Skip to content

NO-JIRA: chore: bump golangci-lint to v2.13.1 - #393

Merged
openshift-merge-bot[bot] merged 1 commit into
mainfrom
chore/bump-golangci-lint
Aug 27, 2026
Merged

openshift-merge-bot[bot] merged 1 commit into
mainfrom
chore/bump-golangci-lint

Conversation

@jmelis

@jmelis jmelis commented Aug 27, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Bumps golangci-lint to v2.13.1 and the gofmt digest it requires, folding in the linter-ecosystem Renovate PRs (#375, #379, #363, #367, #373).

The new golangci-lint ships a stricter staticcheck that flags SA1019 for the deprecated ctrl.Result{Requeue: true} (controller-runtime). This PR fixes the four usages:

  • Finalizer-add sites (cluster, manifest, nodepool controllers): return an empty ctrl.Result{}. The finalizer Update emits a watch event that re-enqueues the object (the controllers use For(&T{}) with no predicates), so no explicit requeue is needed — this is the idiomatic controller-runtime pattern.
  • Placement AlreadyExists site: the Create failed so no watch event is emitted; requeue explicitly with RequeueAfter: 5 * time.Second (matching the existing convention in these controllers).

The three finalizer unit tests are updated to assert no explicit requeue instead of the deprecated Requeue field.

Test plan

  • make build ✅
  • make lint — 0 issues across all modules (previously 4 SA1019 findings, 3 hidden by max-same-issues) ✅
  • make test — full suite green ✅

Closes / supersedes

Covers the golangci-lint-ecosystem Renovate PRs: #375, #379, #363, #367, #373.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Improvements

    • Improved resource reconciliation efficiency by avoiding unnecessary immediate retries after setup actions complete.
    • Added a controlled five-second retry interval when placement creation encounters an existing resource, reducing rapid retry cycles.
  • Maintenance

    • Updated development linting and code-quality tooling to newer versions.
  • Tests

    • Updated reconciliation coverage to reflect the improved retry behavior and retry timing.

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Aug 27, 2026
@openshift-ci-robot

Copy link
Copy Markdown
Collaborator

@jmelis: This pull request explicitly references no jira issue.

Details

In response to this:

Summary

Bumps golangci-lint to v2.13.1 and the gofmt digest it requires, folding in the linter-ecosystem Renovate PRs (#375, #379, #363, #367, #373).

The new golangci-lint ships a stricter staticcheck that flags SA1019 for the deprecated ctrl.Result{Requeue: true} (controller-runtime). This PR fixes the four usages:

  • Finalizer-add sites (cluster, manifest, nodepool controllers): return an empty ctrl.Result{}. The finalizer Update emits a watch event that re-enqueues the object (the controllers use For(&T{}) with no predicates), so no explicit requeue is needed — this is the idiomatic controller-runtime pattern.
  • Placement AlreadyExists site: the Create failed so no watch event is emitted; requeue explicitly with RequeueAfter: 5 * time.Second (matching the existing convention in these controllers).

The three finalizer unit tests are updated to assert no explicit requeue instead of the deprecated Requeue field.

Test plan

  • make build ✅
  • make lint — 0 issues across all modules (previously 4 SA1019 findings, 3 hidden by max-same-issues) ✅
  • make test — full suite green ✅

Closes / supersedes

Covers the golangci-lint-ecosystem Renovate PRs: #375, #379, #363, #367, #373.

🤖 Generated with Claude Code

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 27, 2026
@coderabbitai

coderabbitai Bot commented Aug 27, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: openshift-online/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 7b0d9943-6613-4905-b8e8-050c3dd62b53

📥 Commits

Reviewing files that changed from the base of the PR and between 2aac06e and 22b2216.

⛔ Files ignored due to path filters (1)
  • hack/tools/go.sum is excluded by !**/*.sum
📒 Files selected for processing (1)
  • hack/tools/go.mod

Included review availability: Your plan provides up to 12 included reviews per hour; 10 remain after this review.


Walkthrough

The controllers now rely on finalizer update watch events instead of explicit requeues. Placement retries AlreadyExists errors after five seconds. Go linting tool dependencies are updated.

Changes

Controller reconciliation behavior

Layer / File(s) Summary
Finalizer watch-based requeueing
hyperfleet-operator/internal/controller/*controller.go, hyperfleet-operator/internal/controller/*controller_test.go
Cluster, Manifest, and NodePool reconciliation no longer explicitly requeues after finalizer updates. Tests verify the updated result.
Placement retry delay
hyperfleet-operator/internal/controller/placement_controller.go
Placement creation retries after five seconds when it returns AlreadyExists.

Go linting toolchain updates

Layer / File(s) Summary
Linting dependency refresh
hack/tools/go.mod
The direct golangci-lint dependency and related indirect linting and analysis modules are updated. Exhaustruct is added.

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to 22b22

The dependency and lint configuration updates are localized, with no actionable merge-blocking risk remaining beyond normal checks and review.

Suggested reviewers: typeid

🚥 Pre-merge checks | ✅ 10 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Ai-Attribution ⚠️ Warning AI use is explicit: the PR description says it was generated with Claude Code, and the sole PR commit contains Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>. The PR commit range has no `As… Amend the PR commit message to remove Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> and add the required Assisted-by: or Generated-by: trailer for the AI tool.
✅ Passed checks (10 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the primary change: upgrading golangci-lint to v2.13.1. This matches the main pull request objective.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 7…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No-Weak-Crypto ✅ Passed PASS: The pull-request diff adds no MD5, SHA1, DES, RC4, 3DES, Blowfish, ECB, custom crypto, or secret-comparison code. The changed Go files only modify reconciliation results and add a time import. E…
Container-Privileges ✅ Passed PASS. The pull request changes only Go module files and Go controller/test files. It adds no Kubernetes or container manifest files, and no added line contains privileged, hostPID, hostNetwork, hostIP…
No-Sensitive-Data-In-Logs ✅ Passed No logging changes were introduced. The diff changes requeue behavior, tests, imports, and tooling dependencies only. Existing controller log calls and fields remain unchanged, and no added line logs …
No-Hardcoded-Secrets ✅ Passed No hardcoded secret was introduced. The application changes add only controller comments, ctrl.Result values, and the time import. No added line contains credential assignments, PEM material, or U…
No-Injection-Vectors ✅ Passed PASS. The pull-request diff only updates Go lint-tool dependencies and controller requeue behavior/tests. Focused searches of all changed source files found no SQL concatenation, shell=True, eval/exec…
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 7 files. (1 skipped: 1 unsupported.)

Full details: No-Weak-Crypto

Explanation

PASS: The pull-request diff adds no MD5, SHA1, DES, RC4, 3DES, Blowfish, ECB, custom crypto, or secret-comparison code. The changed Go files only modify reconciliation results and add a time import. Existing SHA-1 code in hyperfleet-operator/internal/oidc/infra.go is unchanged. Dependency changes are linter-toolchain updates and add no weak-crypto package declaration.

Full details: Container-Privileges

Explanation

PASS. The pull request changes only Go module files and Go controller/test files. It adds no Kubernetes or container manifest files, and no added line contains privileged, hostPID, hostNetwork, hostIPC, SYS_ADMIN, or allowPrivilegeEscalation settings. Existing manifests show restrictive settings such as runAsNonRoot: true and allowPrivilegeEscalation: false; they are unchanged.

Full details: No-Sensitive-Data-In-Logs

Explanation

No logging changes were introduced. The diff changes requeue behavior, tests, imports, and tooling dependencies only. Existing controller log calls and fields remain unchanged, and no added line logs passwords, tokens, API keys, PII, session IDs, hostnames, or customer data.

Full details: No-Hardcoded-Secrets

Explanation

No hardcoded secret was introduced. The application changes add only controller comments, ctrl.Result values, and the time import. No added line contains credential assignments, PEM material, or URLs with embedded credentials. The 38 long base64-like additions are valid go.sum h1: dependency checksums, not configuration values.

Full details: No-Injection-Vectors

Explanation

PASS. The pull-request diff only updates Go lint-tool dependencies and controller requeue behavior/tests. Focused searches of all changed source files found no SQL concatenation, shell=True, eval/exec on untrusted data, pickle.loads, yaml.load without SafeLoader, os.system with variables, or dangerouslySetInnerHTML with user data. The repository-wide exec.Command matches are pre-existing Go test/tooling code and are not introduced by this pull request.

Full details: Ai-Attribution

Explanation

AI use is explicit: the PR description says it was generated with Claude Code, and the sole PR commit contains Co-Authored-By: Claude Opus 4.8 &lt;noreply@anthropic.com&gt;. The PR commit range has no Assisted-by or Generated-by trailer. This violates the check because AI attribution is required and Co-Authored-By is disallowed for AI tools.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/bump-golangci-lint

Warning

Some tools did not complete. Review the errors below.

🔧 golangci-lint (2.12.2)

level=error msg="Running error: context loading failed: no go files to analyze: running go mod tidy may solve the problem"


Comment @coderabbitai help to get the list of available commands.

Bumps golangci-lint to v2.13.1 (with the gofmt digest it requires),
which ships a stricter staticcheck that flags SA1019 for the deprecated
ctrl.Result{Requeue: true}.

Replaces the four usages:
- Finalizer-add sites (cluster, manifest, nodepool): return an empty
  ctrl.Result{}. The finalizer Update emits a watch event that
  re-enqueues the object, so no explicit requeue is needed.
- Placement AlreadyExists site: the Create failed so no watch event is
  emitted; requeue explicitly with RequeueAfter: 5s.

Updates the three finalizer unit tests to assert no explicit requeue
instead of the deprecated Requeue field.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@jmelis
jmelis force-pushed the chore/bump-golangci-lint branch from 2aac06e to 22b2216 Compare August 27, 2026 12:36
@psav

psav commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Aug 27, 2026
@openshift-ci

openshift-ci Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: jmelis, psav

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants