Repository navigation
[code sync] Merge code from sonic-net/sonic-gnmi:master to kubesonic - #238
Open
mssonicbld wants to merge 14 commits into
Open
mssonicbld wants to merge 14 commits into
mssonicbld wants to merge 14 commits into
Conversation
* gnoi: require authentication for KillProcess Signed-off-by: Ashutosh Agrawal <ashu@cisco.com> * tests: align KillProcess integration expectations Signed-off-by: Ashutosh Agrawal <ashu@cisco.com> --------- Signed-off-by: Ashutosh Agrawal <ashu@cisco.com>
Signed-off-by: Dawei Huang <daweihuang@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* [gnmi_server]: Authorize native Set bypass before backend Require configured authentication and gNMI write-role authorization before invoking bypass.TrySet. Add focused certificate coverage for mapped read-write success, mapped read-only and unknown-identity denial, and zero backend effect after denial. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Dawei Huang <daweihuang@microsoft.com> * [gnmi_server]: Clarify bypass access-check wording Describe the bypass header as a path request and use precise access-denial wording in the focused certificate tests. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Dawei Huang <daweihuang@microsoft.com> * [gnmi_server]: Use CONFIG_DB role for native Set bypass Resolve the native database target before bypass authorization. When role authorization is configured, require `gnmi_config_db_readwrite` for direct CONFIG_DB bypass requests. Do not attempt this bypass for other database targets. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Dawei Huang <daweihuang@microsoft.com> --------- Signed-off-by: Dawei Huang <daweihuang@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Collaborator
Author
|
/azp run |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
Signed-off-by: Niranjani Vivek <niranjaniv@google.com>
Signed-off-by: Niranjani Vivek <niranjaniv@google.com>
mssonicbld
force-pushed
the
sonicbld/kubesonic-merge
branch
from
September 30, 2026 03:02
e4aabf3 to
a090941
Compare
Collaborator
Author
|
/azp run |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
Signed-off-by: Niranjani Vivek <niranjaniv@google.com>
Why I did it Keep the root Go module's dependencies up to date with regular Dependabot update PRs. How I did it Configured Dependabot to check the root Go module weekly.
mssonicbld
force-pushed
the
sonicbld/kubesonic-merge
branch
from
October 1, 2026 03:03
a090941 to
be935d8
Compare
Collaborator
Author
|
/azp run |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
mssonicbld
force-pushed
the
sonicbld/kubesonic-merge
branch
from
October 2, 2026 03:03
be935d8 to
6d443f4
Compare
Collaborator
Author
|
/azp run |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
Collaborator
Author
|
This cherry pick PR has been opened for more than 3 days. The mssonicbld will attempt to retry. ---Powered by SONiC BuildBot
|
Collaborator
Author
|
/azpw retry |
Collaborator
Author
|
Retrying failed(or canceled) jobs... |
Collaborator
Author
|
Retrying failed(or canceled) stages in build 1236637: ✅Stage Test:
|
mssonicbld
force-pushed
the
sonicbld/kubesonic-merge
branch
from
October 2, 2026 08:14
6d443f4 to
fd0bf66
Compare
Collaborator
Author
|
/azp run |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
Signed-off-by: SRAVANI KANASANI <ksravani-hcl>
mssonicbld
force-pushed
the
sonicbld/kubesonic-merge
branch
from
October 3, 2026 03:03
fd0bf66 to
721fb39
Compare
Collaborator
Author
|
/azp run |
mssonicbld
force-pushed
the
sonicbld/kubesonic-merge
branch
from
October 4, 2026 03:03
721fb39 to
b4c2c5c
Compare
Collaborator
Author
|
/azp run |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
mssonicbld
force-pushed
the
sonicbld/kubesonic-merge
branch
from
October 5, 2026 03:02
b4c2c5c to
2ce8721
Compare
Collaborator
Author
|
/azp run |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
mssonicbld
force-pushed
the
sonicbld/kubesonic-merge
branch
from
October 6, 2026 03:03
2ce8721 to
e56868f
Compare
Collaborator
Author
|
/azp run |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
* [gNOI]: Add secure remote image downloader Add bounded HTTP, HTTPS, SFTP, and SCP downloads for Containerz. Verify SSH host keys against the system trust stores before authentication, disable HTTP redirects and ambient proxies, and sanitize transfer errors. Signed-off-by: Dawei Huang <daweihuang@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * [gNOI]: Download Containerz images natively Replace HostService file downloads and removals with the secure Go downloader and local temporary-file cleanup. Preserve the HostService LoadDockerImage call and send success only after the image is loaded and the temporary file is removed. Signed-off-by: Dawei Huang <daweihuang@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * [gNOI]: Remove unused FileService client APIs Remove the HostService file stat, download, and remove methods after moving the sole Containerz consumer to native Go. Drop the matching fake methods, tests, and counters while retaining the Docker image load operation. Signed-off-by: Dawei Huang <daweihuang@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * [gNOI]: Harden native download defaults Build the HTTP transport from verified standard defaults instead of mutable global state, bound repeated empty reads, and simplify the Containerz test dependency override without changing production behavior. Signed-off-by: Dawei Huang <daweihuang@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * [gNOI]: Keep downloader hooks internal Expose only the validated DownloadRemote entry point so callers cannot replace the production HTTP transport, trust stores, dialer, or timeout behavior. Signed-off-by: Dawei Huang <daweihuang@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * [gNOI]: Close the Containerz D-Bus client Close the retained HostService image loader before local cleanup and response, and preserve load, close, and cleanup failures when more than one stage fails. Signed-off-by: Dawei Huang <daweihuang@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * [gNOI]: Fix Containerz host integration gaps Use host-visible paths for image loading and host-mounted SSH trust stores. Preserve SSH home-path semantics, release HTTP idle connections, and handle temporary-file closure without duplicate closes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Dawei Huang <daweihuang@microsoft.com> * Address PR review feedback (#811) - Report the streamed image byte count in Deploy success responses. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Dawei Huang <daweihuang@microsoft.com> * [gNOI]: Cover Containerz migration paths Exercise default dependency wiring, invalid-request mapping, and combined cleanup failures so the migration remains above the diff-coverage gate. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Dawei Huang <daweihuang@microsoft.com> * Address Copilot review feedback (#811) - Enforce the repository's 4 GiB file limit when image_size is omitted. - Preserve Canceled and DeadlineExceeded for interrupted downloads. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Dawei Huang <daweihuang@microsoft.com> * Preserve shared-memory counter ordinals (#811) - Keep retired file-service counter slots and labels reserved. - Add a regression test for the shared-memory counter layout. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Dawei Huang <daweihuang@microsoft.com> * Tighten Containerz transfer validation (#811) - Require declared image sizes to match downloaded bytes. - Reject HTTP ports outside the valid network range. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Dawei Huang <daweihuang@microsoft.com> * Preserve SSH cancellation errors (#811) - Prefer context cancellation over sanitized SFTP and SCP errors. - Cover cancellation while SFTP Stat is in flight. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Dawei Huang <daweihuang@microsoft.com> * fix(ci): tolerate SCP input close race (#811) - Treat the remote session status as authoritative after the final ACK. - Cover a completed transfer whose input close reports an error. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Dawei Huang <daweihuang@microsoft.com> * Upgrade pkg/sftp to v1.13.11 (#811) - Bound peer-controlled SFTP attribute allocation. - Record the maintenance release's module requirements and sums. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Dawei Huang <daweihuang@microsoft.com> --------- Signed-off-by: Dawei Huang <daweihuang@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
mssonicbld
force-pushed
the
sonicbld/kubesonic-merge
branch
from
October 7, 2026 03:02
e56868f to
f7c1e6b
Compare
Collaborator
Author
|
/azp run |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
mssonicbld
force-pushed
the
sonicbld/kubesonic-merge
branch
from
October 8, 2026 03:02
f7c1e6b to
2738212
Compare
Collaborator
Author
|
/azp run |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
Signed-off-by: Niranjani Vivek <niranjaniv@google.com>
mssonicbld
force-pushed
the
sonicbld/kubesonic-merge
branch
from
October 9, 2026 03:03
2738212 to
4c0ff85
Compare
Collaborator
Author
|
/azp run |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
Signed-off-by: Niranjani Vivek <niranjaniv@google.com>
Signed-off-by: Ashutosh Agrawal <ashu@cisco.com>
mssonicbld
force-pushed
the
sonicbld/kubesonic-merge
branch
from
October 10, 2026 03:03
4c0ff85 to
a14a8bc
Compare
Collaborator
Author
|
/azp run |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
* gnmi: use Unix sockets for local Redis clients Signed-off-by: Ashutosh Agrawal <ashu@cisco.com> * gnmi: reject empty local Redis socket path Signed-off-by: Ashutosh Agrawal <ashu@cisco.com> * gnmi: scope local Redis options helper Signed-off-by: Ashutosh Agrawal <ashu@cisco.com> * tests: cover local Redis option failures Signed-off-by: Ashutosh Agrawal <ashu@cisco.com> --------- Signed-off-by: Ashutosh Agrawal <ashu@cisco.com>
mssonicbld
force-pushed
the
sonicbld/kubesonic-merge
branch
from
October 11, 2026 03:03
a14a8bc to
c307339
Compare
Collaborator
Author
|
/azp run |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.