Skip to content

CLI: Update Hypeman Go SDK to 134587a222aca6307bb75dd0dbd78bf3f604c114 - #68

Open
kernel-internal[bot] wants to merge 4 commits into
mainfrom
cli-coverage-update
Open

kernel-internal[bot] wants to merge 4 commits into
mainfrom
cli-coverage-update

Conversation

@kernel-internal

@kernel-internal kernel-internal Bot commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

This PR updates the Hypeman Go SDK dependency to the latest version.

SDK Update

  • Updated hypeman-go to 134587a222aca6307bb75dd0dbd78bf3f604c114

Coverage Analysis

A full enumeration of SDK methods and CLI commands was performed. No coverage gaps were found.

All 63 endpoints in api.md have a CLI command. client.Instances.Logs and client.Builds.Events are consumed through their streaming variants (LogsStreaming in hypeman logs, EventsStreaming in hypeman build), and client.Instances.Get, client.Instances.Stat, client.Volumes.NewFromArchive and client.Health.Check remain internal as documented. The method surface is unchanged from the previously pinned SDK: both versions report configured_endpoints: 63 and an identical method list.

Heads up: this SDK bump reduces the generated API surface

The previous pin, e6c2b7b, is on the SDK's next branch, not main. 134587a is a main commit carrying the 2026-09-30 vulnerability remediation, so it does not include the "Windows hypervisor primitives" generation from next. Two symbols the branch depended on no longer exist, which broke the build:

Removed symbol Used by Added in
InstanceLogsParamsSourceSwtpm hypeman logs --source swtpm 4ad8ab1
InstanceGPU.DevicePath formatGPU in hypeman ps b73f664

openapi.yaml on main still specifies both (source enum is [app, vmm, hypeman, swtpm], and device_path is on the GPU schema), so the API supports them and only the generated bindings lag. Rather than regress two shipped features, this PR reaches them without the generated types:

  • source is a string-backed enum, so a local instanceLogsSourceSwtpm constant serializes identically. Verified against a test server: --source swtpm sends source=swtpm.
  • device_path arrives in JSON.ExtraFields, so formatGPU decodes it from there. Note that respjson.Field.Valid() reports false for extra fields, so the raw JSON is decoded instead.

Both are commented at the call site and should go back to typed access once next merges to main.

Also included is a merge of main into this branch (commit 5774c56), resolving a go.sum conflict. History was preserved rather than rebased, so no force push was needed.

Triggered by: kernel/hypeman-go@134587a
Reviewer: @ulziibay-kernel


Note

Low Risk
Mostly dependency pins and small CLI shims for untyped API fields; behavior is covered by new unit tests with no auth or data-path changes.

Overview
Pins hypeman-go to 134587a (main) and refreshes docker/docker plus go.sum as part of the dependency update.

The newer SDK no longer generates InstanceLogsParamsSourceSwtpm or InstanceGPU.DevicePath, even though the API still supports them. This PR keeps those behaviors in the CLI without waiting on regenerated types:

hypeman logs documents swtpm as a --source option, validates sources case-insensitively via parseInstanceLogsSource, and uses a local instanceLogsSourceSwtpm constant where the SDK constant is missing.

hypeman ps still shows vgpu when a GPU has no profile by treating device_path from JSON.ExtraFields the same as mdev_uuid (VFIO hosts).

Tests cover mixed-case log sources and GPU rows with device_path only.

Reviewed by Cursor Bugbot for commit 22e9c31. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps github.com/kernel/hypeman-go to
v0.28.1-0.20260902045311-0872a65a3733, which integrates vendor VFIO
vGPUs into the instance lifecycle.

The SDK now documents InstanceGPU.MdevUuid as populated on mdev hosts
only, and adds InstanceGPU.DevicePath for the sysfs path of an assigned
vGPU device. `hypeman ps` gated its GPU column on MdevUuid alone, so an
instance with a vendor VFIO vGPU and no profile name rendered as "-".
formatGPU now also checks DevicePath.

A full enumeration of api.md methods and CLI commands found no other
coverage gaps: every SDK method has a CLI command and every param field
has a corresponding flag.

Co-authored-by: Cursor <cursoragent@cursor.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update hypeman SDK to 0872a65a3733c6bfcc7449222cc4bd28bba43807 and add new commands/flags CLI: Update Hypeman Go SDK to 0872a65a3733c6bfcc7449222cc4bd28bba43807 Sep 2, 2026
Bumps github.com/kernel/hypeman-go to
v0.28.1-0.20260902143136-e6c2b7bc0171, which adds the "swtpm" value to
InstanceLogsParamsSource as part of the Windows hypervisor primitives.

Teaches `hypeman logs --source` about swtpm and validates the flag up
front instead of forwarding an arbitrary string to the API, matching the
parseInstanceWaitState / parseSnapshotTargetHypervisor pattern.

Co-authored-by: Cursor <cursoragent@cursor.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update Hypeman Go SDK to 0872a65a3733c6bfcc7449222cc4bd28bba43807 CLI: Update hypeman SDK to e6c2b7bc0171807b2c891a26e9ab4f4bb786072b and add new commands/flags Sep 2, 2026
kernel-internal Bot and others added 2 commits October 1, 2026 16:10
Co-authored-by: Cursor <cursoragent@cursor.com>

# Conflicts:
#	go.sum
Bumps github.com/kernel/hypeman-go to
v0.28.1-0.20261001160305-134587a222ac, which carries the SDK's 2026-09-30
vulnerability remediation.

This commit is on main, whereas the branch previously pinned e6c2b7b from
the SDK's next branch. The Windows hypervisor primitives generated there
are therefore absent, dropping InstanceLogsParamsSourceSwtpm and
InstanceGPU.DevicePath. Both values are still specified by the API, so
rather than regress `hypeman logs --source swtpm` and the vendor VFIO
vGPU column in `hypeman ps`, read them without the generated bindings:
the log source is a string-backed enum, and device_path arrives in
JSON.ExtraFields. Both can go back to typed access once next lands on
main.

Co-authored-by: Cursor <cursoragent@cursor.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update hypeman SDK to e6c2b7bc0171807b2c891a26e9ab4f4bb786072b and add new commands/flags CLI: Update Hypeman Go SDK to 134587a222aca6307bb75dd0dbd78bf3f604c114 Oct 1, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 22e9c31. Configure here.

Comment thread go.mod
github.com/charmbracelet/lipgloss v1.1.0
github.com/charmbracelet/x/term v0.2.1
github.com/docker/docker v28.5.2+incompatible
github.com/docker/docker v28.5.3-0.20260325120914-0afb41ce194c+incompatible

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Insufficient docker dependency pin

Medium Severity

go.mod now pins github.com/docker/docker to a pseudo-version instead of upgrading go-containerregistry. That keeps the old docker client on the graph, so a pin in this range may not include the docker cp fix for GHSA-rg2x-37c3-w2rh.

Fix in Cursor Fix in Web

Triggered by learned rule: Prefer upgrading go-containerregistry over docker/docker replace pins

Reviewed by Cursor Bugbot for commit 22e9c31. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants