From 6d65ef36acaf3f3790859aa8f471ede291d09115 Mon Sep 17 00:00:00 2001 From: Chai Bot Date: Thu, 10 Sep 2026 22:19:36 +0000 Subject: [PATCH] OCPBUGS-114428: Update build-machinery-go vendor dependency --- go.mod | 4 +- go.sum | 12 +- .../build-machinery-go/.ci-operator.yaml | 2 +- .../openshift/build-machinery-go/.gitignore | 2 + .../openshift/build-machinery-go/AGENTS.md | 38 +++ .../build-machinery-go/ARCHITECTURE.md | 226 ++++++++++++++++++ .../openshift/build-machinery-go/CLAUDE.md | 1 + .../build-machinery-go/CONTRIBUTING.md | 93 +++++++ .../Dockerfile.commitchecker | 13 + .../openshift/build-machinery-go/OWNERS | 12 +- .../build-machinery-go/OWNERS_ALIASES | 16 ++ .../openshift/build-machinery-go/README.md | 11 +- .../make/default.example.mk.help.log | 1 + .../make/golang.example.mk.help.log | 1 + .../build-machinery-go/make/lib/golang.mk | 9 +- .../make/operator.example.mk.help.log | 3 + .../make/targets/golang/test-unit.mk | 4 +- .../make/targets/golang/verify-update.mk | 5 +- .../make/targets/golang/version.mk | 47 +++- .../make/targets/golang/vulncheck.mk | 31 +++ .../make/targets/openshift/controller-gen.mk | 20 ++ .../make/targets/openshift/images.mk | 8 +- .../make/targets/openshift/operator/mom.mk | 10 + .../make/targets/openshift/yq.mk | 3 +- .../scripts/test-operator-integration.sh | 52 ++++ .../build-machinery-go/scripts/vulncheck.sh | 22 ++ vendor/modules.txt | 4 +- 27 files changed, 621 insertions(+), 29 deletions(-) create mode 100644 vendor/github.com/openshift/build-machinery-go/.gitignore create mode 100644 vendor/github.com/openshift/build-machinery-go/AGENTS.md create mode 100644 vendor/github.com/openshift/build-machinery-go/ARCHITECTURE.md create mode 100644 vendor/github.com/openshift/build-machinery-go/CLAUDE.md create mode 100644 vendor/github.com/openshift/build-machinery-go/CONTRIBUTING.md create mode 100644 vendor/github.com/openshift/build-machinery-go/Dockerfile.commitchecker create mode 100644 vendor/github.com/openshift/build-machinery-go/OWNERS_ALIASES create mode 100644 vendor/github.com/openshift/build-machinery-go/make/targets/golang/vulncheck.mk create mode 100644 vendor/github.com/openshift/build-machinery-go/make/targets/openshift/operator/mom.mk create mode 100644 vendor/github.com/openshift/build-machinery-go/scripts/test-operator-integration.sh create mode 100644 vendor/github.com/openshift/build-machinery-go/scripts/vulncheck.sh diff --git a/go.mod b/go.mod index 904d22093..8b8264066 100644 --- a/go.mod +++ b/go.mod @@ -1,10 +1,10 @@ module github.com/openshift/cluster-bootstrap -go 1.19 +go 1.22.0 require ( github.com/coreos/butane v0.17.0 - github.com/openshift/build-machinery-go v0.0.0-20220913142420-e25cf57ea46d + github.com/openshift/build-machinery-go v0.0.0-20260902143904-520f675c892b github.com/openshift/client-go v0.0.0-20230503144108-75015d2347cb github.com/openshift/installer v0.16.1 github.com/openshift/library-go v0.0.0-20230724150037-c515269de16e diff --git a/go.sum b/go.sum index 5358d458e..62c892a9e 100644 --- a/go.sum +++ b/go.sum @@ -74,6 +74,7 @@ github.com/envoyproxy/go-control-plane v0.9.1-0.20191026205805-5f8ba28d4473/go.m github.com/envoyproxy/go-control-plane v0.9.4/go.mod h1:6rpuAdCZL397s3pYoYcLgu1mIlRU8Am5FuJP05cCM98= github.com/envoyproxy/protoc-gen-validate v0.1.0/go.mod h1:iSmxcyjqTsJpI2R4NaDN7+kN2VEUnK/pcBlmesArF7c= github.com/evanphx/json-patch v4.12.0+incompatible h1:4onqiflcdA9EOZ4RxV643DvftH5pOlLGNtQ5lPWQu84= +github.com/evanphx/json-patch v4.12.0+incompatible/go.mod h1:50XU6AFN0ol/bzJsmQLiYLvXMP4fmwYFNcr97nuDLSk= github.com/ghodss/yaml v1.0.1-0.20190212211648-25d852aebe32 h1:Mn26/9ZMNWSw9C9ERFA1PUxfmGpolnw2v0bKOREu5ew= github.com/ghodss/yaml v1.0.1-0.20190212211648-25d852aebe32/go.mod h1:GIjDIg/heH5DOkXY3YJ/wNhfHsQHoXGjl8G8amsYQ1I= github.com/go-gl/glfw v0.0.0-20190409004039-e6da0acd62b1/go.mod h1:vR7hzQXu2zJy9AVAgeJqvqgH9Q5CA+iKCZ2gyEVpxRU= @@ -90,6 +91,7 @@ github.com/go-openapi/swag v0.22.3 h1:yMBqmnQ0gyZvEb/+KzuWZOXgllrXT4SADYbvDaXHv/ github.com/go-openapi/swag v0.22.3/go.mod h1:UzaqsxGiab7freDnrUUra0MwWfN/q7tE4j+VcZ0yl14= github.com/go-sql-driver/mysql v1.5.0/go.mod h1:DCzpHaOWr8IXmIStZouvnhqoel9Qv2LBy8hT2VhHyBg= github.com/go-task/slim-sprig v0.0.0-20230315185526-52ccab3ef572 h1:tfuBGBXKqDEevZMzYi5KSi8KkcZtzBcTgAUUtapy0OI= +github.com/go-task/slim-sprig v0.0.0-20230315185526-52ccab3ef572/go.mod h1:9Pwr4B2jHnOSGXyyzV8ROjYa2ojvAY6HCGYYfMoC3Ls= github.com/godbus/dbus/v5 v5.0.3/go.mod h1:xhWf0FNVPg57R7Z0UbKHbJfkEywrmjJnf7w5xrFpKfA= github.com/godbus/dbus/v5 v5.0.4/go.mod h1:xhWf0FNVPg57R7Z0UbKHbJfkEywrmjJnf7w5xrFpKfA= github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q= @@ -150,6 +152,7 @@ github.com/google/pprof v0.0.0-20200430221834-fc25d7d30c6d/go.mod h1:ZgVRPoUq/hf github.com/google/pprof v0.0.0-20200507031123-427632fa3b1c/go.mod h1:ZgVRPoUq/hfqzAqh7sHMqb3I9Rq5C59dIz2SbBwJ4eM= github.com/google/pprof v0.0.0-20200708004538-1a94d8640e99/go.mod h1:ZgVRPoUq/hfqzAqh7sHMqb3I9Rq5C59dIz2SbBwJ4eM= github.com/google/pprof v0.0.0-20210720184732-4bb14d4b1be1 h1:K6RDEckDVWvDI9JAJYCmNdQXq6neHJOYx3V6jnqNEec= +github.com/google/pprof v0.0.0-20210720184732-4bb14d4b1be1/go.mod h1:kpwsk12EmLew5upagYY7GY0pfYCcupk39gWOCRROcvE= github.com/google/renameio v0.1.0/go.mod h1:KWCgfxg9yswjAJkECMjeO8J8rahYeXnNhOm40UhjYkI= github.com/google/uuid v1.1.1/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo= github.com/google/uuid v1.3.0 h1:t6JiXgmwXMjEs8VusXIJk2BXHsn+wx8BZdTaoZ5fu7I= @@ -176,6 +179,7 @@ github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORN github.com/kr/pretty v0.2.0/go.mod h1:ipq/a2n7PKx3OHsz4KJII5eveXtPO4qwEXGdVfWzfnI= github.com/kr/pretty v0.2.1/go.mod h1:ipq/a2n7PKx3OHsz4KJII5eveXtPO4qwEXGdVfWzfnI= github.com/kr/pretty v0.3.0 h1:WgNl7dwNpEZ6jJ9k1snq4pZsg7DOEN8hP9Xw0Tsjwk0= +github.com/kr/pretty v0.3.0/go.mod h1:640gp4NfQd8pI5XOwp5fnNeVWj67G7CFk/SaSQn7NBk= github.com/kr/pty v1.1.1/go.mod h1:pFQYn66WHrOpPYNljwOMqo10TkYh1fy3cYio2l3bCsQ= github.com/kr/text v0.1.0/go.mod h1:4Jbv+DJW3UT/LiOwJeYQe1efqtUx/iVham/4vfdArNI= github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY= @@ -190,11 +194,13 @@ github.com/modern-go/reflect2 v1.0.2/go.mod h1:yWuevngMOJpCy52FWWMvUC8ws7m/LJsjY github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 h1:C3w9PqII01/Oq1c1nUAm88MOHcQC9l5mIlSMApZMrHA= github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822/go.mod h1:+n7T8mK8HuQTcFwEeznm/DIxMOiR9yIdICNftLE1DvQ= github.com/onsi/ginkgo/v2 v2.9.2 h1:BA2GMJOtfGAfagzYtrAlufIP0lq6QERkFmHLMLPwFSU= +github.com/onsi/ginkgo/v2 v2.9.2/go.mod h1:WHcJJG2dIlcCqVfBAwUCrJxSPFb6v4azBwgxeMeDuts= github.com/onsi/gomega v1.27.4 h1:Z2AnStgsdSayCMDiCU42qIz+HLqEPcgiOCXjAU/w+8E= +github.com/onsi/gomega v1.27.4/go.mod h1:riYq/GJKh8hhoM01HN6Vmuy93AarCXCBGpvFDK3q3fQ= github.com/openshift/api v0.0.0-20230613151523-ba04973d3ed1 h1:sgr89m3ejIIKhSbTtHq7HEZ80et4IAXDrJlk+u+rYX8= github.com/openshift/api v0.0.0-20230613151523-ba04973d3ed1/go.mod h1:4VWG+W22wrB4HfBL88P40DxLEpSOaiBVxUnfalfJo9k= -github.com/openshift/build-machinery-go v0.0.0-20220913142420-e25cf57ea46d h1:RR4ah7FfaPR1WePizm0jlrsbmPu91xQZnAsVVreQV1k= -github.com/openshift/build-machinery-go v0.0.0-20220913142420-e25cf57ea46d/go.mod h1:b1BuldmJlbA/xYtdZvKi+7j5YGB44qJUJDZ9zwiNCfE= +github.com/openshift/build-machinery-go v0.0.0-20260902143904-520f675c892b h1:ErTc+6D1n/rpRaUYP++h0YlOzM+q7UaAdqDZrzhA0ho= +github.com/openshift/build-machinery-go v0.0.0-20260902143904-520f675c892b/go.mod h1:8jcm8UPtg2mCAsxfqKil1xrmRMI3a+XU2TZ9fF8A7TE= github.com/openshift/client-go v0.0.0-20230503144108-75015d2347cb h1:Nij5OnaECrkmcRQMAE9LMbQXPo95aqFnf+12B7SyFVI= github.com/openshift/client-go v0.0.0-20230503144108-75015d2347cb/go.mod h1:Rhb3moCqeiTuGHAbXBOlwPubUMlOZEkrEWTRjIF3jzs= github.com/openshift/installer v0.16.1 h1:PmjALN9x1NVNVi3SCqfz0ZwVCgOkQLQWo2nHYXREq/A= @@ -209,6 +215,7 @@ github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZN github.com/prometheus/client_model v0.0.0-20190812154241-14fe0d1b01d4/go.mod h1:xMI15A0UPsDsEKsMN9yxemIoYk6Tm2C1GtYGdfGttqA= github.com/rogpeppe/go-internal v1.3.0/go.mod h1:M8bDsm7K2OlrFYOpmOWEs/qY81heoFRclV5y23lUDJ4= github.com/rogpeppe/go-internal v1.11.0 h1:cWPaGQEPrBb5/AsnsZesgZZ9yb1OQ+GOISoDNXVBh4M= +github.com/rogpeppe/go-internal v1.11.0/go.mod h1:ddIwULY96R17DhadqLgMfk9H9tvdUzkipdSkR5nkCZA= github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM= github.com/spf13/cobra v1.6.1 h1:o94oiPyS4KD1mPy2fmcYYHHfCxLqYjJOhGsCHFZtEzA= github.com/spf13/cobra v1.6.1/go.mod h1:IOw/AERYS7UzyrGinqmz6HLUo219MORXGxhbaJUqzrY= @@ -415,6 +422,7 @@ golang.org/x/tools v0.0.0-20200804011535-6c149bb5ef0d/go.mod h1:njjCfa9FT2d7l9Bc golang.org/x/tools v0.0.0-20200825202427-b303f430e36d/go.mod h1:njjCfa9FT2d7l9Bc6FUM5FLjQPp3cFF28FI3qnDFljA= golang.org/x/tools v0.0.0-20210106214847-113979e3529a/go.mod h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA= golang.org/x/tools v0.7.0 h1:W4OVu8VVOaIO0yzWMNdepAulS7YfoS3Zabrm8DOXXU4= +golang.org/x/tools v0.7.0/go.mod h1:4pg6aUX35JBAogB10C9AtvVL+qowtN4pT3CGSQex14s= golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= diff --git a/vendor/github.com/openshift/build-machinery-go/.ci-operator.yaml b/vendor/github.com/openshift/build-machinery-go/.ci-operator.yaml index 00d7adfcf..7c15f83e3 100644 --- a/vendor/github.com/openshift/build-machinery-go/.ci-operator.yaml +++ b/vendor/github.com/openshift/build-machinery-go/.ci-operator.yaml @@ -1,4 +1,4 @@ build_root_image: name: release namespace: openshift - tag: rhel-8-release-golang-1.17-openshift-4.10 + tag: rhel-9-release-golang-1.23-openshift-4.19 diff --git a/vendor/github.com/openshift/build-machinery-go/.gitignore b/vendor/github.com/openshift/build-machinery-go/.gitignore new file mode 100644 index 000000000..0ff90ea9b --- /dev/null +++ b/vendor/github.com/openshift/build-machinery-go/.gitignore @@ -0,0 +1,2 @@ +*.log.raw +make/examples/golang-versions-check/_output/ diff --git a/vendor/github.com/openshift/build-machinery-go/AGENTS.md b/vendor/github.com/openshift/build-machinery-go/AGENTS.md new file mode 100644 index 000000000..91c04f1f5 --- /dev/null +++ b/vendor/github.com/openshift/build-machinery-go/AGENTS.md @@ -0,0 +1,38 @@ +# AI Agent Instructions for build-machinery-go + +**Audience:** AI agents editing **this repository** only — not downstream repos +that vendor these fragments. Those repos should maintain their own root-level +`AGENTS.md`. + +| File | Purpose | +|------|---------| +| [ARCHITECTURE.md](ARCHITECTURE.md) | Make stack design, project layout, verification model | +| [CONTRIBUTING.md](CONTRIBUTING.md) | Development workflow, PR expectations, external guidelines | + +## What This Repo Is + +Reusable GNU Make fragments and helper scripts. Downstream repos include one +vendored entry file (`golang.mk`, `default.mk`, or `operator.mk`) in their +`Makefile`. See [ARCHITECTURE.md](ARCHITECTURE.md) for stacks, layout, and +include chains. + +## Critical Rules + +1. **Run `make verify` before considering any change complete.** +2. **Do not hand-edit `*.log` files** — regenerate with `make update`. +3. **Add new behavior in `make/targets/`**, not in entry files. +4. **Keep backward compatibility** — every repo that vendors this module is affected. +5. **Update examples and logs together** when changing `make/targets/`. + +## What NOT to Do + +- Hand-edit `*.example.mk.help.log` or `Makefile.test.log`. +- Change `make/targets/` without updating examples and regenerating logs. +- Edit files under `make/examples/*/vendor/`. +- Duplicate logic across entry files. +- Modify OWNERS or OWNERS_ALIASES. +- Use AI to respond to review comments. + +For workflow details (container image, branch name, commit structure), see +[CONTRIBUTING.md](CONTRIBUTING.md). For org-wide conventions, see the links in +CONTRIBUTING.md and [openshift/coderabbit](https://github.com/openshift/coderabbit). diff --git a/vendor/github.com/openshift/build-machinery-go/ARCHITECTURE.md b/vendor/github.com/openshift/build-machinery-go/ARCHITECTURE.md new file mode 100644 index 000000000..b95b49545 --- /dev/null +++ b/vendor/github.com/openshift/build-machinery-go/ARCHITECTURE.md @@ -0,0 +1,226 @@ +# Architecture Overview + +build-machinery-go provides reusable GNU Make fragments and helper scripts that +OpenShift Go repositories vendor and include in their own `Makefile`. This +document describes how the pieces fit together. Update it when the makefile +layout or verification model changes. + +## 1. Project Structure + +See also [AGENTS.md](AGENTS.md) for contributor-oriented rules. Layout: + +``` +build-machinery-go/ +├── Makefile # Meta-verification of example makefiles and logs +├── make/ +│ ├── golang.mk # Entry: pure Go projects +│ ├── default.mk # Entry: OpenShift Go (+ images, bindata, codegen) +│ ├── operator.mk # Entry: OpenShift operators +│ ├── *.example.mk # Copy-paste starting points for downstream repos +│ ├── *.example.mk.help.log # Checked-in `make help` output (audit trail) +│ ├── targets/ # Composable make modules +│ └── examples/ # Integration tests for makefile fragments +├── scripts/ # Shell helpers invoked by make targets +└── commitchecker/ # Small Go binary using golang.mk (dogfooding) +``` + +## 2. High-Level System Diagram + +This repository is a **library**, not a deployed service. Component repos consume +it at build time: + +``` +┌─────────────────────────┐ +│ OpenShift component │ +│ repo (operator, etc.) │ +└───────────┬─────────────┘ + │ go mod vendor + ▼ +┌─────────────────────────┐ include ┌──────────────────────────┐ +│ vendor/.../build- │ ───────────────► │ Component Makefile │ +│ machinery-go/make/*.mk │ │ (build, test, verify, │ +└─────────────────────────┘ │ images, codegen, ...) │ + ▲ └──────────────────────────┘ + │ verify via examples +┌───────────┴─────────────┐ +│ build-machinery-go │ +│ (this repo) │ +│ make verify / update │ +└─────────────────────────┘ +``` + +Data flow: makefile fragments define targets; component repos run those targets +locally and in CI. This repo validates fragment behavior through checked-in log +output from example makefiles. + +## 3. Core Components + +### 3.1. Make fragment stacks + +Three predefined stacks layer on top of each other. Downstream repos include +exactly one entry file from their vendored copy: + +| Stack | Entry file | Extends | Typical targets | +|----------|--------------------|-----------|------------------------------------------| +| Golang | `make/golang.mk` | — | `build`, `test-unit`, `verify-gofmt` | +| Default | `make/default.mk` | Golang | + `images`, `verify-codegen`, `bindata` | +| Operator | `make/operator.mk` | Default | + `test-operator-integration`, profiles | + +**Include chain:** + +``` +operator.mk + └── default.mk + ├── targets/openshift/deps.mk + ├── targets/openshift/images.mk + ├── targets/openshift/bindata.mk + ├── targets/openshift/codegen.mk + └── golang.mk + ├── targets/help.mk + └── targets/golang/*.mk + +operator.mk also includes: + └── targets/openshift/operator/*.mk +``` + +Entry files are thin wrappers that `include` modules from `make/targets/`. New +behavior belongs in `make/targets/`, not duplicated in entry files. + +### 3.2. Target modules (`make/targets/`) + +| Directory | Purpose | +|-------------------------------|---------------------------------------------------| +| `targets/golang/` | Build, test, fmt, vet, version, vulncheck | +| `targets/openshift/` | Images, bindata, codegen, deps, kustomize, yq, rpm | +| `targets/openshift/operator/` | Release, telepresence, profile manifests, MOM | + +Each `*.mk` file defines related targets and their `verify-*` / `update-*` +counterparts where applicable. + +### 3.3. Scripts (`scripts/`) + +Shell scripts hold logic too complex for inline make recipes: + +| Script | Used by | +|--------------------------------|------------------------------------| +| `update-deps.sh` | Dependency update targets | +| `test-operator-integration.sh` | Operator integration test target | +| `run-telepresence.sh` | Telepresence development workflow | +| `vulncheck.sh` | Vulnerability scanning target | + +### 3.4. commitchecker + +A minimal Go package that includes `golang.mk` from the parent directory. It +dogfoods the Golang stack to confirm fragments still work for real Go builds. +See [`commitchecker/README.md`](commitchecker/README.md) for downstream CI usage. + +## 4. Downstream Consumption + +Component repos vendor this module and include one entry file: + +```makefile +include $(addprefix vendor/github.com/openshift/build-machinery-go/make/, \ + default.mk \ +) +``` + +Paths resolve relative to the included file via +`$(dir $(lastword $(MAKEFILE_LIST)))`, so fragments work regardless of vendored +path depth. + +For a starting point, copy the matching `*.example.mk` into the component repo's +`Makefile` and adjust `GO_BUILD_PACKAGES`, image names, and codegen paths. + +## 5. Verification Model + +This repo does not build OpenShift operators. It verifies makefile fragments +through: + +1. **Example makefiles** (`make/*.example.mk`) — `make help` output captured in + checked-in `*.help.log` files. +2. **Integration examples** (`make/examples/*/Makefile.test`) — exercise + specific targets (codegen, profile manifests, golang version checks). + Output captured in `Makefile.test.log` files. +3. **Root `Makefile`** — runs all examples and diffs output via + `make verify` / `make update`. + +Log files are the audit trail: any change to makefile behavior must be visible +in regenerated log diffs. + +## 6. External Integrations + +| Integration | Purpose | How | +|-------------|---------|-----| +| OpenShift release images | CI build root; reproducible `make update` | `registry.ci.openshift.org/openshift/release` (see `.ci-operator.yaml`) | +| `govulncheck` | Dependency vulnerability scanning | Invoked by `scripts/vulncheck.sh` via `targets/golang/vulncheck.mk` | +| Codegen / image tooling | Bindata, CRD schema, controller-gen, imagebuilder | Referenced by `targets/openshift/*.mk`; run in downstream repos | +| Telepresence | Local operator development | `scripts/run-telepresence.sh` (operator stack only) | + +Downstream repos may integrate additional external tools through their own +Makefile variables; this repo provides the make targets that invoke them. + +## 7. Deployment & Infrastructure + +**Distribution:** Published as the Go module +`github.com/openshift/build-machinery-go`. Downstream repos pin a version in +`go.mod` and copy fragments into `vendor/` via `go mod vendor`. There is no +runtime deployment of this repository itself. + +**CI/CD:** OpenShift Prow via ci-operator. Build root image is defined in +[`.ci-operator.yaml`](.ci-operator.yaml) (`rhel-9-release-golang-1.23-openshift-4.19`). +The primary CI check is `make verify`, which diffs example makefile output +against checked-in logs. + +**Infrastructure owned by this repo:** None. Make targets in downstream repos may +build container images, generate manifests, or interact with clusters, but that +machinery runs in consumer repositories, not here. + +## 8. Security Considerations + +| Area | Practice | +|------|----------| +| Dependency scanning | `vulncheck` target runs `govulncheck`; fails on module vulnerabilities | +| Vendor integrity | `verify-deps` / `update-deps` targets in Default stack validate dependency state in downstream repos | +| Script execution | Helper scripts use `bash -e` and clean up temp files (`trap` in `vulncheck.sh`) | +| Secrets | No credentials or cluster access in this repo; downstream targets that need `KUBECONFIG` run in component repos | +| Supply chain | Changes to makefile fragments are auditable via checked-in `*.log` diffs in PRs | + +This repo does not implement authentication or authorization. Security-sensitive +operations (image pushes, cluster deploys) are gated by CI and credentials in +downstream repositories. + +## 9. Development & Testing Environment + +**Local setup:** Clone the repo and run `make verify`. See +[CONTRIBUTING.md](CONTRIBUTING.md) for the full workflow, including the +container command to match CI log output. + +**Testing approach:** + +| Layer | Mechanism | +|-------|-----------| +| Makefile fragments | `make/examples/*/Makefile.test` integration examples | +| Help output | `make/*.example.mk.help.log` snapshot tests | +| Golang stack | `commitchecker/` dogfooding build | + +**Code quality:** `make verify` is the gate. Downstream stacks additionally +expose `verify-gofmt`, `verify-govet`, `verify-codegen`, and related targets. + +## 10. Project Identification + +| Field | Value | +|-------|-------| +| Project name | build-machinery-go | +| Repository | https://github.com/openshift/build-machinery-go | +| Module path | `github.com/openshift/build-machinery-go` | +| Maintainers | See [OWNERS](OWNERS) (`control-plane-approvers`, `jsafrane`, `sanchezl`) | + +## 11. Glossary + +| Term | Definition | +|------|------------| +| **Stack** | One of Golang, Default, or Operator entry-file layers | +| **Fragment** | A `*.mk` file included into a downstream `Makefile` | +| **Target module** | A composable `make/targets/**/*.mk` file defining related targets | +| **Log audit** | Checked-in `*.log` files that snapshot makefile output for `git diff` verification | +| **Downstream repo** | An OpenShift component repo that vendors and includes these make fragments | diff --git a/vendor/github.com/openshift/build-machinery-go/CLAUDE.md b/vendor/github.com/openshift/build-machinery-go/CLAUDE.md new file mode 100644 index 000000000..43c994c2d --- /dev/null +++ b/vendor/github.com/openshift/build-machinery-go/CLAUDE.md @@ -0,0 +1 @@ +@AGENTS.md diff --git a/vendor/github.com/openshift/build-machinery-go/CONTRIBUTING.md b/vendor/github.com/openshift/build-machinery-go/CONTRIBUTING.md new file mode 100644 index 000000000..5d7814832 --- /dev/null +++ b/vendor/github.com/openshift/build-machinery-go/CONTRIBUTING.md @@ -0,0 +1,93 @@ +# Contributing to build-machinery-go + +build-machinery-go ships reusable GNU Make fragments consumed by many OpenShift +Go projects via `go mod vendor`. Changes here have broad downstream impact. + +Read [ARCHITECTURE.md](ARCHITECTURE.md) for how the make stacks and verification +model work. + +## Related guidelines + +This repository does not define org-wide OpenShift or Go conventions. Use these +instead: + +| Topic | Where | +|-------|-------| +| Control plane code conventions, testing, PR process, review expectations | [openshift/service-ca-operator/CONTRIBUTING.md](https://github.com/openshift/service-ca-operator/blob/main/CONTRIBUTING.md) | +| OpenShift CI / Prow / Jira integration | [docs.ci.openshift.org](https://docs.ci.openshift.org/) | +| Commit signature verification | [OpenShift contribution policy](https://docs.google.com/document/d/1184EPSGunUkcSQYUK8T4a6iyawwi6f2zxdbB2jtG9nQ/edit?usp=sharing) | +| AI code review configuration | [openshift/coderabbit](https://github.com/openshift/coderabbit) | + +For reviews, reach out via [OWNERS](OWNERS) or the control plane Slack channels +listed in the service-ca-operator contributing guide. + +## Development workflow + +1. Fork the repo and clone your fork. +2. Create a feature branch from `master`. +3. Make your changes. When makefile behavior changes, add or update examples under + `make/examples/`. +4. Run `make verify` locally before pushing. +5. Open a PR against `openshift/build-machinery-go:master`. + +Functional changes that regenerate logs should use two commits when applicable: +code first, then `update generated` for `*.log` files only. + +## Verification + +This repo validates makefile fragments through **checked-in log snapshots**, not +unit tests. See [ARCHITECTURE.md §5](ARCHITECTURE.md#5-verification-model) for +details. + +- Run `make update` after changing `make/targets/` or examples, then commit the + regenerated `*.log` files. +- Never hand-edit `*.example.mk.help.log` or `Makefile.test.log`. + +### Matching CI output + +Local `make update` output may differ across distributions. To match CI, run +update in the same build root image as Prow (defined in +[`.ci-operator.yaml`](.ci-operator.yaml)): + +```bash +podman run -it --rm --pull=always \ + -v "$(pwd)":/go/src/$(go list -m) \ + --workdir=/go/src/$(go list -m) \ + registry.ci.openshift.org/openshift/release:rhel-9-release-golang-1.23-openshift-4.19 \ + make update +``` + +## Make fragment changes + +- Add new behavior in `make/targets/`, not in entry files (`golang.mk`, + `default.mk`, `operator.mk`). +- Keep backward compatibility unless a breaking change is explicitly agreed. +- Place complex shell logic in `scripts/` — follow the + [shell styleguide](https://google.github.io/styleguide/shellguide.html). +- Do not add Go dependencies without justification in the PR description. + +## Pull requests + +Follow the linked control plane and OpenShift CI guidelines for Jira titles +(`CNTRLPLANE-XXXX:` or `NO-JIRA:`), `/lgtm`, `/approve`, `/verified`, and Prow +retests. + +Repository-specific expectations: + +- `make verify` must pass in CI. +- Changes to `make/targets/` must include updated examples and regenerated logs. +- Breaking fragment interface changes need maintainer agreement and a migration + note for downstream repos. +- Do not modify `OWNERS` or `OWNERS_ALIASES` without explicit direction. + +For makefile-only changes, `/verified by ci` is typically sufficient when +`make verify` passes. + +## Areas requiring extra care + +- Entry file changes (`golang.mk`, `default.mk`, `operator.mk`) affect every + downstream repo on that stack. +- Target module interface changes (variables, target names, defaults) must stay + backward compatible or document migration. +- Log normalization sed filters in the root `Makefile` must not hide real + behavior changes. diff --git a/vendor/github.com/openshift/build-machinery-go/Dockerfile.commitchecker b/vendor/github.com/openshift/build-machinery-go/Dockerfile.commitchecker new file mode 100644 index 000000000..0651b7e24 --- /dev/null +++ b/vendor/github.com/openshift/build-machinery-go/Dockerfile.commitchecker @@ -0,0 +1,13 @@ +# This Dockerfile must be on the top-level of this repo, because it needs to copy +# both commitchecker/ and make/ into the build container. + +FROM registry.ci.openshift.org/ocp/builder:rhel-9-golang-1.23-openshift-4.19 AS builder +WORKDIR /go/src/github.com/openshift/build-machinery-go +COPY . . +RUN make -C commitchecker + +FROM registry.ci.openshift.org/ocp/4.19:base-rhel9 +COPY --from=builder /go/src/github.com/openshift/build-machinery-go/commitchecker/commitchecker /usr/bin/ +RUN dnf install --setopt=tsflags=nodocs -y git && \ + dnf clean all && rm -rf /var/cache/yum/* +ENTRYPOINT ["/usr/bin/commitchecker"] diff --git a/vendor/github.com/openshift/build-machinery-go/OWNERS b/vendor/github.com/openshift/build-machinery-go/OWNERS index e016cc303..c54ee52b6 100644 --- a/vendor/github.com/openshift/build-machinery-go/OWNERS +++ b/vendor/github.com/openshift/build-machinery-go/OWNERS @@ -1,9 +1,9 @@ reviewers: - - sttts - - mfojtik - - soltysh + - control-plane-approvers - 2uasimojo + - jsafrane + - sanchezl approvers: - - sttts - - mfojtik - - soltysh + - control-plane-approvers + - jsafrane + - sanchezl diff --git a/vendor/github.com/openshift/build-machinery-go/OWNERS_ALIASES b/vendor/github.com/openshift/build-machinery-go/OWNERS_ALIASES new file mode 100644 index 000000000..66464a003 --- /dev/null +++ b/vendor/github.com/openshift/build-machinery-go/OWNERS_ALIASES @@ -0,0 +1,16 @@ +aliases: + control-plane-approvers: + - ardaguclu + - atiratree + - benluddy + - bertinatto + - everettraven + - flavianmissi + - gangwgr + - ingvagabund + - kaleemsiddiqu + - p0lyn0mial + - rh-roman + - ricardomaraschini + - tjungblu + - xueqzhan diff --git a/vendor/github.com/openshift/build-machinery-go/README.md b/vendor/github.com/openshift/build-machinery-go/README.md index 66862f61a..54fbed76b 100644 --- a/vendor/github.com/openshift/build-machinery-go/README.md +++ b/vendor/github.com/openshift/build-machinery-go/README.md @@ -37,8 +37,9 @@ Extends [#Default](). `scripts` contain more complicated logic that is used in some make targets. ## Contributing -### Updating generated files -We track the log output from the makefile tests to make sure any change is visible and can be audited. Unfortunately due to subtle linux tooling differences in distributions and versions, `make update` may not get you the exact output as the CI. To avoid it, just run the command in the same container as CI: -``` -podman run -it --rm --pull=always -v $( pwd ):/go/src/$( go list -m ) --workdir=/go/src/$( go list -m ) registry.ci.openshift.org/openshift/release:rhel-8-release-golang-1.15-openshift-4.7 make update -``` + +See [CONTRIBUTING.md](CONTRIBUTING.md) for development workflow, PR guidelines, +and how to regenerate checked-in makefile logs. + +For architecture details, see [ARCHITECTURE.md](ARCHITECTURE.md). For AI agent +instructions, see [AGENTS.md](AGENTS.md) ([CLAUDE.md](CLAUDE.md) references it via `@AGENTS.md`). diff --git a/vendor/github.com/openshift/build-machinery-go/make/default.example.mk.help.log b/vendor/github.com/openshift/build-machinery-go/make/default.example.mk.help.log index befafb1e2..713d8c72a 100644 --- a/vendor/github.com/openshift/build-machinery-go/make/default.example.mk.help.log +++ b/vendor/github.com/openshift/build-machinery-go/make/default.example.mk.help.log @@ -24,3 +24,4 @@ verify-gofmt verify-golang-versions verify-golint verify-govet +vulncheck diff --git a/vendor/github.com/openshift/build-machinery-go/make/golang.example.mk.help.log b/vendor/github.com/openshift/build-machinery-go/make/golang.example.mk.help.log index 2a908b013..1265d975e 100644 --- a/vendor/github.com/openshift/build-machinery-go/make/golang.example.mk.help.log +++ b/vendor/github.com/openshift/build-machinery-go/make/golang.example.mk.help.log @@ -13,3 +13,4 @@ verify-gofmt verify-golang-versions verify-golint verify-govet +vulncheck diff --git a/vendor/github.com/openshift/build-machinery-go/make/lib/golang.mk b/vendor/github.com/openshift/build-machinery-go/make/lib/golang.mk index d08f74a42..6674f7eb6 100644 --- a/vendor/github.com/openshift/build-machinery-go/make/lib/golang.mk +++ b/vendor/github.com/openshift/build-machinery-go/make/lib/golang.mk @@ -60,10 +60,17 @@ ifndef OS_GIT_VERSION OS_GIT_VERSION = $(SOURCE_GIT_TAG) endif +# OS_MAJOR_VERSION is populated by ART +# If building out of the ART pipeline, fallback to '0' and let implementations decide how they handle it +ifndef OS_MAJOR_VERSION + OS_MAJOR_VERSION = "0" +endif + define version-ldflags -X $(1).versionFromGit="$(OS_GIT_VERSION)" \ -X $(1).commitFromGit="$(SOURCE_GIT_COMMIT)" \ -X $(1).gitTreeState="$(SOURCE_GIT_TREE_STATE)" \ --X $(1).buildDate="$(shell date -u +'%Y-%m-%dT%H:%M:%SZ')" +-X $(1).buildDate="$(shell date -u +'%Y-%m-%dT%H:%M:%SZ')" \ +-X $(1).majorFromGit="$(OS_MAJOR_VERSION)" endef GO_LD_FLAGS ?=-ldflags "$(call version-ldflags,$(GO_PACKAGE)/pkg/version) $(GO_LD_EXTRAFLAGS)" diff --git a/vendor/github.com/openshift/build-machinery-go/make/operator.example.mk.help.log b/vendor/github.com/openshift/build-machinery-go/make/operator.example.mk.help.log index 4c99d2901..b636e3926 100644 --- a/vendor/github.com/openshift/build-machinery-go/make/operator.example.mk.help.log +++ b/vendor/github.com/openshift/build-machinery-go/make/operator.example.mk.help.log @@ -13,6 +13,7 @@ image-ocp-openshift-apiserver-operator images telepresence test +test-operator-integration test-unit update update-bindata @@ -21,6 +22,7 @@ update-deps-overrides update-generated update-gofmt update-profile-manifests +update-test-operator-integration verify verify-bindata verify-codegen @@ -31,3 +33,4 @@ verify-golang-versions verify-golint verify-govet verify-profile-manifests +vulncheck diff --git a/vendor/github.com/openshift/build-machinery-go/make/targets/golang/test-unit.mk b/vendor/github.com/openshift/build-machinery-go/make/targets/golang/test-unit.mk index 5afb24af6..5b3fa5248 100644 --- a/vendor/github.com/openshift/build-machinery-go/make/targets/golang/test-unit.mk +++ b/vendor/github.com/openshift/build-machinery-go/make/targets/golang/test-unit.mk @@ -4,11 +4,11 @@ include $(addprefix $(dir $(lastword $(MAKEFILE_LIST))), \ test-unit: ifndef JUNITFILE - $(GO) test $(GO_MOD_FLAGS) $(GO_TEST_FLAGS) $(GO_TEST_PACKAGES) + $(GO) test $(GO_MOD_FLAGS) $(GO_TEST_FLAGS) $(GO_TEST_PACKAGES) $(GO_TEST_ARGS) else ifeq (, $(shell which gotest2junit 2>/dev/null)) $(error gotest2junit not found! Get it by `go get -mod='' -u github.com/openshift/release/tools/gotest2junit`.) endif - set -o pipefail; $(GO) test $(GO_MOD_FLAGS) $(GO_TEST_FLAGS) -json $(GO_TEST_PACKAGES) | gotest2junit > $(JUNITFILE) + set -o pipefail; $(GO) test $(GO_MOD_FLAGS) $(GO_TEST_FLAGS) -json $(GO_TEST_PACKAGES) $(GO_TEST_ARGS) | gotest2junit > $(JUNITFILE) endif .PHONY: test-unit diff --git a/vendor/github.com/openshift/build-machinery-go/make/targets/golang/verify-update.mk b/vendor/github.com/openshift/build-machinery-go/make/targets/golang/verify-update.mk index 3b71e29dd..0c72a276c 100644 --- a/vendor/github.com/openshift/build-machinery-go/make/targets/golang/verify-update.mk +++ b/vendor/github.com/openshift/build-machinery-go/make/targets/golang/verify-update.mk @@ -3,11 +3,12 @@ include $(addprefix $(dir $(lastword $(MAKEFILE_LIST))), \ ) go_files_count :=$(words $(GO_FILES)) +chunk_size :=1000 verify-gofmt: $(info Running `$(GOFMT) $(GOFMT_FLAGS)` on $(go_files_count) file(s).) @TMP=$$( mktemp ); \ - $(GOFMT) $(GOFMT_FLAGS) $(GO_FILES) | tee $${TMP}; \ + find . -name '*.go' -not -path '*/vendor/*' -not -path '*/_output/*' -print | xargs -n $(chunk_size) $(GOFMT) $(GOFMT_FLAGS) | tee $${TMP}; \ if [ -s $${TMP} ]; then \ echo "$@ failed - please run \`make update-gofmt\`"; \ exit 1; \ @@ -16,7 +17,7 @@ verify-gofmt: update-gofmt: $(info Running `$(GOFMT) $(GOFMT_FLAGS) -w` on $(go_files_count) file(s).) - @$(GOFMT) $(GOFMT_FLAGS) -w $(GO_FILES) + @find . -name '*.go' -not -path '*/vendor/*' -not -path '*/_output/*' -print | xargs -n $(chunk_size) $(GOFMT) $(GOFMT_FLAGS) -w .PHONY: update-gofmt diff --git a/vendor/github.com/openshift/build-machinery-go/make/targets/golang/version.mk b/vendor/github.com/openshift/build-machinery-go/make/targets/golang/version.mk index f84ceb92e..9692c1d82 100644 --- a/vendor/github.com/openshift/build-machinery-go/make/targets/golang/version.mk +++ b/vendor/github.com/openshift/build-machinery-go/make/targets/golang/version.mk @@ -1,3 +1,23 @@ +# verify-golang-versions — ensure Go versions are consistent across build sources. +# +# OpenShift repos declare a Go version in up to three places: go.mod, +# Dockerfile (builder image tag), and .ci-operator.yaml (CI build root). +# When these drift apart, builds can silently use the wrong Go version or +# fail in hard-to-diagnose ways. In particular, if go.mod declares a version +# higher than the CI builder, the build fails because GOTOOLCHAIN=local +# prevents Go from downloading a newer toolchain. This target catches +# that drift at verify time by extracting the Go MAJOR.MINOR from each source +# and comparing them. +# +# Rules: +# 1. All CI sources (Dockerfile, .ci-operator.yaml) must declare the same Go version. +# 2. go.mod may declare a version <= the CI version (Go is backward-compatible). +# 3. go.mod must NOT declare a version higher than the CI builder. +# 4. Every extracted version must be a valid MAJOR.MINOR number. +# +# Usage: +# $(call verify-golang-versions,Dockerfile.rhel7) + include $(addprefix $(dir $(lastword $(MAKEFILE_LIST))), \ ../../lib/golang.mk \ ../../lib/tmp.mk \ @@ -9,11 +29,28 @@ include $(addprefix $(dir $(lastword $(MAKEFILE_LIST))), \ verify-golang-versions: @if [ -f "$(PERMANENT_TMP)/golang-versions" ]; then \ - LINES=$$(cat "$(PERMANENT_TMP)/golang-versions" | sort | uniq | wc -l); \ - if [ $${LINES} -gt 1 ]; then \ + GOMOD_VER=""; \ + CI_VER=""; \ + if [ -f "$(PERMANENT_TMP)/named-golang-versions" ]; then \ + GOMOD_VER=$$(grep '^go\.mod:' "$(PERMANENT_TMP)/named-golang-versions" | sed 's/go\.mod: *//'); \ + CI_VER=$$(grep -v '^go\.mod:' "$(PERMANENT_TMP)/named-golang-versions" | sed 's/^[^:]*: *//' | sort | uniq); \ + fi; \ + CI_COUNT=$$(echo "$${CI_VER}" | grep -c . 2>/dev/null || :); \ + if [ "$${CI_COUNT}" -gt 1 ]; then \ echo "Golang version mismatch:"; \ cat "$(PERMANENT_TMP)/named-golang-versions" | sort | sed 's/^/- /'; \ false; \ + elif [ -n "$${GOMOD_VER}" ] && [ -n "$${CI_VER}" ]; then \ + GOMOD_MAJOR=$$(echo "$${GOMOD_VER}" | cut -d. -f1); \ + GOMOD_MINOR=$$(echo "$${GOMOD_VER}" | cut -d. -f2); \ + CI_MAJOR=$$(echo "$${CI_VER}" | cut -d. -f1); \ + CI_MINOR=$$(echo "$${CI_VER}" | cut -d. -f2); \ + if [ "$${GOMOD_MAJOR}" -gt "$${CI_MAJOR}" ] 2>/dev/null || \ + { [ "$${GOMOD_MAJOR}" -eq "$${CI_MAJOR}" ] 2>/dev/null && [ "$${GOMOD_MINOR}" -gt "$${CI_MINOR}" ] 2>/dev/null; }; then \ + echo "Golang version mismatch:"; \ + cat "$(PERMANENT_TMP)/named-golang-versions" | sort | sed 's/^/- /'; \ + false; \ + fi; \ fi; \ fi .PHONY: verify-golang-versions @@ -24,6 +61,10 @@ define verify-golang-version-reference-internal verify-golang-versions-$(1): .empty-golang-versions-files verify-golang-versions-$(1): @mkdir -p "$(PERMANENT_TMP)" + @if ! echo "$(2)" | grep -qxE '[0-9]+\.[0-9]+'; then \ + echo "Error: could not extract a valid golang version from $(1) (got '$(2)')"; \ + false; \ + fi @echo "$(1): $(2)" >> "$(PERMANENT_TMP)/named-golang-versions" @echo "$(2)" >> "$(PERMANENT_TMP)/golang-versions" .PHONY: verify-golang-versions-$(1) @@ -43,7 +84,7 @@ $(call verify-golang-version-reference,$(1),$(shell grep "AS builder" "$(1)" | s endef define verify-go-mod-golang-version -$(call verify-golang-version-reference,go.mod,$(shell grep -e 'go [[:digit:]]*\.[[:digit:]]*' go.mod 2>/dev/null | sed 's/go //')) +$(call verify-golang-version-reference,go.mod,$(shell grep -e 'go [[:digit:]]*\.[[:digit:]]*' go.mod 2>/dev/null | sed 's/go \([[:digit:]][[:digit:]]*.[[:digit:]][[:digit:]]*\).*/\1/')) endef define verify-buildroot-golang-version diff --git a/vendor/github.com/openshift/build-machinery-go/make/targets/golang/vulncheck.mk b/vendor/github.com/openshift/build-machinery-go/make/targets/golang/vulncheck.mk new file mode 100644 index 000000000..963a9797a --- /dev/null +++ b/vendor/github.com/openshift/build-machinery-go/make/targets/golang/vulncheck.mk @@ -0,0 +1,31 @@ +scripts_dir :=$(shell realpath $(dir $(lastword $(MAKEFILE_LIST)))../../../scripts) + +# `make vulncheck` will emit a report similar to: +# +# [ +# "golang.org/x/net", +# "v0.5.0", +# "v0.7.0" +# ] +# [ +# "stdlib", +# "go1.19.3", +# "go1.20.1" +# ] +# [ +# "stdlib", +# "go1.19.3", +# "go1.19.4" +# ] +# +# Each stanza lists +# - where the vulnerability exists +# - the version it was found in +# - the version it's fixed in +# +# If the report contains any entries that are not in stdlib, the check +# will fail (exit nonzero). Otherwise it will succeed -- i.e. the stdlib +# entries are only warnings. +vulncheck: + bash $(scripts_dir)/vulncheck.sh +.PHONY: vulncheck diff --git a/vendor/github.com/openshift/build-machinery-go/make/targets/openshift/controller-gen.mk b/vendor/github.com/openshift/build-machinery-go/make/targets/openshift/controller-gen.mk index 4e15c771a..c64e5cf92 100644 --- a/vendor/github.com/openshift/build-machinery-go/make/targets/openshift/controller-gen.mk +++ b/vendor/github.com/openshift/build-machinery-go/make/targets/openshift/controller-gen.mk @@ -3,6 +3,26 @@ include $(addprefix $(dir $(lastword $(MAKEFILE_LIST))), \ ../../lib/tmp.mk \ ) +############## +# DEPRECATED # +############## +# This utility is hard to maintain due to the need to continuously build and release binaries for +# multiple platforms and versions. Instead it is recommended that you: +# - Vendor the sigs.k8s.io/controller-tools repository. +# - Write a local rule to (lazily) build the controller-gen binary from the vendored repo. +# For example: +# +# CONTROLLER_GEN_SRC := $(shell realpath vendor/sigs.k8s.io/controller-tools/cmd/controller-gen) +# CONTROLLER_GEN := $(shell go list -f '{{.Target}}' $(CONTROLLER_GEN_SRC)) +# $(CONTROLLER_GEN): $(CONTROLLER_GEN_SRC) +# go install $(CONTROLLER_GEN_SRC) +# +# This allows you to upgrade versions simply by revendoring controller-tools: +# - Bump the semver in your go.mod +# - go mod tidy +# - go mod vendor +############## + # NOTE: The release binary specified here needs to be built properly so that # `--version` works correctly. Just using `go build` will result in it # reporting `(devel)`. To build for a given platform: diff --git a/vendor/github.com/openshift/build-machinery-go/make/targets/openshift/images.mk b/vendor/github.com/openshift/build-machinery-go/make/targets/openshift/images.mk index c53c3f1b9..90096dc5d 100644 --- a/vendor/github.com/openshift/build-machinery-go/make/targets/openshift/images.mk +++ b/vendor/github.com/openshift/build-machinery-go/make/targets/openshift/images.mk @@ -7,15 +7,21 @@ include $(addprefix $(dir $(lastword $(MAKEFILE_LIST))), \ # make images IMAGE_BUILD_EXTRA_FLAGS='-mount ~/projects/origin-repos/4.2/:/etc/yum.repos.d/' IMAGE_BUILD_DEFAULT_FLAGS ?=--allow-pull IMAGE_BUILD_EXTRA_FLAGS ?= +IMAGE_BUILD_BUILDER ?= imagebuilder # $1 - target name # $2 - image ref # $3 - Dockerfile path # $4 - context +# only run ensure-imagebuilder when imagebuilder is used define build-image-internal +ifeq ($(IMAGE_BUILD_BUILDER),imagebuilder) image-$(1): ensure-imagebuilder +else +image-$(1): +endif $(strip \ - imagebuilder \ + $(IMAGE_BUILD_BUILDER) \ $(IMAGE_BUILD_DEFAULT_FLAGS) \ -t $(2) -f $(3) \ diff --git a/vendor/github.com/openshift/build-machinery-go/make/targets/openshift/operator/mom.mk b/vendor/github.com/openshift/build-machinery-go/make/targets/openshift/operator/mom.mk new file mode 100644 index 000000000..21c81afe0 --- /dev/null +++ b/vendor/github.com/openshift/build-machinery-go/make/targets/openshift/operator/mom.mk @@ -0,0 +1,10 @@ +scripts_dir :=$(shell realpath $(dir $(lastword $(MAKEFILE_LIST)))../../../../scripts) + +test-operator-integration: build + bash $(scripts_dir)/test-operator-integration.sh +.PHONY: test-operator-integration + +update-test-operator-integration: build + REPLACE_TEST_OUTPUT=true bash $(scripts_dir)/test-operator-integration.sh + +.PHONY: update-test-operator-integration diff --git a/vendor/github.com/openshift/build-machinery-go/make/targets/openshift/yq.mk b/vendor/github.com/openshift/build-machinery-go/make/targets/openshift/yq.mk index 07726d87c..0854374fe 100644 --- a/vendor/github.com/openshift/build-machinery-go/make/targets/openshift/yq.mk +++ b/vendor/github.com/openshift/build-machinery-go/make/targets/openshift/yq.mk @@ -8,8 +8,7 @@ include $(addprefix $(dir $(lastword $(MAKEFILE_LIST))), \ YQ_VERSION ?=2.4.0 YQ ?=$(PERMANENT_TMP_GOPATH)/bin/yq-$(YQ_VERSION) -yq_dir :=$(dir $(YQ)) - +yq_dir =$(dir $(YQ)) ensure-yq: ifeq "" "$(wildcard $(YQ))" diff --git a/vendor/github.com/openshift/build-machinery-go/scripts/test-operator-integration.sh b/vendor/github.com/openshift/build-machinery-go/scripts/test-operator-integration.sh new file mode 100644 index 000000000..262bf6010 --- /dev/null +++ b/vendor/github.com/openshift/build-machinery-go/scripts/test-operator-integration.sh @@ -0,0 +1,52 @@ +#!/usr/bin/env bash + +set -o errexit +set -o nounset +set -o pipefail +set -x + +# Install multi-operator-manager. This will make sure the latest binary is installed +# If the installation failed, keep going, maybe the binary is available in the system +echo "Installing latest version of multi-operator-manager..." +if ! go install -mod=readonly github.com/openshift/multi-operator-manager/cmd/multi-operator-manager@latest; then + echo "Error: Failed to install multi-operator-manager." +fi + +# Check if the multi-operator-manager is installed; if not, fail +if ! command -v multi-operator-manager &> /dev/null; then + echo "Error: multi-operator-manager binary not available." + exit 1 +fi + +REPLACE_TEST_OUTPUT="${REPLACE_TEST_OUTPUT:-false}" + +# Define the path to the operator binary +MOM_CMD="${MOM_CMD:-multi-operator-manager}" + +# Define input and output directories (can be overridden if necessary) +APPLY_CONFIG_INPUT_DIR="${APPLY_CONFIG_INPUT_DIR:-./test-data/apply-configuration}" +APPLY_CONFIG_OUTPUT_DIR="${ARTIFACT_DIR:-./test-output}" + +# Make sure the output-dir is clean +if [ -d "${APPLY_CONFIG_OUTPUT_DIR}" ]; then + echo "Cleaning up existing ${APPLY_CONFIG_OUTPUT_DIR}" + rm -rf "${APPLY_CONFIG_OUTPUT_DIR}" +fi + +# Assemble the args +APPLY_CONFIG_ARGS=( + test + apply-configuration + --test-dir="$APPLY_CONFIG_INPUT_DIR" + --output-dir="$APPLY_CONFIG_OUTPUT_DIR" +) + +if [ "$REPLACE_TEST_OUTPUT" == "true" ] +then + APPLY_CONFIG_ARGS=("${APPLY_CONFIG_ARGS[@]}" "--replace-expected-output=true") +else + APPLY_CONFIG_ARGS=("${APPLY_CONFIG_ARGS[@]}" "--preserve-policy=KeepAlways") +fi + +# Run the apply-configuration command from the operator +"${MOM_CMD}" "${APPLY_CONFIG_ARGS[@]}" diff --git a/vendor/github.com/openshift/build-machinery-go/scripts/vulncheck.sh b/vendor/github.com/openshift/build-machinery-go/scripts/vulncheck.sh new file mode 100644 index 000000000..71dfe7216 --- /dev/null +++ b/vendor/github.com/openshift/build-machinery-go/scripts/vulncheck.sh @@ -0,0 +1,22 @@ +#!/bin/bash -e + +### Use govulncheck to check for known vulnerabilities in the project. +### Fail if vulnerabilities are found in module dependencies. +### Warn (but do not fail) on stdlib vulnerabilities. +### TODO: Include useful information (ID, URL) about the vulnerability. + +go install golang.org/x/vuln/cmd/govulncheck@latest + +report=`mktemp` +trap "rm $report" EXIT + +govulncheck -json ./... > $report + +modvulns=$(jq -r '.Vulns[].Modules[] | select(.Path != "stdlib") | [.Path, .FoundVersion, .FixedVersion]' < $report) +libvulns=$(jq -r '.Vulns[].Modules[] | select(.Path == "stdlib") | [.Path, .FoundVersion, .FixedVersion]' < $report) + +echo "$modvulns" +echo "$libvulns" + +# Exit nonzero iff there are any vulnerabilities in module dependencies +test -z "$modvulns" diff --git a/vendor/modules.txt b/vendor/modules.txt index 12e2091e0..e99cf1cc6 100644 --- a/vendor/modules.txt +++ b/vendor/modules.txt @@ -219,8 +219,8 @@ github.com/openshift/api/template github.com/openshift/api/template/v1 github.com/openshift/api/user github.com/openshift/api/user/v1 -# github.com/openshift/build-machinery-go v0.0.0-20220913142420-e25cf57ea46d -## explicit; go 1.13 +# github.com/openshift/build-machinery-go v0.0.0-20260902143904-520f675c892b +## explicit; go 1.22.0 github.com/openshift/build-machinery-go github.com/openshift/build-machinery-go/make github.com/openshift/build-machinery-go/make/lib