CLI: Update Hypeman Go SDK to 134587a222aca6307bb75dd0dbd78bf3f604c114 - #68
kernel-internal[bot] wants to merge 4 commits into
Conversation
Bumps github.com/kernel/hypeman-go to v0.28.1-0.20260902045311-0872a65a3733, which integrates vendor VFIO vGPUs into the instance lifecycle. The SDK now documents InstanceGPU.MdevUuid as populated on mdev hosts only, and adds InstanceGPU.DevicePath for the sysfs path of an assigned vGPU device. `hypeman ps` gated its GPU column on MdevUuid alone, so an instance with a vendor VFIO vGPU and no profile name rendered as "-". formatGPU now also checks DevicePath. A full enumeration of api.md methods and CLI commands found no other coverage gaps: every SDK method has a CLI command and every param field has a corresponding flag. Co-authored-by: Cursor <cursoragent@cursor.com>
Bumps github.com/kernel/hypeman-go to v0.28.1-0.20260902143136-e6c2b7bc0171, which adds the "swtpm" value to InstanceLogsParamsSource as part of the Windows hypervisor primitives. Teaches `hypeman logs --source` about swtpm and validates the flag up front instead of forwarding an arbitrary string to the API, matching the parseInstanceWaitState / parseSnapshotTargetHypervisor pattern. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com> # Conflicts: # go.sum
Bumps github.com/kernel/hypeman-go to v0.28.1-0.20261001160305-134587a222ac, which carries the SDK's 2026-09-30 vulnerability remediation. This commit is on main, whereas the branch previously pinned e6c2b7b from the SDK's next branch. The Windows hypervisor primitives generated there are therefore absent, dropping InstanceLogsParamsSourceSwtpm and InstanceGPU.DevicePath. Both values are still specified by the API, so rather than regress `hypeman logs --source swtpm` and the vendor VFIO vGPU column in `hypeman ps`, read them without the generated bindings: the log source is a string-backed enum, and device_path arrives in JSON.ExtraFields. Both can go back to typed access once next lands on main. Co-authored-by: Cursor <cursoragent@cursor.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 22e9c31. Configure here.
| github.com/charmbracelet/lipgloss v1.1.0 | ||
| github.com/charmbracelet/x/term v0.2.1 | ||
| github.com/docker/docker v28.5.2+incompatible | ||
| github.com/docker/docker v28.5.3-0.20260325120914-0afb41ce194c+incompatible |
There was a problem hiding this comment.
Insufficient docker dependency pin
Medium Severity
go.mod now pins github.com/docker/docker to a pseudo-version instead of upgrading go-containerregistry. That keeps the old docker client on the graph, so a pin in this range may not include the docker cp fix for GHSA-rg2x-37c3-w2rh.
Triggered by learned rule: Prefer upgrading go-containerregistry over docker/docker replace pins
Reviewed by Cursor Bugbot for commit 22e9c31. Configure here.


This PR updates the Hypeman Go SDK dependency to the latest version.
SDK Update
Coverage Analysis
A full enumeration of SDK methods and CLI commands was performed. No coverage gaps were found.
All 63 endpoints in
api.mdhave a CLI command.client.Instances.Logsandclient.Builds.Eventsare consumed through their streaming variants (LogsStreaminginhypeman logs,EventsStreaminginhypeman build), andclient.Instances.Get,client.Instances.Stat,client.Volumes.NewFromArchiveandclient.Health.Checkremain internal as documented. The method surface is unchanged from the previously pinned SDK: both versions reportconfigured_endpoints: 63and an identical method list.Heads up: this SDK bump reduces the generated API surface
The previous pin,
e6c2b7b, is on the SDK'snextbranch, notmain.134587ais amaincommit carrying the 2026-09-30 vulnerability remediation, so it does not include the "Windows hypervisor primitives" generation fromnext. Two symbols the branch depended on no longer exist, which broke the build:InstanceLogsParamsSourceSwtpmhypeman logs --source swtpmInstanceGPU.DevicePathformatGPUinhypeman psopenapi.yamlonmainstill specifies both (sourceenum is[app, vmm, hypeman, swtpm], anddevice_pathis on the GPU schema), so the API supports them and only the generated bindings lag. Rather than regress two shipped features, this PR reaches them without the generated types:sourceis a string-backed enum, so a localinstanceLogsSourceSwtpmconstant serializes identically. Verified against a test server:--source swtpmsendssource=swtpm.device_patharrives inJSON.ExtraFields, soformatGPUdecodes it from there. Note thatrespjson.Field.Valid()reportsfalsefor extra fields, so the raw JSON is decoded instead.Both are commented at the call site and should go back to typed access once
nextmerges tomain.Also included is a merge of
maininto this branch (commit 5774c56), resolving ago.sumconflict. History was preserved rather than rebased, so no force push was needed.Triggered by: kernel/hypeman-go@134587a
Reviewer: @ulziibay-kernel
Note
Low Risk
Mostly dependency pins and small CLI shims for untyped API fields; behavior is covered by new unit tests with no auth or data-path changes.
Overview
Pins hypeman-go to
134587a(main) and refreshes docker/docker plus go.sum as part of the dependency update.The newer SDK no longer generates
InstanceLogsParamsSourceSwtpmorInstanceGPU.DevicePath, even though the API still supports them. This PR keeps those behaviors in the CLI without waiting on regenerated types:hypeman logsdocumentsswtpmas a--sourceoption, validates sources case-insensitively viaparseInstanceLogsSource, and uses a localinstanceLogsSourceSwtpmconstant where the SDK constant is missing.hypeman psstill showsvgpuwhen a GPU has no profile by treatingdevice_pathfromJSON.ExtraFieldsthe same asmdev_uuid(VFIO hosts).Tests cover mixed-case log sources and GPU rows with
device_pathonly.Reviewed by Cursor Bugbot for commit 22e9c31. Bugbot is set up for automated code reviews on this repo. Configure here.