Skip to content

[code sync] Merge code from sonic-net/sonic-gnmi:master to kubesonic - #238

Open
mssonicbld wants to merge 14 commits into
Azure:kubesonicfrom
mssonicbld:sonicbld/kubesonic-merge
Open

mssonicbld wants to merge 14 commits into
Azure:kubesonicfrom
mssonicbld:sonicbld/kubesonic-merge

Conversation

@mssonicbld

@mssonicbld mssonicbld commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator
* 99fd4cb - (origin/master, origin/HEAD, test, master) gnmi: use Unix sockets for host-local Redis clients (#820) (2026-10-10) [Ashutosh Agrawal]
* 493e4ce - Fix client counter data race (#821) (2026-10-09) [Ashutosh Agrawal]
* 71790b7 - Component Test For Interface Model - Wildcard Support (#736) (2026-10-09) [niranjanivivek]
* f6010c4 - Component test for Components Model - SoftwareComponents (#724) (2026-10-08) [niranjanivivek]
* 74145dc - (origin/commit-validation) [gNOI] Remove Containerz dependency on HostService file_service (#811) (2026-10-06) [Dawei Huang]
* 3cf83f3 - Component Test For Interface Model - CPU (#737) (2026-10-02) [ksravani-hcl]
* 28e3f9f - Enable weekly Dependabot updates for Go modules (#800) (2026-09-30) [xq9mend]
* 3fbeb40 - Component test for Components Model Wildcard (#738) (2026-09-30) [niranjanivivek]
* f13a08e - Component Test For Components Model - Transceivers (#739) (2026-09-29) [niranjanivivek]
* d8c5fa7 - Component test for OCComponentModel Integrated Circuit (#699) (2026-09-28) [niranjanivivek]
* 6ec3f0f - [gnmi_server]: Run access checks before native Set bypass writes (#791) (2026-09-28) [Dawei Huang]
* 9306178 - [gNOI]: Require write authorization for mutating RPCs (#790) (2026-09-28) [Dawei Huang]
* da943ef - Require authentication for remote gNOI KillProcess calls (#776) (2026-09-28) [Ashutosh Agrawal]<br>```

* gnoi: require authentication for KillProcess

Signed-off-by: Ashutosh Agrawal <ashu@cisco.com>

* tests: align KillProcess integration expectations

Signed-off-by: Ashutosh Agrawal <ashu@cisco.com>

---------

Signed-off-by: Ashutosh Agrawal <ashu@cisco.com>
Signed-off-by: Dawei Huang <daweihuang@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* [gnmi_server]: Authorize native Set bypass before backend

Require configured authentication and gNMI write-role authorization before invoking bypass.TrySet. Add focused certificate coverage for mapped read-write success, mapped read-only and unknown-identity denial, and zero backend effect after denial.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Dawei Huang <daweihuang@microsoft.com>

* [gnmi_server]: Clarify bypass access-check wording

Describe the bypass header as a path request and use precise access-denial wording in the focused certificate tests.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Dawei Huang <daweihuang@microsoft.com>

* [gnmi_server]: Use CONFIG_DB role for native Set bypass

Resolve the native database target before bypass authorization. When role authorization is configured, require `gnmi_config_db_readwrite` for direct CONFIG_DB bypass requests. Do not attempt this bypass for other database targets.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Dawei Huang <daweihuang@microsoft.com>

---------

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@mssonicbld

Copy link
Copy Markdown
Collaborator Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

Signed-off-by: Niranjani Vivek <niranjaniv@google.com>
Signed-off-by: Niranjani Vivek <niranjaniv@google.com>
@mssonicbld
mssonicbld force-pushed the sonicbld/kubesonic-merge branch from e4aabf3 to a090941 Compare September 30, 2026 03:02
@mssonicbld

Copy link
Copy Markdown
Collaborator Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

niranjanivivek and others added 2 commits September 30, 2026 17:19
Signed-off-by: Niranjani Vivek <niranjaniv@google.com>
Why I did it
Keep the root Go module's dependencies up to date with regular Dependabot update PRs.

How I did it
Configured Dependabot to check the root Go module weekly.
@mssonicbld
mssonicbld force-pushed the sonicbld/kubesonic-merge branch from a090941 to be935d8 Compare October 1, 2026 03:03
@mssonicbld

Copy link
Copy Markdown
Collaborator Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

@mssonicbld
mssonicbld force-pushed the sonicbld/kubesonic-merge branch from be935d8 to 6d443f4 Compare October 2, 2026 03:03
@mssonicbld

Copy link
Copy Markdown
Collaborator Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

@mssonicbld

Copy link
Copy Markdown
Collaborator Author

This cherry pick PR has been opened for more than 3 days. The mssonicbld will attempt to retry.

---Powered by SONiC BuildBot

@mssonicbld

Copy link
Copy Markdown
Collaborator Author

/azpw retry

@mssonicbld

Copy link
Copy Markdown
Collaborator Author

Retrying failed(or canceled) jobs...

@mssonicbld

Copy link
Copy Markdown
Collaborator Author

Retrying failed(or canceled) stages in build 1236637:

✅Stage Test:

  • Job Integration tests: retried.

