Skip to content

NO-ISSUE: Synchronize From Upstream Repositories - #701

Merged
openshift-merge-bot[bot] merged 102 commits into
openshift:mainfrom
openshift-bot:synchronize-upstream
Apr 22, 2026
Merged

NO-ISSUE: Synchronize From Upstream Repositories#701
openshift-merge-bot[bot] merged 102 commits into
openshift:mainfrom
openshift-bot:synchronize-upstream

Conversation

@openshift-bot

@openshift-botopenshift-bot commented Apr 17, 2026

Copy link
Copy Markdown

The downstream repository has been updated with the following following upstream commits:

DateCommitAuthorMessage
2026-04-21 15:24:41operator-framework/operator-controller@f5e93c1dependabot[bot]🌱 Bump github.com/google/go-containerregistry (#2666)
2026-04-20 17:44:29operator-framework/operator-controller@baae0a6dependabot[bot]🌱 Bump click from 8.3.1 to 8.3.2 (#2665)
2026-04-20 17:41:45operator-framework/operator-controller@7d7ea81dependabot[bot]🌱 Bump regex from 2026.3.32 to 2026.4.4 (#2664)
2026-04-20 17:39:01operator-framework/operator-controller@91ea0eedependabot[bot]🌱 Bump marocchino/sticky-pull-request-comment (#2663)
2026-04-20 17:30:24operator-framework/operator-controller@e45ca46Joe Lanford🐛 e2e: skip clusterobjectset cleanup when BoxcutterRuntime is disabled (#2662)
2026-04-18 02:27:14operator-framework/operator-controller@52bf60fdependabot[bot]🌱 Bump github.com/go-git/go-git/v5 from 5.17.1 to 5.18.0 (#2661)
2026-04-17 20:23:52operator-framework/operator-controller@2b2669fdependabot[bot]🌱 Bump dorny/paths-filter from 4 to 4.0.1 (#2660)
2026-04-17 20:18:22operator-framework/operator-controller@58375a9dependabot[bot]🌱 Bump go.podman.io/image/v5 from 5.39.1 to 5.39.2 (#2659)
2026-04-17 20:12:53operator-framework/operator-controller@665f701dependabot[bot]🌱 Bump marocchino/sticky-pull-request-comment from 3 to 3.0.2 (#2658)
2026-04-17 11:38:46operator-framework/operator-controller@e20da75Todd Shorttest: add TLS profile unit and e2e tests (#2653)
2026-04-17 06:59:15operator-framework/operator-controller@3fa2e34dependabot[bot]Bump github.com/moby/spdystream in /hack/tools/test-profiling (#2657)
2026-04-16 18:59:04operator-framework/operator-controller@09f3c55dependabot[bot]🌱 Bump charset-normalizer from 3.4.6 to 3.4.7 (#2656)

The vendor/ directory has been updated and the following commits were carried:

DateCommitAuthorMessage
2026-04-16 00:09:10openshift/operator-framework-operator-controller@af81adedtfranzUPSTREAM: <carry>: Add OpenShift specific files
2026-04-16 00:09:12openshift/operator-framework-operator-controller@fcc703aCamila MacedoUPSTREAM: <carry>: Add new tests for single/own namespaces install modes
2026-04-16 00:09:12openshift/operator-framework-operator-controller@cbd4e95Camila MacedoUPSTREAM: <carry>: Upgrade OCP image from 4.20 to 4.21
2026-04-16 00:09:13openshift/operator-framework-operator-controller@18e745aCamila MacedoUPSTREAM: <carry>: [Default Catalog Tests] - Change logic to get ocp images from openshift/catalogd/manifests.yaml
2026-04-16 00:09:14openshift/operator-framework-operator-controller@a8f11a8Todd ShortUPSTREAM: <carry>: Update OCP catalogs to v4.21
2026-04-16 00:09:15openshift/operator-framework-operator-controller@9fa43d7Kui WangUPSTREAM: <carry>: support singleown cases in disconnected
2026-04-16 00:09:16openshift/operator-framework-operator-controller@715d9efKui WangUPSTREAM: <carry>: fix cases 81696 and 74618 for product code changes
2026-04-16 00:09:16openshift/operator-framework-operator-controller@93118e1Camila MacedoUPSTREAM: <carry>: Define Default timeouts and apply their usage accross to avoid flakes
2026-04-16 00:09:17openshift/operator-framework-operator-controller@db1bc13Todd ShortUPSTREAM: <carry>: Update to new feature-gate options in helm
2026-04-16 00:09:18openshift/operator-framework-operator-controller@c9d0247Camila MacedoUPSTREAM: <carry>: Fix flake for single/own ns tests by ensuring uniquess and waiting for k8s cleanups
2026-04-16 00:09:18openshift/operator-framework-operator-controller@0f74b66Camila MacedoUPSTREAM: <carry>: [OTE]: Enhance single/own ns based on review comments ( Follow-Up of: 714977c )
2026-04-16 00:09:19openshift/operator-framework-operator-controller@9d0d6dcKui WangUPSTREAM: <carry>: Update OwnSingle template to use spec.config.inline.watchNamespace
2026-04-16 00:09:20openshift/operator-framework-operator-controller@3fb6ecbCamila MacedoUPSTREAM: <carry>: [OTE]: Add webhook cleanup validation on extension uninstall
2026-04-16 00:09:21openshift/operator-framework-operator-controller@8499f9dKui WangUPSTREAM: <carry>: Add [OTP] to migrated cases
2026-04-16 00:09:22openshift/operator-framework-operator-controller@75a1b47Camila MacedoUPSTREAM: <carry>: [OTE]: Upgrade dependencies used
2026-04-16 00:09:24openshift/operator-framework-operator-controller@205a420Camila MacedoUPSTREAM: <carry>: fix(OTE): fix OpenShift Kubernetes replace version format
2026-04-16 00:09:25openshift/operator-framework-operator-controller@8e398ebCamila MacedoUPSTREAM: <carry>: [Default Catalog Tests] Upgrade go 1.24.6 and dependencies
2026-04-16 00:09:26openshift/operator-framework-operator-controller@e43064dKui WangUPSTREAM: <carry>: add disconnected environment support with custom prow job for migrated qe cases
2026-04-16 00:09:27openshift/operator-framework-operator-controller@5fe86aeJian ZhangUPSTREAM: <carry>: migrate jiazha test cases to OTE
2026-04-16 00:09:28openshift/operator-framework-operator-controller@9720262Xia ZhaoUPSTREAM: <carry>: migrate clustercatalog case to ote
2026-04-16 00:09:28openshift/operator-framework-operator-controller@32512feKui WangUPSTREAM: <carry>: migrate olmv1 QE stress cases
2026-04-16 00:09:29openshift/operator-framework-operator-controller@2b404caTodd ShortUPSTREAM: <carry>: Use busybox/httpd to simulate probes
2026-04-16 00:09:30openshift/operator-framework-operator-controller@8159148Xia ZhaoUPSTREAM: <carry>: migrate olmv1 QE cases
2026-04-16 00:09:31openshift/operator-framework-operator-controller@3f3d37eKui WangUPSTREAM: <carry>: add agent for olmv1 qe cases
2026-04-16 00:09:31openshift/operator-framework-operator-controller@05fecaaTodd ShortUPSTREAM: <carry>: Disable upstream PodDisruptionBudget
2026-04-16 00:09:32openshift/operator-framework-operator-controller@5f322c1Rashmi GottipatiUPSTREAM: <carry>: Add AGENTS.md for AI code contributions
2026-04-16 00:09:33openshift/operator-framework-operator-controller@f152d9fRashmi GottipatiUPSTREAM: <carry>: address review comments through addl prompts
2026-04-16 00:09:33openshift/operator-framework-operator-controller@e9912e3Rashmi GottipatiUPSTREAM: <carry>: addressing some more review comments
2026-04-16 00:09:34openshift/operator-framework-operator-controller@7a2d275Rashmi GottipatiUPSTREAM: <carry>: remove DCO line
2026-04-16 00:09:34openshift/operator-framework-operator-controller@2396b35Bruno AndradeUPSTREAM: <carry>: migrate bandrade test cases to OTE
2026-04-16 00:09:35openshift/operator-framework-operator-controller@9c3a382Bruno AndradeUPSTREAM: <carry>: update metadata
2026-04-16 00:09:36openshift/operator-framework-operator-controller@4a2f583Bruno AndradeUPSTREAM: <carry>: remove originalName
2026-04-16 00:09:36openshift/operator-framework-operator-controller@39de536Jian ZhangUPSTREAM: <carry>: update 80458's timeout to 180s
2026-04-16 00:09:37openshift/operator-framework-operator-controller@767fd8aJian ZhangUPSTREAM: <carry>: update 83026 to specify the clustercatalog
2026-04-16 00:09:38openshift/operator-framework-operator-controller@7344267Catherine Chan-TseUPSTREAM: <carry>: Update to golang 1.25 and ocp 4.22
2026-04-16 00:09:38openshift/operator-framework-operator-controller@bd71ebbPredrag KnezevicUPSTREAM: <carry>: Use oc client for running e2e tests
2026-04-16 00:09:39openshift/operator-framework-operator-controller@8a9f87cPredrag KnezevicUPSTREAM: <carry>: Run upstream e2e tests tagged with @catalogd-update
2026-04-16 00:09:39openshift/operator-framework-operator-controller@2ccb91cKui WangUPSTREAM: <carry>: enhance case to make it more stable
2026-04-16 00:09:40openshift/operator-framework-operator-controller@10f8df0Evan HearneUPSTREAM: <carry>: add service account to curl job
2026-04-16 00:09:41openshift/operator-framework-operator-controller@214b37cEvan HearneUPSTREAM: <carry>: move sa creation out of buildCurlJob()
2026-04-16 00:09:41openshift/operator-framework-operator-controller@862368cEvan HearneUPSTREAM: <carry>: comment out delete service account
2026-04-16 00:09:42openshift/operator-framework-operator-controller@c065d19Evan HearneUPSTREAM: <carry>: move defercleanup for sa for LIFO
2026-04-16 00:09:43openshift/operator-framework-operator-controller@2334992Evan HearneUPSTREAM: <carry>: add polling so job fully deleted before proceed
2026-04-16 00:09:43openshift/operator-framework-operator-controller@287f844Luke MeyerUPSTREAM: <carry>: Revert "Merge pull request #594 from ehearne-redhat/add-service-account-curl-job"
2026-04-16 00:09:44openshift/operator-framework-operator-controller@f4fc074Camila MacedoUPSTREAM: <carry>: Remove openshift-redhat-marketplace catalog tests
2026-04-16 00:09:44openshift/operator-framework-operator-controller@368696cKui WangUPSTREAM: <carry>: config watchnamespace cases
2026-04-16 00:09:45openshift/operator-framework-operator-controller@5e1870eXia ZhaoUPSTREAM: <carry>: enhance ocp-79770
2026-04-16 00:09:46openshift/operator-framework-operator-controller@2a73224Kui WangUPSTREAM: <carry>: upgrade version support case
2026-04-16 00:09:46openshift/operator-framework-operator-controller@0c608caPer Goncalves da SilvaUPSTREAM: <carry>: Remove installed condition check from auth preflight test
2026-04-16 00:09:47openshift/operator-framework-operator-controller@f4a2f5aPer Goncalves da SilvaUPSTREAM: <carry>: Add openshift/api dependency
2026-04-16 00:09:48openshift/operator-framework-operator-controller@f375992Per Goncalves da SilvaUPSTREAM: <carry>: Add boxcutter specific preflight auth test
2026-04-16 00:09:48openshift/operator-framework-operator-controller@c02c49bKui WangUPSTREAM: <carry>: adjust watchnamespace case based on change
2026-04-16 00:09:49openshift/operator-framework-operator-controller@78f1eedCamila MacedoUPSTREAM: <carry>: fix(ote): Use as operator-controller dep from root dir
2026-04-16 00:09:50openshift/operator-framework-operator-controller@4016642Bruno AndradeUPSTREAM: <carry>: add 83979 automation
2026-04-16 00:09:51openshift/operator-framework-operator-controller@48245bdBruno AndradeUPSTREAM: <carry>: add 85889 automation
2026-04-16 00:09:51openshift/operator-framework-operator-controller@5f84555Per Goncalves da SilvaUPSTREAM: <carry>: Update test-operator startup script to fix pod probe endpoints
2026-04-16 00:09:52openshift/operator-framework-operator-controller@98d5345Per Goncalves da SilvaUPSTREAM: <carry>: Fix up own-namespace invalid configuration test
2026-04-16 00:09:52openshift/operator-framework-operator-controller@25b7369Camila MacedoUPSTREAM: <carry>: Preflight tests use in-cluster catalog and bundles instead of openshift-pipelines-operator-rh
2026-04-16 00:09:53openshift/operator-framework-operator-controller@f8d3f4dKui WangUPSTREAM: <carry>: adjust sa and permission test cases per new change from boxcutterruntime
2026-04-16 00:09:54openshift/operator-framework-operator-controller@7534032Camila MacedoUPSTREAM: <carry>: Update OCP catalogs to v4.22
2026-04-16 00:09:55openshift/operator-framework-operator-controller@5bfe0c0Camila MacedoUPSTREAM: <carry>: chore(OTE and Default Catalog Tests) Update go and dependencies
2026-04-16 00:09:56openshift/operator-framework-operator-controller@51876f7Jian ZhangUPSTREAM: <carry>: fix 83026 for TP cluster
2026-04-16 00:09:57openshift/operator-framework-operator-controller@5bf74afKui WangUPSTREAM: <carry>: serviceAccount validation unified across all runtimes
2026-04-16 00:09:57openshift/operator-framework-operator-controller@ba1d766Stephen BenjaminUPSTREAM: <carry>: Fix OLMv1 test operator to listen on IPv6
2026-04-16 00:09:58openshift/operator-framework-operator-controller@670127bCamila MacedoUPSTREAM: <carry>: Increase install timeout and add diagnostic logging for CE install tests
2026-04-16 00:09:59openshift/operator-framework-operator-controller@4c140a5Evan HearneUPSTREAM: <carry>: add service account to curl job
2026-04-16 00:09:59openshift/operator-framework-operator-controller@124c5f8Jian ZhangUPSTREAM: <carry>: update OCP-75441 to support multi-arch
2026-04-16 00:10:00openshift/operator-framework-operator-controller@c2cfab0Kui WangUPSTREAM: <carry>: deployment config cases
2026-04-16 00:10:01openshift/operator-framework-operator-controller@713dc0bTodd ShortUPSTREAM: <carry>: Add OTE tests for OLMv1 DeploymentConfig support
2026-04-16 00:10:01openshift/operator-framework-operator-controller@2583a49Todd ShortUPSTREAM: <carry>: Update openshift/api and client-go
2026-04-16 00:10:02openshift/operator-framework-operator-controller@65172cdCamila MacedoUPSTREAM: <carry>: Add boxcutter tests
2026-04-16 00:10:03openshift/operator-framework-operator-controller@397318fXia ZhaoUPSTREAM: <carry>: enhance QE cases
2026-04-16 00:10:03openshift/operator-framework-operator-controller@e855dc2Daniel FranzUPSTREAM: <carry>: Update quay-operator version to one containing arm64 support
2026-04-16 00:10:04openshift/operator-framework-operator-controller@60602a9Kui WangUPSTREAM: <carry>: verify volume/volumeMount override
2026-04-16 00:10:04openshift/operator-framework-operator-controller@9e9e5b8Jian ZhangUPSTREAM: <carry>: Add long-duration test script and documents
2026-04-16 00:10:05openshift/operator-framework-operator-controller@e72f900Todd ShortUPSTREAM: <carry>: Update grpc in default-catalog-consistency tests
2026-04-16 00:10:06openshift/operator-framework-operator-controller@47661f7Camila MacedoUPSTREAM: <carry>: Rename ClusterExtensionRevision to ClusterObjectSet in OTE tests
2026-04-16 00:10:06openshift/operator-framework-operator-controller@4558a79Camila MacedoUPSTREAM: <carry>: Skip incompatible operator test when Boxcutter uses ClusterObjectSet
2026-04-16 00:10:07openshift/operator-framework-operator-controller@a404e66Bruno AndradeUPSTREAM: <carry>: add ocp-87557
2026-04-16 00:10:07openshift/operator-framework-operator-controller@fb35af9Francesco GiudiciUPSTREAM: <carry>: Add fgiudici as reviewer
2026-04-16 00:10:08openshift/operator-framework-operator-controller@da1694eCamila MacedoUPSTREAM: <carry>: Remove skip for incompatible operator check after rename of CER
2026-04-16 00:10:09openshift/operator-framework-operator-controller@ab83a4bKui WangUPSTREAM: <carry>: Test empty affinity erasure and cleanup
2026-04-16 00:10:09openshift/operator-framework-operator-controller@3585edcCamila MacedoUPSTREAM: <carry>: Fix boxcutter finalizer ResourceNames in preflight test
2026-04-15 16:03:07openshift/operator-framework-operator-controller@1540e2eCamila MacedoUPSTREAM: <carry>: Expand OTE docs with more comprehensive details
2026-04-20 09:57:03openshift/operator-framework-operator-controller@79cfc14Todd ShortUPSTREAM: <carry>: Disable upstream TLSProfile tests
2026-04-20 18:19:32openshift/operator-framework-operator-controller@3903654Camila MacedoUPSTREAM: <carry>: OTE: Simplify by remove option to configure tests to run outside of OCP

This pull request is expected to merge without any human intervention. If tests are failing here, changes must land upstream to fix any issues so that future downstreaming efforts succeed.

/cc @openshift/openshift-team-operator-framework

Bumps [charset-normalizer](https://github.com/jawah/charset_normalizer) from 3.4.6 to 3.4.7.
- [Release notes](https://github.com/jawah/charset_normalizer/releases)
- [Changelog](https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md)
- [Commits](jawah/charset_normalizer@3.4.6...3.4.7)
---
updated-dependencies:
- dependency-name: charset-normalizer
dependency-version: 3.4.7
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@openshift-botopenshift-bot added tide/merge-method-merge Denotes a PR that should use a standard merge by tide when it merges. kind/sync approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged. labels Apr 17, 2026
@openshift-ci-robotopenshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Apr 17, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@openshift-bot: This pull request explicitly references no jira issue.

Details

In response to this:

The downstream repository has been updated with the following following upstream commits:

DateCommitAuthorMessage
2026-04-16 18:59:04operator-framework/operator-controller@09f3c55dependabot[bot]🌱 Bump charset-normalizer from 3.4.6 to 3.4.7 (#2656)

The vendor/ directory has been updated and the following commits were carried:

DateCommitAuthorMessage
2026-04-16 00:09:10openshift/operator-framework-operator-controller@af81adedtfranzUPSTREAM: <carry>: Add OpenShift specific files
2026-04-16 00:09:12openshift/operator-framework-operator-controller@fcc703aCamila MacedoUPSTREAM: <carry>: Add new tests for single/own namespaces install modes
2026-04-16 00:09:12openshift/operator-framework-operator-controller@cbd4e95Camila MacedoUPSTREAM: <carry>: Upgrade OCP image from 4.20 to 4.21
2026-04-16 00:09:13openshift/operator-framework-operator-controller@18e745aCamila MacedoUPSTREAM: <carry>: [Default Catalog Tests] - Change logic to get ocp images from openshift/catalogd/manifests.yaml
2026-04-16 00:09:14openshift/operator-framework-operator-controller@a8f11a8Todd ShortUPSTREAM: <carry>: Update OCP catalogs to v4.21
2026-04-16 00:09:15openshift/operator-framework-operator-controller@9fa43d7Kui WangUPSTREAM: <carry>: support singleown cases in disconnected
2026-04-16 00:09:16openshift/operator-framework-operator-controller@715d9efKui WangUPSTREAM: <carry>: fix cases 81696 and 74618 for product code changes
2026-04-16 00:09:16openshift/operator-framework-operator-controller@93118e1Camila MacedoUPSTREAM: <carry>: Define Default timeouts and apply their usage accross to avoid flakes
2026-04-16 00:09:17openshift/operator-framework-operator-controller@db1bc13Todd ShortUPSTREAM: <carry>: Update to new feature-gate options in helm
2026-04-16 00:09:18openshift/operator-framework-operator-controller@c9d0247Camila MacedoUPSTREAM: <carry>: Fix flake for single/own ns tests by ensuring uniquess and waiting for k8s cleanups
2026-04-16 00:09:18openshift/operator-framework-operator-controller@0f74b66Camila MacedoUPSTREAM: <carry>: [OTE]: Enhance single/own ns based on review comments ( Follow-Up of: 714977c )
2026-04-16 00:09:19openshift/operator-framework-operator-controller@9d0d6dcKui WangUPSTREAM: <carry>: Update OwnSingle template to use spec.config.inline.watchNamespace
2026-04-16 00:09:20openshift/operator-framework-operator-controller@3fb6ecbCamila MacedoUPSTREAM: <carry>: [OTE]: Add webhook cleanup validation on extension uninstall
2026-04-16 00:09:21openshift/operator-framework-operator-controller@8499f9dKui WangUPSTREAM: <carry>: Add [OTP] to migrated cases
2026-04-16 00:09:22openshift/operator-framework-operator-controller@75a1b47Camila MacedoUPSTREAM: <carry>: [OTE]: Upgrade dependencies used
2026-04-16 00:09:24openshift/operator-framework-operator-controller@205a420Camila MacedoUPSTREAM: <carry>: fix(OTE): fix OpenShift Kubernetes replace version format
2026-04-16 00:09:25openshift/operator-framework-operator-controller@8e398ebCamila MacedoUPSTREAM: <carry>: [Default Catalog Tests] Upgrade go 1.24.6 and dependencies
2026-04-16 00:09:26openshift/operator-framework-operator-controller@e43064dKui WangUPSTREAM: <carry>: add disconnected environment support with custom prow job for migrated qe cases
2026-04-16 00:09:27openshift/operator-framework-operator-controller@5fe86aeJian ZhangUPSTREAM: <carry>: migrate jiazha test cases to OTE
2026-04-16 00:09:28openshift/operator-framework-operator-controller@9720262Xia ZhaoUPSTREAM: <carry>: migrate clustercatalog case to ote
2026-04-16 00:09:28openshift/operator-framework-operator-controller@32512feKui WangUPSTREAM: <carry>: migrate olmv1 QE stress cases
2026-04-16 00:09:29openshift/operator-framework-operator-controller@2b404caTodd ShortUPSTREAM: <carry>: Use busybox/httpd to simulate probes
2026-04-16 00:09:30openshift/operator-framework-operator-controller@8159148Xia ZhaoUPSTREAM: <carry>: migrate olmv1 QE cases
2026-04-16 00:09:31openshift/operator-framework-operator-controller@3f3d37eKui WangUPSTREAM: <carry>: add agent for olmv1 qe cases
2026-04-16 00:09:31openshift/operator-framework-operator-controller@05fecaaTodd ShortUPSTREAM: <carry>: Disable upstream PodDisruptionBudget
2026-04-16 00:09:32openshift/operator-framework-operator-controller@5f322c1Rashmi GottipatiUPSTREAM: <carry>: Add AGENTS.md for AI code contributions
2026-04-16 00:09:33openshift/operator-framework-operator-controller@f152d9fRashmi GottipatiUPSTREAM: <carry>: address review comments through addl prompts
2026-04-16 00:09:33openshift/operator-framework-operator-controller@e9912e3Rashmi GottipatiUPSTREAM: <carry>: addressing some more review comments
2026-04-16 00:09:34openshift/operator-framework-operator-controller@7a2d275Rashmi GottipatiUPSTREAM: <carry>: remove DCO line
2026-04-16 00:09:34openshift/operator-framework-operator-controller@2396b35Bruno AndradeUPSTREAM: <carry>: migrate bandrade test cases to OTE
2026-04-16 00:09:35openshift/operator-framework-operator-controller@9c3a382Bruno AndradeUPSTREAM: <carry>: update metadata
2026-04-16 00:09:36openshift/operator-framework-operator-controller@4a2f583Bruno AndradeUPSTREAM: <carry>: remove originalName
2026-04-16 00:09:36openshift/operator-framework-operator-controller@39de536Jian ZhangUPSTREAM: <carry>: update 80458's timeout to 180s
2026-04-16 00:09:37openshift/operator-framework-operator-controller@767fd8aJian ZhangUPSTREAM: <carry>: update 83026 to specify the clustercatalog
2026-04-16 00:09:38openshift/operator-framework-operator-controller@7344267Catherine Chan-TseUPSTREAM: <carry>: Update to golang 1.25 and ocp 4.22
2026-04-16 00:09:38openshift/operator-framework-operator-controller@bd71ebbPredrag KnezevicUPSTREAM: <carry>: Use oc client for running e2e tests
2026-04-16 00:09:39openshift/operator-framework-operator-controller@8a9f87cPredrag KnezevicUPSTREAM: <carry>: Run upstream e2e tests tagged with @catalogd-update
2026-04-16 00:09:39openshift/operator-framework-operator-controller@2ccb91cKui WangUPSTREAM: <carry>: enhance case to make it more stable
2026-04-16 00:09:40openshift/operator-framework-operator-controller@10f8df0Evan HearneUPSTREAM: <carry>: add service account to curl job
2026-04-16 00:09:41openshift/operator-framework-operator-controller@214b37cEvan HearneUPSTREAM: <carry>: move sa creation out of buildCurlJob()
2026-04-16 00:09:41openshift/operator-framework-operator-controller@862368cEvan HearneUPSTREAM: <carry>: comment out delete service account
2026-04-16 00:09:42openshift/operator-framework-operator-controller@c065d19Evan HearneUPSTREAM: <carry>: move defercleanup for sa for LIFO
2026-04-16 00:09:43openshift/operator-framework-operator-controller@2334992Evan HearneUPSTREAM: <carry>: add polling so job fully deleted before proceed
2026-04-16 00:09:43openshift/operator-framework-operator-controller@287f844Luke MeyerUPSTREAM: <carry>: Revert "Merge pull request #594 from ehearne-redhat/add-service-account-curl-job"
2026-04-16 00:09:44openshift/operator-framework-operator-controller@f4fc074Camila MacedoUPSTREAM: <carry>: Remove openshift-redhat-marketplace catalog tests
2026-04-16 00:09:44openshift/operator-framework-operator-controller@368696cKui WangUPSTREAM: <carry>: config watchnamespace cases
2026-04-16 00:09:45openshift/operator-framework-operator-controller@5e1870eXia ZhaoUPSTREAM: <carry>: enhance ocp-79770
2026-04-16 00:09:46openshift/operator-framework-operator-controller@2a73224Kui WangUPSTREAM: <carry>: upgrade version support case
2026-04-16 00:09:46openshift/operator-framework-operator-controller@0c608caPer Goncalves da SilvaUPSTREAM: <carry>: Remove installed condition check from auth preflight test
2026-04-16 00:09:47openshift/operator-framework-operator-controller@f4a2f5aPer Goncalves da SilvaUPSTREAM: <carry>: Add openshift/api dependency
2026-04-16 00:09:48openshift/operator-framework-operator-controller@f375992Per Goncalves da SilvaUPSTREAM: <carry>: Add boxcutter specific preflight auth test
2026-04-16 00:09:48openshift/operator-framework-operator-controller@c02c49bKui WangUPSTREAM: <carry>: adjust watchnamespace case based on change
2026-04-16 00:09:49openshift/operator-framework-operator-controller@78f1eedCamila MacedoUPSTREAM: <carry>: fix(ote): Use as operator-controller dep from root dir
2026-04-16 00:09:50openshift/operator-framework-operator-controller@4016642Bruno AndradeUPSTREAM: <carry>: add 83979 automation
2026-04-16 00:09:51openshift/operator-framework-operator-controller@48245bdBruno AndradeUPSTREAM: <carry>: add 85889 automation
2026-04-16 00:09:51openshift/operator-framework-operator-controller@5f84555Per Goncalves da SilvaUPSTREAM: <carry>: Update test-operator startup script to fix pod probe endpoints
2026-04-16 00:09:52openshift/operator-framework-operator-controller@98d5345Per Goncalves da SilvaUPSTREAM: <carry>: Fix up own-namespace invalid configuration test
2026-04-16 00:09:52openshift/operator-framework-operator-controller@25b7369Camila MacedoUPSTREAM: <carry>: Preflight tests use in-cluster catalog and bundles instead of openshift-pipelines-operator-rh
2026-04-16 00:09:53openshift/operator-framework-operator-controller@f8d3f4dKui WangUPSTREAM: <carry>: adjust sa and permission test cases per new change from boxcutterruntime
2026-04-16 00:09:54openshift/operator-framework-operator-controller@7534032Camila MacedoUPSTREAM: <carry>: Update OCP catalogs to v4.22
2026-04-16 00:09:55openshift/operator-framework-operator-controller@5bfe0c0Camila MacedoUPSTREAM: <carry>: chore(OTE and Default Catalog Tests) Update go and dependencies
2026-04-16 00:09:56openshift/operator-framework-operator-controller@51876f7Jian ZhangUPSTREAM: <carry>: fix 83026 for TP cluster
2026-04-16 00:09:57openshift/operator-framework-operator-controller@5bf74afKui WangUPSTREAM: <carry>: serviceAccount validation unified across all runtimes
2026-04-16 00:09:57openshift/operator-framework-operator-controller@ba1d766Stephen BenjaminUPSTREAM: <carry>: Fix OLMv1 test operator to listen on IPv6
2026-04-16 00:09:58openshift/operator-framework-operator-controller@670127bCamila MacedoUPSTREAM: <carry>: Increase install timeout and add diagnostic logging for CE install tests
2026-04-16 00:09:59openshift/operator-framework-operator-controller@4c140a5Evan HearneUPSTREAM: <carry>: add service account to curl job
2026-04-16 00:09:59openshift/operator-framework-operator-controller@124c5f8Jian ZhangUPSTREAM: <carry>: update OCP-75441 to support multi-arch
2026-04-16 00:10:00openshift/operator-framework-operator-controller@c2cfab0Kui WangUPSTREAM: <carry>: deployment config cases
2026-04-16 00:10:01openshift/operator-framework-operator-controller@713dc0bTodd ShortUPSTREAM: <carry>: Add OTE tests for OLMv1 DeploymentConfig support
2026-04-16 00:10:01openshift/operator-framework-operator-controller@2583a49Todd ShortUPSTREAM: <carry>: Update openshift/api and client-go
2026-04-16 00:10:02openshift/operator-framework-operator-controller@65172cdCamila MacedoUPSTREAM: <carry>: Add boxcutter tests
2026-04-16 00:10:03openshift/operator-framework-operator-controller@397318fXia ZhaoUPSTREAM: <carry>: enhance QE cases
2026-04-16 00:10:03openshift/operator-framework-operator-controller@e855dc2Daniel FranzUPSTREAM: <carry>: Update quay-operator version to one containing arm64 support
2026-04-16 00:10:04openshift/operator-framework-operator-controller@60602a9Kui WangUPSTREAM: <carry>: verify volume/volumeMount override
2026-04-16 00:10:04openshift/operator-framework-operator-controller@9e9e5b8Jian ZhangUPSTREAM: <carry>: Add long-duration test script and documents
2026-04-16 00:10:05openshift/operator-framework-operator-controller@e72f900Todd ShortUPSTREAM: <carry>: Update grpc in default-catalog-consistency tests
2026-04-16 00:10:06openshift/operator-framework-operator-controller@47661f7Camila MacedoUPSTREAM: <carry>: Rename ClusterExtensionRevision to ClusterObjectSet in OTE tests
2026-04-16 00:10:06openshift/operator-framework-operator-controller@4558a79Camila MacedoUPSTREAM: <carry>: Skip incompatible operator test when Boxcutter uses ClusterObjectSet
2026-04-16 00:10:07openshift/operator-framework-operator-controller@a404e66Bruno AndradeUPSTREAM: <carry>: add ocp-87557
2026-04-16 00:10:07openshift/operator-framework-operator-controller@fb35af9Francesco GiudiciUPSTREAM: <carry>: Add fgiudici as reviewer
2026-04-16 00:10:08openshift/operator-framework-operator-controller@da1694eCamila MacedoUPSTREAM: <carry>: Remove skip for incompatible operator check after rename of CER
2026-04-16 00:10:09openshift/operator-framework-operator-controller@ab83a4bKui WangUPSTREAM: <carry>: Test empty affinity erasure and cleanup
2026-04-16 00:10:09openshift/operator-framework-operator-controller@3585edcCamila MacedoUPSTREAM: <carry>: Fix boxcutter finalizer ResourceNames in preflight test

This pull request is expected to merge without any human intervention. If tests are failing here, changes must land upstream to fix any issues so that future downstreaming efforts succeed.

/cc @openshift/openshift-team-operator-framework

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci

Copy link
Copy Markdown
Contributor

@openshift-bot: GitHub didn't allow me to request PR reviews from the following users: openshift/openshift-team-operator-framework.

Note that only openshift members and repo collaborators can review this PR, and authors cannot review their own PRs.

Details

In response to this:

The downstream repository has been updated with the following following upstream commits:

DateCommitAuthorMessage
2026-04-16 18:59:04operator-framework/operator-controller@09f3c55dependabot[bot]🌱 Bump charset-normalizer from 3.4.6 to 3.4.7 (#2656)

The vendor/ directory has been updated and the following commits were carried:

DateCommitAuthorMessage
2026-04-16 00:09:10openshift/operator-framework-operator-controller@af81adedtfranzUPSTREAM: <carry>: Add OpenShift specific files
2026-04-16 00:09:12openshift/operator-framework-operator-controller@fcc703aCamila MacedoUPSTREAM: <carry>: Add new tests for single/own namespaces install modes
2026-04-16 00:09:12openshift/operator-framework-operator-controller@cbd4e95Camila MacedoUPSTREAM: <carry>: Upgrade OCP image from 4.20 to 4.21
2026-04-16 00:09:13openshift/operator-framework-operator-controller@18e745aCamila MacedoUPSTREAM: <carry>: [Default Catalog Tests] - Change logic to get ocp images from openshift/catalogd/manifests.yaml
2026-04-16 00:09:14openshift/operator-framework-operator-controller@a8f11a8Todd ShortUPSTREAM: <carry>: Update OCP catalogs to v4.21
2026-04-16 00:09:15openshift/operator-framework-operator-controller@9fa43d7Kui WangUPSTREAM: <carry>: support singleown cases in disconnected
2026-04-16 00:09:16openshift/operator-framework-operator-controller@715d9efKui WangUPSTREAM: <carry>: fix cases 81696 and 74618 for product code changes
2026-04-16 00:09:16openshift/operator-framework-operator-controller@93118e1Camila MacedoUPSTREAM: <carry>: Define Default timeouts and apply their usage accross to avoid flakes
2026-04-16 00:09:17openshift/operator-framework-operator-controller@db1bc13Todd ShortUPSTREAM: <carry>: Update to new feature-gate options in helm
2026-04-16 00:09:18openshift/operator-framework-operator-controller@c9d0247Camila MacedoUPSTREAM: <carry>: Fix flake for single/own ns tests by ensuring uniquess and waiting for k8s cleanups
2026-04-16 00:09:18openshift/operator-framework-operator-controller@0f74b66Camila MacedoUPSTREAM: <carry>: [OTE]: Enhance single/own ns based on review comments ( Follow-Up of: 714977c )
2026-04-16 00:09:19openshift/operator-framework-operator-controller@9d0d6dcKui WangUPSTREAM: <carry>: Update OwnSingle template to use spec.config.inline.watchNamespace
2026-04-16 00:09:20openshift/operator-framework-operator-controller@3fb6ecbCamila MacedoUPSTREAM: <carry>: [OTE]: Add webhook cleanup validation on extension uninstall
2026-04-16 00:09:21openshift/operator-framework-operator-controller@8499f9dKui WangUPSTREAM: <carry>: Add [OTP] to migrated cases
2026-04-16 00:09:22openshift/operator-framework-operator-controller@75a1b47Camila MacedoUPSTREAM: <carry>: [OTE]: Upgrade dependencies used
2026-04-16 00:09:24openshift/operator-framework-operator-controller@205a420Camila MacedoUPSTREAM: <carry>: fix(OTE): fix OpenShift Kubernetes replace version format
2026-04-16 00:09:25openshift/operator-framework-operator-controller@8e398ebCamila MacedoUPSTREAM: <carry>: [Default Catalog Tests] Upgrade go 1.24.6 and dependencies
2026-04-16 00:09:26openshift/operator-framework-operator-controller@e43064dKui WangUPSTREAM: <carry>: add disconnected environment support with custom prow job for migrated qe cases
2026-04-16 00:09:27openshift/operator-framework-operator-controller@5fe86aeJian ZhangUPSTREAM: <carry>: migrate jiazha test cases to OTE
2026-04-16 00:09:28openshift/operator-framework-operator-controller@9720262Xia ZhaoUPSTREAM: <carry>: migrate clustercatalog case to ote
2026-04-16 00:09:28openshift/operator-framework-operator-controller@32512feKui WangUPSTREAM: <carry>: migrate olmv1 QE stress cases
2026-04-16 00:09:29openshift/operator-framework-operator-controller@2b404caTodd ShortUPSTREAM: <carry>: Use busybox/httpd to simulate probes
2026-04-16 00:09:30openshift/operator-framework-operator-controller@8159148Xia ZhaoUPSTREAM: <carry>: migrate olmv1 QE cases
2026-04-16 00:09:31openshift/operator-framework-operator-controller@3f3d37eKui WangUPSTREAM: <carry>: add agent for olmv1 qe cases
2026-04-16 00:09:31openshift/operator-framework-operator-controller@05fecaaTodd ShortUPSTREAM: <carry>: Disable upstream PodDisruptionBudget
2026-04-16 00:09:32openshift/operator-framework-operator-controller@5f322c1Rashmi GottipatiUPSTREAM: <carry>: Add AGENTS.md for AI code contributions
2026-04-16 00:09:33openshift/operator-framework-operator-controller@f152d9fRashmi GottipatiUPSTREAM: <carry>: address review comments through addl prompts
2026-04-16 00:09:33openshift/operator-framework-operator-controller@e9912e3Rashmi GottipatiUPSTREAM: <carry>: addressing some more review comments
2026-04-16 00:09:34openshift/operator-framework-operator-controller@7a2d275Rashmi GottipatiUPSTREAM: <carry>: remove DCO line
2026-04-16 00:09:34openshift/operator-framework-operator-controller@2396b35Bruno AndradeUPSTREAM: <carry>: migrate bandrade test cases to OTE
2026-04-16 00:09:35openshift/operator-framework-operator-controller@9c3a382Bruno AndradeUPSTREAM: <carry>: update metadata
2026-04-16 00:09:36openshift/operator-framework-operator-controller@4a2f583Bruno AndradeUPSTREAM: <carry>: remove originalName
2026-04-16 00:09:36openshift/operator-framework-operator-controller@39de536Jian ZhangUPSTREAM: <carry>: update 80458's timeout to 180s
2026-04-16 00:09:37openshift/operator-framework-operator-controller@767fd8aJian ZhangUPSTREAM: <carry>: update 83026 to specify the clustercatalog
2026-04-16 00:09:38openshift/operator-framework-operator-controller@7344267Catherine Chan-TseUPSTREAM: <carry>: Update to golang 1.25 and ocp 4.22
2026-04-16 00:09:38openshift/operator-framework-operator-controller@bd71ebbPredrag KnezevicUPSTREAM: <carry>: Use oc client for running e2e tests
2026-04-16 00:09:39openshift/operator-framework-operator-controller@8a9f87cPredrag KnezevicUPSTREAM: <carry>: Run upstream e2e tests tagged with @catalogd-update
2026-04-16 00:09:39openshift/operator-framework-operator-controller@2ccb91cKui WangUPSTREAM: <carry>: enhance case to make it more stable
2026-04-16 00:09:40openshift/operator-framework-operator-controller@10f8df0Evan HearneUPSTREAM: <carry>: add service account to curl job
2026-04-16 00:09:41openshift/operator-framework-operator-controller@214b37cEvan HearneUPSTREAM: <carry>: move sa creation out of buildCurlJob()
2026-04-16 00:09:41openshift/operator-framework-operator-controller@862368cEvan HearneUPSTREAM: <carry>: comment out delete service account
2026-04-16 00:09:42openshift/operator-framework-operator-controller@c065d19Evan HearneUPSTREAM: <carry>: move defercleanup for sa for LIFO
2026-04-16 00:09:43openshift/operator-framework-operator-controller@2334992Evan HearneUPSTREAM: <carry>: add polling so job fully deleted before proceed
2026-04-16 00:09:43openshift/operator-framework-operator-controller@287f844Luke MeyerUPSTREAM: <carry>: Revert "Merge pull request #594 from ehearne-redhat/add-service-account-curl-job"
2026-04-16 00:09:44openshift/operator-framework-operator-controller@f4fc074Camila MacedoUPSTREAM: <carry>: Remove openshift-redhat-marketplace catalog tests
2026-04-16 00:09:44openshift/operator-framework-operator-controller@368696cKui WangUPSTREAM: <carry>: config watchnamespace cases
2026-04-16 00:09:45openshift/operator-framework-operator-controller@5e1870eXia ZhaoUPSTREAM: <carry>: enhance ocp-79770
2026-04-16 00:09:46openshift/operator-framework-operator-controller@2a73224Kui WangUPSTREAM: <carry>: upgrade version support case
2026-04-16 00:09:46openshift/operator-framework-operator-controller@0c608caPer Goncalves da SilvaUPSTREAM: <carry>: Remove installed condition check from auth preflight test
2026-04-16 00:09:47openshift/operator-framework-operator-controller@f4a2f5aPer Goncalves da SilvaUPSTREAM: <carry>: Add openshift/api dependency
2026-04-16 00:09:48openshift/operator-framework-operator-controller@f375992Per Goncalves da SilvaUPSTREAM: <carry>: Add boxcutter specific preflight auth test
2026-04-16 00:09:48openshift/operator-framework-operator-controller@c02c49bKui WangUPSTREAM: <carry>: adjust watchnamespace case based on change
2026-04-16 00:09:49openshift/operator-framework-operator-controller@78f1eedCamila MacedoUPSTREAM: <carry>: fix(ote): Use as operator-controller dep from root dir
2026-04-16 00:09:50openshift/operator-framework-operator-controller@4016642Bruno AndradeUPSTREAM: <carry>: add 83979 automation
2026-04-16 00:09:51openshift/operator-framework-operator-controller@48245bdBruno AndradeUPSTREAM: <carry>: add 85889 automation
2026-04-16 00:09:51openshift/operator-framework-operator-controller@5f84555Per Goncalves da SilvaUPSTREAM: <carry>: Update test-operator startup script to fix pod probe endpoints
2026-04-16 00:09:52openshift/operator-framework-operator-controller@98d5345Per Goncalves da SilvaUPSTREAM: <carry>: Fix up own-namespace invalid configuration test
2026-04-16 00:09:52openshift/operator-framework-operator-controller@25b7369Camila MacedoUPSTREAM: <carry>: Preflight tests use in-cluster catalog and bundles instead of openshift-pipelines-operator-rh
2026-04-16 00:09:53openshift/operator-framework-operator-controller@f8d3f4dKui WangUPSTREAM: <carry>: adjust sa and permission test cases per new change from boxcutterruntime
2026-04-16 00:09:54openshift/operator-framework-operator-controller@7534032Camila MacedoUPSTREAM: <carry>: Update OCP catalogs to v4.22
2026-04-16 00:09:55openshift/operator-framework-operator-controller@5bfe0c0Camila MacedoUPSTREAM: <carry>: chore(OTE and Default Catalog Tests) Update go and dependencies
2026-04-16 00:09:56openshift/operator-framework-operator-controller@51876f7Jian ZhangUPSTREAM: <carry>: fix 83026 for TP cluster
2026-04-16 00:09:57openshift/operator-framework-operator-controller@5bf74afKui WangUPSTREAM: <carry>: serviceAccount validation unified across all runtimes
2026-04-16 00:09:57openshift/operator-framework-operator-controller@ba1d766Stephen BenjaminUPSTREAM: <carry>: Fix OLMv1 test operator to listen on IPv6
2026-04-16 00:09:58openshift/operator-framework-operator-controller@670127bCamila MacedoUPSTREAM: <carry>: Increase install timeout and add diagnostic logging for CE install tests
2026-04-16 00:09:59openshift/operator-framework-operator-controller@4c140a5Evan HearneUPSTREAM: <carry>: add service account to curl job
2026-04-16 00:09:59openshift/operator-framework-operator-controller@124c5f8Jian ZhangUPSTREAM: <carry>: update OCP-75441 to support multi-arch
2026-04-16 00:10:00openshift/operator-framework-operator-controller@c2cfab0Kui WangUPSTREAM: <carry>: deployment config cases
2026-04-16 00:10:01openshift/operator-framework-operator-controller@713dc0bTodd ShortUPSTREAM: <carry>: Add OTE tests for OLMv1 DeploymentConfig support
2026-04-16 00:10:01openshift/operator-framework-operator-controller@2583a49Todd ShortUPSTREAM: <carry>: Update openshift/api and client-go
2026-04-16 00:10:02openshift/operator-framework-operator-controller@65172cdCamila MacedoUPSTREAM: <carry>: Add boxcutter tests
2026-04-16 00:10:03openshift/operator-framework-operator-controller@397318fXia ZhaoUPSTREAM: <carry>: enhance QE cases
2026-04-16 00:10:03openshift/operator-framework-operator-controller@e855dc2Daniel FranzUPSTREAM: <carry>: Update quay-operator version to one containing arm64 support
2026-04-16 00:10:04openshift/operator-framework-operator-controller@60602a9Kui WangUPSTREAM: <carry>: verify volume/volumeMount override
2026-04-16 00:10:04openshift/operator-framework-operator-controller@9e9e5b8Jian ZhangUPSTREAM: <carry>: Add long-duration test script and documents
2026-04-16 00:10:05openshift/operator-framework-operator-controller@e72f900Todd ShortUPSTREAM: <carry>: Update grpc in default-catalog-consistency tests
2026-04-16 00:10:06openshift/operator-framework-operator-controller@47661f7Camila MacedoUPSTREAM: <carry>: Rename ClusterExtensionRevision to ClusterObjectSet in OTE tests
2026-04-16 00:10:06openshift/operator-framework-operator-controller@4558a79Camila MacedoUPSTREAM: <carry>: Skip incompatible operator test when Boxcutter uses ClusterObjectSet
2026-04-16 00:10:07openshift/operator-framework-operator-controller@a404e66Bruno AndradeUPSTREAM: <carry>: add ocp-87557
2026-04-16 00:10:07openshift/operator-framework-operator-controller@fb35af9Francesco GiudiciUPSTREAM: <carry>: Add fgiudici as reviewer
2026-04-16 00:10:08openshift/operator-framework-operator-controller@da1694eCamila MacedoUPSTREAM: <carry>: Remove skip for incompatible operator check after rename of CER
2026-04-16 00:10:09openshift/operator-framework-operator-controller@ab83a4bKui WangUPSTREAM: <carry>: Test empty affinity erasure and cleanup
2026-04-16 00:10:09openshift/operator-framework-operator-controller@3585edcCamila MacedoUPSTREAM: <carry>: Fix boxcutter finalizer ResourceNames in preflight test

This pull request is expected to merge without any human intervention. If tests are failing here, changes must land upstream to fix any issues so that future downstreaming efforts succeed.

/cc @openshift/openshift-team-operator-framework

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@coderabbitai

coderabbitaiBot commented Apr 17, 2026

Copy link
Copy Markdown

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Adds unit and end-to-end TLS profile tests, new E2E step implementations and deployment patch/restore logic, port-forward/TLS helpers, and bumps to several Python and Go module dependencies. No production API signatures were changed.

Changes

Cohort / File(s)Summary
Python dependency
requirements.txt
Pinned bumps: charset-normalizer==3.4.63.4.7, click==8.3.18.3.2, regex==2026.3.322026.4.4.
Go module updates
go.mod, hack/tools/test-profiling/go.mod
Updated go.podman.io/image/v5 v5.39.1 → v5.39.2 and indirect github.com/go-git/go-git/v5 v5.17.1 → v5.18.0; bumped test tooling github.com/moby/spdystream v0.5.0 → v0.5.1.
TLS unit tests
internal/shared/util/tlsprofiles/tlsprofiles_connection_test.go
New integration-style tests that run ephemeral TLS servers and validate cipher, TLS version, and curve negotiation using package-level TLS profile overrides.
E2E feature
test/e2e/features/tls.feature
Added Gherkin scenarios (tagged @TLSProfile) for metrics endpoint TLS enforcement: min version, cipher, and curve checks.
E2E hooks / cleanup
test/e2e/steps/hooks.go
Added deploymentRestore type and scenarioContext.deploymentRestores; ScenarioCleanup restores patched deployment args in reverse order and waits for rollout; clusterObjectSet deletion conditioned on feature gate and name.
E2E step registrations
test/e2e/steps/steps.go
Registered 8+ new Godog steps for configuring deployments with custom TLS profiles and asserting endpoint TLS behaviors.
E2E TLS step implementations
test/e2e/steps/tls_steps.go
New large file: cipher/curve name→ID maps, kubectl service/port discovery, port-forward with TLS readiness probing, deployment patching and arg-recording for restore, and many exported step functions for TLS acceptance/rejection and cipher/curve negotiation assertions.

Sequence Diagram(s)

sequenceDiagram
participant Tester as Tester
participant TestHarness as Test Harness
participant KubeAPI as Kubernetes API
participant Kubectl as kubectl (port-forward)
participant Pod as Target Pod
participant TLSClient as Local TLS Client
Tester->>TestHarness: Start TLS scenario (configure deployment)
TestHarness->>KubeAPI: Patch Deployment args (--tls-profile=custom, ciphers, curves, min-version)
KubeAPI-->>TestHarness: Acknowledge rollout / pods restarting
TestHarness->>KubeAPI: Wait for rollout status
KubeAPI-->>TestHarness: Pod ready
TestHarness->>Kubectl: Start port-forward to Service:metricsPort
Kubectl->>Pod: Forward local port to Pod metrics port
TLSClient->>Kubectl: Dial local port (TLS client config)
Kubectl->>Pod: Forward TLS handshake
Pod-->>TLSClient: TLS handshake result (negotiated cipher/curve or failure)
TLSClient-->>TestHarness: Report handshake outcome
TestHarness->>Tester: Assert expected acceptance/rejection
Tester->>TestHarness: Scenario end
TestHarness->>KubeAPI: Restore original Deployment args (from deploymentRestores)
KubeAPI-->>TestHarness: Rollout restore complete
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

🚥 Pre-merge checks | ✅ 10 | ❌ 2

❌ Failed checks (2 warnings)

Check nameStatusExplanationResolution
Test Structure And Quality⚠️ WarningE2E test steps in tls_steps.go have nine tls.Dial() calls lacking explicit timeout protection, risking indefinite hangs.Replace plain tls.Dial() calls with tls.DialWithDialer() using net.Dialer with 30-second timeout, or enforce context deadlines on network operations.
Ipv6 And Disconnected Network Test Compatibility⚠️ WarningNew TLS e2e tests contain IPv4 hardcoded addresses that cause failures in IPv6-only disconnected CI environments.Modify test code to support both IPv4 and IPv6 loopback addresses, bind to [::1]:0, and add both addresses to certificate IPAddresses list.
✅ Passed checks (10 passed)
Check nameStatusExplanation
Title check✅ PassedThe title "NO-ISSUE: Synchronize From Upstream Repositories" accurately describes the main purpose of this changeset, which is a synchronization of upstream changes. The title is appropriate for a dependency update and test addition PR.
Docstring Coverage✅ PassedDocstring coverage is 93.55% which is sufficient. The required threshold is 80.00%.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names✅ PassedAll test names in newly added TLS test files are stable and deterministic with static function and scenario names containing no dynamic content.
Microshift Test Compatibility✅ PassedThe custom check is for Ginkgo e2e tests (It(), Describe(), Context() patterns). The PR adds standard Go unit tests and Godog BDD tests, not Ginkgo tests, making the check inapplicable.
Single Node Openshift (Sno) Test Compatibility✅ PassedNew tests are not Ginkgo e2e tests; tlsprofiles_connection_test.go uses standard Go testing, while tls.feature uses BDD/Godog framework. Neither makes multi-node assumptions.
Topology-Aware Scheduling Compatibility✅ PassedPR contains only test infrastructure and dependency updates with no scheduling constraints affecting non-standard topologies.
Ote Binary Stdout Contract✅ PassedPR adds E2E test infrastructure files without modifying main entry points or introducing stdout writes in process-level code that violates OTE Binary Stdout Contract.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands and usage tips.

@openshift-ci

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

Approval requirements bypassed by manually added approval.

This pull-request has been approved by: openshift-bot

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

1 similar comment
@openshift-ci

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

Approval requirements bypassed by manually added approval.

This pull-request has been approved by: openshift-bot

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

dependabotBotand others added 5 commits April 17, 2026 06:59
Bumps [github.com/moby/spdystream](https://github.com/moby/spdystream) from 0.5.0 to 0.5.1.
- [Release notes](https://github.com/moby/spdystream/releases)
- [Commits](moby/spdystream@v0.5.0...v0.5.1)
---
updated-dependencies:
- dependency-name: github.com/moby/spdystream
dependency-version: 0.5.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
- Unit tests in tlsprofiles package verify cipher negotiation, cipher
rejection, min-version enforcement, and curve acceptance/rejection
by starting a local TLS server with a custom profile and connecting
to it with a restricted client config.
- e2e feature (tls.feature) patches the catalogd deployment with
specific custom TLS settings for each scenario, asserts the expected
connection behaviour, then restores the original args on cleanup.
Covers min-version enforcement (TLSv1.3), cipher negotiation and
rejection (TLS 1.2 + ECDHE_ECDSA), and curve enforcement (prime256v1
accepted, secp521r1 rejected).
- GODOG_ARGS variable added to the e2e Makefile target so a single
feature file can be run with: make test-e2e GODOG_ARGS=features/tls.feature
Signed-off-by: Todd Short <tshort@redhat.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Bumps [marocchino/sticky-pull-request-comment](https://github.com/marocchino/sticky-pull-request-comment) from 3 to 3.0.2.
- [Release notes](https://github.com/marocchino/sticky-pull-request-comment/releases)
- [Commits](marocchino/sticky-pull-request-comment@v3...v3.0.2)
---
updated-dependencies:
- dependency-name: marocchino/sticky-pull-request-comment
dependency-version: 3.0.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [go.podman.io/image/v5](https://github.com/containers/container-libs) from 5.39.1 to 5.39.2.
- [Release notes](https://github.com/containers/container-libs/releases)
- [Commits](podman-container-tools/container-libs@image/v5.39.1...image/v5.39.2)
---
updated-dependencies:
- dependency-name: go.podman.io/image/v5
dependency-version: 5.39.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [dorny/paths-filter](https://github.com/dorny/paths-filter) from 4 to 4.0.1.
- [Release notes](https://github.com/dorny/paths-filter/releases)
- [Changelog](https://github.com/dorny/paths-filter/blob/master/CHANGELOG.md)
- [Commits](dorny/paths-filter@v4...v4.0.1)
---
updated-dependencies:
- dependency-name: dorny/paths-filter
dependency-version: 4.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@openshift-ciopenshift-ciBot removed the lgtm Indicates that a PR is ready to be merged. label Apr 17, 2026
@openshift-botopenshift-bot added the lgtm Indicates that a PR is ready to be merged. label Apr 17, 2026
@tmshort

Copy link
Copy Markdown
Contributor

I suspect this will fail due to the TLS profiles testing, in which case, we will want to skip them in openshift/Makefile

@tmshort

Copy link
Copy Markdown
Contributor

/lgtm

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
internal/shared/util/tlsprofiles/tlsprofiles_connection_test.go (1)

135-139: Pin MinVersion in all TLS 1.2 client configs to ensure tests remain stable across Go versions.

These tests set MaxVersion: tls.VersionTLS12 to exercise TLS 1.2-specific behavior, but rely on Go's default minimum version (TLS 1.2 since Go 1.18). Go's documentation explicitly states the default is "currently" TLS 1.2, indicating it may change in future releases. Pinning MinVersion ensures these tests continue to validate the intended behavior regardless of Go version updates.

Add MinVersion: tls.VersionTLS12 to the tls.Config structs at lines 135–139, 164–168, 189–192, 216–221, and 247–252.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@internal/shared/util/tlsprofiles/tlsprofiles_connection_test.go` around lines
135 - 139, Tests create tls.Config literals that set MaxVersion:
tls.VersionTLS12 (for example the clientCfg variable) but don't set MinVersion;
add MinVersion: tls.VersionTLS12 to each tls.Config literal that pins MaxVersion
to tls.VersionTLS12 so the tests don't depend on Go's changing default minimum
TLS version—i.e., find every tls.Config struct in this test file that includes
MaxVersion: tls.VersionTLS12 and add MinVersion: tls.VersionTLS12 alongside it.
test/e2e/steps/tls_steps.go (1)

153-156: Set explicit MinVersion: tls.VersionTLS12 alongside MaxVersion for consistent behavior across Go versions.

These TLS 1.2-specific tests currently depend on Go's default minimum TLS version, which varies by release: TLS 1.0 before Go 1.18, and TLS 1.2 from Go 1.18 onward. Without an explicit MinVersion, tests running on Go 1.17 or earlier could unexpectedly negotiate TLS 1.0 or 1.1 instead of 1.2, causing the rejection test to fail and cipher/curve tests to validate incorrect protocol versions.

Suggested change
 conn, err := tls.Dial("tcp", addr, &tls.Config{
InsecureSkipVerify: true, //nolint:gosec // self-signed cert in e2e
+ MinVersion: tls.VersionTLS12,
MaxVersion: tls.VersionTLS12,
CipherSuites: []uint16{cipherID},
})

Apply to lines 153–156, 330–334, 356–360, 381–386, and 407–412.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@test/e2e/steps/tls_steps.go` around lines 153 - 156, The TLS tests set
MaxVersion: tls.VersionTLS12 but omit MinVersion, making behavior vary across Go
versions; update the tls.Config initializations (e.g., the tls.Dial call where
conn, err := tls.Dial("tcp", addr, &tls.Config{...}) and the other tls.Config
occurrences referenced in this file) to include MinVersion: tls.VersionTLS12
alongside MaxVersion so the client explicitly requires TLS 1.2; apply this
change to all mentioned spots (the blocks at the given ranges) to ensure
consistent TLS 1.2-only negotiation.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Nitpick comments:
In `@internal/shared/util/tlsprofiles/tlsprofiles_connection_test.go`:
- Around line 135-139: Tests create tls.Config literals that set MaxVersion:
tls.VersionTLS12 (for example the clientCfg variable) but don't set MinVersion;
add MinVersion: tls.VersionTLS12 to each tls.Config literal that pins MaxVersion
to tls.VersionTLS12 so the tests don't depend on Go's changing default minimum
TLS version—i.e., find every tls.Config struct in this test file that includes
MaxVersion: tls.VersionTLS12 and add MinVersion: tls.VersionTLS12 alongside it.
In `@test/e2e/steps/tls_steps.go`:
- Around line 153-156: The TLS tests set MaxVersion: tls.VersionTLS12 but omit
MinVersion, making behavior vary across Go versions; update the tls.Config
initializations (e.g., the tls.Dial call where conn, err := tls.Dial("tcp",
addr, &tls.Config{...}) and the other tls.Config occurrences referenced in this
file) to include MinVersion: tls.VersionTLS12 alongside MaxVersion so the client
explicitly requires TLS 1.2; apply this change to all mentioned spots (the
blocks at the given ranges) to ensure consistent TLS 1.2-only negotiation.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: b7330088-cf6c-42dd-a75a-46e48b840574

📥 Commits

Reviewing files that changed from the base of the PR and between e79a121 and ac28118.

⛔ Files ignored due to path filters (15)
  • go.sum is excluded by !**/*.sum
  • hack/tools/test-profiling/go.sum is excluded by !**/*.sum
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/NOTICE is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/connection.go is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/spdy/LICENSE is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/spdy/PATENTS is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/spdy/dictionary.go is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/spdy/options.go is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/spdy/read.go is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/spdy/types.go is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/spdy/write.go is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/modules.txt is excluded by !**/vendor/**
  • vendor/go.podman.io/image/v5/docker/docker_client.go is excluded by !**/vendor/**, !vendor/**
  • vendor/go.podman.io/image/v5/version/version.go is excluded by !**/vendor/**, !vendor/**
  • vendor/modules.txt is excluded by !**/vendor/**, !vendor/**
📒 Files selected for processing (8)
  • go.mod
  • hack/tools/test-profiling/go.mod
  • internal/shared/util/tlsprofiles/tlsprofiles_connection_test.go
  • requirements.txt
  • test/e2e/features/tls.feature
  • test/e2e/steps/hooks.go
  • test/e2e/steps/steps.go
  • test/e2e/steps/tls_steps.go
✅ Files skipped from review due to trivial changes (3)
  • hack/tools/test-profiling/go.mod
  • requirements.txt
  • go.mod

Bumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.17.1 to 5.18.0.
- [Release notes](https://github.com/go-git/go-git/releases)
- [Commits](go-git/go-git@v5.17.1...v5.18.0)
---
updated-dependencies:
- dependency-name: github.com/go-git/go-git/v5
dependency-version: 5.18.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@openshift-ciopenshift-ciBot removed the lgtm Indicates that a PR is ready to be merged. label Apr 19, 2026

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
internal/shared/util/tlsprofiles/tlsprofiles_connection_test.go (1)

93-101: Serialize global TLS profile mutation in tests.

setCustomProfile mutates package-level globals for the full test duration. If any test in this package runs in parallel later, this becomes racy and can produce nondeterministic failures.

♻️ Proposed fix
 import (
"crypto/ecdsa"
@@
"net"
+	"sync"
"testing"
"time"
@@
)
+var customProfileMu sync.Mutex+
// setCustomProfile configures the package-level custom TLS profile for the duration
// of the test and restores the original state via t.Cleanup.
func setCustomProfile(t *testing.T, cipherNames []string, curveNames []string, minVersion string) {
t.Helper()
+	customProfileMu.Lock()+	t.Cleanup(func() { customProfileMu.Unlock() })
origProfile := configuredProfile
origCustom := customTLSProfile
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@internal/shared/util/tlsprofiles/tlsprofiles_connection_test.go` around lines
93 - 101, setCustomProfile currently mutates the package-level globals
configuredProfile and customTLSProfile for the full test duration, which is racy
if tests run in parallel; fix it by serializing access: add a package-level
sync.Mutex (e.g., tlsProfileMu) and have setCustomProfile Lock() at the start
and Unlock() in the t.Cleanup closure after restoring origProfile and
origCustom, so the global mutation is held while the test uses the custom
profile and released when cleanup runs.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@test/e2e/steps/tls_steps.go`:
- Around line 254-273: buildCustomTLSArgs currently only strips combined form
flags like "--tls-profile=..." and leaves split-form flags like "--tls-profile"
followed by "custom" in baseArgs, causing stale/conflicting args; update the
filtering loop in buildCustomTLSArgs to also detect split-form TLS flags
("--tls-profile", "--tls-custom-version", "--tls-custom-ciphers",
"--tls-custom-curves") and skip both the flag and its next argument when present
(ensure you check bounds before skipping the next element), so that all old TLS
flags (both joined and split forms) are removed before appending the new custom
TLS flags.
---
Nitpick comments:
In `@internal/shared/util/tlsprofiles/tlsprofiles_connection_test.go`:
- Around line 93-101: setCustomProfile currently mutates the package-level
globals configuredProfile and customTLSProfile for the full test duration, which
is racy if tests run in parallel; fix it by serializing access: add a
package-level sync.Mutex (e.g., tlsProfileMu) and have setCustomProfile Lock()
at the start and Unlock() in the t.Cleanup closure after restoring origProfile
and origCustom, so the global mutation is held while the test uses the custom
profile and released when cleanup runs.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 109c5bfd-4af3-433e-835c-94ef97876c18

📥 Commits

Reviewing files that changed from the base of the PR and between ac28118 and b16e4d4.

⛔ Files ignored due to path filters (15)
  • go.sum is excluded by !**/*.sum
  • hack/tools/test-profiling/go.sum is excluded by !**/*.sum
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/NOTICE is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/connection.go is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/spdy/LICENSE is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/spdy/PATENTS is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/spdy/dictionary.go is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/spdy/options.go is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/spdy/read.go is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/spdy/types.go is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/github.com/moby/spdystream/spdy/write.go is excluded by !**/vendor/**
  • hack/tools/test-profiling/vendor/modules.txt is excluded by !**/vendor/**
  • vendor/go.podman.io/image/v5/docker/docker_client.go is excluded by !**/vendor/**, !vendor/**
  • vendor/go.podman.io/image/v5/version/version.go is excluded by !**/vendor/**, !vendor/**
  • vendor/modules.txt is excluded by !**/vendor/**, !vendor/**
📒 Files selected for processing (8)
  • go.mod
  • hack/tools/test-profiling/go.mod
  • internal/shared/util/tlsprofiles/tlsprofiles_connection_test.go
  • requirements.txt
  • test/e2e/features/tls.feature
  • test/e2e/steps/hooks.go
  • test/e2e/steps/steps.go
  • test/e2e/steps/tls_steps.go
✅ Files skipped from review due to trivial changes (2)
  • hack/tools/test-profiling/go.mod
  • requirements.txt
🚧 Files skipped from review as they are similar to previous changes (3)
  • go.mod
  • test/e2e/steps/hooks.go
  • test/e2e/steps/steps.go

Comment on lines +254 to +273
func buildCustomTLSArgs(baseArgs []string, version, ciphers, curves string) []string {
filtered := make([]string, 0, len(baseArgs)+4)
for _, arg := range baseArgs {
switch {
case strings.HasPrefix(arg, "--tls-profile="),
strings.HasPrefix(arg, "--tls-custom-version="),
strings.HasPrefix(arg, "--tls-custom-ciphers="),
strings.HasPrefix(arg, "--tls-custom-curves="):
// drop — will be replaced below
default:
filtered = append(filtered, arg)
}
}
filtered = append(filtered, "--tls-profile=custom", "--tls-custom-version="+version)
if ciphers != "" {
filtered = append(filtered, "--tls-custom-ciphers="+ciphers)
}
if curves != "" {
filtered = append(filtered, "--tls-custom-curves="+curves)
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

Handle split-form TLS flags when rebuilding deployment args.

Current filtering only removes --tls-*=... forms. If existing args use split form (--tls-profile, custom), stale flags remain and can produce conflicting CLI input.

🐛 Proposed fix
 func buildCustomTLSArgs(baseArgs []string, version, ciphers, curves string) []string {
filtered := make([]string, 0, len(baseArgs)+4)
-	for _, arg := range baseArgs {+	skipNext := false+	for i, arg := range baseArgs {+ if skipNext {+ skipNext = false+ continue+ }
switch {
+ case arg == "--tls-profile",+ arg == "--tls-custom-version",+ arg == "--tls-custom-ciphers",+ arg == "--tls-custom-curves":+ // Drop split-form flag and its following value token (if present).+ if i+1 < len(baseArgs) && !strings.HasPrefix(baseArgs[i+1], "--") {+ skipNext = true+ }
case strings.HasPrefix(arg, "--tls-profile="),
strings.HasPrefix(arg, "--tls-custom-version="),
strings.HasPrefix(arg, "--tls-custom-ciphers="),
strings.HasPrefix(arg, "--tls-custom-curves="):
// drop — will be replaced below
default:
filtered = append(filtered, arg)
}
}
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
funcbuildCustomTLSArgs(baseArgs []string, version, ciphers, curvesstring) []string {
filtered:=make([]string, 0, len(baseArgs)+4)
for_, arg:=rangebaseArgs {
switch {
casestrings.HasPrefix(arg, "--tls-profile="),
strings.HasPrefix(arg, "--tls-custom-version="),
strings.HasPrefix(arg, "--tls-custom-ciphers="),
strings.HasPrefix(arg, "--tls-custom-curves="):
// drop — will be replaced below
default:
filtered=append(filtered, arg)
}
}
filtered=append(filtered, "--tls-profile=custom", "--tls-custom-version="+version)
ifciphers!="" {
filtered=append(filtered, "--tls-custom-ciphers="+ciphers)
}
ifcurves!="" {
filtered=append(filtered, "--tls-custom-curves="+curves)
}
funcbuildCustomTLSArgs(baseArgs []string, version, ciphers, curvesstring) []string {
filtered:=make([]string, 0, len(baseArgs)+4)
skipNext:=false
fori, arg:=rangebaseArgs {
ifskipNext {
skipNext=false
continue
}
switch {
casearg=="--tls-profile",
arg=="--tls-custom-version",
arg=="--tls-custom-ciphers",
arg=="--tls-custom-curves":
// Drop split-form flag and its following value token (if present).
ifi+1<len(baseArgs) &&!strings.HasPrefix(baseArgs[i+1], "--") {
skipNext=true
}
casestrings.HasPrefix(arg, "--tls-profile="),
strings.HasPrefix(arg, "--tls-custom-version="),
strings.HasPrefix(arg, "--tls-custom-ciphers="),
strings.HasPrefix(arg, "--tls-custom-curves="):
// drop — will be replaced below
default:
filtered=append(filtered, arg)
}
}
filtered=append(filtered, "--tls-profile=custom", "--tls-custom-version="+version)
ifciphers!="" {
filtered=append(filtered, "--tls-custom-ciphers="+ciphers)
}
ifcurves!="" {
filtered=append(filtered, "--tls-custom-curves="+curves)
}
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@test/e2e/steps/tls_steps.go` around lines 254 - 273, buildCustomTLSArgs
currently only strips combined form flags like "--tls-profile=..." and leaves
split-form flags like "--tls-profile" followed by "custom" in baseArgs, causing
stale/conflicting args; update the filtering loop in buildCustomTLSArgs to also
detect split-form TLS flags ("--tls-profile", "--tls-custom-version",
"--tls-custom-ciphers", "--tls-custom-curves") and skip both the flag and its
next argument when present (ensure you check bounds before skipping the next
element), so that all old TLS flags (both joined and split forms) are removed
before appending the new custom TLS flags.

@openshift-botopenshift-bot added the lgtm Indicates that a PR is ready to be merged. label Apr 20, 2026
@camilamacedo86

Copy link
Copy Markdown
Contributor

/retest-required

@tmshort

Copy link
Copy Markdown
Contributor

This requires #702 for this to pass.

tmshortand others added 21 commits April 21, 2026 16:53
Add 7 Ginkgo tests under [sig-olmv1][OCPFeatureGate:NewOLMDeploymentConfig]
covering the spec.config.inline.deploymentConfig feature:
Positive tests (verify applied customisations):
- environment variables
- resource requirements
- tolerations
- node selector
- annotations on deployment and pod template
Negative tests (verify terminal validation errors):
- invalid deploymentConfig.env type (string instead of array)
- unknown field inside deploymentConfig (additionalProperties:false)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Todd Short <tshort@redhat.com>
Signed-off-by: Todd Short <tshort@redhat.com>
…64 support
Signed-off-by: Daniel Franz <dfranz@redhat.com>
Signed-off-by: Todd Short <tshort@redhat.com>
…t in OTE tests
Update all remaining references to ClusterExtensionRevision in
openshift/tests-extension to use ClusterObjectSet, matching the
upstream rename in operator-framework/operator-controller#2589.
Files updated:
- test/qe/specs/olmv1_ce.go: RBAC resource names and comments
- test/olmv1-preflight.go: scenario constants, test names, RBAC rules
- .openshift-tests-extension/openshift_payload_olmv1.json: test name
- pkg/bindata/qe/bindata.go: embedded RBAC templates
- test/qe/testdata/olm/sa-nginx-limited-boxcutter.yaml: RBAC resources
- test/qe/testdata/olm/sa-nginx-insufficient-operand-rbac-boxcutter.yaml: RBAC resources
Signed-off-by: Camila Macedo <cmacedo@redhat.com>
Made-with: Cursor
…s ClusterObjectSet
The upstream rename of ClusterExtensionRevision to ClusterObjectSet
(operator-framework/operator-controller#2589) breaks the incompatible
operator detection in cluster-olm-operator. The cluster-olm-operator
binary still reads ClusterExtensionRevision resources to find operators
with olm.maxOpenShiftVersion, so after the rename it never detects
incompatible operators and InstalledOLMOperatorsUpgradeable stays True.
Skip this test when NewOLMBoxCutterRuntime feature gate is enabled
until cluster-olm-operator is updated to read ClusterObjectSet.
Signed-off-by: Camila Macedo <cmacedo@redhat.com>
Made-with: Cursor
Signed-off-by: Francesco Giudici <fgiudici@redhat.com>
Signed-off-by: Todd Short <todd.short@me.com>
@openshift-ciopenshift-ciBot removed the lgtm Indicates that a PR is ready to be merged. label Apr 21, 2026
@tmshort

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-ciopenshift-ciBot added the lgtm Indicates that a PR is ready to be merged. label Apr 21, 2026
@openshift-ci

Copy link
Copy Markdown
Contributor

@openshift-bot: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@tmshort

Copy link
Copy Markdown
Contributor

/verified by tmshort

No extraneous clusterobjectset messages in upstream-e2e logs.

The logs also contain:

go test -count=1 -v ./test/e2e/features_test.go --godog.tags="~@mirrored-registry && ~@TLSProfile" --k8s.cli=oc

Which properly disables the TLSProfiles tests for downstream.

All other changes were dependency bumps, and since the code builds and passes, I'm considering it verified.

@openshift-ci-robotopenshift-ci-robot added the verified Signifies that the PR passed pre-merge verification criteria label Apr 22, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@tmshort: This PR has been marked as verified by tmshort.

Details

In response to this:

/verified by tmshort

No extraneous clusterobjectset messages in upstream-e2e logs.

The logs also contain:

go test -count=1 -v ./test/e2e/features_test.go --godog.tags="~@mirrored-registry && ~@TLSProfile" --k8s.cli=oc

Which properly disables the TLSProfiles tests for downstream.

All other changes were dependency bumps, and since the code builds and passes, I'm considering it verified.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-merge-bot
openshift-merge-botBot merged commit 7c731ae into openshift:mainApr 22, 2026
14 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approvedIndicates a PR has been approved by an approver from all required OWNERS files.jira/valid-referenceIndicates that this PR references a valid Jira ticket of any type.kind/synclgtmIndicates that a PR is ready to be merged.tide/merge-method-mergeDenotes a PR that should use a standard merge by tide when it merges.verifiedSignifies that the PR passed pre-merge verification criteria

Projects

None yet

Development

Successfully merging this pull request may close these issues.

17 participants

@openshift-bot@openshift-ci-robot@tmshort@camilamacedo86@joelanford@dtfranz@kuiwang02@jianzhangbjz@Xia-Zhao-rh@rashmigottipati@bandrade@oceanc80@pedjak@ehearne-redhat@sosiouxme@stbenjam@fgiudici