg/controller/job/job_controller.go +++ b/vendor/k8s.io/kubernetes/pkg/controller/job/job_controller.go @@ -1855,7 +1855,12 @@ func (jm *Controller) manageJob(ctx context.Context, job *batch.Job, jobCtx *syn } if remainingTime > 0 { jm.enqueueSyncJobWithDelay(logger, job, remainingTime) - return 0, metrics.JobSyncActionPodsCreated, nil + // No pods were created or deleted, so return the current active + // count rather than 0. Returning 0 here would cause the status + // update to set Active=0 while Ready still reflects the running + // pods, which the API server rejects ("cannot set more ready pods + // than active"), blocking finalizer removal and status flushing. + return active, metrics.JobSyncActionPodsCreated, nil } if diff > int32(MaxPodCreateDeletePerSync) { diff = int32(MaxPodCreateDeletePerSync) @@ -1868,7 +1873,9 @@ func (jm *Controller) manageJob(ctx context.Context, job *batch.Job, jobCtx *syn indexesToAdd, remainingTime = jm.getPodCreationInfoForIndependentIndexes(logger, indexesToAdd, jobCtx.podsWithDelayedDeletionPerIndex) if remainingTime > 0 { jm.enqueueSyncJobWithDelay(logger, job, remainingTime) - return 0, metrics.JobSyncActionPodsCreated, nil + // No pods were created or deleted, so return the current + // active count rather than 0 (see comment above). + return active, metrics.JobSyncActionPodsCreated, nil } } diff = int32(len(indexesToAdd)) diff --git a/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go b/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go new file mode 100644 index 0000000000..d0c66ab8de --- /dev/null +++ b/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go @@ -0,0 +1,18 @@ +package cache + +type ConflictCounter interface { + GetConflictCount() int +} + +var _ ConflictCounter = &volumeCache{} + +func (c *volumeCache) GetConflictCount() int { + c.mutex.RLock() + defer c.mutex.RUnlock() + + conflictCount := 0 + for _, conflicts := range c.conflicts { + conflictCount += len(conflicts) + } + return conflictCount +} diff --git a/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go b/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go new file mode 100644 index 0000000000..39eeb9853c --- /dev/null +++ b/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go @@ -0,0 +1,102 @@ +package selinuxwarning + +import ( + "context" + "fmt" + "time" + + metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" + utilfeature "k8s.io/apiserver/pkg/util/feature" + applyconfigurationscorev1 "k8s.io/client-go/applyconfigurations/core/v1" + clientset "k8s.io/client-go/kubernetes" + "k8s.io/klog/v2" + "k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/cache" + "k8s.io/kubernetes/pkg/features" +) + +const ( + checkInterval = 30 * time.Second + configMapNamespace = "openshift-config" + configMapName = "selinux-conflicts" + fieldManager = "selinux-conflicts-reporter" +) + +type SELinuxConflictsReporterController struct { + kubeClient clientset.Interface + conflictCounter cache.ConflictCounter + previousConflicts metav1.ConditionStatus +} + +func NewSELinuxConflictsReporterController(kubeClient clientset.Interface, volumeCache cache.VolumeCache) *SELinuxConflictsReporterController { + return &SELinuxConflictsReporterController{ + kubeClient: kubeClient, + // Ugly retype to avoid more carry patches in Kubernetes code. + // We added ConflictCounter in cache/openshift_patch.go, + // therefore we know that VolumeCache implements it. + conflictCounter: volumeCache.(cache.ConflictCounter), + previousConflicts: metav1.ConditionUnknown, + } +} + +func (c *SELinuxConflictsReporterController) Run(ctx context.Context) { + logger := klog.FromContext(ctx) + if !utilfeature.DefaultFeatureGate.Enabled(features.SELinuxMountGAReadiness) { + logger.V(2).Info("SELinuxMountGAReadiness feature gate is disabled, not starting OpenShift SELinux conflicts reporter") + return + } + logger.V(2).Info("Starting OpenShift SELinux conflicts reporter") + timer := time.NewTimer(checkInterval) + defer timer.Stop() + for { + select { + case <-ctx.Done(): + return + case <-timer.C: + c.reportSELinuxConflicts(ctx) + timer.Reset(checkInterval) + } + } +} + +func (c *SELinuxConflictsReporterController) reportSELinuxConflicts(ctx context.Context) { + logger := klog.FromContext(ctx) + logger.V(4).Info("Checking for SELinux conflicts") + + currentConflicts := c.getConflicts(logger) + if currentConflicts == c.previousConflicts { + logger.V(4).Info("SELinux conflict status did not change since last check") + return + } + logger.V(4).Info("SELinux conflict status changed, updating the config map") + if err := c.applySELinuxConflictsConfigMap(ctx, currentConflicts); err != nil { + logger.Error(err, "Error saving conflicts config map") + // To keep it simple: no exponential backoff try again in the next iteration. + return + } + logger.V(2).Info("SELinux conflict updated", "Conflicts", currentConflicts) + c.previousConflicts = currentConflicts +} + +func (c *SELinuxConflictsReporterController) getConflicts(logger klog.Logger) metav1.ConditionStatus { + conflictsCount := c.conflictCounter.GetConflictCount() + if conflictsCount > 0 { + logger.V(4).Info("Found SELinux-conflicting pods", "conflictsCount", conflictsCount) + return metav1.ConditionTrue + } + logger.V(4).Info("Found no SELinux-conflicting pods") + return metav1.ConditionFalse +} + +func (c *SELinuxConflictsReporterController) applySELinuxConflictsConfigMap(ctx context.Context, conflictsPresent metav1.ConditionStatus) error { + cm := applyconfigurationscorev1.ConfigMap(configMapName, configMapNamespace). + WithData(map[string]string{ + "conflictsPresent": string(conflictsPresent), + }).WithAnnotations(map[string]string{ + "Description": "This config map is used to report presence of SELinux conflicts from kube-controller-manager to storage Upgradeable condition in OpenShift 5.0", + }) + _, err := c.kubeClient.CoreV1().ConfigMaps(configMapNamespace).Apply(ctx, cm, metav1.ApplyOptions{FieldManager: fieldManager, Force: true}) + if err != nil { + return fmt.Errorf("error applying config map %s: %w", configMapName, err) + } + return nil +} diff --git a/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go b/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go index 53c08d1f6a..488a19161d 100644 --- a/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go +++ b/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go @@ -380,6 +380,13 @@ func (c *Controller) Run(ctx context.Context, workers int) { wait.UntilWithContext(ctx, c.runWorker, time.Second) }) } + + seLinuxConflictsReporterController := NewSELinuxConflictsReporterController(c.kubeClient, c.labelCache) + wg.Go(func() { + defer utilruntime.HandleCrash() + seLinuxConflictsReporterController.Run(ctx) + }) + <-ctx.Done() } diff --git a/vendor/k8s.io/kubernetes/pkg/features/openshift_features.go b/vendor/k8s.io/kubernetes/pkg/features/openshift_features.go index 434781ba97..b09d7fe484 100644 --- a/vendor/k8s.io/kubernetes/pkg/features/openshift_features.go +++ b/vendor/k8s.io/kubernetes/pkg/features/openshift_features.go @@ -9,6 +9,7 @@ var ( RouteExternalCertificate featuregate.Feature = "RouteExternalCertificate" MinimumKubeletVersion featuregate.Feature = "MinimumKubeletVersion" StoragePerformantSecurityPolicy featuregate.Feature = "StoragePerformantSecurityPolicy" + SELinuxMountGAReadiness featuregate.Feature = "SELinuxMountGAReadiness" ) // registerOpenshiftFeatures injects openshift-specific feature gates @@ -25,8 +26,13 @@ func registerOpenshiftFeatures() { defaultVersionedKubernetesFeatureGates[StoragePerformantSecurityPolicy] = featuregate.VersionedSpecs{ {Version: version.MustParse("1.33"), Default: false, PreRelease: featuregate.Alpha}, } + // Introduced in 5.0 + defaultVersionedKubernetesFeatureGates[SELinuxMountGAReadiness] = featuregate.VersionedSpecs{ + {Version: version.MustParse("1.35"), Default: false, PreRelease: featuregate.Alpha}, + } defaultKubernetesFeatureGateDependencies[RouteExternalCertificate] = []featuregate.Feature{} defaultKubernetesFeatureGateDependencies[MinimumKubeletVersion] = []featuregate.Feature{} defaultKubernetesFeatureGateDependencies[StoragePerformantSecurityPolicy] = []featuregate.Feature{} + defaultKubernetesFeatureGateDependencies[SELinuxMountGAReadiness] = []featuregate.Feature{} } diff --git a/vendor/k8s.io/kubernetes/pkg/kubelet/allocation/allocation_manager.go b/vendor/k8s.io/kubernetes/pkg/kubelet/allocation/allocation_manager.go index 9e8a61470c..6960ec70e2 100644 --- a/vendor/k8s.io/kubernetes/pkg/kubelet/allocation/allocation_manager.go +++ b/vendor/k8s.io/kubernetes/pkg/kubelet/allocation/allocation_manager.go @@ -110,6 +110,9 @@ type Manager interface { // RetryPendingResizes retries all pending resizes. RetryPendingResizes(trigger string) + + // HasPodAllocatedResources returns whether a pod has been allocated resources. + HasPodAllocatedResources(podUID types.UID) bool } type manager struct { @@ -483,6 +486,12 @@ func updatePodFromAllocation(pod *v1.Pod, allocated state.PodResourceInfo) (*v1. return pod, updated } +// HasPodAllocatedResources returns whether a pod has been allocated resources. +func (m *manager) HasPodAllocatedResources(podUID types.UID) bool { + _, allocated := m.allocated.GetPodResourceInfo(podUID) + return allocated +} + // SetAllocatedResources checkpoints the resources allocated to a pod's containers func (m *manager) SetAllocatedResources(pod *v1.Pod) error { // Use klog.TODO() because we currently do not have a proper logger to pass in. @@ -629,9 +638,14 @@ func (m *manager) getAllocatedPods(activePods []*v1.Pod) []*v1.Pod { return activePods } - allocatedPods := make([]*v1.Pod, len(activePods)) - for i, pod := range activePods { - allocatedPods[i], _ = m.UpdatePodFromAllocation(pod) + allocatedPods := make([]*v1.Pod, 0, len(activePods)) + for _, pod := range activePods { + // Filter out pods that don't yet have an allocation, which will filter pods that + // are potentially going to be denied at admission. + if m.HasPodAllocatedResources(pod.UID) { + allocatedPod, _ := m.UpdatePodFromAllocation(pod) + allocatedPods = append(allocatedPods, allocatedPod) + } } return allocatedPods } diff --git a/vendor/k8s.io/kubernetes/pkg/kubelet/kubelet.go b/vendor/k8s.io/kubernetes/pkg/kubelet/kubelet.go index f912a7b54b..2c773dc750 100644 --- a/vendor/k8s.io/kubernetes/pkg/kubelet/kubelet.go +++ b/vendor/k8s.io/kubernetes/pkg/kubelet/kubelet.go @@ -2931,6 +2931,15 @@ func (kl *Kubelet) HandlePodUpdates(ctx context.Context, pods []*v1.Pod) { oldPod, _ := kl.podManager.GetPodByUID(pod.UID) kl.podManager.UpdatePod(pod) + if utilfeature.DefaultFeatureGate.Enabled(features.InPlacePodVerticalScaling) { + // Skip pods that haven't been allocated yet to avoid counting them against + // node capacity before they've been admitted. + if !kl.allocationManager.HasPodAllocatedResources(pod.UID) { + logger.V(4).Info("Skipping pod update for non-allocated pod", "pod", klog.KObj(pod), "podUID", pod.UID) + continue + } + } + pod, mirrorPod, wasMirror := kl.podManager.GetPodAndMirrorPod(pod) if wasMirror { if pod == nil { @@ -3133,6 +3142,8 @@ func (kl *Kubelet) HandlePodReconcile(ctx context.Context, pods []*v1.Pod) { if utilfeature.DefaultFeatureGate.Enabled(features.InPlacePodVerticalScaling) { if hasPendingResizes && !retryPendingResizes && oldPod != nil { // If the pod has reached a terminal phase, we retry all pending resizes. + // A terminated pod releases capacity even if its allocation has already + // been purged, so check this before the non-allocated skip below. if podutil.IsPodTerminal(pod) && !podutil.IsPodTerminal(oldPod) { retryPendingResizes = true triggerReason = allocation.TriggerReasonPodTerminated @@ -3160,6 +3171,13 @@ func (kl *Kubelet) HandlePodReconcile(ctx context.Context, pods []*v1.Pod) { triggerReason = allocation.TriggerReasonPodResized } } + + // Skip further reconciliation for pods that haven't been allocated yet. + // We still updated podManager above to keep status in sync with the API server. + if !kl.allocationManager.HasPodAllocatedResources(pod.UID) { + logger.V(4).Info("Skipping pod reconcile operations for non-allocated pod", "pod", klog.KObj(pod), "podUID", pod.UID) + continue + } } // TODO: reconcile being calculated in the config manager is questionable, and avoiding diff --git a/vendor/k8s.io/kubernetes/pkg/kubelet/kuberuntime/labels.go b/vendor/k8s.io/kubernetes/pkg/kubelet/kuberuntime/labels.go index cef97ec051..0a9f783131 100644 --- a/vendor/k8s.io/kubernetes/pkg/kubelet/kuberuntime/labels.go +++ b/vendor/k8s.io/kubernetes/pkg/kubelet/kuberuntime/labels.go @@ -201,22 +201,22 @@ func getContainerInfoFromAnnotations(ctx context.Context, annotations map[string if containerInfo.RestartCount, err = getIntValueFromLabel(logger, annotations, containerRestartCountLabel); err != nil { logger.Error(err, "Unable to get label value from annotations", "label", containerRestartCountLabel, "annotations", annotations) } - if containerInfo.PodDeletionGracePeriod, err = getInt64PointerFromLabel(logger, annotations, podDeletionGracePeriodLabel); err != nil { + if containerInfo.PodDeletionGracePeriod, err = getInt64PointerFromLabel(annotations, podDeletionGracePeriodLabel); err != nil { logger.Error(err, "Unable to get label value from annotations", "label", podDeletionGracePeriodLabel, "annotations", annotations) } - if containerInfo.PodTerminationGracePeriod, err = getInt64PointerFromLabel(logger, annotations, podTerminationGracePeriodLabel); err != nil { + if containerInfo.PodTerminationGracePeriod, err = getInt64PointerFromLabel(annotations, podTerminationGracePeriodLabel); err != nil { logger.Error(err, "Unable to get label value from annotations", "label", podTerminationGracePeriodLabel, "annotations", annotations) } preStopHandler := &v1.LifecycleHandler{} - if found, err := getJSONObjectFromLabel(logger, annotations, containerPreStopHandlerLabel, preStopHandler); err != nil { + if found, err := getJSONObjectFromLabel(annotations, containerPreStopHandlerLabel, preStopHandler); err != nil { logger.Error(err, "Unable to get label value from annotations", "label", containerPreStopHandlerLabel, "annotations", annotations) } else if found { containerInfo.PreStopHandler = preStopHandler } containerPorts := []v1.ContainerPort{} - if found, err := getJSONObjectFromLabel(logger, annotations, containerPortsLabel, &containerPorts); err != nil { + if found, err := getJSONObjectFromLabel(annotations, containerPortsLabel, &containerPorts); err != nil { logger.Error(err, "Unable to get label value from annotations", "label", containerPortsLabel, "annotations", annotations) } else if found { containerInfo.ContainerPorts = containerPorts @@ -266,7 +266,7 @@ func getUint64ValueFromLabel(ctx context.Context, labels map[string]string, labe return 0, nil } -func getInt64PointerFromLabel(logger klog.Logger, labels map[string]string, label string) (*int64, error) { +func getInt64PointerFromLabel(labels map[string]string, label string) (*int64, error) { if strValue, found := labels[label]; found { int64Value, err := strconv.ParseInt(strValue, 10, 64) if err != nil { @@ -275,17 +275,15 @@ func getInt64PointerFromLabel(logger klog.Logger, labels map[string]string, labe return &int64Value, nil } // If the label is not found, return pointer nil. - logger.V(4).Info("Label not found", "label", label) return nil, nil } // getJSONObjectFromLabel returns a bool value indicating whether an object is found. -func getJSONObjectFromLabel(logger klog.Logger, labels map[string]string, label string, value interface{}) (bool, error) { +func getJSONObjectFromLabel(labels map[string]string, label string, value interface{}) (bool, error) { if strValue, found := labels[label]; found { err := json.Unmarshal([]byte(strValue), value) return found, err } // If the label is not found, return not found. - logger.V(4).Info("Label not found", "label", label) return false, nil } diff --git a/vendor/k8s.io/kubernetes/pkg/kubelet/pod_workers.go b/vendor/k8s.io/kubernetes/pkg/kubelet/pod_workers.go index 0f3034e262..a71f1fbcbd 100644 --- a/vendor/k8s.io/kubernetes/pkg/kubelet/pod_workers.go +++ b/vendor/k8s.io/kubernetes/pkg/kubelet/pod_workers.go @@ -336,6 +336,16 @@ const ( // podSyncStatus tracks per-pod transitions through the three phases of pod // worker sync (setup, terminating, terminated). type podSyncStatus struct { + // ctx is reused across normal pod syncs. + // A new ctx is created on the next startPodSync after explicit cancellation. + // + // TODO: remove this from the struct by having the context initialized + // in startPodSync, the cancelFn used by UpdatePod, and cancellation of + // a parent context for tearing down workers (if needed) on shutdown. + // Be careful not to leak contexts (see #139823). + // Be careful that long-lived goroutines (such as prober workers) outlive + // the lifetime of a single startPodSync cancellation context. + ctx context.Context // cancelFn if set is expected to cancel the current podSyncer operation. cancelFn context.CancelFunc @@ -1152,7 +1162,11 @@ func (p *podWorkers) startPodSync(parentCtx context.Context, podUID types.UID) ( default: } - ctx, status.cancelFn = context.WithCancel(parentCtx) + if status.ctx == nil || status.ctx.Err() != nil { + // create a context with parentCtx's values, and reuse it until it is canceled + status.ctx, status.cancelFn = context.WithCancel(context.WithoutCancel(parentCtx)) + } + ctx = status.ctx // if we are already started, make our state visible to downstream components if status.IsStarted() { diff --git a/vendor/k8s.io/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go b/vendor/k8s.io/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go index 994e716a28..ddcafd16ae 100644 --- a/vendor/k8s.io/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go +++ b/vendor/k8s.io/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go @@ -606,6 +606,10 @@ func buildControllerRoles() ([]rbacv1.ClusterRole, []rbacv1.ClusterRoleBinding) rbacv1helpers.NewRule("get", "list", "watch").Groups(legacyGroup).Resources("persistentvolumeclaims").RuleOrDie(), rbacv1helpers.NewRule("get", "list", "watch").Groups(legacyGroup).Resources("pods").RuleOrDie(), rbacv1helpers.NewRule("get", "list", "watch").Groups(storageGroup).Resources("csidrivers").RuleOrDie(), + // RBAC cannot restrict `create` by resourceName, so adding a generic rule to allow creation of any ConfigMap + rbacv1helpers.NewRule("create").Groups(legacyGroup).Resources("configmaps").RuleOrDie(), + // ... and allow patching only of the selinux-conflicts ConfigMap + rbacv1helpers.NewRule("patch").Groups(legacyGroup).Resources("configmaps").Names("selinux-conflicts").RuleOrDie(), }, }) } diff --git a/vendor/modules.txt b/vendor/modules.txt index 64f8b4ad66..526ec0b4a5 100644 --- a/vendor/modules.txt +++ b/vendor/modules.txt @@ -730,7 +730,7 @@ github.com/openshift/client-go/user/informers/externalversions/internalinterface github.com/openshift/client-go/user/informers/externalversions/user github.com/openshift/client-go/user/informers/externalversions/user/v1 github.com/openshift/client-go/user/listers/user/v1 -# github.com/openshift/cluster-policy-controller v0.0.0-20260721184556-01afc4aac71a +# github.com/openshift/cluster-policy-controller v0.0.0-20260811140609-469bbf211d35 ## explicit; go 1.26.0 github.com/openshift/cluster-policy-controller/pkg/client/genericinformers github.com/openshift/cluster-policy-controller/pkg/cmd/cluster-policy-controller @@ -1290,7 +1290,7 @@ gopkg.in/yaml.v2 # gopkg.in/yaml.v3 v3.0.1 ## explicit gopkg.in/yaml.v3 -# k8s.io/api v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/api +# k8s.io/api v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/api ## explicit; go 1.26.0 k8s.io/api/admission/v1 k8s.io/api/admission/v1beta1 @@ -1350,7 +1350,7 @@ k8s.io/api/storage/v1 k8s.io/api/storage/v1alpha1 k8s.io/api/storage/v1beta1 k8s.io/api/storagemigration/v1beta1 -# k8s.io/apiextensions-apiserver v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiextensions-apiserver +# k8s.io/apiextensions-apiserver v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiextensions-apiserver ## explicit; go 1.26.0 k8s.io/apiextensions-apiserver/pkg/apihelpers k8s.io/apiextensions-apiserver/pkg/apis/apiextensions @@ -1397,7 +1397,7 @@ k8s.io/apiextensions-apiserver/pkg/generated/openapi k8s.io/apiextensions-apiserver/pkg/registry/customresource k8s.io/apiextensions-apiserver/pkg/registry/customresource/tableconvertor k8s.io/apiextensions-apiserver/pkg/registry/customresourcedefinition -# k8s.io/apimachinery v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/apimachinery +# k8s.io/apimachinery v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/apimachinery ## explicit; go 1.26.0 k8s.io/apimachinery/pkg/api/equality k8s.io/apimachinery/pkg/api/errors @@ -1479,7 +1479,7 @@ k8s.io/apimachinery/pkg/watch k8s.io/apimachinery/third_party/forked/golang/json k8s.io/apimachinery/third_party/forked/golang/netutil k8s.io/apimachinery/third_party/forked/golang/reflect -# k8s.io/apiserver v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiserver +# k8s.io/apiserver v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/apiserver ## explicit; go 1.26.0 k8s.io/apiserver/pkg/admission k8s.io/apiserver/pkg/admission/configuration @@ -1687,13 +1687,13 @@ k8s.io/apiserver/plugin/pkg/authenticator/token/oidc k8s.io/apiserver/plugin/pkg/authenticator/token/webhook k8s.io/apiserver/plugin/pkg/authorizer/webhook k8s.io/apiserver/plugin/pkg/authorizer/webhook/metrics -# k8s.io/cli-runtime v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/cli-runtime +# k8s.io/cli-runtime v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/cli-runtime ## explicit; go 1.26.0 k8s.io/cli-runtime/pkg/genericclioptions k8s.io/cli-runtime/pkg/genericiooptions k8s.io/cli-runtime/pkg/printers k8s.io/cli-runtime/pkg/resource -# k8s.io/client-go v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/client-go +# k8s.io/client-go v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/client-go ## explicit; go 1.26.0 k8s.io/client-go/applyconfigurations k8s.io/client-go/applyconfigurations/admissionregistration/v1 @@ -2053,7 +2053,7 @@ k8s.io/client-go/util/keyutil k8s.io/client-go/util/retry k8s.io/client-go/util/watchlist k8s.io/client-go/util/workqueue -# k8s.io/cloud-provider v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/cloud-provider +# k8s.io/cloud-provider v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/cloud-provider ## explicit; go 1.26.0 k8s.io/cloud-provider k8s.io/cloud-provider/api @@ -2071,14 +2071,14 @@ k8s.io/cloud-provider/service/helpers k8s.io/cloud-provider/volume k8s.io/cloud-provider/volume/errors k8s.io/cloud-provider/volume/helpers -# k8s.io/cluster-bootstrap v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/cluster-bootstrap +# k8s.io/cluster-bootstrap v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/cluster-bootstrap ## explicit; go 1.26.0 k8s.io/cluster-bootstrap/token/api k8s.io/cluster-bootstrap/token/jws k8s.io/cluster-bootstrap/token/util k8s.io/cluster-bootstrap/util/secrets k8s.io/cluster-bootstrap/util/tokens -# k8s.io/component-base v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-base +# k8s.io/component-base v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-base ## explicit; go 1.26.0 k8s.io/component-base/cli k8s.io/component-base/cli/flag @@ -2118,7 +2118,7 @@ k8s.io/component-base/tracing/api/v1 k8s.io/component-base/version k8s.io/component-base/version/verflag k8s.io/component-base/zpages/features -# k8s.io/component-helpers v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-helpers +# k8s.io/component-helpers v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/component-helpers ## explicit; go 1.26.0 k8s.io/component-helpers/apimachinery/lease k8s.io/component-helpers/apps/poddisruptionbudget @@ -2139,7 +2139,7 @@ k8s.io/component-helpers/scheduling/corev1 k8s.io/component-helpers/scheduling/corev1/nodeaffinity k8s.io/component-helpers/storage/ephemeral k8s.io/component-helpers/storage/volume -# k8s.io/controller-manager v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/controller-manager +# k8s.io/controller-manager v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/controller-manager ## explicit; go 1.26.0 k8s.io/controller-manager/app k8s.io/controller-manager/config @@ -2156,12 +2156,12 @@ k8s.io/controller-manager/pkg/informerfactory k8s.io/controller-manager/pkg/leadermigration k8s.io/controller-manager/pkg/leadermigration/config k8s.io/controller-manager/pkg/leadermigration/options -# k8s.io/cri-api v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-api +# k8s.io/cri-api v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-api ## explicit; go 1.26.0 k8s.io/cri-api/pkg/apis k8s.io/cri-api/pkg/apis/runtime/v1 k8s.io/cri-api/pkg/errors -# k8s.io/cri-client v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-client +# k8s.io/cri-client v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/cri-client ## explicit; go 1.26.0 k8s.io/cri-client/pkg k8s.io/cri-client/pkg/logs @@ -2172,11 +2172,11 @@ k8s.io/cri-streaming/pkg/streaming k8s.io/cri-streaming/pkg/streaming/internal/httpresponse k8s.io/cri-streaming/pkg/streaming/portforward k8s.io/cri-streaming/pkg/streaming/remotecommand -# k8s.io/csi-translation-lib v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/csi-translation-lib +# k8s.io/csi-translation-lib v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/csi-translation-lib ## explicit; go 1.26.0 k8s.io/csi-translation-lib k8s.io/csi-translation-lib/plugins -# k8s.io/dynamic-resource-allocation v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation +# k8s.io/dynamic-resource-allocation v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/dynamic-resource-allocation ## explicit; go 1.26.0 k8s.io/dynamic-resource-allocation/api k8s.io/dynamic-resource-allocation/cel @@ -2189,14 +2189,14 @@ k8s.io/dynamic-resource-allocation/structured/internal/experimental k8s.io/dynamic-resource-allocation/structured/internal/incubating k8s.io/dynamic-resource-allocation/structured/internal/stable k8s.io/dynamic-resource-allocation/structured/schedulerapi -# k8s.io/endpointslice v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/endpointslice +# k8s.io/endpointslice v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/endpointslice ## explicit; go 1.26.0 k8s.io/endpointslice k8s.io/endpointslice/metrics k8s.io/endpointslice/topologycache k8s.io/endpointslice/trafficdist k8s.io/endpointslice/util -# k8s.io/externaljwt v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/externaljwt +# k8s.io/externaljwt v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/externaljwt ## explicit; go 1.26.0 k8s.io/externaljwt/apis/v1 # k8s.io/gengo/v2 v2.0.0-20250922181213-ec3ebc5fd46b @@ -2218,13 +2218,13 @@ k8s.io/klog/v2/internal/severity k8s.io/klog/v2/internal/sloghandler k8s.io/klog/v2/internal/verbosity k8s.io/klog/v2/textlogger -# k8s.io/kms v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/kms +# k8s.io/kms v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/kms ## explicit; go 1.26.0 k8s.io/kms/apis/v1beta1 k8s.io/kms/apis/v2 k8s.io/kms/pkg/service k8s.io/kms/pkg/util -# k8s.io/kube-aggregator v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-aggregator +# k8s.io/kube-aggregator v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-aggregator ## explicit; go 1.26.0 k8s.io/kube-aggregator/pkg/apis/apiregistration k8s.io/kube-aggregator/pkg/apis/apiregistration/install @@ -2260,7 +2260,7 @@ k8s.io/kube-aggregator/pkg/controllers/status/remote k8s.io/kube-aggregator/pkg/registry/apiservice k8s.io/kube-aggregator/pkg/registry/apiservice/etcd k8s.io/kube-aggregator/pkg/registry/apiservice/rest -# k8s.io/kube-controller-manager v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-controller-manager +# k8s.io/kube-controller-manager v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-controller-manager ## explicit; go 1.26.0 k8s.io/kube-controller-manager/config/v1alpha1 # k8s.io/kube-openapi v0.0.0-20260618221249-bc653b64f974 @@ -2299,15 +2299,15 @@ k8s.io/kube-openapi/pkg/validation/spec k8s.io/kube-openapi/pkg/validation/strfmt k8s.io/kube-openapi/pkg/validation/strfmt/bson k8s.io/kube-openapi/pkg/validation/validate -# k8s.io/kube-proxy v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-proxy +# k8s.io/kube-proxy v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-proxy ## explicit; go 1.26.0 k8s.io/kube-proxy/config/v1alpha1 -# k8s.io/kube-scheduler v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-scheduler +# k8s.io/kube-scheduler v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/kube-scheduler ## explicit; go 1.26.0 k8s.io/kube-scheduler/config/v1 k8s.io/kube-scheduler/extender/v1 k8s.io/kube-scheduler/framework -# k8s.io/kubectl v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubectl +# k8s.io/kubectl v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubectl ## explicit; go 1.26.0 k8s.io/kubectl/pkg/apps k8s.io/kubectl/pkg/cmd/apiresources @@ -2344,7 +2344,7 @@ k8s.io/kubectl/pkg/util/storage k8s.io/kubectl/pkg/util/templates k8s.io/kubectl/pkg/util/term k8s.io/kubectl/pkg/validation -# k8s.io/kubelet v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubelet +# k8s.io/kubelet v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/kubelet ## explicit; go 1.26.0 k8s.io/kubelet/config/v1 k8s.io/kubelet/config/v1alpha1 @@ -2365,7 +2365,7 @@ k8s.io/kubelet/pkg/apis/podresources/v1alpha1 k8s.io/kubelet/pkg/apis/pods/v1alpha1 k8s.io/kubelet/pkg/apis/stats/v1alpha1 k8s.io/kubelet/pkg/types -# k8s.io/kubernetes v1.36.2 => ./deps/github.com/openshift/kubernetes +# k8s.io/kubernetes v1.36.3 => ./deps/github.com/openshift/kubernetes ## explicit; go 1.26.0 k8s.io/kubernetes/cmd/kube-apiserver/app k8s.io/kubernetes/cmd/kube-apiserver/app/options @@ -3229,7 +3229,7 @@ k8s.io/kubernetes/third_party/forked/gonum/graph/simple k8s.io/kubernetes/third_party/forked/gonum/graph/traverse k8s.io/kubernetes/third_party/forked/libcontainer/apparmor k8s.io/kubernetes/third_party/forked/libcontainer/utils -# k8s.io/metrics v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/metrics +# k8s.io/metrics v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/metrics ## explicit; go 1.26.0 k8s.io/metrics/pkg/apis/custom_metrics k8s.io/metrics/pkg/apis/custom_metrics/v1beta1 @@ -3244,10 +3244,10 @@ k8s.io/metrics/pkg/client/clientset/versioned/typed/metrics/v1beta1 k8s.io/metrics/pkg/client/custom_metrics k8s.io/metrics/pkg/client/custom_metrics/scheme k8s.io/metrics/pkg/client/external_metrics -# k8s.io/mount-utils v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/mount-utils +# k8s.io/mount-utils v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/mount-utils ## explicit; go 1.26.0 k8s.io/mount-utils -# k8s.io/pod-security-admission v1.36.2 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/pod-security-admission +# k8s.io/pod-security-admission v1.36.3 => ./deps/github.com/openshift/kubernetes/staging/src/k8s.io/pod-security-admission ## explicit; go 1.26.0 k8s.io/pod-security-admission/admission k8s.io/pod-security-admission/admission/api