Skip to content

NO-ISSUE: Synchronize From Upstream Repositories - #776

Open
openshift-bot wants to merge 112 commits into
openshift:mainfrom
openshift-bot:synchronize-upstream
Open

NO-ISSUE: Synchronize From Upstream Repositories#776
openshift-bot wants to merge 112 commits into
openshift:mainfrom
openshift-bot:synchronize-upstream

Conversation

@openshift-bot

@openshift-bot openshift-bot commented Jul 28, 2026

Copy link
Copy Markdown

The downstream repository has been updated with the following following upstream commits:

Date Commit Author Message
2026-07-27 19:35:10 operator-framework/operator-controller@9111029 dependabot[bot] 🌱 Bump regex from 2026.6.28 to 2026.7.10 (#2834)
2026-07-27 14:28:50 operator-framework/operator-controller@66fcc86 dependabot[bot] 🌱 Bump helm.sh/helm/v3 from 3.21.2 to 3.21.3 (#2833)
2026-07-27 13:10:19 operator-framework/operator-controller@d0757b5 dependabot[bot] 🌱 Bump github.com/prometheus/common from 0.69.0 to 0.70.0 (#2832)

The vendor/ directory has been updated and the following commits were carried:

Date Commit Author Message
2026-07-24 00:14:47 openshift/operator-framework-operator-controller@0ccc077 dtfranz UPSTREAM: <carry>: Add OpenShift specific files
2026-07-24 00:14:49 openshift/operator-framework-operator-controller@60ede30 Camila Macedo UPSTREAM: <carry>: Add new tests for single/own namespaces install modes
2026-07-24 00:14:50 openshift/operator-framework-operator-controller@ee96dc1 Camila Macedo UPSTREAM: <carry>: Upgrade OCP image from 4.20 to 4.21
2026-07-24 00:14:51 openshift/operator-framework-operator-controller@80d97f8 Camila Macedo UPSTREAM: <carry>: [Default Catalog Tests] - Change logic to get ocp images from openshift/catalogd/manifests.yaml
2026-07-24 00:14:52 openshift/operator-framework-operator-controller@071e814 Todd Short UPSTREAM: <carry>: Update OCP catalogs to v4.21
2026-07-24 00:14:53 openshift/operator-framework-operator-controller@f80b47a Kui Wang UPSTREAM: <carry>: support singleown cases in disconnected
2026-07-24 00:14:54 openshift/operator-framework-operator-controller@7d03123 Kui Wang UPSTREAM: <carry>: fix cases 81696 and 74618 for product code changes
2026-07-24 00:14:55 openshift/operator-framework-operator-controller@ea677ef Camila Macedo UPSTREAM: <carry>: Define Default timeouts and apply their usage accross to avoid flakes
2026-07-24 00:14:56 openshift/operator-framework-operator-controller@4922ed2 Todd Short UPSTREAM: <carry>: Update to new feature-gate options in helm
2026-07-24 00:14:57 openshift/operator-framework-operator-controller@aa62f33 Camila Macedo UPSTREAM: <carry>: Fix flake for single/own ns tests by ensuring uniquess and waiting for k8s cleanups
2026-07-24 00:14:58 openshift/operator-framework-operator-controller@2f0f531 Camila Macedo UPSTREAM: <carry>: [OTE]: Enhance single/own ns based on review comments ( Follow-Up of: 714977c )
2026-07-24 00:14:59 openshift/operator-framework-operator-controller@36d61ea Kui Wang UPSTREAM: <carry>: Update OwnSingle template to use spec.config.inline.watchNamespace
2026-07-24 00:15:01 openshift/operator-framework-operator-controller@70bfc13 Camila Macedo UPSTREAM: <carry>: [OTE]: Add webhook cleanup validation on extension uninstall
2026-07-24 00:15:02 openshift/operator-framework-operator-controller@ed7b8d8 Kui Wang UPSTREAM: <carry>: Add [OTP] to migrated cases
2026-07-24 00:15:04 openshift/operator-framework-operator-controller@423ec6f Camila Macedo UPSTREAM: <carry>: [OTE]: Upgrade dependencies used
2026-07-24 00:15:06 openshift/operator-framework-operator-controller@5d0888e Camila Macedo UPSTREAM: <carry>: fix(OTE): fix OpenShift Kubernetes replace version format
2026-07-24 00:15:07 openshift/operator-framework-operator-controller@116d217 Camila Macedo UPSTREAM: <carry>: [Default Catalog Tests] Upgrade go 1.24.6 and dependencies
2026-07-24 00:15:08 openshift/operator-framework-operator-controller@04b0d8b Kui Wang UPSTREAM: <carry>: add disconnected environment support with custom prow job for migrated qe cases
2026-07-24 00:15:09 openshift/operator-framework-operator-controller@ba7f06b Jian Zhang UPSTREAM: <carry>: migrate jiazha test cases to OTE
2026-07-24 00:15:10 openshift/operator-framework-operator-controller@feaf9a0 Xia Zhao UPSTREAM: <carry>: migrate clustercatalog case to ote
2026-07-24 00:15:11 openshift/operator-framework-operator-controller@4ac2b13 Kui Wang UPSTREAM: <carry>: migrate olmv1 QE stress cases
2026-07-24 00:15:12 openshift/operator-framework-operator-controller@e22dafd Todd Short UPSTREAM: <carry>: Use busybox/httpd to simulate probes
2026-07-24 00:15:13 openshift/operator-framework-operator-controller@f97eae3 Xia Zhao UPSTREAM: <carry>: migrate olmv1 QE cases
2026-07-24 00:15:14 openshift/operator-framework-operator-controller@c3019f6 Kui Wang UPSTREAM: <carry>: add agent for olmv1 qe cases
2026-07-24 00:15:15 openshift/operator-framework-operator-controller@8351259 Todd Short UPSTREAM: <carry>: Disable upstream PodDisruptionBudget
2026-07-24 00:15:16 openshift/operator-framework-operator-controller@a923158 Rashmi Gottipati UPSTREAM: <carry>: Add AGENTS.md for AI code contributions
2026-07-24 00:15:17 openshift/operator-framework-operator-controller@744f8e5 Rashmi Gottipati UPSTREAM: <carry>: address review comments through addl prompts
2026-07-24 00:15:18 openshift/operator-framework-operator-controller@9473412 Rashmi Gottipati UPSTREAM: <carry>: addressing some more review comments
2026-07-24 00:15:18 openshift/operator-framework-operator-controller@82649eb Rashmi Gottipati UPSTREAM: <carry>: remove DCO line
2026-07-24 00:15:19 openshift/operator-framework-operator-controller@bf38ba1 Bruno Andrade UPSTREAM: <carry>: migrate bandrade test cases to OTE
2026-07-24 00:15:21 openshift/operator-framework-operator-controller@04a1f5f Bruno Andrade UPSTREAM: <carry>: update metadata
2026-07-24 00:15:22 openshift/operator-framework-operator-controller@42205b5 Bruno Andrade UPSTREAM: <carry>: remove originalName
2026-07-24 00:15:23 openshift/operator-framework-operator-controller@6a979e3 Jian Zhang UPSTREAM: <carry>: update 80458's timeout to 180s
2026-07-24 00:15:24 openshift/operator-framework-operator-controller@d052148 Jian Zhang UPSTREAM: <carry>: update 83026 to specify the clustercatalog
2026-07-24 00:15:25 openshift/operator-framework-operator-controller@c0ee6fc Catherine Chan-Tse UPSTREAM: <carry>: Update to golang 1.25 and ocp 4.22
2026-07-24 00:15:27 openshift/operator-framework-operator-controller@292fae2 Predrag Knezevic UPSTREAM: <carry>: Use oc client for running e2e tests
2026-07-24 00:15:28 openshift/operator-framework-operator-controller@1f586af Predrag Knezevic UPSTREAM: <carry>: Run upstream e2e tests tagged with @catalogd-update
2026-07-24 00:15:29 openshift/operator-framework-operator-controller@12b2772 Kui Wang UPSTREAM: <carry>: enhance case to make it more stable
2026-07-24 00:15:30 openshift/operator-framework-operator-controller@a6c611c Evan Hearne UPSTREAM: <carry>: add service account to curl job
2026-07-24 00:15:32 openshift/operator-framework-operator-controller@d5db55a Evan Hearne UPSTREAM: <carry>: move sa creation out of buildCurlJob()
2026-07-24 00:15:33 openshift/operator-framework-operator-controller@e358b4e Evan Hearne UPSTREAM: <carry>: comment out delete service account
2026-07-24 00:15:34 openshift/operator-framework-operator-controller@e18c52a Evan Hearne UPSTREAM: <carry>: move defercleanup for sa for LIFO
2026-07-24 00:15:35 openshift/operator-framework-operator-controller@0864627 Evan Hearne UPSTREAM: <carry>: add polling so job fully deleted before proceed
2026-07-24 00:15:36 openshift/operator-framework-operator-controller@b00b068 Luke Meyer UPSTREAM: <carry>: Revert "Merge pull request #594 from ehearne-redhat/add-service-account-curl-job"
2026-07-24 00:15:38 openshift/operator-framework-operator-controller@3a55c99 Camila Macedo UPSTREAM: <carry>: Remove openshift-redhat-marketplace catalog tests
2026-07-24 00:15:39 openshift/operator-framework-operator-controller@087501a Kui Wang UPSTREAM: <carry>: config watchnamespace cases
2026-07-24 00:15:40 openshift/operator-framework-operator-controller@e986a41 Xia Zhao UPSTREAM: <carry>: enhance ocp-79770
2026-07-24 00:15:41 openshift/operator-framework-operator-controller@ca0dcd1 Kui Wang UPSTREAM: <carry>: upgrade version support case
2026-07-24 00:15:42 openshift/operator-framework-operator-controller@a586b05 Per Goncalves da Silva UPSTREAM: <carry>: Remove installed condition check from auth preflight test
2026-07-24 00:15:44 openshift/operator-framework-operator-controller@8786c05 Per Goncalves da Silva UPSTREAM: <carry>: Add openshift/api dependency
2026-07-24 00:15:45 openshift/operator-framework-operator-controller@a3425e1 Per Goncalves da Silva UPSTREAM: <carry>: Add boxcutter specific preflight auth test
2026-07-24 00:15:46 openshift/operator-framework-operator-controller@773f3c8 Kui Wang UPSTREAM: <carry>: adjust watchnamespace case based on change
2026-07-24 00:15:48 openshift/operator-framework-operator-controller@6e5861e Camila Macedo UPSTREAM: <carry>: fix(ote): Use as operator-controller dep from root dir
2026-07-24 00:15:49 openshift/operator-framework-operator-controller@bfb77b7 Bruno Andrade UPSTREAM: <carry>: add 83979 automation
2026-07-24 00:15:50 openshift/operator-framework-operator-controller@2d55879 Bruno Andrade UPSTREAM: <carry>: add 85889 automation
2026-07-24 00:15:51 openshift/operator-framework-operator-controller@5bd7e11 Per Goncalves da Silva UPSTREAM: <carry>: Update test-operator startup script to fix pod probe endpoints
2026-07-24 00:15:52 openshift/operator-framework-operator-controller@043cb16 Per Goncalves da Silva UPSTREAM: <carry>: Fix up own-namespace invalid configuration test
2026-07-24 00:15:53 openshift/operator-framework-operator-controller@da8d953 Camila Macedo UPSTREAM: <carry>: Preflight tests use in-cluster catalog and bundles instead of openshift-pipelines-operator-rh
2026-07-24 00:15:54 openshift/operator-framework-operator-controller@9c9b3be Kui Wang UPSTREAM: <carry>: adjust sa and permission test cases per new change from boxcutterruntime
2026-07-24 00:15:55 openshift/operator-framework-operator-controller@0848e4b Camila Macedo UPSTREAM: <carry>: Update OCP catalogs to v4.22
2026-07-24 00:15:57 openshift/operator-framework-operator-controller@a64c39b Camila Macedo UPSTREAM: <carry>: chore(OTE and Default Catalog Tests) Update go and dependencies
2026-07-24 00:15:59 openshift/operator-framework-operator-controller@ebf5161 Jian Zhang UPSTREAM: <carry>: fix 83026 for TP cluster
2026-07-24 00:16:00 openshift/operator-framework-operator-controller@432f3ec Kui Wang UPSTREAM: <carry>: serviceAccount validation unified across all runtimes
2026-07-24 00:16:00 openshift/operator-framework-operator-controller@0c5f694 Stephen Benjamin UPSTREAM: <carry>: Fix OLMv1 test operator to listen on IPv6
2026-07-24 00:16:01 openshift/operator-framework-operator-controller@f1f76ff Camila Macedo UPSTREAM: <carry>: Increase install timeout and add diagnostic logging for CE install tests
2026-07-24 00:16:02 openshift/operator-framework-operator-controller@7a69da8 Evan Hearne UPSTREAM: <carry>: add service account to curl job
2026-07-24 00:16:03 openshift/operator-framework-operator-controller@3255e88 Jian Zhang UPSTREAM: <carry>: update OCP-75441 to support multi-arch
2026-07-24 00:16:04 openshift/operator-framework-operator-controller@f1ed515 Kui Wang UPSTREAM: <carry>: deployment config cases
2026-07-24 00:16:05 openshift/operator-framework-operator-controller@7ba000a Todd Short UPSTREAM: <carry>: Add OTE tests for OLMv1 DeploymentConfig support
2026-07-24 00:16:06 openshift/operator-framework-operator-controller@6a5426f Todd Short UPSTREAM: <carry>: Update openshift/api and client-go
2026-07-24 00:16:07 openshift/operator-framework-operator-controller@f39c7f3 Camila Macedo UPSTREAM: <carry>: Add boxcutter tests
2026-07-24 00:16:08 openshift/operator-framework-operator-controller@eb46fc6 Xia Zhao UPSTREAM: <carry>: enhance QE cases
2026-07-24 00:16:09 openshift/operator-framework-operator-controller@787c756 Daniel Franz UPSTREAM: <carry>: Update quay-operator version to one containing arm64 support
2026-07-24 00:16:10 openshift/operator-framework-operator-controller@da5086b Kui Wang UPSTREAM: <carry>: verify volume/volumeMount override
2026-07-24 00:16:11 openshift/operator-framework-operator-controller@df307bd Jian Zhang UPSTREAM: <carry>: Add long-duration test script and documents
2026-07-24 00:16:12 openshift/operator-framework-operator-controller@4a7d4cb Todd Short UPSTREAM: <carry>: Update grpc in default-catalog-consistency tests
2026-07-24 00:16:14 openshift/operator-framework-operator-controller@07bef4a Camila Macedo UPSTREAM: <carry>: Rename ClusterExtensionRevision to ClusterObjectSet in OTE tests
2026-07-24 00:16:15 openshift/operator-framework-operator-controller@b65aea9 Camila Macedo UPSTREAM: <carry>: Skip incompatible operator test when Boxcutter uses ClusterObjectSet
2026-07-24 00:16:16 openshift/operator-framework-operator-controller@a62aede Bruno Andrade UPSTREAM: <carry>: add ocp-87557
2026-07-24 00:16:17 openshift/operator-framework-operator-controller@6630947 Francesco Giudici UPSTREAM: <carry>: Add fgiudici as reviewer
2026-07-24 00:16:18 openshift/operator-framework-operator-controller@122da91 Camila Macedo UPSTREAM: <carry>: Remove skip for incompatible operator check after rename of CER
2026-07-24 00:16:19 openshift/operator-framework-operator-controller@987c006 Kui Wang UPSTREAM: <carry>: Test empty affinity erasure and cleanup
2026-07-24 00:16:21 openshift/operator-framework-operator-controller@db6d868 Camila Macedo UPSTREAM: <carry>: Fix boxcutter finalizer ResourceNames in preflight test
2026-07-24 00:16:22 openshift/operator-framework-operator-controller@8520c56 Camila Macedo UPSTREAM: <carry>: Expand OTE docs with more comprehensive details
2026-07-24 00:16:23 openshift/operator-framework-operator-controller@accbb54 Todd Short UPSTREAM: <carry>: Disable upstream TLSProfile tests
2026-07-24 00:16:24 openshift/operator-framework-operator-controller@3f1a411 Camila Macedo UPSTREAM: <carry>: OTE: Simplify by remove option to configure tests to run outside of OCP
2026-07-24 00:16:25 openshift/operator-framework-operator-controller@c10ddc8 Camila Macedo UPSTREAM: <carry>: OTE - Make OTE local output easier to read
2026-07-24 00:16:26 openshift/operator-framework-operator-controller@f65f042 Joe Lanford UPSTREAM: <carry>: remove dead e2e registry push job and related variables
2026-07-24 00:16:27 openshift/operator-framework-operator-controller@f6be51a Todd Short UPSTREAM: <carry>: OCPBUGS-62517: Set replicas=1, PDB, and pod anti-affinity for HA topology
2026-07-24 00:16:29 openshift/operator-framework-operator-controller@93b2980 Todd Short UPSTREAM: <carry>: fix(test): drop blocking namespace-deletion wait between both-watch-modes scenarios
2026-07-24 00:16:30 openshift/operator-framework-operator-controller@a611da3 Todd Short UPSTREAM: <carry>: Fix downstream e2e test invocation
2026-07-24 00:16:31 openshift/operator-framework-operator-controller@8446a63 Joe Lanford UPSTREAM: <carry>: Delete openshift/registry.Dockerfile
2026-07-24 00:16:32 openshift/operator-framework-operator-controller@5bee1bf Todd Short UPSTREAM: <carry>: Remove test-experimenal-e2e
2026-07-24 00:16:33 openshift/operator-framework-operator-controller@88dae49 Camila Macedo UPSTREAM: <carry>: Update readme Default Catalog Tests
2026-07-24 00:16:34 openshift/operator-framework-operator-controller@998bb3f Todd Short UPSTREAM: <carry>: add OLMv1 topology-based deployment scaling e2e test
2026-07-24 00:16:35 openshift/operator-framework-operator-controller@c186aae Todd Short UPSTREAM: <carry>: Update dockerfiles to use golang-1.26-release-4.23 builders
2026-07-24 00:16:36 openshift/operator-framework-operator-controller@4351db2 AOS Automation Release Team UPSTREAM: <carry>: Updating ose-olm-operator-controller-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/7691ed4dc0b6585b358f9e73fb736ace9a48a286/images/ose-olm-operator-controller.yml
2026-07-24 00:16:37 openshift/operator-framework-operator-controller@7202e02 AOS Automation Release Team UPSTREAM: <carry>: Updating ose-olm-catalogd-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/7691ed4dc0b6585b358f9e73fb736ace9a48a286/images/ose-olm-catalogd.yml
2026-07-24 00:16:38 openshift/operator-framework-operator-controller@0fd70a8 Todd Short UPSTREAM: <carry>: Update catalogs for 4.23/5.0
2026-07-24 00:16:40 openshift/operator-framework-operator-controller@a41da40 Per G. da Silva UPSTREAM: <carry>: Remove HelmChartSupport feature gate from experimental manifests
2026-07-24 00:16:41 openshift/operator-framework-operator-controller@0f0952e Todd Short UPSTREAM: <carry>: test: add allow-case for operator maxOCPVersion > cluster version
2026-07-24 00:16:42 openshift/operator-framework-operator-controller@fa0c653 Daniel Franz UPSTREAM: <carry>: Add OLMv1 progress deadline QE tests
2026-07-24 00:16:43 openshift/operator-framework-operator-controller@2094c48 Todd Short UPSTREAM: <carry>: Remove stale reviewers/approvers, add trgeiger
2026-07-24 16:44:46 openshift/operator-framework-operator-controller@4afc954 Daniel Franz UPSTREAM: <carry>: Remove openshift/ e2e related to deprecated ServiceAccount usage in ClusterExtension API, Synthetic Permissions, and PreFlight Admissions
2026-07-23 14:47:41 openshift/operator-framework-operator-controller@50b5639 Todd Short UPSTREAM: <carry>: fix(test): update PolarionID:87224 for 4.23/5.0 upgrade boundary

This pull request is expected to merge without any human intervention. If tests are failing here, changes must land upstream to fix any issues so that future downstreaming efforts succeed.

/assign @openshift/openshift-team-operator-runtime

Summary by CodeRabbit

  • Chores
    • Updated underlying Go and Python components to newer versions.
    • Included maintenance updates for monitoring, secure file handling, package management, and regular expression processing.
    • No user-facing features or interface changes were introduced.

dependabot Bot and others added 30 commits July 27, 2026 13:10
Bumps [github.com/prometheus/common](https://github.com/prometheus/common) from 0.69.0 to 0.70.0.
- [Release notes](https://github.com/prometheus/common/releases)
- [Changelog](https://github.com/prometheus/common/blob/main/CHANGELOG.md)
- [Commits](prometheus/common@v0.69.0...v0.70.0)

---
updated-dependencies:
- dependency-name: github.com/prometheus/common
  dependency-version: 0.70.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.21.2 to 3.21.3.
- [Release notes](https://github.com/helm/helm/releases)
- [Commits](helm/helm@v3.21.2...v3.21.3)

---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
  dependency-version: 3.21.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [regex](https://github.com/mrabarnett/mrab-regex) from 2026.6.28 to 2026.7.10.
- [Changelog](https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt)
- [Commits](mrabarnett/mrab-regex@2026.6.28...2026.7.10)

---
updated-dependencies:
- dependency-name: regex
  dependency-version: 2026.7.10
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dtfranz <dfranz@redhat.com>

UPSTREAM: <carry>: Update generate-manifests to handle new directory

The `default` directory was renamed `base`.

Signed-off-by: Todd Short <todd.short@me.com>

The `base` directory was moved to `base\operator-controller`.

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: Drop commitchecker

Signed-off-by: Alexander Greene <greene.al1991@gmail.com>

UPSTREAM: <carry>: Updating ose-olm-operator-controller-container image to be consistent with ART
Reconciling with https://github.com/openshift/ocp-build-data/tree/4022cd290f00a44d667dda03f2d78d84a488c7ed/images/ose-olm-operator-controller.yml

UPSTREAM: <carry>: update owners

* Remove alumni from owners
* Add m1kola to approvers

Signed-off-by: Mikalai Radchuk <mradchuk@redhat.com>

UPSTREAM: <carry>: Add pointer to tooling README

UPSTREAM: <carry>: Disable Validating Admission Policy APIs downstream

Signed-off-by: Mikalai Radchuk <mradchuk@redhat.com>

UPSTREAM: <carry>: Updating ose-olm-operator-controller-container image to be consistent with ART for 4.16
Reconciling with https://github.com/openshift/ocp-build-data/tree/6250d54c4686a708ca5985afb73080e8ca9a1f7f/images/ose-olm-operator-controller.yml

UPSTREAM: <carry>: Enable Validating Admission Policy APIs downstream

* This reverts commit 3f079c4.
* Includes Validating Admission Policy manifests

Signed-off-by: Mikalai Radchuk <mradchuk@redhat.com>

UPSTREAM: <carry>: manifests: set required-scc for openshift workloads

UPSTREAM: <carry>: Updating ose-olm-operator-controller-container image to be consistent with ART for 4.17
Reconciling with https://github.com/openshift/ocp-build-data/tree/4c1326094222f9209876f06833179a1b9178faf7/images/ose-olm-operator-controller.yml

UPSTREAM: <carry>: add everettraven to approvers+reviewers

Signed-off-by: everettraven <everettraven@gmail.com>

UPSTREAM: <carry>: add openshift kustomize overlay

to enable TLS communication with catalogd. Configure the CA certs
using the configmap injection method via service-ca-operator

Signed-off-by: everettraven <everettraven@gmail.com>

UPSTREAM: <carry>: Add tmshort to approvers

Also `s/runtime/framework/g` in the DOWNSTREAM_OWNERS

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: Updating ose-olm-operator-controller-container image to be consistent with ART for 4.18
Reconciling with https://github.com/openshift/ocp-build-data/tree/dd68246f3237db5db458127566fc7b05b55e1660/images/ose-olm-operator-controller.yml

UPSTREAM: <carry>: Properly copy and call kustomize

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: manifests: add hostPath mount for /etc/containers

Signed-off-by: Joe Lanford <joe.lanford@gmail.com>

UPSTREAM: <carry>: Add test-e2e target for downstream Makefile to be run by openshift/release.

Signed-off-by: dtfranz <dfranz@redhat.com>

UPSTREAM: <carry>: Add downstream verify makefile target

Signed-off-by: dtfranz <dfranz@redhat.com>

UPSTREAM: <carry>: openshift: template log verbosity to be managed by cluster-olm-operator

Signed-off-by: Joe Lanford <joe.lanford@gmail.com>

UPSTREAM: <carry>: Add global-pull-secret flag

Pass global-pull-secret to the manager container.

Signed-off-by: Mikalai Radchuk <mradchuk@redhat.com>

UPSTREAM: <carry>: Update openshift CAs to operator-controller

The /run/secrets/kubernetes.io/serviceaccount/ directory is projected
into the pod and contains the following CA certificates:

* configmap/kube-root-ca.crt as ca.crt
* configmap/openshift-service-ca.crt as service-ca.crt

Update the --ca-certs-dir argument to reference the directory.

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: Add HowTo for origin tests

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: Add e2e registry Dockerfile

Signed-off-by: dtfranz <dfranz@redhat.com>

UPSTREAM: <carry>: add nodeSelector and tolerations to operator-controller deployment via kustomize patch

Signed-off-by: everettraven <everettraven@gmail.com>

UPSTREAM: <carry>: namespace: use privileged PSA for audit and warn levels

Signed-off-by: Joe Lanford <joe.lanford@gmail.com>

UPSTREAM: <carry>: Enable downstream e2e

Signed-off-by: dtfranz <dfranz@redhat.com>

UPSTREAM: <carry>: Remove m1kola from owners

Signed-off-by: Mikalai Radchuk <mradchuk@redhat.com>

UPSTREAM: <carry>: Updating ose-olm-operator-controller-container image to be consistent with ART for 4.19
Reconciling with https://github.com/openshift/ocp-build-data/tree/a39508c86497b4e5e463d7b2c78e51e577be9e7d/images/ose-olm-operator-controller.yml

UPSTREAM: <carry>: generate and mount service-ca server cert

Signed-off-by: Joe Lanford <joe.lanford@gmail.com>

UPSTREAM: <carry>: Add support for proxy trustedCAs

Just map the list of trusted ca certs into the deployment

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: Fix error to build the image

Copy correct (new) executable name for operator-controller

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: Fix make verify for mac os envs

Joe Lanford <joe.lanford@gmail.com>

UPSTREAM: <carry>: Move operator-controller openshift files to its own dir

UPSTREAM: <carry>: Upgrade OCP images from 4.18 to 4.19

UPSTREAM: <carry>: Add Openshift's catalogd manifests

- Move to openshift/catalogd the specific manifest under: https://github.com/openshift/operator-framework-catalogd/tree/main/openshift
- Add call to generate catalogd manifest to 'make manifest'. Make verify test is now done for catalogd and operator-controller Openshift's manifests

UPSTREAM: <carry>: resolve issue with pre-mature mounting of trusted CA configmap

Signed-off-by: Joe Lanford <joe.lanford@gmail.com>

UPSTREAM: <carry>: Add /etc/docker to the operator-controller and catalogd deployments

This allows for use of the any image.config.openshift.io trusted CAs

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: fixup catalogd.Dockerfile paths

Signed-off-by: Joe Lanford <joe.lanford@gmail.com>

UPSTREAM: <carry>: Resolve issue with pre-mature mounting of service CA configmap

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: use projected volume for CAs to avoid subPath limitations

Signed-off-by: Joe Lanford <joe.lanford@gmail.com>

UPSTREAM: <carry>: Revert "UPSTREAM: <carry>: use projected volume for CAs to avoid subPath limitations"

This reverts commit 548caa4.

UPSTREAM: <carry>: use projected volume for CAs to avoid subPath limitations

Signed-off-by: Joe Lanford <joe.lanford@gmail.com>

UPSTREAM: <carry>: Remove vet from openshift verify

The `vet` target was removed upstream.

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: Skip another upstream test

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: Cleanup openshift/Makefile by removing no longer required comments regards catalogd e2e tests

UPSTREAM: <carry>: Enable OCP metrics collection by default

Enables OCP to collect Prometheus metrics for both catalogd and
operator-controller by default. This is accomplished
via ServiceMonitor CRs which are now created for both projects.

UPSTREAM: <carry>: Fix catalogd.Dockerfile to use new paths

The root catalogd directory has been removed

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: Update DOWNSTREAM_OWNERS_ALIASES

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: Add openshift node selector annotation

Signed-off-by: Catherine Chan-Tse <cchantse@redhat.com>
(cherry picked from commit 9b4a113)

UPSTREAM: <carry>: Add caalogd-cas-dir option to op-con

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: set the SElinux type

Signed-off-by: Jian Zhang <jiazha@redhat.com>

UPSTREAM: <carry>: Add initial stack to run tests to validate the catalogs

UPSTREAM: <carry>: Add vendor files for the catalog-sync tests

UPSTREAM: <carry>: Bump catalog versions to 4.19

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: revert "Bump catalog versions to 4.19"

This reverts commit a98980b.

UPSTREAM: <carry>: Update HOWTO-origin-tests

techpreview is no longer a required option.

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: [DefaultCatalogTests]: Allow to pass auth path for docker credentials"

UPSTREAM: <carry>: fix: set NoLchown=true to allow image unpack on OCPci

UPSTREAM: <carry>: [DefaultCatalogTests]: Moving parse of ENVVAR to the caller (follow-up 345)

UPSTREAM: <carry>: [Default Catalog]: Create tmp dir to extract layers with right permissions to avoid issues scenarios

UPSTREAM: <carry>: [Default Catalog](cleanp) Remove hack directory which is not used

UPSTREAM: <carry>: Change code implementation to extract layers in OCP env

UPSTREAM: <carry>: Add vendor files for change in the extract code implementation

UPSTREAM: <carry>: [Default Catalog Tests]: Final cleanups and enhancements of initial implementation

UPSTREAM: <carry>: SELinux type for operator-controller

Signed-off-by: Jian Zhang <jiazha@redhat.com>

UPSTREAM: <carry>: Bump catalog versions to 4.19

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: [Default Catalog Consistency Test] (feat) add check for executable files in filesystem

Checks if given paths exist and point to executable files or valid symlinks.

UPSTREAM: <carry>: [Default Catalog Consistency Test]: fix junit output format to allow generate xml

UPSTREAM: <carry>: [Default Catalog Consistency Test] (feat) add check to validate multi-arch support

UPSTREAM: <carry>: [Default Catalog Consistency Test]: Enable CatalogChecks

UPSTREAM: <carry>: [Default Catalog Consistency Test]: Rename Tests suite and small cleanups

UPSTREAM: <carry>: Updating ose-olm-operator-controller-container image to be consistent with ART for 4.20
Reconciling with https://github.com/openshift/ocp-build-data/tree/dfb5c7d531490cfdc61a3b88bc533702b9624997/images/ose-olm-operator-controller.yml

UPSTREAM: <carry>: Updating ose-olm-catalogd-container image to be consistent with ART for 4.20
Reconciling with https://github.com/openshift/ocp-build-data/tree/dfb5c7d531490cfdc61a3b88bc533702b9624997/images/ose-olm-catalogd.yml

UPSTREAM: <carry>: Update e2e registry to use 1.24/4.20

Update the e2e registry Dockerfile to use golang 1.24/OCP 4.20

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: [Catalog Default Tests]: Upgrade go version to 1.24.3, dependencies and fix new lint issue

UPSTREAM: <carry>: Add structure to allow move the orgin tests using OTE

This commit introduces a binary and supporting structure to enable the
execution of OpenShift origin (olmv1) tests using the Open Test Environment (OTE).

It lays the groundwork for moving origin test in openshift/origin to
be executed from this repository using OTE.

UPSTREAM: <carry>: Add support for experimental manifests

Update the openshift kustomize configuration for both operator-controller
and catalogd.

Update the manifest generation scripts to put the core generation code
into a function (ignore-whitespace will help with the review), so that
it can be called twice; once for standard, and once for experimental.

Move around some of the kustomization directives to
* Create a patch kustomization (Component) file and move the patch directives from olmv1-ns there. This allows it to be referenced from a different directory.
* Add a kustomization file for tusted-ca. This allows it to be referenced from a different directory.
* Move the setting of the namePrefix for operator-controller; this makes the generation compatible with upstream feature components.
* Define experimental kustomization files that reference existing components.
* Reference the correct CRDs (standard or experimental).
* Add references to upstream feature components into the experimental manifests.

This *will* add `--feature-gates` options from the upstream feature
components to the experimental manifests. The cluster-olm-operator will
strip those arguments from the deployments before adding the enabled
feature gates.

Update the Dockerfiles to include the experimental manifests and a copy
script (`cp-manifests`) into the image containers. The complexity of
having multiple sets of manifests mean that the simple initContainer
copy mechanism found in cluster-olm-operator is no longer sufficient.

This attempts to keep backwards compatibility with older versions of
cluster-olm-operator, specifically by keeping the original (standard)
manifests in the original location, and adding the experimental
manifests in a new directory. The new `cp-manifests` script is used
by newer versions of cluster-olm-operator.

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: [OTE] - chore: follow up openshift#383 – remove unreachable target call

UPSTREAM: <carry>: Remove build of test image registry

Upstream now uses a different image

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: Add test-experimental-e2e target to openshift Makefile

This adds a test-experimental-e2e target to allow the CI to run the
experimental e2e test.

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: [OTE]: Add binary in the operator controller image to allow proper integration with OCP tests

UPSTREAM: <carry>: Fix experimental manifest copying

The standard manifest was being copied rather than the experimental
manifest. This meant that the expected feature-flags are not present.
This is failing now that we are doing a check for those feature-flags.

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: Update manifest generation for upstream rbac/webhooks

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: [OTE] - Add tracking mechanism

UPSTREAM: <carry>: Update OTE dep to get fix

UPSTREAM: <carry>: [OTE] Add Readme

UPSTREAM: <carry>: set GIT_COMMIT env from SOURCE_GIT_COMMIT in Dockerfiles for operator-controller and catalogd

Signed-off-by: Rashmi Gottipati <chowdary.grashmi@gmail.com>

UPSTREAM: <carry>: add openshift specific build target to pass commit info downstream

Signed-off-by: Ankita Thomas <ankithom@redhat.com>

UPSTREAM: <carry>: add source commit into binaries when linking

- Removes extra GIT_COMMIT set
- fixup Dockerfiles after rebase
- consider "" unset so build-info can fill commit/date
- double quote go flags & honor GIT_COMMIT if set
- improve robustness of build-info parsing
- Trim whitespace on all version fields
- isUnset and valueOrUnknown now call strings.TrimSpace
- Avoid clobbering values injected via ldflags
- set repoState from build-info only when repoState is still unset
- set version from build-info only when unset and build-info value is non-empty

UPSTREAM: <carry>: OTE add first test from openshift/origin olmv1.go

UPSTREAM: <carry>: Migrate tasks from openshift/origin olm v1.go file which are remaining

This commit moves the final OLMv1 tests from openshift/origin/test/extended/olm/olmv1.go to their proper location in this repository. This migration is part of a larger effort to streamline development by co-locating tests with the component they validate. This will reduce CI overhead and allow for faster, more atomic changes.

Assisted-by: Gemini

UPSTREAM: <carry>: OTE - How to test locally with OCP instances

UPSTREAM: <carry>: [OTE] Refac: refac helper and olmv1 test to create namespace instead to use pre-existent

UPSTREAM: <carry>: [OTE] add webhook tests

Migrates OLMv1 webhook operator tests from using external YAML files to
defining resources in Go structs. This change removes file dependencies,
improving test reliability and simplifying test setup.

The migration is a refactoring of code from openshift/origin#30059.
The new code uses better naming conventions and adapts the tests to work
with a controller-runtime client, enhancing test consistency and maintainability.

The migration covers all core test scenarios:
- Validating, mutating, and conversion webhooks.
- Certificate and secret rotation tolerance.

Assisted-by: Gemini

UPSTREAM: <carry>: OTE: rewrite the upgrade incompatible operator test

This test replaces the existing upgrade incompatible test.
The main change is that operator and catalog bundles are created on-the-fly
to support OCP 4.20. This means we are no longer dependent on public
operators for this test.

This creates new bundles in the OCP ImageRegistry, this requires using
a number of OCP APIs, including using a raw API URL to invoke the build.
This is done by invoking an external k8s client (either `oc` or `kubectl`),
and passing it a tarball of the bundle to be created. So, it can't be done
by the golang k8sClient normally available (i.e. the create input is a
tarball not a YAML file).

This introduces the use of go-bindata to store the bundle contents.

It also pulls in openshift mage, buld and operator APIs.

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: Handle service-ca cert availability/rotation

There is problem when the service-ca certificate is not available at pod start.
This is an issue because the SystemCertPool is created from SSL_CERT_DIR,
which may include the empty service-ca. The SystemCertPool is never regenerated
during the lifetime of the program execution, so it will never get updated when
the service-ca is filled. Thus, we need to use --pull-cas-dir to reference the
CAs that we want to use. This will also allow OLMv1 to reload the service-ca
when it is reloaded (after 2 years, mind you). Removing the SSL_CERT_DIR setting,
and adding the --pull-cas-dir flag ought to be equivalent to what we have now
(i.e. SSL_CERT_DIR and no --pull-cas-dir), except that rotation will be handled
better.

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: [OTE] add webhook tests

Revert "UPSTREAM: <carry>: [OTE] add webhook tests"

This reverts commit 9963614.

UPSTREAM: <carry>: Upgrade OCP Catalog images from 4.19 to 4.20

UPSTREAM: <carry>: Remove bindata generation from build

Using go-bindata is causing problems with ART builds.

This removes the use of go-bindata from the builds.

This will subsequently require that users MANUALLY run
the `bindata` target to refresh the bindata, or use
the `build-update` target.

This is a quickfix to put out the fire.

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: [OTE] Add webhook tests

- Add dumping of container logs and `kubectl describe pods` output for better diagnostics.
- Include targeted certificate details dump (`tls.crt` parse) when failures occur.
- Add additional check to verify webhook responsiveness after certificate rotation.

This change is a refactor of code from openshift/origin#30059.

Assisted-by: Gemini

UPSTREAM: <carry>: OTE add logs and dumps for olmv1 test and fix helper for clusterextensions

UPSTREAM: <carry>: [OTE] Migrate preflight checks from openshift/origin

Migrated OLMv1 operator preflight checks from using external YAML files to
defining ClusterRole permissions directly in Go structs. This improves test
reliability and simplifies test setup by removing file dependencies.

The changes ensure precise replication of original test scenarios,
including specific permission omissions for services, create verbs,
ClusterRoleBindings, ConfigMap resourceNames, and escalate/bind verbs.

Assisted-by: Gemini

UPSTREAM: <carry>: [OTE] Add webhook to validate openshift-service-ca certificate rotation

This change is a refactor of code from openshift/origin#30059.

Assisted-by: Gemini

UPSTREAM: <carry>: Adds ResourceVersion checks to the tls secret deletion test, mirroring the logic used in the certificate rotation test. This makes the test more robust by ensuring a new secret is created, not just that an existing one is still present.

UPSTREAM: <carry>: [OTE] - Readme:Add info to help use payload-aggregate with new tests

UPSTREAM: <carry>: remove obsolete owners

Signed-off-by: grokspawn <jordan@nimblewidget.com>

UPSTREAM: <carry>: [OTE] add catalog tests from openshift/origin

This commit migrates the olmv1_catalog set of tests from openshift/origin
to OTE as part the broad effort to migrate all tests.

Assisted-by: Gemini

UPSTREAM: <carry>: Migrate single/own namespace tests

This commit migrates the OLMv1 single and own namespace watch mode tests from openshift/origin/test/extended/olm/olmv1-singleownnamespace.go to this repository. This is part of the effort to move component-specific tests into their respective downstream locations.

Assisted-by: Gemini

UPSTREAM: <carry>: Adds ResourceVersion checks to the tls secret deletion test, mirroring the logic used in the certificate rotation test. This makes the test more robust by ensuring a new secret is created, not just that an existing one is still present.

This reverts commit 0bb1953.

UPSTREAM: <carry>: [OTE] Add webhook to validate openshift-service-ca certificate rotation

This reverts commit e9e3220.

UPSTREAM: <carry>: Ensure unique name for bad-catalog tests

UPSTREAM: <carry>: Revert "Handle service-ca cert availability/rotation"

This reverts commit 9cc13d8.

UPSTREAM: <carry>: grant QE approver permission for OTE

UPSTREAM: <carry>: Update webhook ote tests to use latest webhook-operator

Signed-off-by: Per Goncalves da Silva <pegoncal@redhat.com>

UPSTREAM: <carry>: update operator-controller to v1.5.1

UPSTREAM: <carry>: configure watchnamespace using spec.config for OTE tests

UPSTREAM: <carry>: add jiazha to approvers

UPSTREAM: <carry>: Create combined manifests for comparison

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: Use Helm charts for openshift manifests

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: add support for tests-private cases and add the case

UPSTREAM: <carry>: Fix cp-manifests copying of helm charts

The method used to copy the helm charts is including an extra `helm`
directory in the destination path, that is making the cluster-olm-operator
code just a bit more complicated than it needs to be.

This fixes the copy location.

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: Remove kustomize manifests from images and repo

Now that helm manifests are being used to dynamically generate the
manifests, the pre-generated manifests are no longer needed. So,
we can remove them from the repo and the images.

However, because we still want to verify the manifests are "good",
we are still creating a "single-file" version of the manifests
for verification purposes, and to allow us to see what changes
are happening to the manifests (from upstream and/or downstream
sources).

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: Add pedjak and trgeiger as reviewers

UPSTREAM: <carry>: migrate more cases from tests-private and enhance suites with filters

UPSTREAM: <carry>: Updating ose-olm-operator-controller-container image to be consistent with ART for 4.21
Reconciling with https://github.com/openshift/ocp-build-data/tree/4fbe3fab45239dc4be6f5d9d98a0bf36e0274ec9/images/ose-olm-operator-controller.yml

UPSTREAM: <carry>: Updating ose-olm-catalogd-container image to be consistent with ART for 4.21
Reconciling with https://github.com/openshift/ocp-build-data/tree/4fbe3fab45239dc4be6f5d9d98a0bf36e0274ec9/images/ose-olm-catalogd.yml

UPSTREAM: <carry>: OTE: Enable disconnected environment and build test operator controller image

Signed-off-by: Per Goncalves da Silva <pegoncal@redhat.com>

UPSTREAM: <carry>: for incompatible test add func to wait builder and deployer SA creation by OCP controller

UPSTREAM: <carry>: Fix VERSION replacement in catalog bindata

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: check kubeconfig only run-test and run-suite

UPSTREAM: <carry>: Clean up cp-manifests

There is no longer a need to copy conditionally

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: Update does-not-exist and simple install to work in a disconnected environment

Signed-off-by: Todd Short <todd.short@me.com>

UPSTREAM: <carry>: support webhook case in disconnected

UPSTREAM: <carry>: Consolidate build API

This consolidates the in-cluster building of a bundle and catalog.
The catalog and bundle bindata are inputs, along with a set of
replacements so that catalog and bundle templates can be used to
create the images.

This can be done in the BeforeEach() for a set of tests that use the
same data.

Signed-off-by: Todd Short <todd.short@me.com>
…images from openshift/catalogd/manifests.yaml
Signed-off-by: Todd Short <todd.short@me.com>
Signed-off-by: Todd Short <todd.short@me.com>
…uess and waiting for k8s cleanups

Co-Author: kuiwang@redhat.com
… format

Fix k8s.io/kubernetes replace version from v1.30.1-0... to v0.0.0-... format to resolve
bumper tool verification failures. Add hack/ocp-replace.sh script to manage OCP fork
replaces properly.

Assisted-by: Cursor
🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
The current pod simply does a `sleep 1000`, which means that the startup,
liveness and readiness probes all fail. Use a busybox containter to run a
simple script and httpd server to emulate the probes.
Signed-off-by: Todd Short <todd.short@me.com>
Signed-off-by: Rashmi Gottipati <rgottipa@redhat.com>
tmshort and others added 18 commits July 28, 2026 00:13
- Replace broken test-experimental-e2e target (test/experimental-e2e no
  longer exists) with /bin/true so triggered jobs always succeed
- Pass -timeout=60m to go test; the previous invocation relied on Go's
  10m default which is too short for BoxcutterRuntime clusters
- Set E2E_STEP_TIMEOUT=15m; BoxcutterRuntime applies resources through
  sequential phases (CRD must reach Established before the deploy phase
  starts), making installations slower than the upstream 5m default
- Skip ~@CatalogdHA scenarios (require multiple catalogd replicas not
  present in standard topology)
- Skip ~@ProgressDeadline scenarios (require progressDeadlineMinutes < 10
  but the OpenShift CRD enforces a minimum of 10)
- Skip ~@httpproxy scenarios (too disruptive to cluster networking)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Todd Short <tshort@redhat.com>
The e2e-test-registry image is no longer built by CI after
openshift/release#78581 removed it from the CI config. The dynamic
per-scenario catalog system replaced the pre-built registry image,
making this Dockerfile dead code.
It's no longer bring used.

Signed-off-by: Todd Short <tshort@redhat.com>
Adds a new test that verifies cluster-olm-operator correctly configures
operator-controller and catalogd deployments based on the cluster's
control plane topology:
- HA topologies (HighlyAvailable, HighlyAvailableArbiter, DualReplica):
  replicas=2 with a PodDisruptionBudget present
- Non-HA topologies (SingleReplica/SNO, External): replicas=1, no PDB

Also registers policyv1 in the test scheme to support PDB list queries.

Assisted-by: claude
Signed-off-by: Todd Short <tshort@redhat.com>
… builders

Signed-off-by: Todd Short <tshort@redhat.com>
Set catalog image tags to v5.0 for the 4.23/5.0 release.

Dynamically discover an installable package from the serving catalogs
instead of hardcoding quay-operator v3.13.10, preferring quay-operator,
cluster-logging, serverless-operator, logic-operator in that order then
alling back to the first available package.

Signed-off-by: Todd Short <tshort@redhat.com>
…ntal manifests

HelmChartSupport was removed upstream in dbc9b4a but the downstream
experimental.yaml values file and its generated manifest still referenced
it, causing operator-controller to crash on startup with:

  invalid argument "HelmChartSupport=false" for "--feature-gates" flag:
  unrecognized feature gate: HelmChartSupport

This made the OLM cluster operator Degraded/Unavailable and caused cluster
installation to time out (exit code 6).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…cluster version

Add a second ReleaseGate-eligible OTE test verifying that an operator
whose olm.maxOpenShiftVersion exceeds the current cluster version does
not block cluster upgrade (InstalledOLMOperatorsUpgradeable stays True).

The existing test only covered the blocking path (maxOCPVersion ==
current version → False). This covers the complementary allow path
(maxOCPVersion == next minor → True), directly exercising the
normalization logic introduced for the 4.23/5.0 co-release boundary.

A nextMinorVersion() helper mirrors the 4.23→5.1 special case so the
bundle annotation is always set to the correct next upgrade target.

Run 'make build-update' to register the new allow-case test in the
extension metadata after adding it to olmv1-incompatible.go.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Todd Short <tshort@redhat.com>
Automate the ClusterExtension rollout failure coverage for OCP-88331 and OCP-88332 by building in-cluster bundle and catalog images for successful and failing bundle versions.

The new QE specs verify ProgressDeadlineExceeded on an initial failed rollout and ProbeFailure while upgrading to a bad revision under the BoxCutter runtime.

Signed-off-by: Daniel Franz <dfranz@redhat.com>
Co-authored-by: Bruno Andrade <bruno.balint@gmail.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Todd Short <tshort@redhat.com>
…eAccount usage in ClusterExtension API, Synthetic Permissions, and PreFlight Admissions

Signed-off-by: Daniel Franz <dfranz@redhat.com>
…grade boundary

Fix GetNextMinorVersion to return "5.1" for 4.23 clusters instead of
"4.24": OCP 4.23 and 5.0 are co-released equivalents whose only upgrade
target is 5.1.

Remove the redundant `&& strings.Contains(message, "5")` guard from the
Upgradeable message poll — the expectedPattern built from
GetNextMinorVersion now encodes the full version string and is
sufficient on its own.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
@openshift-bot openshift-bot added tide/merge-method-merge Denotes a PR that should use a standard merge by tide when it merges. kind/sync labels Jul 28, 2026
@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Jul 28, 2026
@openshift-bot openshift-bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 28, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@openshift-bot: This pull request explicitly references no jira issue.

Details

In response to this:

The downstream repository has been updated with the following following upstream commits:

Date Commit Author Message
2026-07-27 19:35:10 operator-framework/operator-controller@9111029 dependabot[bot] 🌱 Bump regex from 2026.6.28 to 2026.7.10 (#2834)
2026-07-27 14:28:50 operator-framework/operator-controller@66fcc86 dependabot[bot] 🌱 Bump helm.sh/helm/v3 from 3.21.2 to 3.21.3 (#2833)
2026-07-27 13:10:19 operator-framework/operator-controller@d0757b5 dependabot[bot] 🌱 Bump github.com/prometheus/common from 0.69.0 to 0.70.0 (#2832)

The vendor/ directory has been updated and the following commits were carried:

Date Commit Author Message
2026-07-24 00:14:47 openshift/operator-framework-operator-controller@0ccc077 dtfranz UPSTREAM: <carry>: Add OpenShift specific files
2026-07-24 00:14:49 openshift/operator-framework-operator-controller@60ede30 Camila Macedo UPSTREAM: <carry>: Add new tests for single/own namespaces install modes
2026-07-24 00:14:50 openshift/operator-framework-operator-controller@ee96dc1 Camila Macedo UPSTREAM: <carry>: Upgrade OCP image from 4.20 to 4.21
2026-07-24 00:14:51 openshift/operator-framework-operator-controller@80d97f8 Camila Macedo UPSTREAM: <carry>: [Default Catalog Tests] - Change logic to get ocp images from openshift/catalogd/manifests.yaml
2026-07-24 00:14:52 openshift/operator-framework-operator-controller@071e814 Todd Short UPSTREAM: <carry>: Update OCP catalogs to v4.21
2026-07-24 00:14:53 openshift/operator-framework-operator-controller@f80b47a Kui Wang UPSTREAM: <carry>: support singleown cases in disconnected
2026-07-24 00:14:54 openshift/operator-framework-operator-controller@7d03123 Kui Wang UPSTREAM: <carry>: fix cases 81696 and 74618 for product code changes
2026-07-24 00:14:55 openshift/operator-framework-operator-controller@ea677ef Camila Macedo UPSTREAM: <carry>: Define Default timeouts and apply their usage accross to avoid flakes
2026-07-24 00:14:56 openshift/operator-framework-operator-controller@4922ed2 Todd Short UPSTREAM: <carry>: Update to new feature-gate options in helm
2026-07-24 00:14:57 openshift/operator-framework-operator-controller@aa62f33 Camila Macedo UPSTREAM: <carry>: Fix flake for single/own ns tests by ensuring uniquess and waiting for k8s cleanups
2026-07-24 00:14:58 openshift/operator-framework-operator-controller@2f0f531 Camila Macedo UPSTREAM: <carry>: [OTE]: Enhance single/own ns based on review comments ( Follow-Up of: 714977c )
2026-07-24 00:14:59 openshift/operator-framework-operator-controller@36d61ea Kui Wang UPSTREAM: <carry>: Update OwnSingle template to use spec.config.inline.watchNamespace
2026-07-24 00:15:01 openshift/operator-framework-operator-controller@70bfc13 Camila Macedo UPSTREAM: <carry>: [OTE]: Add webhook cleanup validation on extension uninstall
2026-07-24 00:15:02 openshift/operator-framework-operator-controller@ed7b8d8 Kui Wang UPSTREAM: <carry>: Add [OTP] to migrated cases
2026-07-24 00:15:04 openshift/operator-framework-operator-controller@423ec6f Camila Macedo UPSTREAM: <carry>: [OTE]: Upgrade dependencies used
2026-07-24 00:15:06 openshift/operator-framework-operator-controller@5d0888e Camila Macedo UPSTREAM: <carry>: fix(OTE): fix OpenShift Kubernetes replace version format
2026-07-24 00:15:07 openshift/operator-framework-operator-controller@116d217 Camila Macedo UPSTREAM: <carry>: [Default Catalog Tests] Upgrade go 1.24.6 and dependencies
2026-07-24 00:15:08 openshift/operator-framework-operator-controller@04b0d8b Kui Wang UPSTREAM: <carry>: add disconnected environment support with custom prow job for migrated qe cases
2026-07-24 00:15:09 openshift/operator-framework-operator-controller@ba7f06b Jian Zhang UPSTREAM: <carry>: migrate jiazha test cases to OTE
2026-07-24 00:15:10 openshift/operator-framework-operator-controller@feaf9a0 Xia Zhao UPSTREAM: <carry>: migrate clustercatalog case to ote
2026-07-24 00:15:11 openshift/operator-framework-operator-controller@4ac2b13 Kui Wang UPSTREAM: <carry>: migrate olmv1 QE stress cases
2026-07-24 00:15:12 openshift/operator-framework-operator-controller@e22dafd Todd Short UPSTREAM: <carry>: Use busybox/httpd to simulate probes
2026-07-24 00:15:13 openshift/operator-framework-operator-controller@f97eae3 Xia Zhao UPSTREAM: <carry>: migrate olmv1 QE cases
2026-07-24 00:15:14 openshift/operator-framework-operator-controller@c3019f6 Kui Wang UPSTREAM: <carry>: add agent for olmv1 qe cases
2026-07-24 00:15:15 openshift/operator-framework-operator-controller@8351259 Todd Short UPSTREAM: <carry>: Disable upstream PodDisruptionBudget
2026-07-24 00:15:16 openshift/operator-framework-operator-controller@a923158 Rashmi Gottipati UPSTREAM: <carry>: Add AGENTS.md for AI code contributions
2026-07-24 00:15:17 openshift/operator-framework-operator-controller@744f8e5 Rashmi Gottipati UPSTREAM: <carry>: address review comments through addl prompts
2026-07-24 00:15:18 openshift/operator-framework-operator-controller@9473412 Rashmi Gottipati UPSTREAM: <carry>: addressing some more review comments
2026-07-24 00:15:18 openshift/operator-framework-operator-controller@82649eb Rashmi Gottipati UPSTREAM: <carry>: remove DCO line
2026-07-24 00:15:19 openshift/operator-framework-operator-controller@bf38ba1 Bruno Andrade UPSTREAM: <carry>: migrate bandrade test cases to OTE
2026-07-24 00:15:21 openshift/operator-framework-operator-controller@04a1f5f Bruno Andrade UPSTREAM: <carry>: update metadata
2026-07-24 00:15:22 openshift/operator-framework-operator-controller@42205b5 Bruno Andrade UPSTREAM: <carry>: remove originalName
2026-07-24 00:15:23 openshift/operator-framework-operator-controller@6a979e3 Jian Zhang UPSTREAM: <carry>: update 80458's timeout to 180s
2026-07-24 00:15:24 openshift/operator-framework-operator-controller@d052148 Jian Zhang UPSTREAM: <carry>: update 83026 to specify the clustercatalog
2026-07-24 00:15:25 openshift/operator-framework-operator-controller@c0ee6fc Catherine Chan-Tse UPSTREAM: <carry>: Update to golang 1.25 and ocp 4.22
2026-07-24 00:15:27 openshift/operator-framework-operator-controller@292fae2 Predrag Knezevic UPSTREAM: <carry>: Use oc client for running e2e tests
2026-07-24 00:15:28 openshift/operator-framework-operator-controller@1f586af Predrag Knezevic UPSTREAM: <carry>: Run upstream e2e tests tagged with @catalogd-update
2026-07-24 00:15:29 openshift/operator-framework-operator-controller@12b2772 Kui Wang UPSTREAM: <carry>: enhance case to make it more stable
2026-07-24 00:15:30 openshift/operator-framework-operator-controller@a6c611c Evan Hearne UPSTREAM: <carry>: add service account to curl job
2026-07-24 00:15:32 openshift/operator-framework-operator-controller@d5db55a Evan Hearne UPSTREAM: <carry>: move sa creation out of buildCurlJob()
2026-07-24 00:15:33 openshift/operator-framework-operator-controller@e358b4e Evan Hearne UPSTREAM: <carry>: comment out delete service account
2026-07-24 00:15:34 openshift/operator-framework-operator-controller@e18c52a Evan Hearne UPSTREAM: <carry>: move defercleanup for sa for LIFO
2026-07-24 00:15:35 openshift/operator-framework-operator-controller@0864627 Evan Hearne UPSTREAM: <carry>: add polling so job fully deleted before proceed
2026-07-24 00:15:36 openshift/operator-framework-operator-controller@b00b068 Luke Meyer UPSTREAM: <carry>: Revert "Merge pull request #594 from ehearne-redhat/add-service-account-curl-job"
2026-07-24 00:15:38 openshift/operator-framework-operator-controller@3a55c99 Camila Macedo UPSTREAM: <carry>: Remove openshift-redhat-marketplace catalog tests
2026-07-24 00:15:39 openshift/operator-framework-operator-controller@087501a Kui Wang UPSTREAM: <carry>: config watchnamespace cases
2026-07-24 00:15:40 openshift/operator-framework-operator-controller@e986a41 Xia Zhao UPSTREAM: <carry>: enhance ocp-79770
2026-07-24 00:15:41 openshift/operator-framework-operator-controller@ca0dcd1 Kui Wang UPSTREAM: <carry>: upgrade version support case
2026-07-24 00:15:42 openshift/operator-framework-operator-controller@a586b05 Per Goncalves da Silva UPSTREAM: <carry>: Remove installed condition check from auth preflight test
2026-07-24 00:15:44 openshift/operator-framework-operator-controller@8786c05 Per Goncalves da Silva UPSTREAM: <carry>: Add openshift/api dependency
2026-07-24 00:15:45 openshift/operator-framework-operator-controller@a3425e1 Per Goncalves da Silva UPSTREAM: <carry>: Add boxcutter specific preflight auth test
2026-07-24 00:15:46 openshift/operator-framework-operator-controller@773f3c8 Kui Wang UPSTREAM: <carry>: adjust watchnamespace case based on change
2026-07-24 00:15:48 openshift/operator-framework-operator-controller@6e5861e Camila Macedo UPSTREAM: <carry>: fix(ote): Use as operator-controller dep from root dir
2026-07-24 00:15:49 openshift/operator-framework-operator-controller@bfb77b7 Bruno Andrade UPSTREAM: <carry>: add 83979 automation
2026-07-24 00:15:50 openshift/operator-framework-operator-controller@2d55879 Bruno Andrade UPSTREAM: <carry>: add 85889 automation
2026-07-24 00:15:51 openshift/operator-framework-operator-controller@5bd7e11 Per Goncalves da Silva UPSTREAM: <carry>: Update test-operator startup script to fix pod probe endpoints
2026-07-24 00:15:52 openshift/operator-framework-operator-controller@043cb16 Per Goncalves da Silva UPSTREAM: <carry>: Fix up own-namespace invalid configuration test
2026-07-24 00:15:53 openshift/operator-framework-operator-controller@da8d953 Camila Macedo UPSTREAM: <carry>: Preflight tests use in-cluster catalog and bundles instead of openshift-pipelines-operator-rh
2026-07-24 00:15:54 openshift/operator-framework-operator-controller@9c9b3be Kui Wang UPSTREAM: <carry>: adjust sa and permission test cases per new change from boxcutterruntime
2026-07-24 00:15:55 openshift/operator-framework-operator-controller@0848e4b Camila Macedo UPSTREAM: <carry>: Update OCP catalogs to v4.22
2026-07-24 00:15:57 openshift/operator-framework-operator-controller@a64c39b Camila Macedo UPSTREAM: <carry>: chore(OTE and Default Catalog Tests) Update go and dependencies
2026-07-24 00:15:59 openshift/operator-framework-operator-controller@ebf5161 Jian Zhang UPSTREAM: <carry>: fix 83026 for TP cluster
2026-07-24 00:16:00 openshift/operator-framework-operator-controller@432f3ec Kui Wang UPSTREAM: <carry>: serviceAccount validation unified across all runtimes
2026-07-24 00:16:00 openshift/operator-framework-operator-controller@0c5f694 Stephen Benjamin UPSTREAM: <carry>: Fix OLMv1 test operator to listen on IPv6
2026-07-24 00:16:01 openshift/operator-framework-operator-controller@f1f76ff Camila Macedo UPSTREAM: <carry>: Increase install timeout and add diagnostic logging for CE install tests
2026-07-24 00:16:02 openshift/operator-framework-operator-controller@7a69da8 Evan Hearne UPSTREAM: <carry>: add service account to curl job
2026-07-24 00:16:03 openshift/operator-framework-operator-controller@3255e88 Jian Zhang UPSTREAM: <carry>: update OCP-75441 to support multi-arch
2026-07-24 00:16:04 openshift/operator-framework-operator-controller@f1ed515 Kui Wang UPSTREAM: <carry>: deployment config cases
2026-07-24 00:16:05 openshift/operator-framework-operator-controller@7ba000a Todd Short UPSTREAM: <carry>: Add OTE tests for OLMv1 DeploymentConfig support
2026-07-24 00:16:06 openshift/operator-framework-operator-controller@6a5426f Todd Short UPSTREAM: <carry>: Update openshift/api and client-go
2026-07-24 00:16:07 openshift/operator-framework-operator-controller@f39c7f3 Camila Macedo UPSTREAM: <carry>: Add boxcutter tests
2026-07-24 00:16:08 openshift/operator-framework-operator-controller@eb46fc6 Xia Zhao UPSTREAM: <carry>: enhance QE cases
2026-07-24 00:16:09 openshift/operator-framework-operator-controller@787c756 Daniel Franz UPSTREAM: <carry>: Update quay-operator version to one containing arm64 support
2026-07-24 00:16:10 openshift/operator-framework-operator-controller@da5086b Kui Wang UPSTREAM: <carry>: verify volume/volumeMount override
2026-07-24 00:16:11 openshift/operator-framework-operator-controller@df307bd Jian Zhang UPSTREAM: <carry>: Add long-duration test script and documents
2026-07-24 00:16:12 openshift/operator-framework-operator-controller@4a7d4cb Todd Short UPSTREAM: <carry>: Update grpc in default-catalog-consistency tests
2026-07-24 00:16:14 openshift/operator-framework-operator-controller@07bef4a Camila Macedo UPSTREAM: <carry>: Rename ClusterExtensionRevision to ClusterObjectSet in OTE tests
2026-07-24 00:16:15 openshift/operator-framework-operator-controller@b65aea9 Camila Macedo UPSTREAM: <carry>: Skip incompatible operator test when Boxcutter uses ClusterObjectSet
2026-07-24 00:16:16 openshift/operator-framework-operator-controller@a62aede Bruno Andrade UPSTREAM: <carry>: add ocp-87557
2026-07-24 00:16:17 openshift/operator-framework-operator-controller@6630947 Francesco Giudici UPSTREAM: <carry>: Add fgiudici as reviewer
2026-07-24 00:16:18 openshift/operator-framework-operator-controller@122da91 Camila Macedo UPSTREAM: <carry>: Remove skip for incompatible operator check after rename of CER
2026-07-24 00:16:19 openshift/operator-framework-operator-controller@987c006 Kui Wang UPSTREAM: <carry>: Test empty affinity erasure and cleanup
2026-07-24 00:16:21 openshift/operator-framework-operator-controller@db6d868 Camila Macedo UPSTREAM: <carry>: Fix boxcutter finalizer ResourceNames in preflight test
2026-07-24 00:16:22 openshift/operator-framework-operator-controller@8520c56 Camila Macedo UPSTREAM: <carry>: Expand OTE docs with more comprehensive details
2026-07-24 00:16:23 openshift/operator-framework-operator-controller@accbb54 Todd Short UPSTREAM: <carry>: Disable upstream TLSProfile tests
2026-07-24 00:16:24 openshift/operator-framework-operator-controller@3f1a411 Camila Macedo UPSTREAM: <carry>: OTE: Simplify by remove option to configure tests to run outside of OCP
2026-07-24 00:16:25 openshift/operator-framework-operator-controller@c10ddc8 Camila Macedo UPSTREAM: <carry>: OTE - Make OTE local output easier to read
2026-07-24 00:16:26 openshift/operator-framework-operator-controller@f65f042 Joe Lanford UPSTREAM: <carry>: remove dead e2e registry push job and related variables
2026-07-24 00:16:27 openshift/operator-framework-operator-controller@f6be51a Todd Short UPSTREAM: <carry>: OCPBUGS-62517: Set replicas=1, PDB, and pod anti-affinity for HA topology
2026-07-24 00:16:29 openshift/operator-framework-operator-controller@93b2980 Todd Short UPSTREAM: <carry>: fix(test): drop blocking namespace-deletion wait between both-watch-modes scenarios
2026-07-24 00:16:30 openshift/operator-framework-operator-controller@a611da3 Todd Short UPSTREAM: <carry>: Fix downstream e2e test invocation
2026-07-24 00:16:31 openshift/operator-framework-operator-controller@8446a63 Joe Lanford UPSTREAM: <carry>: Delete openshift/registry.Dockerfile
2026-07-24 00:16:32 openshift/operator-framework-operator-controller@5bee1bf Todd Short UPSTREAM: <carry>: Remove test-experimenal-e2e
2026-07-24 00:16:33 openshift/operator-framework-operator-controller@88dae49 Camila Macedo UPSTREAM: <carry>: Update readme Default Catalog Tests
2026-07-24 00:16:34 openshift/operator-framework-operator-controller@998bb3f Todd Short UPSTREAM: <carry>: add OLMv1 topology-based deployment scaling e2e test
2026-07-24 00:16:35 openshift/operator-framework-operator-controller@c186aae Todd Short UPSTREAM: <carry>: Update dockerfiles to use golang-1.26-release-4.23 builders
2026-07-24 00:16:36 openshift/operator-framework-operator-controller@4351db2 AOS Automation Release Team UPSTREAM: <carry>: Updating ose-olm-operator-controller-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/7691ed4dc0b6585b358f9e73fb736ace9a48a286/images/ose-olm-operator-controller.yml
2026-07-24 00:16:37 openshift/operator-framework-operator-controller@7202e02 AOS Automation Release Team UPSTREAM: <carry>: Updating ose-olm-catalogd-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/7691ed4dc0b6585b358f9e73fb736ace9a48a286/images/ose-olm-catalogd.yml
2026-07-24 00:16:38 openshift/operator-framework-operator-controller@0fd70a8 Todd Short UPSTREAM: <carry>: Update catalogs for 4.23/5.0
2026-07-24 00:16:40 openshift/operator-framework-operator-controller@a41da40 Per G. da Silva UPSTREAM: <carry>: Remove HelmChartSupport feature gate from experimental manifests
2026-07-24 00:16:41 openshift/operator-framework-operator-controller@0f0952e Todd Short UPSTREAM: <carry>: test: add allow-case for operator maxOCPVersion > cluster version
2026-07-24 00:16:42 openshift/operator-framework-operator-controller@fa0c653 Daniel Franz UPSTREAM: <carry>: Add OLMv1 progress deadline QE tests
2026-07-24 00:16:43 openshift/operator-framework-operator-controller@2094c48 Todd Short UPSTREAM: <carry>: Remove stale reviewers/approvers, add trgeiger
2026-07-24 16:44:46 openshift/operator-framework-operator-controller@4afc954 Daniel Franz UPSTREAM: <carry>: Remove openshift/ e2e related to deprecated ServiceAccount usage in ClusterExtension API, Synthetic Permissions, and PreFlight Admissions
2026-07-23 14:47:41 openshift/operator-framework-operator-controller@50b5639 Todd Short UPSTREAM: <carry>: fix(test): update PolarionID:87224 for 4.23/5.0 upgrade boundary

This pull request is expected to merge without any human intervention. If tests are failing here, changes must land upstream to fix any issues so that future downstreaming efforts succeed.

/assign @openshift/openshift-team-operator-runtime

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-bot openshift-bot added the lgtm Indicates that a PR is ready to be merged. label Jul 28, 2026
@openshift-ci
openshift-ci Bot requested review from fgiudici and pedjak July 28, 2026 00:19
@openshift-ci

openshift-ci Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

Approval requirements bypassed by manually added approval.

This pull-request has been approved by: openshift-bot

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@coderabbitai

coderabbitai Bot commented Jul 28, 2026

Copy link
Copy Markdown

Walkthrough

Dependency versions are updated in the main Go module, the OpenShift tests extension module, and requirements.txt.

Changes

Dependency updates

Layer / File(s) Summary
Go dependency pins
go.mod, openshift/tests-extension/go.mod
Direct and indirect Go dependency versions are incremented, including Prometheus modules, Helm, and filepath-securejoin.
Python dependency pin
requirements.txt
The pinned regex version is updated from 2026.6.28 to 2026.7.10.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Suggested reviewers: tmshort, grokspawn

🚥 Pre-merge checks | ✅ 15
✅ Passed checks (15 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately reflects the main change: syncing downstream with upstream repository updates.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed The PR only changes dependency/vendor files; no test files or Ginkgo titles were modified, and the diff scan found no dynamic test-name construction.
Test Structure And Quality ✅ Passed No Ginkgo test files changed; diff is limited to dependency/go.sum/vendor updates and requirements.txt, so the test-structure rules are not applicable.
Microshift Test Compatibility ✅ Passed No new Ginkgo/e2e test files or Ginkgo declarations were added; the PR only updates dependency/vendor files, so MicroShift API compatibility is not implicated.
Single Node Openshift (Sno) Test Compatibility ✅ Passed Diff only updates dependencies/vendor files; no new Ginkgo e2e tests or SNO-unsafe test additions were introduced.
Topology-Aware Scheduling Compatibility ✅ Passed Diff only updates dependency/vendor files; no deployment manifests, controllers, nodeSelectors, anti-affinity, or PDBs changed, so no topology-unsafe scheduling was introduced.
Ote Binary Stdout Contract ✅ Passed No added stdout writes in main/init/TestMain/suite setup; the diff is dependency/vendor updates only.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed No new Ginkgo e2e test files were added; the PR only bumps deps and vendor files, so this IPv6/disconnected-network check is not applicable.
No-Weak-Crypto ✅ Passed Only dependency manifest bumps are present; no MD5/SHA1/DES/RC4/3DES/Blowfish/ECB, custom crypto, or secret comparisons were added.
Container-Privileges ✅ Passed PASS: Scans found only hardened securityContext settings (allowPrivilegeEscalation: false, runAsNonRoot: true) and no privileged/hostPID/hostNetwork/hostIPC in changed manifests.
No-Sensitive-Data-In-Logs ✅ Passed No new logging/print calls or sensitive fields were introduced; the diff is dependency/vendor updates plus generic parsing errors.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@requirements.txt`:
- Line 30: Update the pinned regex dependency entry in requirements.txt to
include the appropriate --hash= values for every supported distribution, and
ensure the pip installation path enables --require-hashes so the lockfile
enforces those hashes.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 91ae1944-959b-447c-8767-2cbd349067e1

📥 Commits

Reviewing files that changed from the base of the PR and between be80e0c and f0005dc.

⛔ Files ignored due to path filters (17)
  • go.sum is excluded by !**/*.sum
  • openshift/tests-extension/go.sum is excluded by !**/*.sum
  • openshift/tests-extension/vendor/github.com/prometheus/procfs/Makefile.common is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/procfs/README.md is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/procfs/SECURITY.md is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/procfs/crypto.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/github.com/prometheus/procfs/mountinfo.go is excluded by !**/vendor/**
  • openshift/tests-extension/vendor/modules.txt is excluded by !**/vendor/**
  • vendor/github.com/cyphar/filepath-securejoin/CHANGELOG.md is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/cyphar/filepath-securejoin/VERSION is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/Makefile.common is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/README.md is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/SECURITY.md is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/crypto.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/mountinfo.go is excluded by !**/vendor/**, !vendor/**
  • vendor/helm.sh/helm/v3/pkg/registry/client.go is excluded by !**/vendor/**, !vendor/**
  • vendor/modules.txt is excluded by !**/vendor/**, !vendor/**
📒 Files selected for processing (3)
  • go.mod
  • openshift/tests-extension/go.mod
  • requirements.txt

Comment thread requirements.txt
pyyaml_env_tag==1.1
readtime==3.0.0
regex==2026.6.28
regex==2026.7.10

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== requirements.txt =="
if [ -f requirements.txt ]; then
  nl -ba requirements.txt | sed -n '1,120p'
fi

echo
echo "== search for hashes / require-hashes / pip install =="
rg -n --hidden --glob '!**/.git/**' --glob '!*node_modules*' --glob '!**/dist/**' --glob '!**/build/**' \
  'require-hashes|--hash=|pip install|pip-compile|regex==2026\.7\.10|regex' .

Repository: openshift/operator-framework-operator-controller

Length of output: 249


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== requirements.txt =="
if [ -f requirements.txt ]; then
  sed -n '1,120p' requirements.txt | cat -n
fi

echo
echo "== search for hashes / require-hashes / pip install / regex =="
rg -n --hidden --glob '!**/.git/**' --glob '!**/node_modules/**' --glob '!**/dist/**' --glob '!**/build/**' \
  'require-hashes|--hash=|pip install|pip-compile|regex==2026\.7\.10|regex' .

Repository: openshift/operator-framework-operator-controller

Length of output: 50405


Add hashes for regex requirements.txt:30 is pinned, but it still lacks --hash= entries, and the pip install path does not enforce --require-hashes.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@requirements.txt` at line 30, Update the pinned regex dependency entry in
requirements.txt to include the appropriate --hash= values for every supported
distribution, and ensure the pip installation path enables --require-hashes so
the lockfile enforces those hashes.

Source: Coding guidelines

@openshift-ci

openshift-ci Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

@openshift-bot: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. kind/sync lgtm Indicates that a PR is ready to be merged. tide/merge-method-merge Denotes a PR that should use a standard merge by tide when it merges.

Projects

None yet

Development

Successfully merging this pull request may close these issues.