Skip to content

fix: kmeshctl authz enable/disable exit 0 despite failures and print false success message - #1895

Open
bhumikadangayach wants to merge 1 commit into
kmesh-net:mainfrom
bhumikadangayach:fix/authz-enable-disable-exit-code
Open

bhumikadangayach wants to merge 1 commit into
kmesh-net:mainfrom
bhumikadangayach:fix/authz-enable-disable-exit-code

Conversation

@bhumikadangayach

Copy link
Copy Markdown

Fixes #1894

kmeshctl authz disable <bad-pod> logged the failure but still exited with code 0 and printed Authorization has been disabled.

The root cause was that SetAuthzPerKmeshDaemon logged errors from request creation, the HTTP request, and non-200 responses without returning them. As a result, SetAuthzForPods couldn't detect failures, and the enable/disable commands always printed a success message regardless of the outcome.

This is the same underlying issue as #1871 and #1880 (and #1892 for the secret command).

Changes

  • Make SetAuthzPerKmeshDaemon return errors.
  • Track failures in SetAuthzForPods and return an error if all requested pods fail.
  • Remove the unconditional success messages from the enable/disable commands.

Verification

  • kmeshctl authz disable <nonexistent-pod> now exits with code 1 and no longer prints a false success message.

@kmesh-bot

Copy link
Copy Markdown
Collaborator

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign nlgwcy for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@codecov

codecov Bot commented Aug 7, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 39.67%. Comparing base (09e96d3) to head (1cb790d).
⚠️ Report is 3 commits behind head on main.
see 3 files with indirect coverage changes


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 60881fc...1cb790d. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

…false success message

Signed-off-by: Bhumika Dangayach <139267865+bhumikadangayach@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

kmeshctl authz enable/disable exit 0 and print false success even when the request fails

2 participants