@mssonicbld
mssonicbld force-pushed the sonicbld/kubesonic-merge branch from 6d443f4 to fd0bf66 Compare October 2, 2026 08:14
@mssonicbld

Copy link
Copy Markdown
Collaborator Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

Signed-off-by: SRAVANI KANASANI <ksravani-hcl>
@mssonicbld
mssonicbld force-pushed the sonicbld/kubesonic-merge branch from fd0bf66 to 721fb39 Compare October 3, 2026 03:03
@mssonicbld

Copy link
Copy Markdown
Collaborator Author

/azp run

@mssonicbld
mssonicbld force-pushed the sonicbld/kubesonic-merge branch from 721fb39 to b4c2c5c Compare October 4, 2026 03:03
@mssonicbld

Copy link
Copy Markdown
Collaborator Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

@mssonicbld
mssonicbld force-pushed the sonicbld/kubesonic-merge branch from b4c2c5c to 2ce8721 Compare October 5, 2026 03:02
@mssonicbld

Copy link
Copy Markdown
Collaborator Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

@mssonicbld
mssonicbld force-pushed the sonicbld/kubesonic-merge branch from 2ce8721 to e56868f Compare October 6, 2026 03:03
@mssonicbld

Copy link
Copy Markdown
Collaborator Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

* [gNOI]: Add secure remote image downloader

Add bounded HTTP, HTTPS, SFTP, and SCP downloads for Containerz.
Verify SSH host keys against the system trust stores before authentication,
disable HTTP redirects and ambient proxies, and sanitize transfer errors.

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* [gNOI]: Download Containerz images natively

Replace HostService file downloads and removals with the secure Go
downloader and local temporary-file cleanup. Preserve the HostService
LoadDockerImage call and send success only after the image is loaded and
the temporary file is removed.

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* [gNOI]: Remove unused FileService client APIs

Remove the HostService file stat, download, and remove methods after moving
the sole Containerz consumer to native Go. Drop the matching fake methods,
tests, and counters while retaining the Docker image load operation.

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* [gNOI]: Harden native download defaults

Build the HTTP transport from verified standard defaults instead of mutable
global state, bound repeated empty reads, and simplify the Containerz test
dependency override without changing production behavior.

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* [gNOI]: Keep downloader hooks internal

Expose only the validated DownloadRemote entry point so callers cannot replace
the production HTTP transport, trust stores, dialer, or timeout behavior.

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* [gNOI]: Close the Containerz D-Bus client

Close the retained HostService image loader before local cleanup and response,
and preserve load, close, and cleanup failures when more than one stage fails.

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* [gNOI]: Fix Containerz host integration gaps

Use host-visible paths for image loading and host-mounted SSH trust stores.
Preserve SSH home-path semantics, release HTTP idle connections, and handle
temporary-file closure without duplicate closes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>

* Address PR review feedback (#811)

- Report the streamed image byte count in Deploy success responses.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>

* [gNOI]: Cover Containerz migration paths

Exercise default dependency wiring, invalid-request mapping, and combined
cleanup failures so the migration remains above the diff-coverage gate.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>

* Address Copilot review feedback (#811)

- Enforce the repository's 4 GiB file limit when image_size is omitted.
- Preserve Canceled and DeadlineExceeded for interrupted downloads.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>

* Preserve shared-memory counter ordinals (#811)

- Keep retired file-service counter slots and labels reserved.
- Add a regression test for the shared-memory counter layout.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>

* Tighten Containerz transfer validation (#811)

- Require declared image sizes to match downloaded bytes.
- Reject HTTP ports outside the valid network range.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>

* Preserve SSH cancellation errors (#811)

- Prefer context cancellation over sanitized SFTP and SCP errors.
- Cover cancellation while SFTP Stat is in flight.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>

* fix(ci): tolerate SCP input close race (#811)

- Treat the remote session status as authoritative after the final ACK.
- Cover a completed transfer whose input close reports an error.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>

* Upgrade pkg/sftp to v1.13.11 (#811)

- Bound peer-controlled SFTP attribute allocation.
- Record the maintenance release's module requirements and sums.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>

---------

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@mssonicbld
mssonicbld force-pushed the sonicbld/kubesonic-merge branch from e56868f to f7c1e6b Compare October 7, 2026 03:02
@mssonicbld

Copy link
Copy Markdown
Collaborator Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

@mssonicbld
mssonicbld force-pushed the sonicbld/kubesonic-merge branch from f7c1e6b to 2738212 Compare October 8, 2026 03:02
@mssonicbld

Copy link
Copy Markdown
Collaborator Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

Signed-off-by: Niranjani Vivek <niranjaniv@google.com>
@mssonicbld
mssonicbld force-pushed the sonicbld/kubesonic-merge branch from 2738212 to 4c0ff85 Compare October 9, 2026 03:03
@mssonicbld

Copy link
Copy Markdown
Collaborator Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

niranjanivivek and others added 2 commits October 9, 2026 13:22
Signed-off-by: Niranjani Vivek <niranjaniv@google.com>
Signed-off-by: Ashutosh Agrawal <ashu@cisco.com>
@mssonicbld
mssonicbld force-pushed the sonicbld/kubesonic-merge branch from 4c0ff85 to a14a8bc Compare October 10, 2026 03:03
@mssonicbld

Copy link
Copy Markdown
Collaborator Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

* gnmi: use Unix sockets for local Redis clients

Signed-off-by: Ashutosh Agrawal <ashu@cisco.com>

* gnmi: reject empty local Redis socket path

Signed-off-by: Ashutosh Agrawal <ashu@cisco.com>

* gnmi: scope local Redis options helper

Signed-off-by: Ashutosh Agrawal <ashu@cisco.com>

* tests: cover local Redis option failures

Signed-off-by: Ashutosh Agrawal <ashu@cisco.com>

---------

Signed-off-by: Ashutosh Agrawal <ashu@cisco.com>
@mssonicbld
mssonicbld force-pushed the sonicbld/kubesonic-merge branch from a14a8bc to c307339 Compare October 11, 2026 03:03
@mssonicbld

Copy link
Copy Markdown
Collaborator Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants