Skip to content

NE-2126: Migrating Ipfailover test cases to images repo - #245

Open
melvinjoseph86 wants to merge 1 commit into
openshift:masterfrom
melvinjoseph86:ipfailover-migrate
Open

NE-2126: Migrating Ipfailover test cases to images repo#245
melvinjoseph86 wants to merge 1 commit into
openshift:masterfrom
melvinjoseph86:ipfailover-migrate

Conversation

@melvinjoseph86

@melvinjoseph86 melvinjoseph86 commented Jul 22, 2026

Copy link
Copy Markdown
➜  ./bin/ipfailover-tests-ext run-suite ipfailover/all --max-concurrency=1
  I0722 22:35:05.065743 23079 test_context.go:566] The --provider flag is not set. Continuing as if --provider=skeleton had been used.
[
  {
    "name": "[OTP][sig-network-edge] Network_Edge Author:hongli-NonHyperShiftHOST-ConnectedOnly-Critical-41025-support to deploy ipfailover [Serial]",
    "lifecycle": "blocking",
    "duration": 58652,
    "startTime": "2026-07-22 17:05:05.236625 UTC",
    "endTime": "2026-07-22 17:06:03.888726 UTC",
    "result": "passed",
    "output": "  STEP: Creating a kubernetes client @ 07/22/26 22:35:05.237\nI0722 22:35:09.460724 23080 client.go:293] configPath is now \"/var/folders/7h/zgpvgd5946bcf53ktsvp95_40000gn/T/configfile1449509705\"\nI0722 22:35:09.460818 23080 client.go:368] The user is now \"e2e-test-router-ipfailover-tjr2r-user\"\nI0722 22:35:09.460843 23080 client.go:370] Creating project \"e2e-test-router-ipfailover-tjr2r\"\nI0722 22:35:09.841043 23080 client.go:378] Waiting on permissions in project \"e2e-test-router-ipfailover-tjr2r\" ...\nI0722 22:35:10.849109 23080 client.go:407] DeploymentConfig capability is enabled, adding 'deployer' SA to the list of default SAs\nI0722 22:35:11.096987 23080 client.go:422] Waiting for ServiceAccount \"default\" to be provisioned...\nI0722 22:35:11.699374 23080 client.go:422] Waiting for ServiceAccount \"builder\" to be provisioned...\nI0722 22:35:12.313775 23080 client.go:422] Waiting for ServiceAccount \"deployer\" to be provisioned...\nI0722 22:35:12.922410 23080 client.go:432] Waiting for RoleBinding \"system:image-pullers\" to be provisioned...\nI0722 22:35:13.187856 23080 client.go:432] Waiting for RoleBinding \"system:image-builders\" to be provisioned...\nI0722 22:35:13.446990 23080 client.go:432] Waiting for RoleBinding \"system:deployers\" to be provisioned...\nI0722 22:35:15.182120 23080 client.go:469] Project \"e2e-test-router-ipfailover-tjr2r\" has been fully provisioned.\n  STEP: Check platforms @ 07/22/26 22:35:15.182\n  STEP: check whether there are two worker nodes present for testing hostnetwork @ 07/22/26 22:35:15.972\nI0722 22:35:17.373584 23080 util.go:61] Linux worker node details:\ngnfq2hk-b5564-9ks7d-worker-0-4bnpj\ngnfq2hk-b5564-9ks7d-worker-0-6fjsr\ngnfq2hk-b5564-9ks7d-worker-0-jdf4g\nI0722 22:35:17.373642 23080 util.go:62] Available linux worker node count is: 3\n  STEP: check the cluster has remote worker profile @ 07/22/26 22:35:20.744\n  STEP: check whether the cluster is not ipv6 single stack @ 07/22/26 22:35:22.412\n  STEP: Check network type @ 07/22/26 22:35:23.212\n  STEP: get pull spec of ipfailover image from payload @ 07/22/26 22:35:24.045\nI0722 22:35:29.916828 23080 util.go:121] the pull spec of image keepalived-ipfailover is: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:93c0a2b5ccfa1b27c43b02d4e8773e2641056c8ce85490a1a5c1dfaada6d1ad2\n  STEP: create ipfailover deployment and ensure one of pod enter MASTER state @ 07/22/26 22:35:29.934\nnamespace/e2e-test-router-ipfailover-tjr2r labeled\nI0722 22:35:32.157571 23080 util.go:275] Successfully added privileged labels (enforce, audit, warn) to namespace e2e-test-router-ipfailover-tjr2r\nI0722 22:35:38.301090 23080 util.go:356] the file of resource is /tmp/e2e-test-router-ipfailover-tjr2r-zpkarvr3-temp-resource.json\ndeployment.apps/ipf-41025 created\nI0722 22:35:45.979804 23080 util.go:363] the Ready status of pod is True True\nI0722 22:35:47.035865 23080 util.go:185] The pod list is [ipf-41025-7b94bb7cf8-8kp8q ipf-41025-7b94bb7cf8-tv4bm]\nI0722 22:36:01.476231 23080 util.go:136] The first pod log's failover status:- Wed Jul 22 17:05:39 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\nI0722 22:36:02.917546 23080 util.go:143] The second pod log's failover status:- Wed Jul 22 17:05:39 2026: (ipfailover_VIP_1) Entering BACKUP STATE\nWed Jul 22 17:05:42 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\nI0722 22:36:02.917677 23080 util.go:164] The Master pod is ipf-41025-7b94bb7cf8-tv4bm and Backup pod is ipf-41025-7b94bb7cf8-8kp8q\nI0722 22:36:03.160570 23080 client.go:689] Deleted {user.openshift.io/v1, Resource=users  e2e-test-router-ipfailover-tjr2r-user}, err: \u003cnil\u003e\nI0722 22:36:03.405692 23080 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthclients  e2e-client-e2e-test-router-ipfailover-tjr2r}, err: \u003cnil\u003e\nI0722 22:36:03.644934 23080 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthaccesstokens  sha256~XsypUcqoliXDUcscW4CtaZviMNhkVKu8U-Y-dwuh9jk}, err: \u003cnil\u003e\n  STEP: Destroying namespace \"e2e-test-router-ipfailover-tjr2r\" for this suite. @ 07/22/26 22:36:03.645\n",
    "error": "    STEP: Creating a kubernetes client @ 07/22/26 22:35:05.237\n  I0722 22:35:09.460724 23080 client.go:293] configPath is now \"/var/folders/7h/zgpvgd5946bcf53ktsvp95_40000gn/T/configfile1449509705\"\n  I0722 22:35:09.460818 23080 client.go:368] The user is now \"e2e-test-router-ipfailover-tjr2r-user\"\n  I0722 22:35:09.460843 23080 client.go:370] Creating project \"e2e-test-router-ipfailover-tjr2r\"\n  I0722 22:35:09.841043 23080 client.go:378] Waiting on permissions in project \"e2e-test-router-ipfailover-tjr2r\" ...\n  I0722 22:35:10.849109 23080 client.go:407] DeploymentConfig capability is enabled, adding 'deployer' SA to the list of default SAs\n  I0722 22:35:11.096987 23080 client.go:422] Waiting for ServiceAccount \"default\" to be provisioned...\n  I0722 22:35:11.699374 23080 client.go:422] Waiting for ServiceAccount \"builder\" to be provisioned...\n  I0722 22:35:12.313775 23080 client.go:422] Waiting for ServiceAccount \"deployer\" to be provisioned...\n  I0722 22:35:12.922410 23080 client.go:432] Waiting for RoleBinding \"system:image-pullers\" to be provisioned...\n  I0722 22:35:13.187856 23080 client.go:432] Waiting for RoleBinding \"system:image-builders\" to be provisioned...\n  I0722 22:35:13.446990 23080 client.go:432] Waiting for RoleBinding \"system:deployers\" to be provisioned...\n  I0722 22:35:15.182120 23080 client.go:469] Project \"e2e-test-router-ipfailover-tjr2r\" has been fully provisioned.\n    STEP: Check platforms @ 07/22/26 22:35:15.182\n    STEP: check whether there are two worker nodes present for testing hostnetwork @ 07/22/26 22:35:15.972\n  I0722 22:35:17.373584 23080 util.go:61] Linux worker node details:\n  gnfq2hk-b5564-9ks7d-worker-0-4bnpj\n  gnfq2hk-b5564-9ks7d-worker-0-6fjsr\n  gnfq2hk-b5564-9ks7d-worker-0-jdf4g\n  I0722 22:35:17.373642 23080 util.go:62] Available linux worker node count is: 3\n    STEP: check the cluster has remote worker profile @ 07/22/26 22:35:20.744\n    STEP: check whether the cluster is not ipv6 single stack @ 07/22/26 22:35:22.412\n    STEP: Check network type @ 07/22/26 22:35:23.212\n    STEP: get pull spec of ipfailover image from payload @ 07/22/26 22:35:24.045\n  I0722 22:35:29.916828 23080 util.go:121] the pull spec of image keepalived-ipfailover is: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:93c0a2b5ccfa1b27c43b02d4e8773e2641056c8ce85490a1a5c1dfaada6d1ad2\n    STEP: create ipfailover deployment and ensure one of pod enter MASTER state @ 07/22/26 22:35:29.934\n  namespace/e2e-test-router-ipfailover-tjr2r labeled\n  I0722 22:35:32.157571 23080 util.go:275] Successfully added privileged labels (enforce, audit, warn) to namespace e2e-test-router-ipfailover-tjr2r\n  I0722 22:35:38.301090 23080 util.go:356] the file of resource is /tmp/e2e-test-router-ipfailover-tjr2r-zpkarvr3-temp-resource.json\n  deployment.apps/ipf-41025 created\n  I0722 22:35:45.979804 23080 util.go:363] the Ready status of pod is True True\n  I0722 22:35:47.035865 23080 util.go:185] The pod list is [ipf-41025-7b94bb7cf8-8kp8q ipf-41025-7b94bb7cf8-tv4bm]\n  I0722 22:36:01.476231 23080 util.go:136] The first pod log's failover status:- Wed Jul 22 17:05:39 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\n  I0722 22:36:02.917546 23080 util.go:143] The second pod log's failover status:- Wed Jul 22 17:05:39 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n  Wed Jul 22 17:05:42 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\n  I0722 22:36:02.917677 23080 util.go:164] The Master pod is ipf-41025-7b94bb7cf8-tv4bm and Backup pod is ipf-41025-7b94bb7cf8-8kp8q\n  I0722 22:36:03.160570 23080 client.go:689] Deleted {user.openshift.io/v1, Resource=users  e2e-test-router-ipfailover-tjr2r-user}, err: \u003cnil\u003e\n  I0722 22:36:03.405692 23080 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthclients  e2e-client-e2e-test-router-ipfailover-tjr2r}, err: \u003cnil\u003e\n  I0722 22:36:03.644934 23080 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthaccesstokens  sha256~XsypUcqoliXDUcscW4CtaZviMNhkVKu8U-Y-dwuh9jk}, err: \u003cnil\u003e\n    STEP: Destroying namespace \"e2e-test-router-ipfailover-tjr2r\" for this suite. @ 07/22/26 22:36:03.645\n"
  },
  {
    "name": "[OTP][sig-network-edge] Network_Edge Author:mjoseph-NonHyperShiftHOST-ConnectedOnly-Medium-41027-pod and service automatically switched over to standby when master fails [Disruptive]",
    "lifecycle": "blocking",
    "duration": 138694,
    "startTime": "2026-07-22 17:06:04.483263 UTC",
    "endTime": "2026-07-22 17:08:23.178121 UTC",
    "result": "passed",
    "output": "  STEP: Creating a kubernetes client @ 07/22/26 22:36:04.483\nI0722 22:36:08.805796 23191 client.go:293] configPath is now \"/var/folders/7h/zgpvgd5946bcf53ktsvp95_40000gn/T/configfile2173069665\"\nI0722 22:36:08.805834 23191 client.go:368] The user is now \"e2e-test-router-ipfailover-pc82p-user\"\nI0722 22:36:08.805846 23191 client.go:370] Creating project \"e2e-test-router-ipfailover-pc82p\"\nI0722 22:36:09.174807 23191 client.go:378] Waiting on permissions in project \"e2e-test-router-ipfailover-pc82p\" ...\nI0722 22:36:10.238399 23191 client.go:407] DeploymentConfig capability is enabled, adding 'deployer' SA to the list of default SAs\nI0722 22:36:10.515301 23191 client.go:422] Waiting for ServiceAccount \"default\" to be provisioned...\nI0722 22:36:12.045617 23191 client.go:422] Waiting for ServiceAccount \"builder\" to be provisioned...\nI0722 22:36:12.676937 23191 client.go:422] Waiting for ServiceAccount \"deployer\" to be provisioned...\nI0722 22:36:13.305840 23191 client.go:432] Waiting for RoleBinding \"system:image-pullers\" to be provisioned...\nI0722 22:36:13.565583 23191 client.go:432] Waiting for RoleBinding \"system:image-builders\" to be provisioned...\nI0722 22:36:13.823288 23191 client.go:432] Waiting for RoleBinding \"system:deployers\" to be provisioned...\nI0722 22:36:15.646899 23191 client.go:469] Project \"e2e-test-router-ipfailover-pc82p\" has been fully provisioned.\n  STEP: Check platforms @ 07/22/26 22:36:15.647\n  STEP: check whether there are two worker nodes present for testing hostnetwork @ 07/22/26 22:36:16.76\nI0722 22:36:18.035220 23191 util.go:61] Linux worker node details:\ngnfq2hk-b5564-9ks7d-worker-0-4bnpj\ngnfq2hk-b5564-9ks7d-worker-0-6fjsr\ngnfq2hk-b5564-9ks7d-worker-0-jdf4g\nI0722 22:36:18.035267 23191 util.go:62] Available linux worker node count is: 3\n  STEP: check the cluster has remote worker profile @ 07/22/26 22:36:21.468\n  STEP: check whether the cluster is not ipv6 single stack @ 07/22/26 22:36:23.087\n  STEP: Check network type @ 07/22/26 22:36:23.866\n  STEP: 1. Get pull spec of ipfailover image from payload @ 07/22/26 22:36:24.753\nI0722 22:36:30.972027 23191 util.go:121] the pull spec of image keepalived-ipfailover is: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:93c0a2b5ccfa1b27c43b02d4e8773e2641056c8ce85490a1a5c1dfaada6d1ad2\n  STEP: 2. Create ipfailover deployment and ensure one of pod enter MASTER state @ 07/22/26 22:36:30.99\nnamespace/e2e-test-router-ipfailover-pc82p labeled\nI0722 22:36:32.124377 23191 util.go:275] Successfully added privileged labels (enforce, audit, warn) to namespace e2e-test-router-ipfailover-pc82p\nI0722 22:36:38.287868 23191 util.go:356] the file of resource is /tmp/e2e-test-router-ipfailover-pc82p-w1q5zs0t-temp-resource.json\ndeployment.apps/ipf-41027 created\nI0722 22:36:46.155249 23191 util.go:363] the Ready status of pod is True True\nI0722 22:36:47.171938 23191 util.go:185] The pod list is [ipf-41027-7b94bb7cf8-wchsm ipf-41027-7b94bb7cf8-xzlxn]\nI0722 22:37:01.662686 23191 util.go:136] The first pod log's failover status:- Wed Jul 22 17:06:39 2026: (ipfailover_VIP_1) Entering BACKUP STATE\nWed Jul 22 17:06:42 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\nI0722 22:37:03.078051 23191 util.go:143] The second pod log's failover status:- Wed Jul 22 17:06:39 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\nI0722 22:37:03.078102 23191 util.go:164] The Master pod is ipf-41027-7b94bb7cf8-wchsm and Backup pod is ipf-41027-7b94bb7cf8-xzlxn\n  STEP: 3. Set the HA virtual IP for the failover group @ 07/22/26 22:37:03.078\nI0722 22:37:04.705772 23191 util.go:302] The pod  ipf-41027-7b94bb7cf8-wchsm IP in namespace e2e-test-router-ipfailover-pc82p is \"10.0.2.136\"\nI0722 22:37:04.705830 23191 util.go:176] The modified ipaddress is 10.0.2.100 \ndeployment.apps/ipf-41027 updated\n  STEP: 4. Verify the HA virtual ip ENV variable @ 07/22/26 22:37:15.813\nI0722 22:37:22.135036 23191 util.go:363] the Ready status of pod is True True\nI0722 22:37:23.243090 23191 util.go:185] The pod list is [ipf-41027-cc767d447-6h66q ipf-41027-cc767d447-hhvgw]\nI0722 22:37:37.630567 23191 util.go:136] The first pod log's failover status:- Wed Jul 22 17:07:06 2026: (ipfailover_VIP_1) Entering BACKUP STATE\nWed Jul 22 17:07:09 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\nI0722 22:37:39.056730 23191 util.go:143] The second pod log's failover status:- Wed Jul 22 17:07:06 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\nI0722 22:37:39.056831 23191 util.go:164] The Master pod is ipf-41027-cc767d447-6h66q and Backup pod is ipf-41027-cc767d447-hhvgw\nI0722 22:37:45.967186 23191 util.go:264] the matching part is: OPENSHIFT_HA_VIRTUAL_IPS=10.0.2.100\n  STEP: 5. Find the primary and the secondary pod using the virtual IP @ 07/22/26 22:37:45.968\nI0722 22:37:47.631666 23191 util.go:207] The pod owning the VIP is ipf-41027-cc767d447-6h66q\n  STEP: 6. Restarting the ipfailover primary pod @ 07/22/26 22:37:47.631\npod \"ipf-41027-cc767d447-6h66q\" deleted\n  STEP: 6a. Wait for replica replacement after pod deletion @ 07/22/26 22:37:49.528\n  STEP: 7. Verify the virtual IP is floated onto the new MASTER node @ 07/22/26 22:37:55.343\nI0722 22:37:56.512171 23191 util.go:185] The pod list is [ipf-41027-cc767d447-hhvgw ipf-41027-cc767d447-wrs2n]\nI0722 22:38:10.765942 23191 util.go:136] The first pod log's failover status:- Wed Jul 22 17:07:06 2026: (ipfailover_VIP_1) Entering BACKUP STATE\nWed Jul 22 17:07:49 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\nI0722 22:38:12.252562 23191 util.go:143] The second pod log's failover status:- Wed Jul 22 17:07:49 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\nI0722 22:38:12.252757 23191 util.go:164] The Master pod is ipf-41027-cc767d447-hhvgw and Backup pod is ipf-41027-cc767d447-wrs2n\nI0722 22:38:19.240679 23191 util.go:241] The new pod ipf-41027-cc767d447-hhvgw is the master\nI0722 22:38:22.338061 23191 client.go:689] Deleted {user.openshift.io/v1, Resource=users  e2e-test-router-ipfailover-pc82p-user}, err: \u003cnil\u003e\nI0722 22:38:22.616212 23191 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthclients  e2e-client-e2e-test-router-ipfailover-pc82p}, err: \u003cnil\u003e\nI0722 22:38:22.894930 23191 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthaccesstokens  sha256~mWr9ElxsNakVbOwaL-ssK00WlPvaA4Q_JqpqTh9jJq0}, err: \u003cnil\u003e\n  STEP: Destroying namespace \"e2e-test-router-ipfailover-pc82p\" for this suite. @ 07/22/26 22:38:22.897\n",
    "error": "    STEP: Creating a kubernetes client @ 07/22/26 22:36:04.483\n  I0722 22:36:08.805796 23191 client.go:293] configPath is now \"/var/folders/7h/zgpvgd5946bcf53ktsvp95_40000gn/T/configfile2173069665\"\n  I0722 22:36:08.805834 23191 client.go:368] The user is now \"e2e-test-router-ipfailover-pc82p-user\"\n  I0722 22:36:08.805846 23191 client.go:370] Creating project \"e2e-test-router-ipfailover-pc82p\"\n  I0722 22:36:09.174807 23191 client.go:378] Waiting on permissions in project \"e2e-test-router-ipfailover-pc82p\" ...\n  I0722 22:36:10.238399 23191 client.go:407] DeploymentConfig capability is enabled, adding 'deployer' SA to the list of default SAs\n  I0722 22:36:10.515301 23191 client.go:422] Waiting for ServiceAccount \"default\" to be provisioned...\n  I0722 22:36:12.045617 23191 client.go:422] Waiting for ServiceAccount \"builder\" to be provisioned...\n  I0722 22:36:12.676937 23191 client.go:422] Waiting for ServiceAccount \"deployer\" to be provisioned...\n  I0722 22:36:13.305840 23191 client.go:432] Waiting for RoleBinding \"system:image-pullers\" to be provisioned...\n  I0722 22:36:13.565583 23191 client.go:432] Waiting for RoleBinding \"system:image-builders\" to be provisioned...\n  I0722 22:36:13.823288 23191 client.go:432] Waiting for RoleBinding \"system:deployers\" to be provisioned...\n  I0722 22:36:15.646899 23191 client.go:469] Project \"e2e-test-router-ipfailover-pc82p\" has been fully provisioned.\n    STEP: Check platforms @ 07/22/26 22:36:15.647\n    STEP: check whether there are two worker nodes present for testing hostnetwork @ 07/22/26 22:36:16.76\n  I0722 22:36:18.035220 23191 util.go:61] Linux worker node details:\n  gnfq2hk-b5564-9ks7d-worker-0-4bnpj\n  gnfq2hk-b5564-9ks7d-worker-0-6fjsr\n  gnfq2hk-b5564-9ks7d-worker-0-jdf4g\n  I0722 22:36:18.035267 23191 util.go:62] Available linux worker node count is: 3\n    STEP: check the cluster has remote worker profile @ 07/22/26 22:36:21.468\n    STEP: check whether the cluster is not ipv6 single stack @ 07/22/26 22:36:23.087\n    STEP: Check network type @ 07/22/26 22:36:23.866\n    STEP: 1. Get pull spec of ipfailover image from payload @ 07/22/26 22:36:24.753\n  I0722 22:36:30.972027 23191 util.go:121] the pull spec of image keepalived-ipfailover is: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:93c0a2b5ccfa1b27c43b02d4e8773e2641056c8ce85490a1a5c1dfaada6d1ad2\n    STEP: 2. Create ipfailover deployment and ensure one of pod enter MASTER state @ 07/22/26 22:36:30.99\n  namespace/e2e-test-router-ipfailover-pc82p labeled\n  I0722 22:36:32.124377 23191 util.go:275] Successfully added privileged labels (enforce, audit, warn) to namespace e2e-test-router-ipfailover-pc82p\n  I0722 22:36:38.287868 23191 util.go:356] the file of resource is /tmp/e2e-test-router-ipfailover-pc82p-w1q5zs0t-temp-resource.json\n  deployment.apps/ipf-41027 created\n  I0722 22:36:46.155249 23191 util.go:363] the Ready status of pod is True True\n  I0722 22:36:47.171938 23191 util.go:185] The pod list is [ipf-41027-7b94bb7cf8-wchsm ipf-41027-7b94bb7cf8-xzlxn]\n  I0722 22:37:01.662686 23191 util.go:136] The first pod log's failover status:- Wed Jul 22 17:06:39 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n  Wed Jul 22 17:06:42 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\n  I0722 22:37:03.078051 23191 util.go:143] The second pod log's failover status:- Wed Jul 22 17:06:39 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\n  I0722 22:37:03.078102 23191 util.go:164] The Master pod is ipf-41027-7b94bb7cf8-wchsm and Backup pod is ipf-41027-7b94bb7cf8-xzlxn\n    STEP: 3. Set the HA virtual IP for the failover group @ 07/22/26 22:37:03.078\n  I0722 22:37:04.705772 23191 util.go:302] The pod  ipf-41027-7b94bb7cf8-wchsm IP in namespace e2e-test-router-ipfailover-pc82p is \"10.0.2.136\"\n  I0722 22:37:04.705830 23191 util.go:176] The modified ipaddress is 10.0.2.100 \n  deployment.apps/ipf-41027 updated\n    STEP: 4. Verify the HA virtual ip ENV variable @ 07/22/26 22:37:15.813\n  I0722 22:37:22.135036 23191 util.go:363] the Ready status of pod is True True\n  I0722 22:37:23.243090 23191 util.go:185] The pod list is [ipf-41027-cc767d447-6h66q ipf-41027-cc767d447-hhvgw]\n  I0722 22:37:37.630567 23191 util.go:136] The first pod log's failover status:- Wed Jul 22 17:07:06 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n  Wed Jul 22 17:07:09 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\n  I0722 22:37:39.056730 23191 util.go:143] The second pod log's failover status:- Wed Jul 22 17:07:06 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\n  I0722 22:37:39.056831 23191 util.go:164] The Master pod is ipf-41027-cc767d447-6h66q and Backup pod is ipf-41027-cc767d447-hhvgw\n  I0722 22:37:45.967186 23191 util.go:264] the matching part is: OPENSHIFT_HA_VIRTUAL_IPS=10.0.2.100\n    STEP: 5. Find the primary and the secondary pod using the virtual IP @ 07/22/26 22:37:45.968\n  I0722 22:37:47.631666 23191 util.go:207] The pod owning the VIP is ipf-41027-cc767d447-6h66q\n    STEP: 6. Restarting the ipfailover primary pod @ 07/22/26 22:37:47.631\n  pod \"ipf-41027-cc767d447-6h66q\" deleted\n    STEP: 6a. Wait for replica replacement after pod deletion @ 07/22/26 22:37:49.528\n    STEP: 7. Verify the virtual IP is floated onto the new MASTER node @ 07/22/26 22:37:55.343\n  I0722 22:37:56.512171 23191 util.go:185] The pod list is [ipf-41027-cc767d447-hhvgw ipf-41027-cc767d447-wrs2n]\n  I0722 22:38:10.765942 23191 util.go:136] The first pod log's failover status:- Wed Jul 22 17:07:06 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n  Wed Jul 22 17:07:49 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\n  I0722 22:38:12.252562 23191 util.go:143] The second pod log's failover status:- Wed Jul 22 17:07:49 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\n  I0722 22:38:12.252757 23191 util.go:164] The Master pod is ipf-41027-cc767d447-hhvgw and Backup pod is ipf-41027-cc767d447-wrs2n\n  I0722 22:38:19.240679 23191 util.go:241] The new pod ipf-41027-cc767d447-hhvgw is the master\n  I0722 22:38:22.338061 23191 client.go:689] Deleted {user.openshift.io/v1, Resource=users  e2e-test-router-ipfailover-pc82p-user}, err: \u003cnil\u003e\n  I0722 22:38:22.616212 23191 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthclients  e2e-client-e2e-test-router-ipfailover-pc82p}, err: \u003cnil\u003e\n  I0722 22:38:22.894930 23191 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthaccesstokens  sha256~mWr9ElxsNakVbOwaL-ssK00WlPvaA4Q_JqpqTh9jJq0}, err: \u003cnil\u003e\n    STEP: Destroying namespace \"e2e-test-router-ipfailover-pc82p\" for this suite. @ 07/22/26 22:38:22.897\n"
  },
  {
    "name": "[OTP][sig-network-edge] Network_Edge Author:mjoseph-NonHyperShiftHOST-ConnectedOnly-Medium-41028-ipfailover configuration can be customized by ENV [Serial]",
    "lifecycle": "blocking",
    "duration": 212493,
    "startTime": "2026-07-22 17:08:23.498163 UTC",
    "endTime": "2026-07-22 17:11:55.991846 UTC",
    "result": "passed",
    "output": "  STEP: Creating a kubernetes client @ 07/22/26 22:38:23.498\nI0722 22:38:27.667750 23543 client.go:293] configPath is now \"/var/folders/7h/zgpvgd5946bcf53ktsvp95_40000gn/T/configfile689012487\"\nI0722 22:38:27.667803 23543 client.go:368] The user is now \"e2e-test-router-ipfailover-ncxn6-user\"\nI0722 22:38:27.667810 23543 client.go:370] Creating project \"e2e-test-router-ipfailover-ncxn6\"\nI0722 22:38:28.036250 23543 client.go:378] Waiting on permissions in project \"e2e-test-router-ipfailover-ncxn6\" ...\nI0722 22:38:29.068812 23543 client.go:407] DeploymentConfig capability is enabled, adding 'deployer' SA to the list of default SAs\nI0722 22:38:29.323203 23543 client.go:422] Waiting for ServiceAccount \"default\" to be provisioned...\nI0722 22:38:29.950014 23543 client.go:422] Waiting for ServiceAccount \"builder\" to be provisioned...\nI0722 22:38:30.578281 23543 client.go:422] Waiting for ServiceAccount \"deployer\" to be provisioned...\nI0722 22:38:31.211135 23543 client.go:432] Waiting for RoleBinding \"system:image-pullers\" to be provisioned...\nI0722 22:38:31.490350 23543 client.go:432] Waiting for RoleBinding \"system:image-builders\" to be provisioned...\nI0722 22:38:31.758479 23543 client.go:432] Waiting for RoleBinding \"system:deployers\" to be provisioned...\nI0722 22:38:33.661757 23543 client.go:469] Project \"e2e-test-router-ipfailover-ncxn6\" has been fully provisioned.\n  STEP: Check platforms @ 07/22/26 22:38:33.662\n  STEP: check whether there are two worker nodes present for testing hostnetwork @ 07/22/26 22:38:34.693\nI0722 22:38:36.076431 23543 util.go:61] Linux worker node details:\ngnfq2hk-b5564-9ks7d-worker-0-4bnpj\ngnfq2hk-b5564-9ks7d-worker-0-6fjsr\ngnfq2hk-b5564-9ks7d-worker-0-jdf4g\nI0722 22:38:36.076480 23543 util.go:62] Available linux worker node count is: 3\n  STEP: check the cluster has remote worker profile @ 07/22/26 22:38:39.519\n  STEP: check whether the cluster is not ipv6 single stack @ 07/22/26 22:38:41.193\n  STEP: Check network type @ 07/22/26 22:38:42.012\n  STEP: get pull spec of ipfailover image from payload @ 07/22/26 22:38:42.867\nI0722 22:38:49.406071 23543 util.go:121] the pull spec of image keepalived-ipfailover is: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:93c0a2b5ccfa1b27c43b02d4e8773e2641056c8ce85490a1a5c1dfaada6d1ad2\n  STEP: create ipfailover deployment and ensure one of pod enter MASTER state @ 07/22/26 22:38:49.433\nnamespace/e2e-test-router-ipfailover-ncxn6 labeled\nI0722 22:38:50.540835 23543 util.go:275] Successfully added privileged labels (enforce, audit, warn) to namespace e2e-test-router-ipfailover-ncxn6\nI0722 22:38:56.567236 23543 util.go:356] the file of resource is /tmp/e2e-test-router-ipfailover-ncxn6-ouc8z9eb-temp-resource.json\ndeployment.apps/ipf-41028 created\nI0722 22:39:04.310895 23543 util.go:363] the Ready status of pod is True True\n  STEP: set the HA virtual IP for the failover group @ 07/22/26 22:39:04.311\nI0722 22:39:05.398904 23543 util.go:185] The pod list is [ipf-41028-7b94bb7cf8-5n5jw ipf-41028-7b94bb7cf8-l9vn5]\nI0722 22:39:07.056221 23543 util.go:302] The pod  ipf-41028-7b94bb7cf8-5n5jw IP in namespace e2e-test-router-ipfailover-ncxn6 is \"10.0.0.127\"\nI0722 22:39:07.056293 23543 util.go:176] The modified ipaddress is 10.0.0.100 \ndeployment.apps/ipf-41028 updated\n  STEP: set other ipfailover env varibales @ 07/22/26 22:39:18.194\ndeployment.apps/ipf-41028 updated\ndeployment.apps/ipf-41028 updated\ndeployment.apps/ipf-41028 updated\ndeployment.apps/ipf-41028 updated\ndeployment.apps/ipf-41028 updated\ndeployment.apps/ipf-41028 updated\ndeployment.apps/ipf-41028 updated\ndeployment.apps/ipf-41028 updated\ndeployment.apps/ipf-41028 updated\ndeployment.apps/ipf-41028 updated\ndeployment.apps/ipf-41028 updated\n  STEP: verify the HA virtual ip ENV variable @ 07/22/26 22:41:21.388\nI0722 22:41:27.615429 23543 util.go:363] the Ready status of pod is True True\nI0722 22:41:29.574614 23543 util.go:185] The pod list is [ipf-41028-6958b878f-5l5xr ipf-41028-6958b878f-dh8wq]\nI0722 22:41:44.429594 23543 util.go:136] The first pod log's failover status:- Wed Jul 22 17:11:12 2026: (ipfailover_VIP_1) Entering BACKUP STATE (init)\nWed Jul 22 17:11:15 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\nI0722 22:41:45.788035 23543 util.go:143] The second pod log's failover status:- Wed Jul 22 17:11:12 2026: (ipfailover_VIP_1) Entering BACKUP STATE (init)\n\nI0722 22:41:45.788133 23543 util.go:164] The Master pod is ipf-41028-6958b878f-5l5xr and Backup pod is ipf-41028-6958b878f-dh8wq\nI0722 22:41:53.065280 23543 util.go:264] the matching part is: E0722 22:41:53.026079   23861 websocket.go:296] Unknown stream id 1, discarding message\nOPENSHIFT_HA_VIRTUAL_IPS=10.0.0.100\n  STEP: check the ipfailover configurations and verify the other ENV variables @ 07/22/26 22:41:53.065\nI0722 22:41:55.287164 23543 client.go:689] Deleted {user.openshift.io/v1, Resource=users  e2e-test-router-ipfailover-ncxn6-user}, err: \u003cnil\u003e\nI0722 22:41:55.518581 23543 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthclients  e2e-client-e2e-test-router-ipfailover-ncxn6}, err: \u003cnil\u003e\nI0722 22:41:55.752656 23543 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthaccesstokens  sha256~ENTCG7xyk8Nsbcc-Prj5IoTLZEmBWgFr3-0c3J-kzyM}, err: \u003cnil\u003e\n  STEP: Destroying namespace \"e2e-test-router-ipfailover-ncxn6\" for this suite. @ 07/22/26 22:41:55.753\n",
    "error": "    STEP: Creating a kubernetes client @ 07/22/26 22:38:23.498\n  I0722 22:38:27.667750 23543 client.go:293] configPath is now \"/var/folders/7h/zgpvgd5946bcf53ktsvp95_40000gn/T/configfile689012487\"\n  I0722 22:38:27.667803 23543 client.go:368] The user is now \"e2e-test-router-ipfailover-ncxn6-user\"\n  I0722 22:38:27.667810 23543 client.go:370] Creating project \"e2e-test-router-ipfailover-ncxn6\"\n  I0722 22:38:28.036250 23543 client.go:378] Waiting on permissions in project \"e2e-test-router-ipfailover-ncxn6\" ...\n  I0722 22:38:29.068812 23543 client.go:407] DeploymentConfig capability is enabled, adding 'deployer' SA to the list of default SAs\n  I0722 22:38:29.323203 23543 client.go:422] Waiting for ServiceAccount \"default\" to be provisioned...\n  I0722 22:38:29.950014 23543 client.go:422] Waiting for ServiceAccount \"builder\" to be provisioned...\n  I0722 22:38:30.578281 23543 client.go:422] Waiting for ServiceAccount \"deployer\" to be provisioned...\n  I0722 22:38:31.211135 23543 client.go:432] Waiting for RoleBinding \"system:image-pullers\" to be provisioned...\n  I0722 22:38:31.490350 23543 client.go:432] Waiting for RoleBinding \"system:image-builders\" to be provisioned...\n  I0722 22:38:31.758479 23543 client.go:432] Waiting for RoleBinding \"system:deployers\" to be provisioned...\n  I0722 22:38:33.661757 23543 client.go:469] Project \"e2e-test-router-ipfailover-ncxn6\" has been fully provisioned.\n    STEP: Check platforms @ 07/22/26 22:38:33.662\n    STEP: check whether there are two worker nodes present for testing hostnetwork @ 07/22/26 22:38:34.693\n  I0722 22:38:36.076431 23543 util.go:61] Linux worker node details:\n  gnfq2hk-b5564-9ks7d-worker-0-4bnpj\n  gnfq2hk-b5564-9ks7d-worker-0-6fjsr\n  gnfq2hk-b5564-9ks7d-worker-0-jdf4g\n  I0722 22:38:36.076480 23543 util.go:62] Available linux worker node count is: 3\n    STEP: check the cluster has remote worker profile @ 07/22/26 22:38:39.519\n    STEP: check whether the cluster is not ipv6 single stack @ 07/22/26 22:38:41.193\n    STEP: Check network type @ 07/22/26 22:38:42.012\n    STEP: get pull spec of ipfailover image from payload @ 07/22/26 22:38:42.867\n  I0722 22:38:49.406071 23543 util.go:121] the pull spec of image keepalived-ipfailover is: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:93c0a2b5ccfa1b27c43b02d4e8773e2641056c8ce85490a1a5c1dfaada6d1ad2\n    STEP: create ipfailover deployment and ensure one of pod enter MASTER state @ 07/22/26 22:38:49.433\n  namespace/e2e-test-router-ipfailover-ncxn6 labeled\n  I0722 22:38:50.540835 23543 util.go:275] Successfully added privileged labels (enforce, audit, warn) to namespace e2e-test-router-ipfailover-ncxn6\n  I0722 22:38:56.567236 23543 util.go:356] the file of resource is /tmp/e2e-test-router-ipfailover-ncxn6-ouc8z9eb-temp-resource.json\n  deployment.apps/ipf-41028 created\n  I0722 22:39:04.310895 23543 util.go:363] the Ready status of pod is True True\n    STEP: set the HA virtual IP for the failover group @ 07/22/26 22:39:04.311\n  I0722 22:39:05.398904 23543 util.go:185] The pod list is [ipf-41028-7b94bb7cf8-5n5jw ipf-41028-7b94bb7cf8-l9vn5]\n  I0722 22:39:07.056221 23543 util.go:302] The pod  ipf-41028-7b94bb7cf8-5n5jw IP in namespace e2e-test-router-ipfailover-ncxn6 is \"10.0.0.127\"\n  I0722 22:39:07.056293 23543 util.go:176] The modified ipaddress is 10.0.0.100 \n  deployment.apps/ipf-41028 updated\n    STEP: set other ipfailover env varibales @ 07/22/26 22:39:18.194\n  deployment.apps/ipf-41028 updated\n  deployment.apps/ipf-41028 updated\n  deployment.apps/ipf-41028 updated\n  deployment.apps/ipf-41028 updated\n  deployment.apps/ipf-41028 updated\n  deployment.apps/ipf-41028 updated\n  deployment.apps/ipf-41028 updated\n  deployment.apps/ipf-41028 updated\n  deployment.apps/ipf-41028 updated\n  deployment.apps/ipf-41028 updated\n  deployment.apps/ipf-41028 updated\n    STEP: verify the HA virtual ip ENV variable @ 07/22/26 22:41:21.388\n  I0722 22:41:27.615429 23543 util.go:363] the Ready status of pod is True True\n  I0722 22:41:29.574614 23543 util.go:185] The pod list is [ipf-41028-6958b878f-5l5xr ipf-41028-6958b878f-dh8wq]\n  I0722 22:41:44.429594 23543 util.go:136] The first pod log's failover status:- Wed Jul 22 17:11:12 2026: (ipfailover_VIP_1) Entering BACKUP STATE (init)\n  Wed Jul 22 17:11:15 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\n  I0722 22:41:45.788035 23543 util.go:143] The second pod log's failover status:- Wed Jul 22 17:11:12 2026: (ipfailover_VIP_1) Entering BACKUP STATE (init)\n\n  I0722 22:41:45.788133 23543 util.go:164] The Master pod is ipf-41028-6958b878f-5l5xr and Backup pod is ipf-41028-6958b878f-dh8wq\n  I0722 22:41:53.065280 23543 util.go:264] the matching part is: E0722 22:41:53.026079   23861 websocket.go:296] Unknown stream id 1, discarding message\n  OPENSHIFT_HA_VIRTUAL_IPS=10.0.0.100\n    STEP: check the ipfailover configurations and verify the other ENV variables @ 07/22/26 22:41:53.065\n  I0722 22:41:55.287164 23543 client.go:689] Deleted {user.openshift.io/v1, Resource=users  e2e-test-router-ipfailover-ncxn6-user}, err: \u003cnil\u003e\n  I0722 22:41:55.518581 23543 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthclients  e2e-client-e2e-test-router-ipfailover-ncxn6}, err: \u003cnil\u003e\n  I0722 22:41:55.752656 23543 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthaccesstokens  sha256~ENTCG7xyk8Nsbcc-Prj5IoTLZEmBWgFr3-0c3J-kzyM}, err: \u003cnil\u003e\n    STEP: Destroying namespace \"e2e-test-router-ipfailover-ncxn6\" for this suite. @ 07/22/26 22:41:55.753\n"
  },
  {
    "name": "[OTP][sig-network-edge] Network_Edge Author:mjoseph-NonHyperShiftHOST-ConnectedOnly-Medium-41029-ipfailover can support up to a maximum of 255 VIPs for the entire cluster [Serial]",
    "lifecycle": "blocking",
    "duration": 112469,
    "startTime": "2026-07-22 17:11:56.237167 UTC",
    "endTime": "2026-07-22 17:13:48.706310 UTC",
    "result": "passed",
    "output": "  STEP: Creating a kubernetes client @ 07/22/26 22:41:56.237\nI0722 22:42:00.818175 23866 client.go:293] configPath is now \"/var/folders/7h/zgpvgd5946bcf53ktsvp95_40000gn/T/configfile3515751469\"\nI0722 22:42:00.818227 23866 client.go:368] The user is now \"e2e-test-router-ipfailover-sdbjh-user\"\nI0722 22:42:00.818236 23866 client.go:370] Creating project \"e2e-test-router-ipfailover-sdbjh\"\nI0722 22:42:01.198944 23866 client.go:378] Waiting on permissions in project \"e2e-test-router-ipfailover-sdbjh\" ...\nI0722 22:42:02.157501 23866 client.go:407] DeploymentConfig capability is enabled, adding 'deployer' SA to the list of default SAs\nI0722 22:42:02.396168 23866 client.go:422] Waiting for ServiceAccount \"default\" to be provisioned...\nI0722 22:42:02.987693 23866 client.go:422] Waiting for ServiceAccount \"builder\" to be provisioned...\nI0722 22:42:03.582075 23866 client.go:422] Waiting for ServiceAccount \"deployer\" to be provisioned...\nI0722 22:42:04.164098 23866 client.go:432] Waiting for RoleBinding \"system:image-pullers\" to be provisioned...\nI0722 22:42:04.400702 23866 client.go:432] Waiting for RoleBinding \"system:image-builders\" to be provisioned...\nI0722 22:42:04.650018 23866 client.go:432] Waiting for RoleBinding \"system:deployers\" to be provisioned...\nI0722 22:42:06.347231 23866 client.go:469] Project \"e2e-test-router-ipfailover-sdbjh\" has been fully provisioned.\n  STEP: Check platforms @ 07/22/26 22:42:06.347\n  STEP: check whether there are two worker nodes present for testing hostnetwork @ 07/22/26 22:42:07.828\nI0722 22:42:09.244987 23866 util.go:61] Linux worker node details:\ngnfq2hk-b5564-9ks7d-worker-0-4bnpj\ngnfq2hk-b5564-9ks7d-worker-0-6fjsr\ngnfq2hk-b5564-9ks7d-worker-0-jdf4g\nI0722 22:42:09.245060 23866 util.go:62] Available linux worker node count is: 3\n  STEP: check the cluster has remote worker profile @ 07/22/26 22:42:12.862\n  STEP: check whether the cluster is not ipv6 single stack @ 07/22/26 22:42:14.382\n  STEP: Check network type @ 07/22/26 22:42:15.21\n  STEP: get pull spec of ipfailover image from payload @ 07/22/26 22:42:16.928\nI0722 22:42:24.622975 23866 util.go:121] the pull spec of image keepalived-ipfailover is: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:93c0a2b5ccfa1b27c43b02d4e8773e2641056c8ce85490a1a5c1dfaada6d1ad2\n  STEP: create ipfailover deployment and ensure one of pod enter MASTER state @ 07/22/26 22:42:24.647\nnamespace/e2e-test-router-ipfailover-sdbjh labeled\nI0722 22:42:25.760687 23866 util.go:275] Successfully added privileged labels (enforce, audit, warn) to namespace e2e-test-router-ipfailover-sdbjh\nI0722 22:42:31.967935 23866 util.go:356] the file of resource is /tmp/e2e-test-router-ipfailover-sdbjh-tswoknxp-temp-resource.json\ndeployment.apps/ipf-41029 created\nI0722 22:42:39.942025 23866 util.go:363] the Ready status of pod is True True\nI0722 22:42:41.097159 23866 util.go:185] The pod list is [ipf-41029-7b94bb7cf8-959q5 ipf-41029-7b94bb7cf8-rqdpm]\nI0722 22:42:55.786112 23866 util.go:136] The first pod log's failover status:- Wed Jul 22 17:12:33 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\nI0722 22:42:57.162911 23866 util.go:143] The second pod log's failover status:- Wed Jul 22 17:12:33 2026: (ipfailover_VIP_1) Entering BACKUP STATE\nWed Jul 22 17:12:36 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\nI0722 22:42:57.163007 23866 util.go:164] The Master pod is ipf-41029-7b94bb7cf8-rqdpm and Backup pod is ipf-41029-7b94bb7cf8-959q5\n  STEP: add some VIP configuration for the failover group @ 07/22/26 22:42:57.163\ndeployment.apps/ipf-41029 updated\ndeployment.apps/ipf-41029 updated\ndeployment.apps/ipf-41029 updated\n  STEP: verify from the ipfailover pod, the 255 VIPs are added @ 07/22/26 22:43:31.363\nI0722 22:43:38.259061 23866 util.go:363] the Ready status of pod is True True\nI0722 22:43:39.324208 23866 util.go:185] The pod list is [ipf-41029-88dc7654-554vt ipf-41029-88dc7654-s9ksr]\nI0722 22:43:45.998422 23866 util.go:264] the matching part is: E0722 22:43:45.943725   23961 websocket.go:296] Unknown stream id 1, discarding message\nOPENSHIFT_HA_VIP_GROUPS=238\nI0722 22:43:47.921873 23866 client.go:689] Deleted {user.openshift.io/v1, Resource=users  e2e-test-router-ipfailover-sdbjh-user}, err: \u003cnil\u003e\nI0722 22:43:48.189494 23866 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthclients  e2e-client-e2e-test-router-ipfailover-sdbjh}, err: \u003cnil\u003e\nI0722 22:43:48.446303 23866 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthaccesstokens  sha256~ylCo7gGXaygSwLSBw4fS_zYk65G4fnGr6gReznhFQJA}, err: \u003cnil\u003e\n  STEP: Destroying namespace \"e2e-test-router-ipfailover-sdbjh\" for this suite. @ 07/22/26 22:43:48.446\n",
    "error": "    STEP: Creating a kubernetes client @ 07/22/26 22:41:56.237\n  I0722 22:42:00.818175 23866 client.go:293] configPath is now \"/var/folders/7h/zgpvgd5946bcf53ktsvp95_40000gn/T/configfile3515751469\"\n  I0722 22:42:00.818227 23866 client.go:368] The user is now \"e2e-test-router-ipfailover-sdbjh-user\"\n  I0722 22:42:00.818236 23866 client.go:370] Creating project \"e2e-test-router-ipfailover-sdbjh\"\n  I0722 22:42:01.198944 23866 client.go:378] Waiting on permissions in project \"e2e-test-router-ipfailover-sdbjh\" ...\n  I0722 22:42:02.157501 23866 client.go:407] DeploymentConfig capability is enabled, adding 'deployer' SA to the list of default SAs\n  I0722 22:42:02.396168 23866 client.go:422] Waiting for ServiceAccount \"default\" to be provisioned...\n  I0722 22:42:02.987693 23866 client.go:422] Waiting for ServiceAccount \"builder\" to be provisioned...\n  I0722 22:42:03.582075 23866 client.go:422] Waiting for ServiceAccount \"deployer\" to be provisioned...\n  I0722 22:42:04.164098 23866 client.go:432] Waiting for RoleBinding \"system:image-pullers\" to be provisioned...\n  I0722 22:42:04.400702 23866 client.go:432] Waiting for RoleBinding \"system:image-builders\" to be provisioned...\n  I0722 22:42:04.650018 23866 client.go:432] Waiting for RoleBinding \"system:deployers\" to be provisioned...\n  I0722 22:42:06.347231 23866 client.go:469] Project \"e2e-test-router-ipfailover-sdbjh\" has been fully provisioned.\n    STEP: Check platforms @ 07/22/26 22:42:06.347\n    STEP: check whether there are two worker nodes present for testing hostnetwork @ 07/22/26 22:42:07.828\n  I0722 22:42:09.244987 23866 util.go:61] Linux worker node details:\n  gnfq2hk-b5564-9ks7d-worker-0-4bnpj\n  gnfq2hk-b5564-9ks7d-worker-0-6fjsr\n  gnfq2hk-b5564-9ks7d-worker-0-jdf4g\n  I0722 22:42:09.245060 23866 util.go:62] Available linux worker node count is: 3\n    STEP: check the cluster has remote worker profile @ 07/22/26 22:42:12.862\n    STEP: check whether the cluster is not ipv6 single stack @ 07/22/26 22:42:14.382\n    STEP: Check network type @ 07/22/26 22:42:15.21\n    STEP: get pull spec of ipfailover image from payload @ 07/22/26 22:42:16.928\n  I0722 22:42:24.622975 23866 util.go:121] the pull spec of image keepalived-ipfailover is: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:93c0a2b5ccfa1b27c43b02d4e8773e2641056c8ce85490a1a5c1dfaada6d1ad2\n    STEP: create ipfailover deployment and ensure one of pod enter MASTER state @ 07/22/26 22:42:24.647\n  namespace/e2e-test-router-ipfailover-sdbjh labeled\n  I0722 22:42:25.760687 23866 util.go:275] Successfully added privileged labels (enforce, audit, warn) to namespace e2e-test-router-ipfailover-sdbjh\n  I0722 22:42:31.967935 23866 util.go:356] the file of resource is /tmp/e2e-test-router-ipfailover-sdbjh-tswoknxp-temp-resource.json\n  deployment.apps/ipf-41029 created\n  I0722 22:42:39.942025 23866 util.go:363] the Ready status of pod is True True\n  I0722 22:42:41.097159 23866 util.go:185] The pod list is [ipf-41029-7b94bb7cf8-959q5 ipf-41029-7b94bb7cf8-rqdpm]\n  I0722 22:42:55.786112 23866 util.go:136] The first pod log's failover status:- Wed Jul 22 17:12:33 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\n  I0722 22:42:57.162911 23866 util.go:143] The second pod log's failover status:- Wed Jul 22 17:12:33 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n  Wed Jul 22 17:12:36 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\n  I0722 22:42:57.163007 23866 util.go:164] The Master pod is ipf-41029-7b94bb7cf8-rqdpm and Backup pod is ipf-41029-7b94bb7cf8-959q5\n    STEP: add some VIP configuration for the failover group @ 07/22/26 22:42:57.163\n  deployment.apps/ipf-41029 updated\n  deployment.apps/ipf-41029 updated\n  deployment.apps/ipf-41029 updated\n    STEP: verify from the ipfailover pod, the 255 VIPs are added @ 07/22/26 22:43:31.363\n  I0722 22:43:38.259061 23866 util.go:363] the Ready status of pod is True True\n  I0722 22:43:39.324208 23866 util.go:185] The pod list is [ipf-41029-88dc7654-554vt ipf-41029-88dc7654-s9ksr]\n  I0722 22:43:45.998422 23866 util.go:264] the matching part is: E0722 22:43:45.943725   23961 websocket.go:296] Unknown stream id 1, discarding message\n  OPENSHIFT_HA_VIP_GROUPS=238\n  I0722 22:43:47.921873 23866 client.go:689] Deleted {user.openshift.io/v1, Resource=users  e2e-test-router-ipfailover-sdbjh-user}, err: \u003cnil\u003e\n  I0722 22:43:48.189494 23866 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthclients  e2e-client-e2e-test-router-ipfailover-sdbjh}, err: \u003cnil\u003e\n  I0722 22:43:48.446303 23866 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthaccesstokens  sha256~ylCo7gGXaygSwLSBw4fS_zYk65G4fnGr6gReznhFQJA}, err: \u003cnil\u003e\n    STEP: Destroying namespace \"e2e-test-router-ipfailover-sdbjh\" for this suite. @ 07/22/26 22:43:48.446\n"
  },
  {
    "name": "[OTP][sig-network-edge] Network_Edge Author:mjoseph-NonHyperShiftHOST-ConnectedOnly-High-41030-preemption strategy for keepalived ipfailover [Disruptive]",
    "lifecycle": "blocking",
    "duration": 301986,
    "startTime": "2026-07-22 17:13:48.983365 UTC",
    "endTime": "2026-07-22 17:18:50.969461 UTC",
    "result": "passed",
    "output": "  STEP: Creating a kubernetes client @ 07/22/26 22:43:48.983\nI0722 22:43:53.367467 23972 client.go:293] configPath is now \"/var/folders/7h/zgpvgd5946bcf53ktsvp95_40000gn/T/configfile1265874192\"\nI0722 22:43:53.367598 23972 client.go:368] The user is now \"e2e-test-router-ipfailover-vr5xf-user\"\nI0722 22:43:53.367664 23972 client.go:370] Creating project \"e2e-test-router-ipfailover-vr5xf\"\nI0722 22:43:53.717634 23972 client.go:378] Waiting on permissions in project \"e2e-test-router-ipfailover-vr5xf\" ...\nI0722 22:43:54.777874 23972 client.go:407] DeploymentConfig capability is enabled, adding 'deployer' SA to the list of default SAs\nI0722 22:43:55.050263 23972 client.go:422] Waiting for ServiceAccount \"default\" to be provisioned...\nI0722 22:43:55.668535 23972 client.go:422] Waiting for ServiceAccount \"builder\" to be provisioned...\nI0722 22:43:56.276997 23972 client.go:422] Waiting for ServiceAccount \"deployer\" to be provisioned...\nI0722 22:43:56.892934 23972 client.go:432] Waiting for RoleBinding \"system:image-pullers\" to be provisioned...\nI0722 22:43:57.136045 23972 client.go:432] Waiting for RoleBinding \"system:image-builders\" to be provisioned...\nI0722 22:43:57.378148 23972 client.go:432] Waiting for RoleBinding \"system:deployers\" to be provisioned...\nI0722 22:43:59.196972 23972 client.go:469] Project \"e2e-test-router-ipfailover-vr5xf\" has been fully provisioned.\n  STEP: Check platforms @ 07/22/26 22:43:59.197\n  STEP: check whether there are two worker nodes present for testing hostnetwork @ 07/22/26 22:44:00.024\nI0722 22:44:01.330503 23972 util.go:61] Linux worker node details:\ngnfq2hk-b5564-9ks7d-worker-0-4bnpj\ngnfq2hk-b5564-9ks7d-worker-0-6fjsr\ngnfq2hk-b5564-9ks7d-worker-0-jdf4g\nI0722 22:44:01.330599 23972 util.go:62] Available linux worker node count is: 3\n  STEP: check the cluster has remote worker profile @ 07/22/26 22:44:04.691\n  STEP: check whether the cluster is not ipv6 single stack @ 07/22/26 22:44:06.217\n  STEP: Check network type @ 07/22/26 22:44:07.1\n  STEP: 1. Get pull spec of ipfailover image from payload @ 07/22/26 22:44:08.079\nI0722 22:44:15.331560 23972 util.go:121] the pull spec of image keepalived-ipfailover is: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:93c0a2b5ccfa1b27c43b02d4e8773e2641056c8ce85490a1a5c1dfaada6d1ad2\n  STEP: 2. Create ipfailover deployment and ensure one of pod enter MASTER state @ 07/22/26 22:44:15.349\nnamespace/e2e-test-router-ipfailover-vr5xf labeled\nI0722 22:44:16.402498 23972 util.go:275] Successfully added privileged labels (enforce, audit, warn) to namespace e2e-test-router-ipfailover-vr5xf\nI0722 22:44:23.209768 23972 util.go:356] the file of resource is /tmp/e2e-test-router-ipfailover-vr5xf-ughjtayh-temp-resource.json\ndeployment.apps/ipf-41030 created\nI0722 22:44:31.005650 23972 util.go:363] the Ready status of pod is True True\nI0722 22:44:32.202188 23972 util.go:185] The pod list is [ipf-41030-7b94bb7cf8-btv75 ipf-41030-7b94bb7cf8-f6m2j]\nI0722 22:44:46.906992 23972 util.go:136] The first pod log's failover status:- Wed Jul 22 17:14:24 2026: (ipfailover_VIP_1) Entering BACKUP STATE\nWed Jul 22 17:14:27 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\nI0722 22:44:48.069074 23972 util.go:143] The second pod log's failover status:- Wed Jul 22 17:14:24 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\nI0722 22:44:48.069206 23972 util.go:164] The Master pod is ipf-41030-7b94bb7cf8-btv75 and Backup pod is ipf-41030-7b94bb7cf8-f6m2j\n  STEP: 3. Set the HA virtual IP for the failover group @ 07/22/26 22:44:48.069\nI0722 22:44:49.199686 23972 util.go:185] The pod list is [ipf-41030-7b94bb7cf8-btv75 ipf-41030-7b94bb7cf8-f6m2j]\nI0722 22:44:51.085516 23972 util.go:302] The pod  ipf-41030-7b94bb7cf8-btv75 IP in namespace e2e-test-router-ipfailover-vr5xf is \"10.0.2.136\"\nI0722 22:44:51.085571 23972 util.go:176] The modified ipaddress is 10.0.2.100 \ndeployment.apps/ipf-41030 updated\n  STEP: 4. Verify the HA virtual ip ENV variable @ 07/22/26 22:45:02.151\nI0722 22:45:08.259251 23972 util.go:363] the Ready status of pod is True True\nI0722 22:45:09.345920 23972 util.go:185] The pod list is [ipf-41030-cc767d447-pbdfw ipf-41030-cc767d447-xz8tb]\nI0722 22:45:23.738035 23972 util.go:136] The first pod log's failover status:- Wed Jul 22 17:14:53 2026: (ipfailover_VIP_1) Entering BACKUP STATE\nWed Jul 22 17:14:56 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\nI0722 22:45:25.159566 23972 util.go:143] The second pod log's failover status:- Wed Jul 22 17:14:52 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\nI0722 22:45:25.159670 23972 util.go:164] The Master pod is ipf-41030-cc767d447-pbdfw and Backup pod is ipf-41030-cc767d447-xz8tb\nI0722 22:45:32.242805 23972 util.go:264] the matching part is: E0722 22:45:32.207133   24038 websocket.go:296] Unknown stream id 1, discarding message\nOPENSHIFT_HA_VIRTUAL_IPS=10.0.2.100\nI0722 22:45:38.947453 23972 util.go:264] the matching part is: OPENSHIFT_HA_PREEMPTION=nopreempt\n  STEP: 5. Find the primary and the secondary pod @ 07/22/26 22:45:38.947\nI0722 22:45:40.518275 23972 util.go:207] The pod owning the VIP is ipf-41030-cc767d447-pbdfw\nI0722 22:45:40.518409 23972 util.go:223] The remaining pod/s in the list is [ipf-41030-cc767d447-xz8tb]\n  STEP: 6. Restarting the ipfailover primary pod @ 07/22/26 22:45:40.519\npod \"ipf-41030-cc767d447-pbdfw\" deleted\n  STEP: 7. Verify whether the other pod becomes primary and it has the VIP @ 07/22/26 22:45:42.244\nI0722 22:45:48.910104 23972 util.go:241] The new pod ipf-41030-cc767d447-xz8tb is the master\n  STEP: 8. Now set the preemption delay timer of 120s for the failover group @ 07/22/26 22:45:50.774\ndeployment.apps/ipf-41030 updated\nI0722 22:46:08.306450 23972 util.go:363] the Ready status of pod is True True\nI0722 22:46:09.442697 23972 util.go:185] The pod list is [ipf-41030-6889776bc9-f49km ipf-41030-6889776bc9-pnhrk]\nI0722 22:46:23.916147 23972 util.go:136] The first pod log's failover status:- Wed Jul 22 17:15:52 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\nI0722 22:46:25.400970 23972 util.go:143] The second pod log's failover status:- Wed Jul 22 17:15:52 2026: (ipfailover_VIP_1) Entering BACKUP STATE\nWed Jul 22 17:15:55 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\nI0722 22:46:25.401088 23972 util.go:164] The Master pod is ipf-41030-6889776bc9-pnhrk and Backup pod is ipf-41030-6889776bc9-f49km\nI0722 22:46:32.333815 23972 util.go:264] the matching part is: OPENSHIFT_HA_PREEMPTION=preempt_delay 120\n  STEP: 9. Again restart the ipfailover primary(master) pod @ 07/22/26 22:46:32.334\npod \"ipf-41030-6889776bc9-pnhrk\" deleted\n  STEP: 10. Verify the newly created pod preempts the exiting primary after the delay expires @ 07/22/26 22:46:34.237\nI0722 22:46:35.523792 23972 util.go:185] The pod list is [ipf-41030-6889776bc9-f49km ipf-41030-6889776bc9-mlln8]\nI0722 22:46:35.523908 23972 util.go:223] The remaining pod/s in the list is [ipf-41030-6889776bc9-mlln8]\nI0722 22:48:47.781998 23972 util.go:241] The new pod ipf-41030-6889776bc9-mlln8 is the master\nI0722 22:48:50.240868 23972 client.go:689] Deleted {user.openshift.io/v1, Resource=users  e2e-test-router-ipfailover-vr5xf-user}, err: \u003cnil\u003e\nI0722 22:48:50.482611 23972 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthclients  e2e-client-e2e-test-router-ipfailover-vr5xf}, err: \u003cnil\u003e\nI0722 22:48:50.725985 23972 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthaccesstokens  sha256~XbjpnyBGVpFopP1Exfm9DpWCrxJ8ZS6v_8zeY_YfhiM}, err: \u003cnil\u003e\n  STEP: Destroying namespace \"e2e-test-router-ipfailover-vr5xf\" for this suite. @ 07/22/26 22:48:50.726\n",
    "error": "    STEP: Creating a kubernetes client @ 07/22/26 22:43:48.983\n  I0722 22:43:53.367467 23972 client.go:293] configPath is now \"/var/folders/7h/zgpvgd5946bcf53ktsvp95_40000gn/T/configfile1265874192\"\n  I0722 22:43:53.367598 23972 client.go:368] The user is now \"e2e-test-router-ipfailover-vr5xf-user\"\n  I0722 22:43:53.367664 23972 client.go:370] Creating project \"e2e-test-router-ipfailover-vr5xf\"\n  I0722 22:43:53.717634 23972 client.go:378] Waiting on permissions in project \"e2e-test-router-ipfailover-vr5xf\" ...\n  I0722 22:43:54.777874 23972 client.go:407] DeploymentConfig capability is enabled, adding 'deployer' SA to the list of default SAs\n  I0722 22:43:55.050263 23972 client.go:422] Waiting for ServiceAccount \"default\" to be provisioned...\n  I0722 22:43:55.668535 23972 client.go:422] Waiting for ServiceAccount \"builder\" to be provisioned...\n  I0722 22:43:56.276997 23972 client.go:422] Waiting for ServiceAccount \"deployer\" to be provisioned...\n  I0722 22:43:56.892934 23972 client.go:432] Waiting for RoleBinding \"system:image-pullers\" to be provisioned...\n  I0722 22:43:57.136045 23972 client.go:432] Waiting for RoleBinding \"system:image-builders\" to be provisioned...\n  I0722 22:43:57.378148 23972 client.go:432] Waiting for RoleBinding \"system:deployers\" to be provisioned...\n  I0722 22:43:59.196972 23972 client.go:469] Project \"e2e-test-router-ipfailover-vr5xf\" has been fully provisioned.\n    STEP: Check platforms @ 07/22/26 22:43:59.197\n    STEP: check whether there are two worker nodes present for testing hostnetwork @ 07/22/26 22:44:00.024\n  I0722 22:44:01.330503 23972 util.go:61] Linux worker node details:\n  gnfq2hk-b5564-9ks7d-worker-0-4bnpj\n  gnfq2hk-b5564-9ks7d-worker-0-6fjsr\n  gnfq2hk-b5564-9ks7d-worker-0-jdf4g\n  I0722 22:44:01.330599 23972 util.go:62] Available linux worker node count is: 3\n    STEP: check the cluster has remote worker profile @ 07/22/26 22:44:04.691\n    STEP: check whether the cluster is not ipv6 single stack @ 07/22/26 22:44:06.217\n    STEP: Check network type @ 07/22/26 22:44:07.1\n    STEP: 1. Get pull spec of ipfailover image from payload @ 07/22/26 22:44:08.079\n  I0722 22:44:15.331560 23972 util.go:121] the pull spec of image keepalived-ipfailover is: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:93c0a2b5ccfa1b27c43b02d4e8773e2641056c8ce85490a1a5c1dfaada6d1ad2\n    STEP: 2. Create ipfailover deployment and ensure one of pod enter MASTER state @ 07/22/26 22:44:15.349\n  namespace/e2e-test-router-ipfailover-vr5xf labeled\n  I0722 22:44:16.402498 23972 util.go:275] Successfully added privileged labels (enforce, audit, warn) to namespace e2e-test-router-ipfailover-vr5xf\n  I0722 22:44:23.209768 23972 util.go:356] the file of resource is /tmp/e2e-test-router-ipfailover-vr5xf-ughjtayh-temp-resource.json\n  deployment.apps/ipf-41030 created\n  I0722 22:44:31.005650 23972 util.go:363] the Ready status of pod is True True\n  I0722 22:44:32.202188 23972 util.go:185] The pod list is [ipf-41030-7b94bb7cf8-btv75 ipf-41030-7b94bb7cf8-f6m2j]\n  I0722 22:44:46.906992 23972 util.go:136] The first pod log's failover status:- Wed Jul 22 17:14:24 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n  Wed Jul 22 17:14:27 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\n  I0722 22:44:48.069074 23972 util.go:143] The second pod log's failover status:- Wed Jul 22 17:14:24 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\n  I0722 22:44:48.069206 23972 util.go:164] The Master pod is ipf-41030-7b94bb7cf8-btv75 and Backup pod is ipf-41030-7b94bb7cf8-f6m2j\n    STEP: 3. Set the HA virtual IP for the failover group @ 07/22/26 22:44:48.069\n  I0722 22:44:49.199686 23972 util.go:185] The pod list is [ipf-41030-7b94bb7cf8-btv75 ipf-41030-7b94bb7cf8-f6m2j]\n  I0722 22:44:51.085516 23972 util.go:302] The pod  ipf-41030-7b94bb7cf8-btv75 IP in namespace e2e-test-router-ipfailover-vr5xf is \"10.0.2.136\"\n  I0722 22:44:51.085571 23972 util.go:176] The modified ipaddress is 10.0.2.100 \n  deployment.apps/ipf-41030 updated\n    STEP: 4. Verify the HA virtual ip ENV variable @ 07/22/26 22:45:02.151\n  I0722 22:45:08.259251 23972 util.go:363] the Ready status of pod is True True\n  I0722 22:45:09.345920 23972 util.go:185] The pod list is [ipf-41030-cc767d447-pbdfw ipf-41030-cc767d447-xz8tb]\n  I0722 22:45:23.738035 23972 util.go:136] The first pod log's failover status:- Wed Jul 22 17:14:53 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n  Wed Jul 22 17:14:56 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\n  I0722 22:45:25.159566 23972 util.go:143] The second pod log's failover status:- Wed Jul 22 17:14:52 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\n  I0722 22:45:25.159670 23972 util.go:164] The Master pod is ipf-41030-cc767d447-pbdfw and Backup pod is ipf-41030-cc767d447-xz8tb\n  I0722 22:45:32.242805 23972 util.go:264] the matching part is: E0722 22:45:32.207133   24038 websocket.go:296] Unknown stream id 1, discarding message\n  OPENSHIFT_HA_VIRTUAL_IPS=10.0.2.100\n  I0722 22:45:38.947453 23972 util.go:264] the matching part is: OPENSHIFT_HA_PREEMPTION=nopreempt\n    STEP: 5. Find the primary and the secondary pod @ 07/22/26 22:45:38.947\n  I0722 22:45:40.518275 23972 util.go:207] The pod owning the VIP is ipf-41030-cc767d447-pbdfw\n  I0722 22:45:40.518409 23972 util.go:223] The remaining pod/s in the list is [ipf-41030-cc767d447-xz8tb]\n    STEP: 6. Restarting the ipfailover primary pod @ 07/22/26 22:45:40.519\n  pod \"ipf-41030-cc767d447-pbdfw\" deleted\n    STEP: 7. Verify whether the other pod becomes primary and it has the VIP @ 07/22/26 22:45:42.244\n  I0722 22:45:48.910104 23972 util.go:241] The new pod ipf-41030-cc767d447-xz8tb is the master\n    STEP: 8. Now set the preemption delay timer of 120s for the failover group @ 07/22/26 22:45:50.774\n  deployment.apps/ipf-41030 updated\n  I0722 22:46:08.306450 23972 util.go:363] the Ready status of pod is True True\n  I0722 22:46:09.442697 23972 util.go:185] The pod list is [ipf-41030-6889776bc9-f49km ipf-41030-6889776bc9-pnhrk]\n  I0722 22:46:23.916147 23972 util.go:136] The first pod log's failover status:- Wed Jul 22 17:15:52 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\n  I0722 22:46:25.400970 23972 util.go:143] The second pod log's failover status:- Wed Jul 22 17:15:52 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n  Wed Jul 22 17:15:55 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\n  I0722 22:46:25.401088 23972 util.go:164] The Master pod is ipf-41030-6889776bc9-pnhrk and Backup pod is ipf-41030-6889776bc9-f49km\n  I0722 22:46:32.333815 23972 util.go:264] the matching part is: OPENSHIFT_HA_PREEMPTION=preempt_delay 120\n    STEP: 9. Again restart the ipfailover primary(master) pod @ 07/22/26 22:46:32.334\n  pod \"ipf-41030-6889776bc9-pnhrk\" deleted\n    STEP: 10. Verify the newly created pod preempts the exiting primary after the delay expires @ 07/22/26 22:46:34.237\n  I0722 22:46:35.523792 23972 util.go:185] The pod list is [ipf-41030-6889776bc9-f49km ipf-41030-6889776bc9-mlln8]\n  I0722 22:46:35.523908 23972 util.go:223] The remaining pod/s in the list is [ipf-41030-6889776bc9-mlln8]\n  I0722 22:48:47.781998 23972 util.go:241] The new pod ipf-41030-6889776bc9-mlln8 is the master\n  I0722 22:48:50.240868 23972 client.go:689] Deleted {user.openshift.io/v1, Resource=users  e2e-test-router-ipfailover-vr5xf-user}, err: \u003cnil\u003e\n  I0722 22:48:50.482611 23972 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthclients  e2e-client-e2e-test-router-ipfailover-vr5xf}, err: \u003cnil\u003e\n  I0722 22:48:50.725985 23972 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthaccesstokens  sha256~XbjpnyBGVpFopP1Exfm9DpWCrxJ8ZS6v_8zeY_YfhiM}, err: \u003cnil\u003e\n    STEP: Destroying namespace \"e2e-test-router-ipfailover-vr5xf\" for this suite. @ 07/22/26 22:48:50.726\n"
  },
  {
    "name": "[OTP][sig-network-edge] Network_Edge Author:mjoseph-NonHyperShiftHOST-ConnectedOnly-Medium-49214-Excluding the existing VRRP cluster ID from ipfailover deployments [Serial]",
    "lifecycle": "blocking",
    "duration": 104946,
    "startTime": "2026-07-22 17:18:51.270912 UTC",
    "endTime": "2026-07-22 17:20:36.217040 UTC",
    "result": "passed",
    "output": "  STEP: Creating a kubernetes client @ 07/22/26 22:48:51.271\nI0722 22:48:55.716456 24179 client.go:293] configPath is now \"/var/folders/7h/zgpvgd5946bcf53ktsvp95_40000gn/T/configfile342872708\"\nI0722 22:48:55.716536 24179 client.go:368] The user is now \"e2e-test-router-ipfailover-6kj4p-user\"\nI0722 22:48:55.716564 24179 client.go:370] Creating project \"e2e-test-router-ipfailover-6kj4p\"\nI0722 22:48:56.099059 24179 client.go:378] Waiting on permissions in project \"e2e-test-router-ipfailover-6kj4p\" ...\nI0722 22:48:57.225029 24179 client.go:407] DeploymentConfig capability is enabled, adding 'deployer' SA to the list of default SAs\nI0722 22:48:57.494843 24179 client.go:422] Waiting for ServiceAccount \"default\" to be provisioned...\nI0722 22:48:58.097690 24179 client.go:422] Waiting for ServiceAccount \"builder\" to be provisioned...\nI0722 22:48:58.702188 24179 client.go:422] Waiting for ServiceAccount \"deployer\" to be provisioned...\nI0722 22:48:59.304715 24179 client.go:432] Waiting for RoleBinding \"system:image-pullers\" to be provisioned...\nI0722 22:48:59.552334 24179 client.go:432] Waiting for RoleBinding \"system:image-builders\" to be provisioned...\nI0722 22:48:59.803416 24179 client.go:432] Waiting for RoleBinding \"system:deployers\" to be provisioned...\nI0722 22:49:01.572693 24179 client.go:469] Project \"e2e-test-router-ipfailover-6kj4p\" has been fully provisioned.\n  STEP: Check platforms @ 07/22/26 22:49:01.572\n  STEP: check whether there are two worker nodes present for testing hostnetwork @ 07/22/26 22:49:02.649\nI0722 22:49:03.974069 24179 util.go:61] Linux worker node details:\ngnfq2hk-b5564-9ks7d-worker-0-4bnpj\ngnfq2hk-b5564-9ks7d-worker-0-6fjsr\ngnfq2hk-b5564-9ks7d-worker-0-jdf4g\nI0722 22:49:03.974172 24179 util.go:62] Available linux worker node count is: 3\n  STEP: check the cluster has remote worker profile @ 07/22/26 22:49:07.562\n  STEP: check whether the cluster is not ipv6 single stack @ 07/22/26 22:49:09.25\n  STEP: Check network type @ 07/22/26 22:49:10.131\n  STEP: get pull spec of ipfailover image from payload @ 07/22/26 22:49:10.952\nI0722 22:49:17.395202 24179 util.go:121] the pull spec of image keepalived-ipfailover is: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:93c0a2b5ccfa1b27c43b02d4e8773e2641056c8ce85490a1a5c1dfaada6d1ad2\n  STEP: create ipfailover deployment and ensure one of pod enter MASTER state @ 07/22/26 22:49:17.418\nnamespace/e2e-test-router-ipfailover-6kj4p labeled\nI0722 22:49:18.584802 24179 util.go:275] Successfully added privileged labels (enforce, audit, warn) to namespace e2e-test-router-ipfailover-6kj4p\nI0722 22:49:24.699854 24179 util.go:356] the file of resource is /tmp/e2e-test-router-ipfailover-6kj4p-jsgniyqi-temp-resource.json\ndeployment.apps/ipf-49214 created\nI0722 22:49:32.579448 24179 util.go:363] the Ready status of pod is True True\nI0722 22:49:33.677306 24179 util.go:185] The pod list is [ipf-49214-7b94bb7cf8-pz5wr ipf-49214-7b94bb7cf8-xzgd7]\nI0722 22:49:48.303426 24179 util.go:136] The first pod log's failover status:- Wed Jul 22 17:19:26 2026: (ipfailover_VIP_1) Entering BACKUP STATE\nWed Jul 22 17:19:29 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\nI0722 22:49:49.499919 24179 util.go:143] The second pod log's failover status:- Wed Jul 22 17:19:26 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\nI0722 22:49:49.500163 24179 util.go:164] The Master pod is ipf-49214-7b94bb7cf8-pz5wr and Backup pod is ipf-49214-7b94bb7cf8-xzgd7\n  STEP: add 254 VIPs for the failover group @ 07/22/26 22:49:49.5\ndeployment.apps/ipf-49214 updated\n  STEP: Exclude VIP '9' from the ipfailover group @ 07/22/26 22:50:00.601\nI0722 22:50:01.912147 24179 util.go:185] The pod list is [ipf-49214-6c875f9f7b-jff5r ipf-49214-6c875f9f7b-vhkzq]\ndeployment.apps/ipf-49214 updated\n  STEP: verify from the ipfailover pod, the excluded VRRP_ID is configured @ 07/22/26 22:50:12.98\nI0722 22:50:19.413903 24179 util.go:363] the Ready status of pod is True True\nI0722 22:50:20.612602 24179 util.go:185] The pod list is [ipf-49214-f8c479674-5ls8r ipf-49214-f8c479674-rj2nx]\nI0722 22:50:27.633542 24179 util.go:264] the matching part is: E0722 22:50:27.597341   24257 websocket.go:296] Unknown stream id 1, discarding message\nHA_EXCLUDED_VRRP_IDS=9\n  STEP: verify the excluded VIP is removed from the router_ids of ipfailover pods @ 07/22/26 22:50:27.633\nI0722 22:50:34.603661 24179 util.go:264] the matching part is: virtual_router_id 10\n   virtual_router_id 11\n   virtual_router_id 12\n   virtual_router_id 13\n   virtual_router_id 14\n   virtual_router_id 15\n   virtual_router_id 16\n   virtual_router_id 17\n   virtual_router_id 18\n   virtual_router_id 19\nI0722 22:50:35.415750 24179 client.go:689] Deleted {user.openshift.io/v1, Resource=users  e2e-test-router-ipfailover-6kj4p-user}, err: \u003cnil\u003e\nI0722 22:50:35.682550 24179 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthclients  e2e-client-e2e-test-router-ipfailover-6kj4p}, err: \u003cnil\u003e\nI0722 22:50:35.950750 24179 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthaccesstokens  sha256~HhaZRLffihRqRdknee1uohaNwMLg7CnEB8CHE5VYKmo}, err: \u003cnil\u003e\n  STEP: Destroying namespace \"e2e-test-router-ipfailover-6kj4p\" for this suite. @ 07/22/26 22:50:35.951\n",
    "error": "    STEP: Creating a kubernetes client @ 07/22/26 22:48:51.271\n  I0722 22:48:55.716456 24179 client.go:293] configPath is now \"/var/folders/7h/zgpvgd5946bcf53ktsvp95_40000gn/T/configfile342872708\"\n  I0722 22:48:55.716536 24179 client.go:368] The user is now \"e2e-test-router-ipfailover-6kj4p-user\"\n  I0722 22:48:55.716564 24179 client.go:370] Creating project \"e2e-test-router-ipfailover-6kj4p\"\n  I0722 22:48:56.099059 24179 client.go:378] Waiting on permissions in project \"e2e-test-router-ipfailover-6kj4p\" ...\n  I0722 22:48:57.225029 24179 client.go:407] DeploymentConfig capability is enabled, adding 'deployer' SA to the list of default SAs\n  I0722 22:48:57.494843 24179 client.go:422] Waiting for ServiceAccount \"default\" to be provisioned...\n  I0722 22:48:58.097690 24179 client.go:422] Waiting for ServiceAccount \"builder\" to be provisioned...\n  I0722 22:48:58.702188 24179 client.go:422] Waiting for ServiceAccount \"deployer\" to be provisioned...\n  I0722 22:48:59.304715 24179 client.go:432] Waiting for RoleBinding \"system:image-pullers\" to be provisioned...\n  I0722 22:48:59.552334 24179 client.go:432] Waiting for RoleBinding \"system:image-builders\" to be provisioned...\n  I0722 22:48:59.803416 24179 client.go:432] Waiting for RoleBinding \"system:deployers\" to be provisioned...\n  I0722 22:49:01.572693 24179 client.go:469] Project \"e2e-test-router-ipfailover-6kj4p\" has been fully provisioned.\n    STEP: Check platforms @ 07/22/26 22:49:01.572\n    STEP: check whether there are two worker nodes present for testing hostnetwork @ 07/22/26 22:49:02.649\n  I0722 22:49:03.974069 24179 util.go:61] Linux worker node details:\n  gnfq2hk-b5564-9ks7d-worker-0-4bnpj\n  gnfq2hk-b5564-9ks7d-worker-0-6fjsr\n  gnfq2hk-b5564-9ks7d-worker-0-jdf4g\n  I0722 22:49:03.974172 24179 util.go:62] Available linux worker node count is: 3\n    STEP: check the cluster has remote worker profile @ 07/22/26 22:49:07.562\n    STEP: check whether the cluster is not ipv6 single stack @ 07/22/26 22:49:09.25\n    STEP: Check network type @ 07/22/26 22:49:10.131\n    STEP: get pull spec of ipfailover image from payload @ 07/22/26 22:49:10.952\n  I0722 22:49:17.395202 24179 util.go:121] the pull spec of image keepalived-ipfailover is: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:93c0a2b5ccfa1b27c43b02d4e8773e2641056c8ce85490a1a5c1dfaada6d1ad2\n    STEP: create ipfailover deployment and ensure one of pod enter MASTER state @ 07/22/26 22:49:17.418\n  namespace/e2e-test-router-ipfailover-6kj4p labeled\n  I0722 22:49:18.584802 24179 util.go:275] Successfully added privileged labels (enforce, audit, warn) to namespace e2e-test-router-ipfailover-6kj4p\n  I0722 22:49:24.699854 24179 util.go:356] the file of resource is /tmp/e2e-test-router-ipfailover-6kj4p-jsgniyqi-temp-resource.json\n  deployment.apps/ipf-49214 created\n  I0722 22:49:32.579448 24179 util.go:363] the Ready status of pod is True True\n  I0722 22:49:33.677306 24179 util.go:185] The pod list is [ipf-49214-7b94bb7cf8-pz5wr ipf-49214-7b94bb7cf8-xzgd7]\n  I0722 22:49:48.303426 24179 util.go:136] The first pod log's failover status:- Wed Jul 22 17:19:26 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n  Wed Jul 22 17:19:29 2026: (ipfailover_VIP_1) Entering MASTER STATE\n\n  I0722 22:49:49.499919 24179 util.go:143] The second pod log's failover status:- Wed Jul 22 17:19:26 2026: (ipfailover_VIP_1) Entering BACKUP STATE\n\n  I0722 22:49:49.500163 24179 util.go:164] The Master pod is ipf-49214-7b94bb7cf8-pz5wr and Backup pod is ipf-49214-7b94bb7cf8-xzgd7\n    STEP: add 254 VIPs for the failover group @ 07/22/26 22:49:49.5\n  deployment.apps/ipf-49214 updated\n    STEP: Exclude VIP '9' from the ipfailover group @ 07/22/26 22:50:00.601\n  I0722 22:50:01.912147 24179 util.go:185] The pod list is [ipf-49214-6c875f9f7b-jff5r ipf-49214-6c875f9f7b-vhkzq]\n  deployment.apps/ipf-49214 updated\n    STEP: verify from the ipfailover pod, the excluded VRRP_ID is configured @ 07/22/26 22:50:12.98\n  I0722 22:50:19.413903 24179 util.go:363] the Ready status of pod is True True\n  I0722 22:50:20.612602 24179 util.go:185] The pod list is [ipf-49214-f8c479674-5ls8r ipf-49214-f8c479674-rj2nx]\n  I0722 22:50:27.633542 24179 util.go:264] the matching part is: E0722 22:50:27.597341   24257 websocket.go:296] Unknown stream id 1, discarding message\n  HA_EXCLUDED_VRRP_IDS=9\n    STEP: verify the excluded VIP is removed from the router_ids of ipfailover pods @ 07/22/26 22:50:27.633\n  I0722 22:50:34.603661 24179 util.go:264] the matching part is: virtual_router_id 10\n     virtual_router_id 11\n     virtual_router_id 12\n     virtual_router_id 13\n     virtual_router_id 14\n     virtual_router_id 15\n     virtual_router_id 16\n     virtual_router_id 17\n     virtual_router_id 18\n     virtual_router_id 19\n  I0722 22:50:35.415750 24179 client.go:689] Deleted {user.openshift.io/v1, Resource=users  e2e-test-router-ipfailover-6kj4p-user}, err: \u003cnil\u003e\n  I0722 22:50:35.682550 24179 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthclients  e2e-client-e2e-test-router-ipfailover-6kj4p}, err: \u003cnil\u003e\n  I0722 22:50:35.950750 24179 client.go:689] Deleted {oauth.openshift.io/v1, Resource=oauthaccesstokens  sha256~HhaZRLffihRqRdknee1uohaNwMLg7CnEB8CHE5VYKmo}, err: \u003cnil\u003e\n    STEP: Destroying namespace \"e2e-test-router-ipfailover-6kj4p\" for this suite. @ 07/22/26 22:50:35.951\n"
  }
]%  

Summary by CodeRabbit

  • New Features

    • Added an automated end-to-end test extension for IP failover behavior.
    • Expanded coverage for master/backup election, VIP failover, configuration, preemption, and multi-VIP scenarios.
    • Packaged the test extension in the container image.
  • Documentation

    • Added instructions for building, running, and understanding the test suites.
  • Chores

    • Added build and cleanup tooling and test deployment configuration.
    • Updated the CI build environment to Go 1.25.

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Jul 22, 2026
@openshift-ci openshift-ci Bot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jul 22, 2026
@openshift-ci-robot

openshift-ci-robot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

@melvinjoseph86: This pull request references NE-2126 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the epic to target the "5.0.0" version, but no target version was set.

Details

In response to this:

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci

openshift-ci Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@coderabbitai

coderabbitai Bot commented Jul 22, 2026

Copy link
Copy Markdown

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Adds a Go-based ipfailover OTE test extension with cluster utilities, six E2E scenarios, suite registration, and Docker image packaging. The Docker build produces a gzip-compressed extension binary and copies it into the final image.

Changes

Ip­failover test extension

Layer / File(s) Summary
Extension build and image packaging
.ci-operator.yaml, ipfailover/keepalived/.dockerignore, ipfailover/keepalived/Dockerfile, ipfailover/keepalived/tests/go.mod, ipfailover/keepalived/tests/Makefile, ipfailover/keepalived/tests/.gitignore, ipfailover/keepalived/tests/README.md
Defines the Go module and build targets, updates the CI image, includes tests in the Docker context, and packages the compressed extension binary.
Extension entrypoint and cluster harness
ipfailover/keepalived/tests/cmd/main.go, ipfailover/keepalived/tests/e2e/testdata/router/ipfailover.yaml, ipfailover/keepalived/tests/e2e/testdata_embed.go, ipfailover/keepalived/tests/e2e/util.go
Registers filtered test suites and adds the embedded deployment template with cluster inspection, resource creation, networking, readiness, failover polling, and diagnostic utilities.
Ip­failover E2E scenarios
ipfailover/keepalived/tests/e2e/ipfailover.go
Adds tests for election, VIP failover, configuration, large VIP sets, delayed preemption, and VRRP ID exclusion.

Estimated code review effort: 4 (Complex) | ~45 minutes

Suggested reviewers: knobunc, thealisyed

Sequence Diagram(s)

sequenceDiagram
  participant TestExtension
  participant GinkgoSuite
  participant OpenShiftCluster
  participant KeepalivedPods
  TestExtension->>GinkgoSuite: build and filter test specs
  GinkgoSuite->>OpenShiftCluster: create ipfailover deployment
  OpenShiftCluster->>KeepalivedPods: start keepalived replicas
  KeepalivedPods-->>GinkgoSuite: return roles, VIPs, and logs
  GinkgoSuite-->>TestExtension: report test results
Loading

Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (2 errors, 5 warnings)

Check name Status Explanation Resolution
Container-Privileges ❌ Error The new Deployment template sets pod privileged: true and hostNetwork: true at lines 24-25, and container privileged: true at line 36. Remove privileged mode and hostNetwork, or replace them with the minimum required capabilities and isolation settings for the test workload.
No-Sensitive-Data-In-Logs ❌ Error New e2e.Logf calls emit worker node names and raw node details, pod names, namespaces, pod logs, and cluster IPs; the supplied run also exposes an OAuth access token. Remove or redact cluster-derived identifiers and raw command/log output before e2e.Logf; never include credentials or OAuth/session tokens in test output.
Docstring Coverage ⚠️ Warning Docstring coverage is 12.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Test Structure And Quality ⚠️ Warning The suite has 47 common assertions without explicit diagnostic messages, including cluster errors at ipfailover.go:69,161 and util.go:324,326; waits are bounded and NewCLI teardown cleans namespaces. Add meaningful context to every assertion, especially cluster command failures and each configuration check; remove temporary OutputToFile artifacts in cleanup hooks.
Microshift Test Compatibility ⚠️ Warning All six Ginkgo tests lack MicroShift guards. The suite uses config.openshift.io, operator.openshift.io, and template.openshift.io APIs, and requires two workers plus two HA replicas. Add [Skipped:MicroShift] or IsMicroShiftCluster()+g.Skip at the Describe. If applicable, run the MicroShift conformance and conformance-serial payload jobs; otherwise add suitable apigroup tags.
Single Node Openshift (Sno) Test Compatibility ⚠️ Warning Six new Ginkgo tests require at least two ready Linux workers and HA failover, but no listed SNO label or topology guard protects the Describe. Add [Skipped:SingleReplicaTopology] or a canonical SNO topology skip; otherwise run serial SNO CI and the disruptive test in the parallel SNO job.
Ipv6 And Disconnected Network Test Compatibility ⚠️ Warning The new tests hard-code IPv4 VIPs and generate VIPs with strings.Split on dots; replaceIPOctet cannot produce IPv6 values, and the suite skips IPv6 single-stack clusters. Use family-aware VIP generation and literals, or skip IPv4-only cases; run the serial IPv6 job /payload-job periodic-ci-openshift-release-master-nightly-4.22-e2e-metal-ipi-serial-ovn-ipv6.
✅ Passed checks (8 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the primary change: migrating Ipfailover test cases to the images repository.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed All six local Ginkgo titles and the suite title are string literals; no title uses runtime interpolation, pod/namespace/node names, IPs, timestamps, UUIDs, or generated values.
Topology-Aware Scheduling Compatibility ✅ Passed The test Deployment selects worker nodes, but the suite checks for at least two ready Linux workers and skips before creation; no anti-affinity, topology spread, PDB, or control-plane constraint is...
Ote Binary Stdout Contract ✅ Passed No process-level stdout writes exist; e2e init routes klog and REST warnings to os.Stderr, and OTE configures GinkgoWriter to stderr before tests.
No-Weak-Crypto ✅ Passed Authored test code has no weak-crypto imports or implementations; its only string comparison checks fixed timeout errors, not secrets or tokens. Weak algorithms are confined to vendored dependencies.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@melvinjoseph86

Copy link
Copy Markdown
Author

/test tests-extension
/test e2e-metal-ipi-tests-ext
/test e2e-vsphere-ovn-tests-ext
/test e2e-openstack-ipi-tests-ext

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 7

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@ipfailover/keepalived/Dockerfile`:
- Line 4: Replace the broad COPY . . instruction in the Dockerfile with explicit
COPY directives for only the test module’s required files and directories,
ensuring unrelated files and secrets are excluded from the builder context.
- Around line 24-25: Update the final base-rhel9 stage in the Dockerfile to run
with a non-root USER, not only the builder stage. Verify keepalived still
functions with that identity; if elevated privileges are required, document the
exception and restrict execution to the minimum necessary capabilities.
- Around line 24-25: The final image lacks a healthcheck for the keepalived
service. Add a Docker HEALTHCHECK to the keepalived Dockerfile that verifies
both monitor.sh and the keepalived process are running successfully, using an
appropriate command and interval, timeout, retries, and startup grace period.

In `@ipfailover/keepalived/tests/e2e/util.go`:
- Around line 107-123: Update the temporary directory creation in
getImagePullSpecFromPayload to use owner-only permissions instead of 0755,
ensuring the extracted pull-secret and its parent directory are inaccessible to
other local users while preserving the existing extraction and cleanup flow.
- Around line 414-437: Update getSpecificPodLogs to remove the bash-based
exec.Command filtering and extra cat process. Read podLogs directly in Go, apply
the optional case-insensitive filter in memory, and return the matching log
content while preserving the existing error logging and return behavior.

In `@ipfailover/keepalived/tests/README.md`:
- Line 49: Update the fenced directory-tree code block in the README to specify
the text language, changing the untyped fence to a text fence while preserving
its contents.

In `@tests-extension/README.md`:
- Line 38: Update the documented CI command in the execution instructions to
include --max-concurrency=1 when invoking run-suite for ipfailover/all,
preserving serial test execution required by the hostNetwork-based tests.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 10b4db7b-9654-4cb0-94fa-6e7281579f0b

📥 Commits

Reviewing files that changed from the base of the PR and between c29cc6c and 1bed137.

⛔ Files ignored due to path filters (1)
  • ipfailover/keepalived/tests/go.sum is excluded by !**/*.sum
📒 Files selected for processing (13)
  • ipfailover/keepalived/.dockerignore
  • ipfailover/keepalived/Dockerfile
  • ipfailover/keepalived/tests/.gitignore
  • ipfailover/keepalived/tests/Makefile
  • ipfailover/keepalived/tests/README.md
  • ipfailover/keepalived/tests/cmd/main.go
  • ipfailover/keepalived/tests/e2e/ipfailover.go
  • ipfailover/keepalived/tests/e2e/testdata/router/ipfailover.yaml
  • ipfailover/keepalived/tests/e2e/util.go
  • ipfailover/keepalived/tests/go.mod
  • tests-extension/.gitignore
  • tests-extension/Makefile
  • tests-extension/README.md
💤 Files with no reviewable changes (1)
  • ipfailover/keepalived/.dockerignore

Comment thread ipfailover/keepalived/Dockerfile Outdated
Comment thread ipfailover/keepalived/Dockerfile Outdated
Comment thread ipfailover/keepalived/tests/e2e/util.go
Comment thread ipfailover/keepalived/tests/e2e/util.go
Comment thread ipfailover/keepalived/tests/README.md Outdated
Comment thread tests-extension/README.md Outdated
@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 31, 2026
@coderabbitai

coderabbitai Bot commented Jul 31, 2026

Copy link
Copy Markdown

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
Validation Failed: {"resource":"IssueComment","code":"custom","field":"body","message":"body is too long (maximum is 65536 characters)"} - https://docs.github.com/rest/issues/comments#update-an-issue-comment

@melvinjoseph86

Copy link
Copy Markdown
Author

/test tests-extension
/test e2e-metal-ipi-tests-ext
/test e2e-vsphere-ovn-tests-ext
/test e2e-openstack-ipi-tests-ext

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 5

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@ipfailover/keepalived/Dockerfile`:
- Around line 8-9: Update the Dockerfile artifact packaging commands to
gzip-compress the built ipfailover-tests-ext executable with gzip rather than
creating a tar archive, and publish the resulting raw gzip artifact at the
registered /usr/bin/ipfailover-test-extension.tar.gz path while preserving the
expected executable build flow.

In `@ipfailover/keepalived/tests/e2e/testdata/router/ipfailover.yaml`:
- Around line 69-74: Add a readinessProbe alongside the existing livenessProbe
in the Deployment container configuration, using a check that confirms
keepalived initialization and VRRP/VIP readiness (or the VRRP controller port)
rather than merely checking that the process is running. Keep the existing
livenessProbe unchanged.
- Around line 28-69: Add a resources block to the openshift-ipfailover container
definition, specifying both CPU and memory requests and limits. Keep the
existing container configuration unchanged and use the repository’s established
resource values or conventions if available.
- Around line 14-27: Update the ipfailover e2e setup around the deployment
replica configuration and OPENSHIFT_HA_REPLICA_COUNT to derive the count from
eligible worker nodes rather than assuming two workers. Inspect
infrastructure.Status.ControlPlaneTopology before running these tests, and
explicitly skip SingleReplica, HyperShift, arbiter, and External topologies;
keep the node-role.kubernetes.io/worker selection aligned with the computed
placement.
- Around line 22-47: Harden the ipfailover test PodSpec by removing the invalid
PodSpec-level privileged setting, hostNetwork, and host-slash host-path mount
unless each is demonstrably required; retain only required host integrations.
For the remaining container configuration, remove unnecessary privileges and add
allowPrivilegeEscalation: false, runAsNonRoot: true, and readOnlyRootFilesystem:
true where supported, using only verified capabilities if host networking must
remain.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

Comment thread ipfailover/keepalived/Dockerfile Outdated
Comment thread ipfailover/keepalived/tests/e2e/testdata/router/ipfailover.yaml
Comment thread ipfailover/keepalived/tests/e2e/testdata/router/ipfailover.yaml
Comment thread ipfailover/keepalived/tests/e2e/testdata/router/ipfailover.yaml
Comment thread ipfailover/keepalived/tests/e2e/testdata/router/ipfailover.yaml
@melvinjoseph86

Copy link
Copy Markdown
Author

/test tests-extension
/test e2e-metal-ipi-tests-ext
/test e2e-vsphere-ovn-tests-ext
/test e2e-openstack-ipi-tests-ext

@openshift-ci

openshift-ci Bot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: melvinjoseph86
Once this PR has been reviewed and has the lgtm label, please assign sdodson for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot removed the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 31, 2026
@coderabbitai

coderabbitai Bot commented Jul 31, 2026

Copy link
Copy Markdown

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
Validation Failed: {"resource":"IssueComment","code":"custom","field":"body","message":"body is too long (maximum is 65536 characters)"} - https://docs.github.com/rest/issues/comments#update-an-issue-comment

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 6

🧹 Nitpick comments (4)
ipfailover/keepalived/tests/e2e/ipfailover.go (2)

388-390: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Remove the pod list call with no effect.

Line 389 calls getPodListByLabel and discards the result. The same pattern exists in ipfailover/keepalived/tests/e2e/util.go line 282. Delete both calls, or capture and use the result.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ipfailover/keepalived/tests/e2e/ipfailover.go` around lines 388 - 390, Remove
the unused getPodListByLabel call in the “Exclude VIP '9' from the ipfailover
group” test flow, and remove the matching discarded call in the related utility
flow. Keep the surrounding setEnvVariable behavior unchanged.

244-251: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Reuse the checkPlatform helper.

util.go already provides checkPlatform(oc), which runs the same oc get infrastructure query and lowercases the result. Lines 43-47 and this block duplicate that logic.

♻️ Proposed refactor
-		// Get platform type using oc command instead of compat_otp
-		infraOutput, err := oc.AsAdmin().WithoutNamespace().Run("get").Args("infrastructure", "cluster", "-o=jsonpath={.status.platformStatus.type}").Output()
-		if err == nil {
-			platformtype := strings.ToLower(strings.TrimSpace(infraOutput))
-			if platformtype == "nutanix" {
-				g.Skip("This test will not works for Nutanix")
-			}
-		}
+		if checkPlatform(oc) == "nutanix" {
+			g.Skip("This test does not work on Nutanix")
+		}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ipfailover/keepalived/tests/e2e/ipfailover.go` around lines 244 - 251,
Replace the duplicated platform query and normalization in the test setup with
the existing checkPlatform helper, passing the current oc client. Preserve the
Nutanix-specific skip behavior based on the helper’s returned platform value and
remove the local infrastructure query logic.
ipfailover/keepalived/tests/e2e/util.go (1)

110-113: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Replace the rm -rf subprocess with os.RemoveAll.

Line 112 spawns an external process and discards its error. os.RemoveAll removes the directory in-process and returns an error you can log. This also removes the os/exec dependency from this function.

♻️ Proposed refactor
 	dockerconfigjsonpath := filepath.Join(indexTmpPath, ".dockerconfigjson")
-	defer exec.Command("rm", "-rf", indexTmpPath).Output()
+	defer func() {
+		if rmErr := os.RemoveAll(indexTmpPath); rmErr != nil {
+			e2e.Logf("failed to remove temporary directory %s: %v", indexTmpPath, rmErr)
+		}
+	}()
 	err := os.MkdirAll(indexTmpPath, 0700)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ipfailover/keepalived/tests/e2e/util.go` around lines 110 - 113, Update the
cleanup in the test utility around indexTmpPath to call os.RemoveAll instead of
spawning rm -rf through exec.Command. Handle or log the returned cleanup error,
and remove the now-unused os/exec dependency if it is only needed by this call.
ipfailover/keepalived/tests/Makefile (1)

14-18: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Expose the test command through the Makefile.

This new test extension has no test target. Add a target that runs the supported E2E and vet commands. If checkmake is enforced, add its required all target or configure the check for this project.

Based on learnings, run the full test suite and vet checks before submitting a pull request.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ipfailover/keepalived/tests/Makefile` around lines 14 - 18, Add a test target
to the Makefile that runs the supported end-to-end test and vet commands for the
extension. Also provide the required all target if checkmake enforces it, or
configure the project’s check accordingly, while preserving the existing help,
build, and clean targets.

Sources: Learnings, Linters/SAST tools

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@ipfailover/keepalived/tests/e2e/ipfailover.go`:
- Around line 346-358: Update the step 10 flow around getPodListByLabel and
futurePrimaryPod to wait until the replacement pod is ready and the deleted
new_master pod no longer appears, then compute futurePrimaryPod using the
refreshed pod list while excluding new_master before calling waitForPrimaryPod.

In `@ipfailover/keepalived/tests/e2e/util.go`:
- Around line 180-187: In ipfailover/keepalived/tests/e2e/util.go lines 180-187,
update getPodListByLabel to use whitespace-aware field parsing and assert the
returned pod list is non-empty; in lines 125-143, update
ensureIpfailoverMasterBackup to assert len(podList) is at least 2 before
accessing podList[0] and podList[1].
- Around line 109-110: The e2e extension resolves testdata from relative paths
that are unavailable outside the source tree. Update the testdata path setup in
util.go around baseDir and the ipfailover.go loading paths at lines 96-97,
121-122, 180-181, 252-253, 288-289, and 362-363 to use one embedded-filesystem
or executable-location-based resolution mechanism; replace relative
buildPruningBaseDir usage while preserving the existing file-loading behavior.
- Around line 215-225: Update slicingElement to remove the matching element
without modifying podList’s backing array: construct and return a separate slice
containing all non-matching pods, while preserving the existing logging and
behavior when no element matches.
- Around line 189-213: Update getVipOwnerPod to assert that primaryNode is
non-empty after the pod search completes and before returning it, so failure
occurs when no pod reports the VIP while preserving the existing
successful-owner return path.
- Around line 296-314: Update getPodIP to assert that the returned podIp slice
is non-empty before returning it, including a clear failure message for an
unknown or unsupported IP stack type. Preserve the existing single-stack and
dual-stack collection behavior.

---

Nitpick comments:
In `@ipfailover/keepalived/tests/e2e/ipfailover.go`:
- Around line 388-390: Remove the unused getPodListByLabel call in the “Exclude
VIP '9' from the ipfailover group” test flow, and remove the matching discarded
call in the related utility flow. Keep the surrounding setEnvVariable behavior
unchanged.
- Around line 244-251: Replace the duplicated platform query and normalization
in the test setup with the existing checkPlatform helper, passing the current oc
client. Preserve the Nutanix-specific skip behavior based on the helper’s
returned platform value and remove the local infrastructure query logic.

In `@ipfailover/keepalived/tests/e2e/util.go`:
- Around line 110-113: Update the cleanup in the test utility around
indexTmpPath to call os.RemoveAll instead of spawning rm -rf through
exec.Command. Handle or log the returned cleanup error, and remove the
now-unused os/exec dependency if it is only needed by this call.

In `@ipfailover/keepalived/tests/Makefile`:
- Around line 14-18: Add a test target to the Makefile that runs the supported
end-to-end test and vet commands for the extension. Also provide the required
all target if checkmake enforces it, or configure the project’s check
accordingly, while preserving the existing help, build, and clean targets.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

Comment thread ipfailover/keepalived/tests/e2e/ipfailover.go Outdated
Comment on lines +109 to +110
baseDir := "e2e/testdata/router"
indexTmpPath := filepath.Join(baseDir, getRandomString())

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟠 Major | 🏗️ Heavy lift

Testdata files are resolved by relative path but are not shipped with the extension binary. Both files build paths from the relative directory e2e/testdata/router. The image contains only /usr/bin/ipfailover-tests-ext.gz, and the extracted binary runs with an arbitrary working directory, so these lookups fail outside the source tree.

  • ipfailover/keepalived/tests/e2e/util.go#L109-L110: resolve baseDir from an embedded filesystem or from a path derived from the binary location.
  • ipfailover/keepalived/tests/e2e/ipfailover.go#L96-L97: load ipfailover.yaml through the same resolution mechanism instead of the relative buildPruningBaseDir. The same pattern repeats at lines 121-122, 180-181, 252-253, 288-289, and 362-363.
📍 Affects 2 files
  • ipfailover/keepalived/tests/e2e/util.go#L109-L110 (this comment)
  • ipfailover/keepalived/tests/e2e/ipfailover.go#L96-L97
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ipfailover/keepalived/tests/e2e/util.go` around lines 109 - 110, The e2e
extension resolves testdata from relative paths that are unavailable outside the
source tree. Update the testdata path setup in util.go around baseDir and the
ipfailover.go loading paths at lines 96-97, 121-122, 180-181, 252-253, 288-289,
and 362-363 to use one embedded-filesystem or executable-location-based
resolution mechanism; replace relative buildPruningBaseDir usage while
preserving the existing file-loading behavior.

Comment thread ipfailover/keepalived/tests/e2e/util.go
Comment thread ipfailover/keepalived/tests/e2e/util.go
Comment thread ipfailover/keepalived/tests/e2e/util.go
Comment thread ipfailover/keepalived/tests/e2e/util.go
@melvinjoseph86

Copy link
Copy Markdown
Author

/test tests-extension
/test e2e-metal-ipi-tests-ext
/test e2e-vsphere-ovn-tests-ext
/test e2e-openstack-ipi-tests-ext

@coderabbitai

coderabbitai Bot commented Jul 31, 2026

Copy link
Copy Markdown

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
Validation Failed: {"resource":"IssueComment","code":"custom","field":"body","message":"body is too long (maximum is 65536 characters)"} - https://docs.github.com/rest/issues/comments#update-an-issue-comment

@coderabbitai

coderabbitai Bot commented Jul 31, 2026

Copy link
Copy Markdown

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
Validation Failed: {"resource":"IssueComment","code":"custom","field":"body","message":"body is too long (maximum is 65536 characters)"} - https://docs.github.com/rest/issues/comments#update-an-issue-comment

@melvinjoseph86

Copy link
Copy Markdown
Author

/test tests-extension
/test e2e-metal-ipi-tests-ext
/test e2e-vsphere-ovn-tests-ext
/test e2e-openstack-ipi-tests-ext

@melvinjoseph86
melvinjoseph86 marked this pull request as ready for review July 31, 2026 18:07
@openshift-ci openshift-ci Bot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jul 31, 2026
@melvinjoseph86

Copy link
Copy Markdown
Author

@rikatz Kindly review...

@openshift-ci
openshift-ci Bot requested review from Thealisyed and knobunc July 31, 2026 18:07
@coderabbitai

coderabbitai Bot commented Jul 31, 2026

Copy link
Copy Markdown

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
Validation Failed: {"resource":"IssueComment","code":"custom","field":"body","message":"body is too long (maximum is 65536 characters)"} - https://docs.github.com/rest/issues/comments#update-an-issue-comment

@coderabbitai

coderabbitai Bot commented Aug 1, 2026

Copy link
Copy Markdown

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
Validation Failed: {"resource":"IssueComment","code":"custom","field":"body","message":"body is too long (maximum is 65536 characters)"} - https://docs.github.com/rest/issues/comments#update-an-issue-comment

@melvinjoseph86

Copy link
Copy Markdown
Author

/test tests-extension
/test e2e-metal-ipi-tests-ext
/test e2e-vsphere-ovn-tests-ext
/test e2e-openstack-ipi-tests-ext

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🧹 Nitpick comments (1)
ipfailover/keepalived/tests/Makefile (1)

7-7: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick win

Keep the compiler selection deterministic.

GOTOOLCHAIN=auto can switch to and download another Go toolchain. The Docker builder and go.mod already target Go 1.25. Use GOTOOLCHAIN=local or an explicitly pinned toolchain unless automatic upgrades are required. Go documents this automatic switching behavior. (go.dev)

Proposed fix
-	GOTOOLCHAIN=auto GOSUMDB=sum.golang.org go build -o $(BINARY) ./cmd
+	GOTOOLCHAIN=local GOSUMDB=sum.golang.org go build -o $(BINARY) ./cmd
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ipfailover/keepalived/tests/Makefile` at line 7, Update the go build command
in the Makefile to use deterministic compiler selection by replacing
GOTOOLCHAIN=auto with GOTOOLCHAIN=local, preserving the existing Go 1.25 target
and build flags.

Source: MCP tools

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@ipfailover/keepalived/tests/e2e/testdata_embed.go`:
- Around line 14-23: The testdata initialization around the package init flow
must materialize ipfailoverTemplate at a stable writable absolute location
rather than relative e2e paths. Use the explicit writable location expected by
the OTE environment, assign that concrete path to
ipfailoverDescription.template, and propagate wrapped errors from MkdirAll,
WriteFile, and both fmt.Fprintf calls instead of warning and continuing; ensure
initialization fails when materialization cannot complete.
- Around line 20-24: Update Init() to validate the destination before use:
inspect it with os.Lstat or equivalent, reject symlinks and non-regular files,
propagate non-ENOENT errors, and compare existing ipfailover.yaml contents with
ipfailoverTemplate, failing on mismatches. For a missing destination, create the
template atomically and report creation errors instead of accepting partial or
stale content.

In `@ipfailover/keepalived/tests/go.mod`:
- Line 48: Update the dependency resolution for the ipfailover/keepalived/tests
module by running govulncheck ./... and addressing the reported vulnerable
transitive packages, including github.com/moby/spdystream,
go.opentelemetry.io/otel/sdk, golang.org/x/crypto, and google.golang.org/grpc.
If the affected Docker, SPDY, SSH-agent, or gRPC-server paths are unreachable,
document the reachable-code exemption explicitly rather than relying on the //
indirect annotation in go.mod.

In `@ipfailover/keepalived/tests/Makefile`:
- Around line 3-8: Add a .PHONY test target to the Makefile that depends on
build, then execute the specified local OTE/Ginkgo coverage command with its
existing arguments. Do not add an all target; keep the current build, clean, and
help targets unchanged.

---

Nitpick comments:
In `@ipfailover/keepalived/tests/Makefile`:
- Line 7: Update the go build command in the Makefile to use deterministic
compiler selection by replacing GOTOOLCHAIN=auto with GOTOOLCHAIN=local,
preserving the existing Go 1.25 target and build flags.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

Comment on lines +14 to +23
dir := filepath.Join("e2e", "testdata", "router")
if err := os.MkdirAll(dir, 0755); err != nil {
fmt.Fprintf(os.Stderr, "warning: could not create testdata dir: %v\n", err)
return
}
dest := filepath.Join(dir, "ipfailover.yaml")
if _, err := os.Stat(dest); os.IsNotExist(err) {
if err := os.WriteFile(dest, ipfailoverTemplate, 0644); err != nil {
fmt.Fprintf(os.Stderr, "warning: could not write embedded testdata: %v\n", err)
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

rg -n -C 6 \
  'ipfailoverDescription|template[[:space:]]*[:=]|e2e/testdata/router|os\.Chdir|WORKDIR|ENTRYPOINT|CMD' \
  ipfailover/keepalived/tests \
  ipfailover/keepalived/Dockerfile \
  .ci-operator.yaml

Repository: openshift/images

Length of output: 50373


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '--- target file exists ---\n'
git ls-files | grep -F 'ipfailover/keepalived/tests/e2e/testdata_embed.go' || true

printf '\n--- relevant non-vendor files ---\n'
git ls-files 'ipfailover/keepalived/tests/e2e/*.go' 'ipfailover/keepalived/Dockerfile' '.ci-operator.yaml' | sed 's#^`#-` #'

printf '\n--- target file ---\n'
if git ls-files | grep -F 'ipfailover/keepalived/tests/e2e/testdata_embed.go' >/dev/null; then
  cat -n ipfailover/keepalived/tests/e2e/testdata_embed.go
fi

printf '\n--- util context ---\n'
if git ls-files | grep -F 'ipfailover/keepalived/tests/e2e/util.go' >/dev/null; then
  nl -ba ipfailover/keepalived/tests/e2e/util.go | sed -n '260,355p'
fi

printf '\n--- focused workspace/test related patterns ---\n'
rg -n --glob '!ipfailover/keepalived/tests/vendor/**' \
  'pwd|working directory|WORKDIR|ENTRYPOINT|CMD|os\.Chdir|RunInWorkspace|go test|TestMain|TestE2E|ipfailoverDescription|ipf\.template|testdata_embed|e2e/testdata/router' \
  ipfailover/keepalived/tests \
  ipfailover/keepalived/Dockerfile \
  .ci-operator.yaml || true

Repository: openshift/images

Length of output: 245


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '%s\n' '--- target file exists ---'
git ls-files | grep -F 'ipfailover/keepalived/tests/e2e/testdata_embed.go' || true

printf '%s\n' ''
printf '%s\n' '--- relevant non-vendor files ---'
git ls-files 'ipfailover/keepalived/tests/e2e/*.go' 'ipfailover/keepalived/Dockerfile' '.ci-operator.yaml' | sed 's#^`#-` #'

printf '%s\n' ''
printf '%s\n' '--- target file ---'
if git ls-files | grep -F 'ipfailover/keepalived/tests/e2e/testdata_embed.go' >/dev/null; then
  cat -n ipfailover/keepalived/tests/e2e/testdata_embed.go
fi

printf '%s\n' ''
printf '%s\n' '--- util context ---'
if git ls-files | grep -F 'ipfailover/keepalived/tests/e2e/util.go' >/dev/null; then
  nl -ba ipfailover/keepalived/tests/e2e/util.go | sed -n '260,355p'
fi

printf '%s\n' ''
printf '%s\n' '--- focused workspace/test related patterns ---'
rg -n --glob '!ipfailover/keepalived/tests/vendor/**' \
  'pwd|working directory|WORKDIR|ENTRYPOINT|CMD|os\.Chdir|RunInWorkspace|go test|TestMain|TestE2E|ipfailoverDescription|ipf\.template|testdata_embed|e2e/testdata/router' \
  ipfailover/keepalived/tests \
  ipfailover/keepalived/Dockerfile \
  .ci-operator.yaml || true

Repository: openshift/images

Length of output: 1328


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '%s\n' '--- util.go relevant lines ---'
awk '{printf "%5d  %s\n", NR, $0}' ipfailover/keepalived/tests/e2e/util.go | sed -n '260,355p'

printf '%s\n' ''
printf '%s\n' '--- other e2e files outline-ish relevant definitions using grep ---'
rg -n --glob '!ipfailover/keepalived/tests/vendor/**' \
  'type ipfailoverDescription|template|func create|createResourceFromTemplate|testdata|router/ipfailover\.yaml' \
  ipfailover/keepalived/tests/e2e/ipfailover.go \
  ipfailover/keepalived/tests/e2e/util.go \
  .ci-operator.yaml \
  ipfailover/keepalived/Dockerfile \
  || true

printf '%s\n' ''
printf '%s\n' '--- focused repo paths ---'
awk '{printf "%5d  %s\n", NR, $0}' ipfailover/keepalived/tests/e2e/ipfailover.go | sed -n '1,260p'

Repository: openshift/images

Length of output: 20308


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '%s\n' '--- util.go ipfailoverDescription and helper lines ---'
awk '{printf "%5d  %s\n", NR, $0}' ipfailover/keepalived/tests/e2e/util.go | sed -n '1,130p'

printf '%s\n' ''
printf '%s\n' '--- ci-operator and docker runner/workdir ---'
awk '{printf "%5d  %s\n", NR, $0}' .ci-operator.yaml | sed -n '1,260p'
printf '%s\n' ''
awk '{printf "%5d  %s\n", NR, $0}' ipfailover/keepalived/Dockerfile | sed -n '1,220p'

Repository: openshift/images

Length of output: 8071


Materialize the embedded template into a stable writable path and fail on write errors.

dir and dest are relative to the process working directory, while the ci-operator build runs make build from tests and the OTE image uses /var/lib/ipfailover as its WORKDIR. If MkdirAll or the first WriteFile fails, init() continues and later tests pass a non-existent relative path to createResourceFromTemplate. Use an explicit writable location, set ipfailoverDescription.template to that concrete path, and return a wrapped error instead of logging and returning. Also propagate errors from the fmt.Fprintf calls.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ipfailover/keepalived/tests/e2e/testdata_embed.go` around lines 14 - 23, The
testdata initialization around the package init flow must materialize
ipfailoverTemplate at a stable writable absolute location rather than relative
e2e paths. Use the explicit writable location expected by the OTE environment,
assign that concrete path to ipfailoverDescription.template, and propagate
wrapped errors from MkdirAll, WriteFile, and both fmt.Fprintf calls instead of
warning and continuing; ensure initialization fails when materialization cannot
complete.

Sources: Path instructions, MCP tools

Comment on lines +20 to +24
if _, err := os.Stat(dest); os.IsNotExist(err) {
if err := os.WriteFile(dest, ipfailoverTemplate, 0644); err != nil {
fmt.Fprintf(os.Stderr, "warning: could not write embedded testdata: %v\n", err)
}
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== locate files =="
fd -a 'testdata_embed\.go|util\.go' . || true

echo "== outline target =="
ast-grep outline ipfailover/keepalived/tests/e2e/testdata_embed.go --view compact || true

echo "== stat relevant util section =="
wc -l ipfailover/keepalived/tests/e2e/util.go
sed -n '280,345p' ipfailover/keepalived/tests/e2e/util.go

echo "== target file =="
wc -l ipfailover/keepalived/tests/e2e/testdata_embed.go
cat -n ipfailover/keepalived/tests/e2e/testdata_embed.go

echo "== search ipf.template usage =="
rg -n 'ipf\.template|testdata|generateEmbed|os\.Stat|WriteFile|ReadFile' ipfailover/keepalived/tests/e2e -S

Repository: openshift/images

Length of output: 16226


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== outline util.go around ipfailoverDescription =="
ast-grep outline ipfailover/keepalived/tests/e2e/util.go --view expanded || true

echo "== util.go relevant section =="
sed -n '80,130p' ipfailover/keepalived/tests/e2e/util.go

echo "== ipfailover.go template and file discovery context =="
sed -n '88,128p' ipfailover/keepalived/tests/e2e/ipfailover.go
sed -n '172,190p' ipfailover/keepalived/tests/e2e/ipfailover.go
sed -n '246,295p' ipfailover/keepalived/tests/e2e/ipfailover.go
sed -n '356,368p' ipfailover/keepalived/tests/e2e/ipfailover.go

echo "== Go os.Stat/WriteFile behavior probe in temp dir =="
tmpdir="$(mktemp -d)"
cat > "$tmpdir/statwriteprobe.go" <<'GO'
package main

import (
	"fmt"
	"io/fs"
	"os"
	"path/filepath"
)

func probe(name string, dest string, expectNotExists bool, fn func() error) {
	err := fn()
	fmt.Println(name)
	fmt.Println("error:", errToString(err))
	fmt.Println("isNotExist:", err != nil && os.IsNotExist(err))
	if expectNotExists {
		st, statErr := os.Stat(dest)
		fmt.Println("statAfter:", statErrToString(statErr), "isRegular:", isRegular(st), "mode:", st.Mode().String())
		content, readErr := os.ReadFile(dest)
		fmt.Println("readContent:", content, "readErr:", readErrToString(readErr))
	}
}

func errToString(err error) string {
	if err == nil {
		return "<nil>"
	}
	return err.Error()
}
func statErrToString(err error) string {
	if err == nil {
		return "<nil>"
	}
	return err.Error()
}
func readErrToString(err error) string {
	if err == nil {
		return "<nil>"
	}
	return err.Error()
}
func isRegular(info fs.FileInfo) bool {
	return info != nil && info.Mode().IsRegular()
}

func main() {
	base := filepath.Join(os.TempDir(), "probe-"+fmt.Sprint(os.Getpid()))
	os.RemoveAll(base)
	os.MkdirAll(base, 0755)
	dest := filepath.Join(base, "ipfailover.yaml")
	content := []byte("generated-template\n")
	probe("missing-file", dest, true, func() error {
		if _, err := os.Stat(dest); os.IsNotExist(err) {
			return os.WriteFile(dest, content, 0644)
		}
		return nil
	})
	probe("existing-regular-file", dest, true, func() error {
		if _, err := os.Stat(dest); os.IsNotExist(err) {
			return os.WriteFile(dest, content, 0644)
		}
		return nil
	})
	probe("permission-errors-ignored", dest, true, func() error {
		permfile := filepath.Join(base, "noperm")
		if err := os.WriteFile(permfile, []byte("x"), 0); err != nil {
			panic(errToString(err))
		}
		if _, err := os.Stat(permfile); os.IsNotExist(err) {
			return os.WriteFile(permfile, content, 0644)
		}
		return nil
	})
	proc := filepath.Join(base, "child")
	if err := os.WriteFile(proc, []byte("child"), 0644); err != nil {
		panic(errToString(err))
	}
	destSym := filepath.Join(base, "ipfailover.yaml")
	if err := os.Symlink(proc, destSym); err != nil {
		panic(errToString(err))
	}
	probe("symlink-exists-path", destSym, true, func() error {
		if _, err := os.Stat(destSym); os.IsNotExist(err) {
			return os.WriteFile(destSym, content, 0644)
		}
		return nil
	})
	st, _ := os.Stat(destSym)
	file, _ := os.OpenFile(destSym, os.O_RDWR|os.O_CREATE|os.O_TRUNC, 0644)
	if file != nil {
		file.WriteString("symlink-partial\n")
		file.Close()
	}
	newcontent, _ := os.ReadFile(destSym)
	fmt.Println("symlink-partial-content-after-init:", string(newcontent))
}
GO
go run "$tmpdir/statwriteprobe.go"

Repository: openshift/images

Length of output: 9910


🏁 Script executed:

#!/bin/bash
set -euo pipefail

tmpdir="$(mktemp -d)"
cat > "$tmpdir/statwriteprobe.go" <<'GO'
package main

import (
	"fmt"
	"io/fs"
	"os"
	"path/filepath"
)

func main() {
	base := filepath.Join(os.TempDir(), "probe-"+fmt.Sprint(os.Getpid()))
	os.RemoveAll(base)
	os.MkdirAll(base, 0755)
	dest := filepath.Join(base, "ipfailover.yaml")
	content := []byte("generated-template\n")
	probe := func(name string, dest string, fn func() error) {
		fmt.Println(name)
		err := fn()
		fmt.Println("init_error:", errToString(err))
		fmt.Println("isNotExist:", err != nil && os.IsNotExist(err))
		st, statErr := os.Stat(dest)
		fmt.Println("statAfter:", statErrToString(statErr), "isRegular:", isRegular(st), "mode:", st.Mode().String())
		fileContent, readErr := os.ReadFile(dest)
		fmt.Println("readContent:", string(fileContent), "readErr:", readErrToString(readErr))
		if err == nil && os.IsNotExist(statErr) {
			fmt.Println("ERROR path did not create file")
		}
	}
	probe("missing-file", dest, func() error {
		if _, err := os.Stat(dest); os.IsNotExist(err) {
			return os.WriteFile(dest, content, 0644)
		}
		return nil
	})
	probe("existing-regular-file", dest, func() error {
		if _, err := os.Stat(dest); os.IsNotExist(err) {
			return os.WriteFile(dest, content, 0644)
		}
		return nil
	})
	permfile := filepath.Join(base, "noperm")
	if err := os.WriteFile(permfile, []byte("x"), 0000); err != nil {
		panic(errToString(err))
	}
	defer os.Chmod(permfile, 0644)
	probe("permission-errors-ignored", permfile, func() error {
		if _, err := os.Stat(permfile); os.IsNotExist(err) {
			return os.WriteFile(permfile, content, 0644)
		}
		return nil
	})
	proc := filepath.Join(base, "child")
	if err := os.WriteFile(proc, []byte("child"), 0644); err != nil {
		panic(errToString(err))
	}
	destSym := filepath.Join(base, "ipfailover.yaml")
	if err := os.Symlink(proc, destSym); err != nil {
		panic(errToString(err))
	}
	probe("symlink-exists-path", destSym, func() error {
		if _, err := os.Stat(destSym); os.IsNotExist(err) {
			return os.WriteFile(destSym, content, 0644)
		}
		return nil
	})
	file, _ := os.OpenFile(destSym, os.O_RDWR|os.O_CREATE|os.O_TRUNC, 0644)
	if file != nil {
		if _, err := file.WriteString("symlink-partial\n"); err != nil {
			panic(errToString(err))
		}
		file.Close()
	}
	pr, ph := os.ReadFile(destSym)
	fmt.Println("symlink-partial-content-after-init:", string(pr))
	fmt.Println("symlink-partial-readErr:", readErrToString(ph))
}
func errToString(err error) string {
	if err == nil {
		return "<nil>"
	}
	return err.Error()
}
func statErrToString(err error) string {
	if err == nil {
		return "<nil>"
	}
	return err.Error()
}
func readErrToString(err error) string {
	if err == nil {
		return "<nil>"
	}
	return err.Error()
}
func isRegular(info fs.FileInfo) bool {
	return info != nil && info.Mode().IsRegular()
}
GO
go run "$tmpdir/statwriteprobe.go"

Repository: openshift/images

Length of output: 814


Validate ipfailover.yaml contents before using it.

Init() only writes when os.Stat("e2e/testdata/router/ipfailover.yaml") returns a non-existence error. Existing files, permission errors from previous state, and symlinks are accepted as-is, and no content comparison is done. Tests pass "-f" directly to oc create, so stale, partial, or invalid YAML can be used. Read or os.Lstat the destination first, fail on mismatches, non-regular files, symlinks, and non-ENOENT errors, then create the missing file atomically.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ipfailover/keepalived/tests/e2e/testdata_embed.go` around lines 20 - 24,
Update Init() to validate the destination before use: inspect it with os.Lstat
or equivalent, reject symlinks and non-regular files, propagate non-ENOENT
errors, and compare existing ipfailover.yaml contents with ipfailoverTemplate,
failing on mismatches. For a missing destination, create the template atomically
and report creation errors instead of accepting partial or stale content.

Source: Path instructions

github.com/cyphar/filepath-securejoin v0.6.0 // indirect
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
github.com/distribution/reference v0.6.0 // indirect
github.com/docker/docker v28.5.2+incompatible // indirect

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

module_dir="ipfailover/keepalived/tests"

rg -n \
  'github.com/docker/docker|github.com/moby/spdystream|go.opentelemetry.io/otel|golang.org/x/crypto|google.golang.org/grpc' \
  "$module_dir" --glob '*.go' --glob 'go.mod' || true

echo "Run in a Go-enabled environment:"
echo "  (cd $module_dir && govulncheck ./...)"

Repository: openshift/images

Length of output: 50373


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "Module summary:"
sed -n '1,190p' ipfailover/keepalived/tests/go.mod

echo
echo "Imports of affected modules in non-vendor Go source:"
grep -R -n --include='*.go' --exclude-dir=vendor \
  '["/]' ipfailover/keepalived/tests --glob '!ipfailover/keepalived/tests/vendor/**' \
  | grep -E 'github\.com/docker/docker|github\.com/moby/spdystream|go\.opentelemetry\.io/otel|golang\.org/x/crypto|google\.golang\.org/grpc|go\.opentelemetry\.io/otel/sdk' || true

echo
echo "Affected module versions in go.mod:"
grep -E 'github.com/docker/docker|github.com/moby/spdystream|golang.org/x/crypto|go\.opentelemetry\.io/otel/sdk|google\.golang\.org/grpc' ipfailover/keepalived/tests/go.mod || true

Repository: openshift/images

Length of output: 10524


🌐 Web query:

OSV GO-2026-4958 go.opentelemetry.io/otel/sdk path hijacking

💡 Result:

The identifier GO-2026-4958 does not correspond to a vulnerability in go.opentelemetry.io/otel/sdk, but rather to an uncontrolled resource consumption vulnerability in github.com/moby/spdystream [1][2]. The vulnerability in go.opentelemetry.io/otel/sdk related to path hijacking is tracked under different identifiers: 1. macOS/Darwin Path Hijacking: This was tracked as CVE-2026-24051 (GHSA-9h8m-3fm2-qjrq) and affected go.opentelemetry.io/otel/sdk versions 1.20.0 through 1.39.0 [3][4]. It was addressed in version 1.40.0 [3]. 2. BSD/Solaris Path Hijacking (Incomplete Fix): This was an incomplete fix for the previous issue, tracked as GO-2026-5426 (CVE-2026-39883, GHSA-hfvc-g4fc-pqhx) [5][6][7][8]. It affected versions 1.15.0 through 1.42.0 and was fixed in version 1.43.0 [6][8][9]. This issue involved the use of a relative path for the kenv command, which could be exploited by an attacker with local access to perform arbitrary code execution [6][8]. If you are looking for information on GO-2026-4958 specifically, it refers to an out-of-memory vulnerability in the SPDY/3 frame parser within github.com/moby/spdystream, which was fixed in version 0.5.1 [1][2][10].

Citations:


Resolve the vulnerable transitive dependencies or document reachable-code exemptions.

ipfailover/keepalived/tests depends transititively on fixed vulnerable packages: github.com/moby/spdystream v0.5.0, go.opentelemetry.io/otel/sdk v1.37.0, golang.org/x/crypto v0.50.0, and google.golang.org/grpc v1.75.1. Run govulncheck ./... in a Go-enabled environment and, if the affected Docker/SPDY/SSH-agent/gRPC-server code paths are not reachable, document that exemption. Do not rely on // indirect as evidence of safety. (osv.dev)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ipfailover/keepalived/tests/go.mod` at line 48, Update the dependency
resolution for the ipfailover/keepalived/tests module by running govulncheck
./... and addressing the reported vulnerable transitive packages, including
github.com/moby/spdystream, go.opentelemetry.io/otel/sdk, golang.org/x/crypto,
and google.golang.org/grpc. If the affected Docker, SPDY, SSH-agent, or
gRPC-server paths are unreachable, document the reachable-code exemption
explicitly rather than relying on the // indirect annotation in go.mod.

Sources: Path instructions, MCP tools, Linters/SAST tools

Comment on lines +3 to +8
.PHONY: build
build:
@echo "Building extension binary..."
@mkdir -p bin
GOTOOLCHAIN=auto GOSUMDB=sum.golang.org go build -o $(BINARY) ./cmd
@echo "Binary built: $(BINARY)"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

rg -n '^(all|test):|go test|go vet|ginkgo|tests-extension|e2e-' \
  ipfailover/keepalived/tests/Makefile \
  ipfailover/keepalived/tests \
  .ci-operator.yaml 2>/dev/null || true

Repository: openshift/images

Length of output: 50373


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== Makefile =="
cat -n ipfailover/keepalived/tests/Makefile

echo
echo "== CI/operator files in repo =="
git ls-files | rg '(^|/)\.ci-operator\.ya?ml$|ci|workflow|github/workflows|Makefile|e2e|Ginkgo|tests-extension'

echo
echo "== Target definitions and test commands outside vendor =="
rg -n --glob '!ipfailover/keepalived/tests/vendor/**' '^(all|test|build|clean|help):|go test|go vet|onsi/ginkgo|ginkgo run|ginkgo \.|e2e-|tests-extension|E2E|kind|oc|openshift' .

echo
echo "== .ci-operator.yaml if present =="
if [ -f .ci-operator.yaml ]; then cat -n .ci-operator.yaml; else echo "no .ci-operator.yaml"; fi

Repository: openshift/images

Length of output: 50373


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== Root .ci-operator.yaml =="
cat -n .ci-operator.yaml

echo
echo "== Non-vendor test commands/targets =="
rg -n --glob '!ipfailover/keepalived/tests/vendor/**' \
  --glob '!ipfailover/keepalived/tests/vendor/**' \
  '^(all|test|build|clean|help):|go test|go vet|onsi/ginkgo|ginkgo run|ginkgo \.|e2e-|tests-extension|E2E|kind|oc|openshift|keepalived|ipfailover' . \
  | head -n 500

echo
echo "== Makefile target list =="
python3 - <<'PY'
import re
from pathlib import Path
p = Path("ipfailover/keepalived/tests/Makefile")
for i, line in enumerate(p.read_text().splitlines(), 1):
    if re.match(r'^[A-Za-z0-9_/.-]+\s*:', line) and not line.startswith("\t"):
        print(f"{i}: {line.strip()}")
PY

Repository: openshift/images

Length of output: 50372


Add a test target for the local E2E path.

ipfailover/keepalived/tests/Makefile only exposes build, clean, and help, so developers cannot run the OTE/Ginkgo suite from this directory. Add a test target that builds the extension and runs coverage via ./bin/ipfailover-tests-ext run-suite ipfailover/all --max-concurrency=-1 -cover -covermode=atomic. Do not add an all target only to satisfy the linter.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ipfailover/keepalived/tests/Makefile` around lines 3 - 8, Add a .PHONY test
target to the Makefile that depends on build, then execute the specified local
OTE/Ginkgo coverage command with its existing arguments. Do not add an all
target; keep the current build, clean, and help targets unchanged.

Sources: Learnings, Linters/SAST tools

@melvinjoseph86

Copy link
Copy Markdown
Author

/test tests-extension
/test e2e-metal-ipi-tests-ext
/test e2e-vsphere-ovn-tests-ext
/test e2e-openstack-ipi-tests-ext

@coderabbitai

coderabbitai Bot commented Aug 1, 2026

Copy link
Copy Markdown

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
Validation Failed: {"resource":"IssueComment","code":"custom","field":"body","message":"body is too long (maximum is 65536 characters)"} - https://docs.github.com/rest/issues/comments#update-an-issue-comment

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

♻️ Duplicate comments (1)
ipfailover/keepalived/tests/e2e/testdata_embed.go (1)

19-23: ⚠️ Potential issue | 🟠 Major

Validate the destination before using it.

When os.Stat returns an error other than os.IsNotExist(err), the code discards that error. When dest exists, the code accepts its type and contents without checking ipfailoverTemplate. A stale, partial, invalid, or symlinked file can become the deployment template consumed by ipfailover.go. Use os.Lstat, handle every error, reject symlinks and non-regular files, compare existing bytes, and atomically create a missing file.

As per path instructions, Go code must not ignore error returns.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ipfailover/keepalived/tests/e2e/testdata_embed.go` around lines 19 - 23,
Update the destination setup around os.Stat to use os.Lstat and handle every
returned error explicitly. Reject symlinks and non-regular files, read existing
regular files and compare their bytes with ipfailoverTemplate, and atomically
create the file when it is missing. Preserve the existing panic context while
ensuring all filesystem error returns are checked.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@ipfailover/keepalived/tests/go.mod`:
- Around line 6-10: Align the dependency declarations for
github.com/onsi/ginkgo/v2 with the vendored module resolution: either require
the forked github.com/openshift/onsi-ginkgo/v2 version used by vendor, or remove
the fork replacement so direct imports consistently use upstream Ginkgo v2.
Ensure the go.mod require/replace entries and vendored module agree.

---

Duplicate comments:
In `@ipfailover/keepalived/tests/e2e/testdata_embed.go`:
- Around line 19-23: Update the destination setup around os.Stat to use os.Lstat
and handle every returned error explicitly. Reject symlinks and non-regular
files, read existing regular files and compare their bytes with
ipfailoverTemplate, and atomically create the file when it is missing. Preserve
the existing panic context while ensuring all filesystem error returns are
checked.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

Comment thread ipfailover/keepalived/tests/go.mod
@melvinjoseph86

Copy link
Copy Markdown
Author

/test tests-extension
/test e2e-metal-ipi-tests-ext
/test e2e-vsphere-ovn-tests-ext
/test e2e-openstack-ipi-tests-ext

@melvinjoseph86

Copy link
Copy Markdown
Author

/test e2e-metal-ipi-tests-ext

@openshift-ci

openshift-ci Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

@melvinjoseph86: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-metal-ipi-tests-ext 94367c1 link false /test e2e-metal-ipi-tests-ext

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

jira/valid-reference Indicates that this PR references a valid Jira ticket of any type.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants