Skip to content

OCPBUGS-83757: Remove network dependencies from unit tests - #8277

Merged
openshift-merge-bot[bot] merged 4 commits into
openshift:mainfrom
sdminonne:OCPBUGS-83757
May 1, 2026
Merged

openshift-merge-bot[bot] merged 4 commits into
openshift:mainfrom
sdminonne:OCPBUGS-83757

Conversation

@sdminonne

@sdminonne sdminonne commented Apr 18, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Remove network dependencies from unit tests so make test passes 100% with no network
  • Add injectable MetadataGetter parameter to SeekOverride so tests can avoid real HTTP calls to container registries
  • Remove GetRepoSetup calls from registryclient test fake and shared FakeRegistryClientImageMetadataProvider (affects ~20 test files)
  • Add injectable repoSetupFn to ProviderWithOpenShiftImageRegistryOverridesDecorator for mirror verification
  • Replace real RegistryClientImageMetadataProvider in util_test.go with a local fake
  • Pre-populate OpenID discovery and password grant caches in oauth tests to avoid HTTP calls to accounts.google.com

Details

Multiple unit tests made real HTTP calls to container registries (quay.io, registry-1.docker.io) and identity providers (accounts.google.com), causing test failures when the network was unavailable or slow. This was observed in CI:
https://github.com/openshift/hypershift/actions/runs/24573813584/job/71853756467?pr=8247

Jira: https://issues.redhat.com/browse/OCPBUGS-83757

Test plan

  • make test passes 100% with no network connectivity
  • make verify passes (excluding git-clean check)
  • go vet passes on all modified packages

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Tests

    • Improved isolation and determinism by removing filesystem/network I/O, inlining test secrets, pre-populating caches, injecting mock behaviors, and updating expectations to match mirrored-image scenarios.
  • Refactor

    • Made metadata retrieval and repo-verification checks injectable and converted standalone override logic into provider-scoped methods for controlled verification and testing.
  • Bug Fix

    • Test fakes now fail fast on missing pull secrets and return clearer parse/failure responses to surface invalid inputs.

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Pipeline controller notification
This repo is configured to use the pipeline controller. Second-stage tests will be triggered either automatically or after lgtm label is added, depending on the repository configuration. The pipeline controller will automatically detect which contexts are required and will utilize /test Prow commands to trigger the second stage.

For optional jobs, comment /test ? to see a list of all defined jobs. To trigger manually all jobs from second stage use /pipeline required command.

This repository is configured in: LGTM mode

@openshift-ci-robot openshift-ci-robot added jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. jira/invalid-bug Indicates that a referenced Jira bug is invalid for the branch this PR is targeting. labels Apr 18, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@sdminonne: This pull request references Jira Issue OCPBUGS-83757, which is invalid:

  • expected the bug to target the "5.0.0" version, but no target version was set

Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.

The bug has been updated to refer to the pull request using the external bug tracker.

Details

In response to this:

Summary

  • Add injectable MetadataGetter parameter to SeekOverride so tests can avoid real HTTP calls to container registries
  • Remove GetRepoSetup calls from registryclient test fake, replacing with local reference.Parse()
  • Fixes flaky CI failures when network is unavailable or slow

Details

Two unit test files made real HTTP calls to container registries, causing test failures
when the network was unavailable or slow. This was observed in CI:
https://github.com/openshift/hypershift/actions/runs/24573813584/job/71853756467?pr=8247

Jira: https://issues.redhat.com/browse/OCPBUGS-83757

Test plan

  • go test -race ./support/util/ -run TestSeekOverride passes without network
  • go test -race ./support/releaseinfo/registryclient/ -run TestIsMultiArchManifestList passes without network
  • make verify passes (excluding git-clean check)
  • Full go vet passes on modified packages

🤖 Generated with Claude Code

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai

coderabbitai Bot commented Apr 18, 2026 •

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Introduces injectable hooks for image-metadata and repo-setup verification: RegistryClientImageMetadataProvider gains an injectable metadataGetter (with getMetadataGetter) and a provider method seekOverride that uses provider.OpenShiftImageRegistryOverrides and the injected getter. ProviderWithOpenShiftImageRegistryOverridesDecorator gains a repoSetupFn field and uses it (falling back to registryclient.GetRepoSetup) during mirror verification. Fake image-metadata provider adds an Err field, returns fake manifests directly, and parses image references in GetDigest. Tests were refactored to inject mocks, inline pull secrets, and avoid filesystem/network access.

Sequence Diagram(s)

sequenceDiagram
    participant Consumer as Caller
    participant Provider as RegistryClientImageMetadataProvider
    participant Getter as metadataGetter (injected)
    participant RepoSetup as repoSetupFn / registryclient.GetRepoSetup
    participant Registry as Remote Registry

    Consumer->>Provider: seekOverride(ctx, parsedImageRef, pullSecret)
    Provider->>Getter: getMetadata(ctx, candidateMirrorRef, pullSecret)
    alt Getter returns metadata (mirror reachable)
        Getter-->>Provider: metadata (success)
        Provider->>Consumer: return candidateMirrorRef
    else Getter returns error (mirror unreachable)
        Getter-->>Provider: error
        Provider->>RepoSetup: repoSetup(ctx, candidateMirrorRef, pullSecret)
        alt repoSetup returns repository (repo accessible)
            RepoSetup-->>Provider: repository, parsedRef, nil
            Provider->>Consumer: return parsedRef
        else repoSetup returns error
            RepoSetup-->>Provider: nil, nil, error
            Provider->>Consumer: return original parsedImageRef
        end
    end
Loading
🚥 Pre-merge checks | ✅ 10 | ❌ 2

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 16.67% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Test Structure And Quality ❓ Inconclusive Tests use standard Go testing.T with Gomega assertions rather than Ginkgo Describe/It blocks. Single responsibility, setup/cleanup, and isolation are well-implemented, but assertion messages are frequently missing, making test failures harder to diagnose. Clarify if the check applies to all Go tests or only Ginkgo tests. Systematically add descriptive failure messages to all Expect() calls throughout test files to improve diagnostic value.
✅ Passed checks (10 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title directly and accurately describes the main objective of the pull request: removing network dependencies from unit tests to enable reliable CI execution without network connectivity.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed The check targeting Ginkgo test syntax is not applicable to this PR, which uses standard Go unit tests with table-driven cases and static, descriptive test names.
Microshift Test Compatibility ✅ Passed This PR does not add any new Ginkgo e2e tests; it only modifies existing unit tests and has minor formatting changes to an existing e2e test helper function.
Single Node Openshift (Sno) Test Compatibility ✅ Passed No new Ginkgo e2e tests were added in this PR. Only a minor log message formatting adjustment to an existing test was made.
Topology-Aware Scheduling Compatibility ✅ Passed No deployment manifests, pod specs, or scheduling constraints are introduced or modified. Changes are confined to test files and utility libraries for image metadata retrieval.
Ote Binary Stdout Contract ✅ Passed No stdout write operations found in modified production files; no init/TestMain/suite functions with non-JSON output; refactoring maintains OTE JSON output compatibility.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed PR removes network dependencies from tests without adding new Ginkgo e2e tests or IPv4 assumptions.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands and usage tips.

@openshift-ci
openshift-ci Bot requested review from Nirshal and enxebre April 18, 2026 12:08
@openshift-ci openshift-ci Bot added area/control-plane-operator Indicates the PR includes changes for the control plane operator - in an OCP release area/hypershift-operator Indicates the PR includes changes for the hypershift operator and API - outside an OCP release and removed do-not-merge/needs-area labels Apr 18, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
support/util/imagemetadata_test.go (1)

1026-1032: TestSeekOverrideTimeout no longer exercises timeout-specific behavior.

The current failing getter returns immediately, so this test now checks generic failure fallback rather than timeout handling. Consider renaming it or making the fake block on ctx.Done() to preserve timeout semantics.

Possible deterministic timeout-focused test tweak
-func TestSeekOverrideTimeout(t *testing.T) {
+func TestSeekOverrideTimeout(t *testing.T) {
@@
-	ctx := context.Background()
+	ctx, cancel := context.WithTimeout(context.Background(), 10*time.Millisecond)
+	defer cancel()
@@
-	failingMetadataGetter := func(ctx context.Context, imageRef string, pullSecret []byte) (*dockerv1client.DockerImageConfig, []distribution.Descriptor, distribution.BlobStore, error) {
-		return nil, nil, nil, fmt.Errorf("simulated mirror unavailable")
-	}
+	failingMetadataGetter := func(ctx context.Context, imageRef string, pullSecret []byte) (*dockerv1client.DockerImageConfig, []distribution.Descriptor, distribution.BlobStore, error) {
+		<-ctx.Done()
+		return nil, nil, nil, ctx.Err()
+	}
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@support/util/imagemetadata_test.go` around lines 1026 - 1032, The test
TestSeekOverrideTimeout no longer simulates a timeout because
failingMetadataGetter returns immediately; update the test so it either (A) is
renamed to reflect generic failure behavior, or (B) preserves timeout semantics
by changing failingMetadataGetter to block until ctx.Done() (e.g., wait for ctx
cancellation and then return a context error) so SeekOverride is exercised under
a real timeout using the existing ctx and parsedRef/overrides; adjust assertions
accordingly to expect timeout-driven fallback when using the blocking getter.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Nitpick comments:
In `@support/util/imagemetadata_test.go`:
- Around line 1026-1032: The test TestSeekOverrideTimeout no longer simulates a
timeout because failingMetadataGetter returns immediately; update the test so it
either (A) is renamed to reflect generic failure behavior, or (B) preserves
timeout semantics by changing failingMetadataGetter to block until ctx.Done()
(e.g., wait for ctx cancellation and then return a context error) so
SeekOverride is exercised under a real timeout using the existing ctx and
parsedRef/overrides; adjust assertions accordingly to expect timeout-driven
fallback when using the blocking getter.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 5c3c731c-8940-48b3-a4b0-176ffa2499cd

📥 Commits

Reviewing files that changed from the base of the PR and between ad1df60 and 044d661.

📒 Files selected for processing (3)
  • support/releaseinfo/registryclient/client_test.go
  • support/util/imagemetadata.go
  • support/util/imagemetadata_test.go

@codecov

codecov Bot commented Apr 18, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 84.21053% with 3 lines in your changes missing coverage. Please review.
✅ Project coverage is 36.87%. Comparing base (5eaee74) to head (5f640b4).
⚠️ Report is 40 commits behind head on main.

Files with missing lines Patch % Lines
support/util/imagemetadata.go 78.57% 3 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #8277      +/-   ##
==========================================
+ Coverage   36.42%   36.87%   +0.45%     
==========================================
  Files         765      747      -18     
  Lines       93302    91669    -1633     
==========================================
- Hits        33981    33799     -182     
+ Misses      56606    55190    -1416     
+ Partials     2715     2680      -35     
Files with missing lines Coverage Δ
...ort/releaseinfo/registry_image_content_policies.go 79.41% <100.00%> (+9.41%) ⬆️
support/util/imagemetadata.go 51.01% <78.57%> (-13.61%) ⬇️

... and 22 files with indirect coverage changes

Flag Coverage Δ
cmd-support 31.80% <84.21%> (+1.43%) ⬆️
cpo-hostedcontrolplane 36.34% <ø> (-0.75%) ⬇️
cpo-other 35.69% <ø> (ø)
hypershift-operator 47.88% <ø> (ø)
other 27.76% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🧹 Nitpick comments (1)
support/util/util_test.go (1)

726-728: Return nil manifest when err is set in the fake.

Line 727 currently returns both a manifest and an error. Returning nil, err gives more realistic behavior and prevents accidental use of stale values in failing paths.

Proposed fix
 func (f *fakeImageMetadataProviderForTest) GetManifest(_ context.Context, _ string, _ []byte) (distribution.Manifest, error) {
-	return &fakeManifestForTest{mediaType: f.mediaType}, f.err
+	if f.err != nil {
+		return nil, f.err
+	}
+	return &fakeManifestForTest{mediaType: f.mediaType}, nil
 }
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@support/util/util_test.go` around lines 726 - 728, In
fakeImageMetadataProviderForTest.GetManifest change the return behavior so that
when f.err is set you return (nil, f.err) instead of returning a
fakeManifestForTest plus the error; update the function (GetManifest) to check
f.err and return nil,f.err on error and only return
&fakeManifestForTest{mediaType: f.mediaType}, nil when no error is present to
avoid leaking a stale manifest on failure.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In
`@control-plane-operator/controllers/hostedcontrolplane/oauth/idp_convert_test.go`:
- Around line 28-35: The test seeds package-global caches (openIDURLsCache.Set
and oidcPasswordCheckCache.Set) but does not restore them; modify the test to
call t.Cleanup to remove or restore those entries after seeding so state doesn't
leak across tests—e.g., after calling openIDURLsCache.Set and
oidcPasswordCheckCache.Set, register cleanup functions that delete the specific
keys from openIDURLsCache and oidcPasswordCheckCache (or restore previous
values) so the global caches are reset when the test finishes.

In
`@control-plane-operator/controllers/hostedcontrolplane/v2/oauth/idp_convert_test.go`:
- Around line 28-35: The test is mutating package-level caches openIDURLsCache
and oidcPasswordCheckCache directly which risks cross-test leakage; wrap these
cache population steps so you save prior state (e.g., previous entries or
existence flags) and register a t.Cleanup that restores or deletes the inserted
keys (the "https://accounts.google.com/.well-known/openid-configuration" entry
and the "1" key) or fully resets the caches after the test, and ensure you use
the same TTL variables openIDURLsTTL and oidcPasswordTTL when restoring so the
test leaves openIDURLsCache and oidcPasswordCheckCache unchanged for other
tests.

In `@support/releaseinfo/registry_image_content_policies_test.go`:
- Around line 42-44: The injected repoSetupFn currently ignores errors from
reference.Parse which can let invalid image refs pass in tests; modify
repoSetupFn so it captures the error returned by reference.Parse(imageRef) and
return that error (instead of nil) when parse fails, e.g., change the code path
in repoSetupFn that calls reference.Parse to check the error and propagate it
back to the caller so tests fail on invalid refs.

In `@support/util/util_test.go`:
- Around line 730-733: The fakeImageMetadataProviderForTest methods currently
ignore errors from reference.Parse (e.g., in GetDigest) which masks invalid
image refs; update these methods to capture the parse error (ref, err :=
reference.Parse(imageRef)), and if err != nil return an appropriate zero values
plus the parse error instead of discarding it; apply the same change to the
other fake provider method(s) around lines 739-742 so all parse failures are
propagated to callers.

---

Nitpick comments:
In `@support/util/util_test.go`:
- Around line 726-728: In fakeImageMetadataProviderForTest.GetManifest change
the return behavior so that when f.err is set you return (nil, f.err) instead of
returning a fakeManifestForTest plus the error; update the function
(GetManifest) to check f.err and return nil,f.err on error and only return
&fakeManifestForTest{mediaType: f.mediaType}, nil when no error is present to
avoid leaking a stale manifest on failure.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 5f4d8096-3389-430a-8310-86494e189136

📥 Commits

Reviewing files that changed from the base of the PR and between 044d661 and 15c879c.

📒 Files selected for processing (7)
  • control-plane-operator/controllers/hostedcontrolplane/oauth/idp_convert_test.go
  • control-plane-operator/controllers/hostedcontrolplane/v2/oauth/idp_convert_test.go
  • support/catalogs/images_test.go
  • support/releaseinfo/registry_image_content_policies.go
  • support/releaseinfo/registry_image_content_policies_test.go
  • support/util/fakeimagemetadataprovider/fakeimagemetadataprovider.go
  • support/util/util_test.go

Comment thread support/releaseinfo/registry_image_content_policies_test.go
Comment thread support/util/util_test.go Outdated

@jparrill jparrill left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dropped some comments

Comment thread support/catalogs/images_test.go Outdated
expectedExists: false,
expectedError: true,
pullSecret: []byte("12345"),
name: "Management cluster should fail when image not found",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you please change the test names to follow Gherkin format "When...it should format"?

Comment thread support/util/util_test.go Outdated
}

// fakeImageMetadataProviderForTest is a minimal ImageMetadataProvider for unit tests.
type fakeImageMetadataProviderForTest struct {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why not just extend the shared FakeRegistryClientImageMetadataProvider adding a Err field?

Comment thread support/util/imagemetadata.go Outdated
}

func SeekOverride(ctx context.Context, openshiftImageRegistryOverrides map[string][]string, parsedImageReference reference.DockerImageReference, pullSecret []byte) *reference.DockerImageReference {
func SeekOverride(ctx context.Context, openshiftImageRegistryOverrides map[string][]string, parsedImageReference reference.DockerImageReference, pullSecret []byte, metadataGetter MetadataGetter) *reference.DockerImageReference {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Refactor SeekOverride to use struct field injection instead of a public function parameter. Make MetadataGetter a field on RegistryClientImageMetadataProvider, consistent with the repoSetupFn pattern already used in this PR.

},
// Mock repoSetupFn to avoid real network calls for mirror verification.
repoSetupFn: func(ctx context.Context, imageRef string, pullSecret []byte) (distribution.Repository, *reference.DockerImageReference, error) {
ref, _ := reference.Parse(imageRef)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Check errors instead of discard.

Comment thread support/util/imagemetadata_test.go Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Rename it to something that reflects the current behavior. It no longer tests timeout.

Comment thread support/util/imagemetadata.go Outdated
}

// MetadataGetter is a function that retrieves image metadata from a registry.
type MetadataGetter func(ctx context.Context, imageRef string, pullSecret []byte) (*dockerv1client.DockerImageConfig, []distribution.Descriptor, distribution.BlobStore, error)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why this needs to be public?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

done

@sdminonne

Copy link
Copy Markdown
Contributor Author

@jparrill ptal

@sdminonne

Copy link
Copy Markdown
Contributor Author

/verified by unit-tests

@openshift-ci-robot openshift-ci-robot added the verified Signifies that the PR passed pre-merge verification criteria label Apr 20, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@sdminonne: This PR has been marked as verified by unit-tests.

Details

In response to this:

/verified by unit-tests

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@sdminonne

Copy link
Copy Markdown
Contributor Author

@coderabbitai ptal

@coderabbitai

coderabbitai Bot commented Apr 20, 2026

Copy link
Copy Markdown
Contributor

@sdminonne, sure! I'll take a look at the PR right away.

✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@jparrill

Copy link
Copy Markdown
Contributor

/approve

@jparrill

Copy link
Copy Markdown
Contributor

/jira refresh

@openshift-ci-robot openshift-ci-robot added jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. and removed jira/invalid-bug Indicates that a referenced Jira bug is invalid for the branch this PR is targeting. labels Apr 20, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@jparrill: This pull request references Jira Issue OCPBUGS-83757, which is valid. The bug has been moved to the POST state.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (5.0.0) matches configured target version for branch (5.0.0)
  • bug is in the state New, which is one of the valid states (NEW, ASSIGNED, POST)
Details

In response to this:

/jira refresh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci

openshift-ci Bot commented Apr 20, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: jparrill, sdminonne

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Apr 20, 2026
@csrwng

csrwng commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD c1a8bb6 and 2 for PR HEAD 44ce39e in total

@hypershift-jira-solve-ci

Copy link
Copy Markdown
Contributor

AI Test Failure Analysis

Job: pull-ci-openshift-hypershift-main-e2e-azure-self-managed | Build: 2048626093337874432 | Cost: $1.10967075 | Failed step: hypershift-azure-run-e2e-self-managed

View full analysis report


Generated by hypershift-analyze-e2e-failure post-step using Claude claude-opus-4-6

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD b4192d4 and 1 for PR HEAD 44ce39e in total

sdminonne and others added 3 commits April 30, 2026 11:44
OCPBUGS-83757

SeekOverride() called getMetadata() directly to verify mirror
availability, making real HTTP calls to container registries. This
caused test failures when the network was unavailable or slow in CI.

Add a MetadataGetter parameter to SeekOverride so tests can inject a
fake. When nil, the real getMetadata is used, keeping production
behavior unchanged.

Also remove GetRepoSetup calls from the registryclient test fake
provider, replacing them with local reference.Parse() calls that
don't require network access.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
OCPBUGS-83757

Remove GetRepoSetup calls from the shared
FakeRegistryClientImageMetadataProvider used across ~20 test files.
This was the root cause for widespread offline test failures beyond
the two files fixed in the previous commit.

Also replace direct use of RegistryClientImageMetadataProvider in
util_test.go with a local fake, make the catalogs "image not found"
test explicit about its error expectation, add injectable repoSetupFn
to ProviderWithOpenShiftImageRegistryOverridesDecorator, and
pre-populate the OpenID discovery cache in oauth tests to avoid
HTTP calls to accounts.google.com.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Refactor SeekOverride into unexported seekOverride method on
  RegistryClientImageMetadataProvider with metadataGetter struct field
  injection, consistent with the repoSetupFn pattern
- Remove public MetadataGetter type in favor of unexported
  metadataGetterFn
- Extend shared FakeRegistryClientImageMetadataProvider with Err field
  and remove duplicate local fakeImageMetadataProviderForTest
- Fix FakeManifest.Payload() to return valid JSON
- Add t.Cleanup for global cache mutations in oauth idp_convert tests
  to prevent cross-test state leakage
- Propagate reference.Parse errors in test fakes instead of discarding
- Rename TestSeekOverrideTimeout to
  TestSeekOverrideFallsBackWhenMirrorUnavailable
- Rename test cases in images_test.go to Gherkin format

Jira: https://issues.redhat.com/browse/OCPBUGS-83757

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@openshift-ci-robot openshift-ci-robot removed the verified Signifies that the PR passed pre-merge verification criteria label Apr 30, 2026
@openshift-ci openshift-ci Bot removed the lgtm Indicates that a PR is ready to be merged. label Apr 30, 2026
Exclude test fake packages from codecov analysis since they are test
helpers analogous to already-excluded mock files. Add tests for the
nil-fallback paths in getMetadataGetter and repoSetupFn to cover the
default injection logic without requiring network calls.

Jira: OCPBUGS-83757

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@sdminonne

Copy link
Copy Markdown
Contributor Author

/verified by unit-test

@openshift-ci-robot openshift-ci-robot added the verified Signifies that the PR passed pre-merge verification criteria label Apr 30, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@sdminonne: This PR has been marked as verified by unit-test.

Details

In response to this:

/verified by unit-test

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@csrwng

csrwng commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Apr 30, 2026
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Scheduling tests matching the pipeline_run_if_changed or not excluded by pipeline_skip_if_only_changed parameters:
/test e2e-aks
/test e2e-aws
/test e2e-aws-upgrade-hypershift-operator
/test e2e-azure-self-managed
/test e2e-kubevirt-aws-ovn-reduced
/test e2e-v2-aws

@hypershift-jira-solve-ci

Copy link
Copy Markdown
Contributor

AI Test Failure Analysis

Job: pull-ci-openshift-hypershift-main-e2e-aws | Build: 2049848131599732736 | Cost: $3.4061506500000003 | Failed step: hypershift-aws-run-e2e-nested

View full analysis report


Generated by hypershift-analyze-e2e-failure post-step using Claude claude-opus-4-6

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD 9bb7d76 and 2 for PR HEAD 5f640b4 in total

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD 5e3afb8 and 1 for PR HEAD 5f640b4 in total

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD afd63bd and 0 for PR HEAD 5f640b4 in total

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/hold

Revision 5f640b4 was retested 3 times: holding

@openshift-ci openshift-ci Bot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Apr 30, 2026
@hypershift-jira-solve-ci

Copy link
Copy Markdown
Contributor

Now I have the complete picture. Here is the analysis:

Test Failure Analysis Complete

Job Information

  • Prow Job: pull-ci-openshift-hypershift-main-verify-workflows
  • Build ID: 2049964896275140608
  • Target: verify-workflows
  • Job Type: presubmit
  • PR: OCPBUGS-83757: Remove network dependencies from unit tests #8277 (OCPBUGS-83757: Remove network dependencies from unit tests)
  • State: failure
  • Duration: ~3m 36s (21:31:28Z → 21:35:04Z)
  • Cluster: build01

Test Failure Analysis

Error

MISSING: .github/workflows/codespell-reusable.yaml exists on main but not on this branch.
MISSING: .github/workflows/cpo-container-sync-reusable.yaml exists on main but not on this branch.
MISSING: .github/workflows/docs-build-reusable.yaml exists on main but not on this branch.
MISSING: .github/workflows/envtest-kube-reusable.yaml exists on main but not on this branch.
OUTDATED: .github/workflows/envtest-kube.yaml has been updated on main since this branch diverged.
MISSING: .github/workflows/envtest-ocp-reusable.yaml exists on main but not on this branch.
OUTDATED: .github/workflows/envtest-ocp.yaml has been updated on main since this branch diverged.
MISSING: .github/workflows/gitlint-reusable.yaml exists on main but not on this branch.
MISSING: .github/workflows/lint-reusable.yaml exists on main but not on this branch.
MISSING: .github/workflows/test-reusable.yaml exists on main but not on this branch.
MISSING: .github/workflows/verify-reusable.yaml exists on main but not on this branch.

Rebase your branch on main: git fetch upstream main && git rebase upstream/main

Summary

The verify-workflows CI check failed because the PR branch (OCPBUGS-83757) is not rebased on top of the current main branch. On 2026-04-30, a commit titled "ci: add reusable workflow definitions for all 9 GHA workflows" landed on main, adding 9 new *-reusable.yaml GitHub Actions workflow files and updating 2 existing workflow files. The PR branch (created 2026-04-18) does not contain these files. The verify-workflows check explicitly compares every .github/workflows/ file between the PR branch and main, and fails if any file is missing or outdated on the PR branch.

Root Cause

The verify-workflows presubmit check enforces that PR branches carry the latest versions of all .github/workflows/ files from main. It works by:

  1. Fetching main from GitHub as FETCH_HEAD
  2. Resolving the actual PR head commit (HEAD^2 of the ci-operator merge commit)
  3. Computing the merge-base between the PR head and main
  4. Iterating over every file in .github/workflows/ on main and comparing its hash to the PR branch's version
  5. Flagging files as MISSING (exist on main but not on the PR branch) or OUTDATED (main has a newer version than what the PR branch has, and the PR branch still has the merge-base version)

On 2026-04-30, two commits landed on main that added/updated GitHub Actions workflow files:

  • "ci: add reusable workflow definitions for all 9 GHA workflows" — added 9 new *-reusable.yaml files
  • "ci: address review feedback on reusable workflows" — updated several of the reusable files and 2 existing files (envtest-kube.yaml, envtest-ocp.yaml)

The PR branch OCPBUGS-83757 was created on 2026-04-18 and has not been rebased since these workflow changes merged. This is not a product bug or test flake — it is a branch staleness issue that is resolved by rebasing.

Recommendations
  1. Rebase the PR branch on main — this is the only fix needed:

    git fetch upstream main && git rebase upstream/main

    Then force-push the rebased branch to re-trigger CI.

  2. This failure is completely unrelated to the PR's actual changes (removing network dependencies from unit tests). The PR's code changes are not involved in the failure.

  3. After rebasing, the branch will pick up the 9 new *-reusable.yaml files and the 2 updated workflow files, and the verify-workflows check will pass.

Evidence
Evidence Detail
Failing step verify-workflows container exited with code 1
Missing files (9) codespell-reusable.yaml, cpo-container-sync-reusable.yaml, docs-build-reusable.yaml, envtest-kube-reusable.yaml, envtest-ocp-reusable.yaml, gitlint-reusable.yaml, lint-reusable.yaml, test-reusable.yaml, verify-reusable.yaml
Outdated files (2) envtest-kube.yaml, envtest-ocp.yaml
Commit that added files "ci: add reusable workflow definitions for all 9 GHA workflows" (merged 2026-04-30)
PR branch created 2026-04-18 (12 days before the workflow files were added)
PR HEAD 5f640b4bba14ee2780424dfd83aea1a9baf64a60
Main HEAD 5e3afb8557b05cd735d969f62be6c35f283f578a
Merge base 5eaee747fb5e2d37cda2d7caa796526eefbed01b
Failure type Branch staleness (not a product bug or test flake)

@sdminonne

Copy link
Copy Markdown
Contributor Author

/hold cancel

@openshift-ci openshift-ci Bot removed the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label May 1, 2026
@openshift-ci

openshift-ci Bot commented May 1, 2026

Copy link
Copy Markdown
Contributor

@sdminonne: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/verify-workflows 5f640b4 link true /test verify-workflows

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@openshift-merge-bot
openshift-merge-bot Bot merged commit 03e1f02 into openshift:main May 1, 2026
41 checks passed
@openshift-ci-robot

Copy link
Copy Markdown

@sdminonne: Jira Issue Verification Checks: Jira Issue OCPBUGS-83757
✔️ This pull request was pre-merge verified.
✔️ All associated pull requests have merged.
✔️ All associated, merged pull requests were pre-merge verified.

Jira Issue OCPBUGS-83757 has been moved to the MODIFIED state and will move to the VERIFIED state when the change is available in an accepted nightly payload. 🕓

Details

In response to this:

Summary

  • Remove network dependencies from unit tests so make test passes 100% with no network
  • Add injectable MetadataGetter parameter to SeekOverride so tests can avoid real HTTP calls to container registries
  • Remove GetRepoSetup calls from registryclient test fake and shared FakeRegistryClientImageMetadataProvider (affects ~20 test files)
  • Add injectable repoSetupFn to ProviderWithOpenShiftImageRegistryOverridesDecorator for mirror verification
  • Replace real RegistryClientImageMetadataProvider in util_test.go with a local fake
  • Pre-populate OpenID discovery and password grant caches in oauth tests to avoid HTTP calls to accounts.google.com

Details

Multiple unit tests made real HTTP calls to container registries (quay.io, registry-1.docker.io) and identity providers (accounts.google.com), causing test failures when the network was unavailable or slow. This was observed in CI:
https://github.com/openshift/hypershift/actions/runs/24573813584/job/71853756467?pr=8247

Jira: https://issues.redhat.com/browse/OCPBUGS-83757

Test plan

  • make test passes 100% with no network connectivity
  • make verify passes (excluding git-clean check)
  • go vet passes on all modified packages

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Tests

  • Improved isolation and determinism by removing filesystem/network I/O, inlining test secrets, pre-populating caches, injecting mock behaviors, and updating expectations to match mirrored-image scenarios.

  • Refactor

  • Made metadata retrieval and repo-verification checks injectable and converted standalone override logic into provider-scoped methods for controlled verification and testing.

  • Bug Fix

  • Test fakes now fail fast on missing pull secrets and return clearer parse/failure responses to surface invalid inputs.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-merge-robot

Copy link
Copy Markdown
Contributor

Fix included in release 5.0.0-0.nightly-2026-05-02-042818

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/control-plane-operator Indicates the PR includes changes for the control plane operator - in an OCP release area/hypershift-operator Indicates the PR includes changes for the hypershift operator and API - outside an OCP release area/testing Indicates the PR includes changes for e2e testing jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. verified Signifies that the PR passed pre-merge verification criteria

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants