Skip to content

Convert SCC annotation tests to dynamic subtests - #5968

Open
OhadRevah wants to merge 1 commit into
RedHatQE:mainfrom
OhadRevah:optimizeDeploymentRequiredScc
Open

Convert SCC annotation tests to dynamic subtests#5968
OhadRevah wants to merge 1 commit into
RedHatQE:mainfrom
OhadRevah:optimizeDeploymentRequiredScc

Conversation

@OhadRevah

@OhadRevah OhadRevah commented Aug 11, 2026

Copy link
Copy Markdown
Contributor
What this PR does / why we need it:

Combine test_deployments_missing_required_scc_annotation and test_deployments_with_incorrect_required_scc into a single test using subtests over discovered_cnv_deployments. Remove the required_scc_deployment_check fixture.

Xfail virt-template deployments while CNV-94717 is open.

This is part of the effort for stabilizing the 5.0 DS and rhcos lanes.
assisted by: claude code claude-opus-4-6

Which issue(s) this PR fixes:
Special notes for reviewer:
jira-ticket:

Summary by CodeRabbit

  • Tests
    • Improved validation of required security settings across all discovered CNV deployments.
    • Added coverage for deployment-specific configurations, including handling for known exceptions.
    • Replaced fixed deployment lists and aggregate checks with targeted per-deployment validation.
    • Added automatic discovery of applicable deployments to improve test coverage as deployments change.

@openshift-virtualization-qe-bot-6

Copy link
Copy Markdown

Report bugs in Issues

Welcome! 🎉

This pull request will be automatically processed with the following features:

🔄 Automatic Actions

  • Reviewer Assignment: Reviewers are automatically assigned based on the OWNERS file in the repository root
  • Size Labeling: PR size labels (XS, S, M, L, XL, XXL) are automatically applied based on changes
  • Issue Creation: A tracking issue is created for this PR and will be closed when the PR is merged or closed
  • Branch Labeling: Branch-specific labels are applied to track the target branch
  • Auto-verification: Auto-verified users have their PRs automatically marked as verified
  • Labels: Enabled categories: branch, can-be-merged, cherry-pick, has-conflicts, hold, needs-rebase, size, verified, wip

📋 Available Commands

PR Status Management

  • /wip - Mark PR as work in progress (adds WIP: prefix to title)
  • /wip cancel - Remove work in progress status
  • /hold - Block PR merging (PR author or approvers)
  • /hold cancel - Unblock PR merging (PR author or approvers)
  • /verified - Mark PR as verified
  • /verified cancel - Remove verification status
  • /reprocess - Trigger complete PR workflow reprocessing (useful if webhook failed or configuration changed)
  • /regenerate-welcome - Regenerate this welcome message
  • /security-override - Set security check runs to pass (maintainers only)
  • /security-override cancel - Re-run security checks

Review & Approval

  • /lgtm - Approve changes (looks good to me)
  • /approve - Approve PR (approvers only)
  • /assign-reviewers - Assign reviewers based on OWNERS file
  • /assign-reviewer @username - Assign specific reviewer
  • /check-can-merge - Check if PR meets merge requirements

Testing & Validation

  • /retest tox - Run Python test suite with tox
  • /retest build-container - Rebuild and test container image
  • /retest verify-bugs-are-open - verify-bugs-are-open
  • /retest all - Run all available tests

Container Operations

  • /build-and-push-container - Build and push container image (tagged with PR number)
    • Supports additional build arguments: /build-and-push-container --build-arg KEY=value

Cherry-pick Operations

  • /cherry-pick <branch> - Schedule cherry-pick to target branch when PR is merged
    • Multiple branches: /cherry-pick branch1 branch2 branch3
  • /cherry-pick-retry <branch> - Retry a failed cherry-pick (merged PRs only)

Branch Management

  • /rebase - Rebase this PR branch onto its base branch

Label Management

  • /<label-name> - Add a label to the PR
  • /<label-name> cancel - Remove a label from the PR

✅ Merge Requirements

This PR will be automatically approved when the following conditions are met:

  1. Approval: /approve from at least one approver
  2. LGTM Count: Minimum 2 /lgtm from reviewers
  3. Status Checks: All required status checks must pass
  4. No Blockers: No wip, hold, has-conflicts labels and PR must be mergeable (no conflicts)
  5. Verified: PR must be marked as verified

📊 Review Process

Approvers and Reviewers

Approvers:

  • dshchedr
  • myakove
  • rnetser
  • vsibirsk

Reviewers:

  • OhadRevah
  • RoniKishner
  • albarker-rh
  • dshchedr
  • hmeir
  • rlobillo
  • rnetser
  • vsibirsk
Available Labels
  • hold
  • verified
  • wip
  • lgtm
  • approve
AI Features
  • Cherry-Pick Conflict Resolution: Enabled (claude/claude-opus-4-6-1m)
Security Checks
  • Suspicious Path Detection: Monitors paths: .claude/, .vscode/, .cursor/, .devcontainer/, .pi/, .github/workflows/, .github/actions/
  • Committer Identity Check: Verifies last committer matches PR author
  • Mandatory: Security checks block merge (use /security-override to bypass — maintainers only)

💡 Tips

  • WIP Status: Use /wip when your PR is not ready for review
  • Verification: The verified label is removed on new commits unless the push is detected as a clean rebase
  • Cherry-picking: Cherry-pick labels are processed when the PR is merged
  • Container Builds: Container images are automatically tagged with the PR number
  • Permission Levels: Some commands require approver permissions
  • Auto-verified Users: Certain users have automatic verification and merge privileges

📌 Additional Information

Custom Commands:

  • /test-plan — Triggers CodeRabbit to analyze the PR's changed files and post a test execution plan
  • /rerun-smoke — Adds retest-smoke label on the PR to trigger smoke tests execution

For more information, please refer to the project documentation or contact the maintainers.

@coderabbitai

coderabbitai Bot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 529216d2-b0b5-403a-88c5-3e1546ecbf39

📥 Commits

Reviewing files that changed from the base of the PR and between 2ed3c57 and 866985c.

📒 Files selected for processing (2)
  • tests/install_upgrade_operators/conftest.py
  • tests/install_upgrade_operators/security/scc/test_cnv_deployment_required_scc.py
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • RedHatQE/openshift-virtualization-tests-design-docs (manual)

📝 Walkthrough

Walkthrough

Changes

CNV SCC validation

Layer / File(s) Summary
Deployment discovery
tests/install_upgrade_operators/conftest.py
Adds a session-scoped fixture that discovers CNV deployments in the HCO namespace by label.
Per-deployment SCC validation
tests/install_upgrade_operators/security/scc/test_cnv_deployment_required_scc.py
Validates the restricted-v2 SCC annotation for each discovered deployment. HPP deployments are skipped, and virt-template deployments are conditionally xfailed while CNV-94717 is open.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested labels: new-tests

Suggested reviewers: hmeir, rnetser, vsibirsk


Caution

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

  • Ignore

❌ Failed checks (1 error)

Check name Status Explanation Resolution
Stp Link Required ❌ Error The diff adds test_deployment_required_scc, but its module and function docstrings contain no STP:, RFE:, or Jira: URL; the Polarion marker does not satisfy the check. HIGH: Add a docstring line such as STP: https://... or RFE: https://... to the module or test function. Do not use an unmarked Jira: traceability line.
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title is 48 characters and clearly describes the conversion of SCC annotation tests to dynamic subtests.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Pr Template Sections ✅ Passed The live PR body includes all four required headings, and the What/why section contains meaningful change and stabilization details.
Stp Scenario Coverage ✅ Passed PASS: The changed test has no STP:, Jira:, or RFE: URL in its module, class, or test docstring; the only Jira mention is code-level CNV-94717 handling.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In
`@tests/install_upgrade_operators/security/scc/test_cnv_deployment_required_scc.py`:
- Around line 18-19: Add an assertion in test_deployment_required_scc before
iterating over discovered_cnv_deployments to require at least one discovered
deployment. Preserve the existing per-deployment subtest loop while ensuring an
empty discovery result fails the test.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 6be017c4-5627-43e2-ae72-4713b3632433

📥 Commits

Reviewing files that changed from the base of the PR and between 718a778 and 2ed3c57.

📒 Files selected for processing (2)
  • tests/install_upgrade_operators/conftest.py
  • tests/install_upgrade_operators/security/scc/test_cnv_deployment_required_scc.py
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • RedHatQE/openshift-virtualization-tests-design-docs (manual)

@OhadRevah

Copy link
Copy Markdown
Contributor Author

/build-and-push-container

@openshift-virtualization-qe-bot-2

Copy link
Copy Markdown
Contributor

New container for quay.io/openshift-cnv/openshift-virtualization-tests:pr-5968 published

@openshift-virtualization-qe-bot

Copy link
Copy Markdown

/build-and-push-container

1 similar comment
@openshift-virtualization-qe-bot

Copy link
Copy Markdown

/build-and-push-container

@openshift-virtualization-qe-bot-6

Copy link
Copy Markdown

New container for quay.io/openshift-cnv/openshift-virtualization-tests:pr-5968 published

1 similar comment
@openshift-virtualization-qe-bot-6

Copy link
Copy Markdown

New container for quay.io/openshift-cnv/openshift-virtualization-tests:pr-5968 published

@openshift-virtualization-qe-bot

Copy link
Copy Markdown

/verified

All tests passed for PR #5968.
Job: openshift-virtualization-tests-runner #6128

Execution details
pytest tests/install_upgrade_operators/security/scc/test_cnv_deployment_required_scc.py -s -o log_cli=true -m tier2 --jira
Image: openshift-virtualization-tests:pr-5968

@openshift-virtualization-qe-bot

Copy link
Copy Markdown

/verified

All tests passed for PR #5968.
Job: openshift-virtualization-tests-runner #6127

Execution details
pytest tests/install_upgrade_operators/security/scc/test_cnv_deployment_required_scc.py -s -o log_cli=true -m tier2 --jira
Image: openshift-virtualization-tests:pr-5968

@openshift-virtualization-qe-bot-3

Copy link
Copy Markdown
Contributor

@coderabbitai

Test execution plan request details

CRITICAL: You MUST post an inline review comment on the first changed line of the first file.
The inline comment should contain the full Test Execution Plan (smoke decision, gating decision, and specific affected tests).
Do NOT submit a blocking review event (REQUEST_CHANGES/APPROVE).
Post a single inline PR comment on Files Changed (non-blocking COMMENT flow).

As an expert software testing engineer, analyze all modified files in this PR and create a targeted test execution plan.
You will post an inline review comment with the test execution plan on the first changed file.
If you fail to run or post a comment, retry.

Analysis Requirements:

  1. Examine code changes in each modified file

  2. Identify affected code paths, functions, and classes

  3. Analyze pytest-specific elements: fixtures (scope, dependencies), parametrization, markers, conftest changes

  4. Trace test dependencies through imports, shared utilities, fixture inheritance, fixture teardown, and yield from cleanup in conftest

  5. Detect new tests introduced in the PR

  6. Utilities and libs impact (when utilities/ or libs/ changes):
    You MUST use shell scripts (rg, git diff) to trace the full impact.
    Follow these sub-steps in order:

    6a. Identify modified symbols: For each changed file under utilities/ or libs/,
    list every modified function or method.
    Example: git diff HEAD~1 --unified=0 -- utilities/hco.py | grep '^[+-]def '

    6b. Find direct callers: Search tests and conftest for each symbol from 6a.
    Example: rg -l 'get_hco_version' tests/

    6c. Trace fixture teardown and cleanup: Find fixtures that reach
    the modified symbol through yield from or context-manager wrappers.
    Example: rg -l 'yield from.*enable_common_boot|def.*enable_common_boot' tests/

    6d. Trace same-file callers: In each changed file, find other functions
    whose body calls a modified symbol (including code after yield
    in @contextmanager helpers).
    Example: rg 'get_hco_version|enable_common_boot' utilities/hco.py

    6e. Expand transitively: If function A calls modified B, then
    tests/fixtures that call A are affected — even when the test body
    never imports B directly.

    Do NOT limit impact to tests that import the modified symbol only.

  7. Smoke test impact: Intersect the affected set from step 6 with smoke-marked tests.
    Run: rg -l '@pytest.mark.smoke' tests/
    VERIFY the above command returned actual file paths before concluding False.
    Set True if either condition is met:

    • a smoke-marked file appears in the affected set from 6b-6e, OR
    • any conftest.py in the smoke test's parent-directory hierarchy (up to repo root)
      imports or calls a modified utilities/libs symbol — including autouse fixtures
      that depend on modified functions. ALL tests in that directory and below are affected.
      Example check: for each smoke_file, scan dirname(smoke_file)/conftest.py,
      dirname(dirname(smoke_file))/conftest.py, etc. for modified symbol imports
      and autouse fixtures that depend on modified symbols.
  8. Gating test impact: Intersect the affected set from step 6 with gating-marked tests.
    Run: rg -l '@pytest.mark.gating' tests/
    Set True if a gating-marked file also appears in the affected set from 6b-6e.
    Utilities/libs changes often affect gating tests without affecting smoke tests.
    Do NOT stop analysis after concluding Run smoke tests: False.

Output rules:
Do NOT include analysis step numbers (1-8) in your visible output.

Your deliverable:
Your inline informational comment will be based on the following requirements:

Test Execution Plan

  • Run smoke tests: True / False — If True, state the dependency path (test → fixture → changed symbol). True ONLY with a verified path.
  • Run gating tests: True / False — If True, state the dependency path. True if any gating-marked test is in the affected set.
  • Affected tests to run (required when utilities/, libs/, or shared conftest changes — list concrete paths even when smoke is False)

Use these formats:

  • path/to/test_file.py - When the entire test file needs verification
  • path/to/test_file.py::TestClass::test_method - When specific test(s) needed
  • path/to/test_file.py::test_function - When specific test(s) needed
  • -m marker - When a marker covers multiple affected tests (e.g. -m gating only if ALL gating tests in scope need run)
  • Tag each listed test or group with its marker when not obvious, e.g. (gating) or (smoke)

Real test commands (MANDATORY when changes affect session/runtime code):

When the affected code runs at session/collection time (conftest fixtures, pytest plugins,
config hooks, session-scoped setup) or modifies runtime behavior that unit tests mock away,
you MUST include concrete pytest commands the PR author must run on a real cluster
to verify the change works end-to-end. Include:

  • A command for the error/fix path (the scenario the PR fixes)
  • A command for the happy path (regression: the normal case still works)
  • Use lightweight tests (e.g., --collect-only for startup failures,
    a single small test for runtime behavior)
    If the PR only changes test logic (not utilities/libs/conftest), the affected test
    paths themselves serve as the real test commands — no separate section needed.

Example output for a session-startup fix:

**Real tests (cluster required)**
Error path (the fix):
`pytest tests/storage/.../test_foo.py --storage-class-matrix=nonexistent-sc --collect-only`
Expected: ValueError with clear message, not IndexError

Happy path (regression):
`pytest tests/storage/.../test_foo.py --storage-class-matrix=<valid-sc> -k test_bar`
Expected: session starts normally

Guidelines:

  • Include tests affected directly OR via fixture setup/teardown, yield from cleanup, or transitive utility call chains (caller calls modified helper)
  • Use a full file path only if ALL tests in that file require verification
  • Use file path + test name when only specific tests use an affected fixture or utility wrapper (preferred for partial file impact)
  • If a test marker can cover multiple files/tests, provide the marker
  • Balance coverage vs over-testing - Keep descriptions minimal
  • Example: if leaf helper foo() changes, include tests whose fixture teardown calls wrapper bar() where bar() calls foo(), even when the test body only imports an unrelated symbol from the same utilities module

Hardware-Related Checks (SR-IOV, GPU, DPDK):

When PR modifies fixtures for hardware-specific resources:

  • Collection Safety: Fixtures MUST have existence checks (return None when hardware unavailable)
  • Test Plan: MUST verify both WITH and WITHOUT hardware:
    • Run affected tests on cluster WITH hardware
    • Verify collection succeeds on cluster WITHOUT hardware

CRITICAL WORKFLOW COMPLETION RULES:

When responding to this test execution plan request, you MUST follow these rules EXACTLY:

  1. YOUR ONLY DELIVERABLE: Post one non-blocking inline comment containing the test execution plan on the first changed line
  2. THEN STOP IMMEDIATELY - Do NOT generate any additional response
  3. FALLBACK ONLY: If inline comment API calls fail after retrying, post as a regular PR comment
  4. SILENCE = SUCCESS: After successfully submitting the review, your task is complete. No confirmation needed.

ABSOLUTE PROHIBITIONS (violating these creates empty/meaningless reviews):

  • ❌ Do NOT post acknowledgment messages like "Test execution plan posted", "Review posted successfully", "I've successfully posted"
  • ❌ Do NOT mention review IDs, URLs, or confirmation of posting in the PR thread
  • ❌ Do NOT add any follow-up comments after submitting the review
  • ❌ Do NOT reply to confirm task completion
  • ❌ Do NOT explain what you did - just do it and stop

Remember: The pull request review is visible to users. Additional comments are redundant noise.

CRITICAL — Verification rules for smoke and gating decisions:
- For each True decision, you must have traced a concrete path: test file → fixture → utility function → modified symbol.
- Do NOT assume impact based on scope, file proximity, or infrastructure-sounding names.
Only set True when you trace a concrete path through steps 6a-6e, then 7 or 8.
WRONG: "utilities/hco.py changed → run smoke" (no traced dependency path)
WRONG: "Run smoke tests: False" with no affected-test list when gating tests use the changed utility
RIGHT: "Run smoke tests: False, Run gating tests: True" plus tests/.../test_foo.py::TestBar::test_baz (gating)
RIGHT: "Smoke test X uses fixture Y → wrapper Z → changed function W in utilities/hco.py"

Comment thread tests/install_upgrade_operators/conftest.py Outdated
@coderabbitai

coderabbitai Bot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '=== PR metadata and changed files ==='
gh pr view 5968 --json baseRefName,headRefName,files --jq '.baseRefName, .headRefName, (.files[] | "\(.path) +\(.additions) -\(.deletions)")'

echo '=== Diff with zero context ==='
gh pr diff 5968 --unified=0 -- \
  tests/install_upgrade_operators/conftest.py \
  tests/install_upgrade_operators/security/scc/test_cnv_deployment_required_scc.py

echo '=== Outline: changed files ==='
ast-grep outline tests/install_upgrade_operators/conftest.py --items all
ast-grep outline tests/install_upgrade_operators/security/scc/test_cnv_deployment_required_scc.py --items all

echo '=== Fixture and test consumers ==='
rg -n -C 4 '\bdiscovered_cnv_deployments\b|\bget_deployments\b|\btest_deployment_required_scc\b' tests

echo '=== SCC test markers and fixture context ==='
rg -n -C 5 '`@pytest`\.mark|def test_|def [A-Za-z_][A-Za-z0-9_]*\(' \
  tests/install_upgrade_operators/security/scc/test_cnv_deployment_required_scc.py

echo '=== Smoke-marked test files ==='
rg -l '`@pytest`\.mark\.smoke' tests || true

echo '=== Gating-marked test files ==='
rg -l '`@pytest`\.mark\.gating' tests || true

echo '=== Parent conftest files and references ==='
for f in \
  tests/conftest.py \
  tests/install_upgrade_operators/conftest.py \
  tests/install_upgrade_operators/security/conftest.py \
  tests/install_upgrade_operators/security/scc/conftest.py
do
  if [ -f "$f" ]; then
    echo "--- $f ---"
    rg -n -C 3 '\bdiscovered_cnv_deployments\b|\bget_deployments\b|`@pytest`\.fixture|yield' "$f" || true
  fi
done

Length of output: 2728


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '=== PR head SHA and changed-file patches ==='
gh pr view 5968 --json headRefOid --jq '.headRefOid'
gh api --paginate 'repos/RedHatQE/openshift-virtualization-tests/pulls/5968/files?per_page=100' \
  --jq '.[] | "=== \(.filename) ===\n\(.patch // "(patch unavailable)")"'

echo '=== Outline: changed files ==='
ast-grep outline tests/install_upgrade_operators/conftest.py --items all
ast-grep outline tests/install_upgrade_operators/security/scc/test_cnv_deployment_required_scc.py --items all

echo '=== Fixture and test consumers ==='
rg -n -C 5 '\bdiscovered_cnv_deployments\b|\bget_deployments\b|\btest_deployment_required_scc\b' tests

echo '=== SCC test markers and fixture context ==='
rg -n -C 5 '`@pytest`\.mark|def test_|def [A-Za-z_][A-Za-z0-9_]*\(' \
  tests/install_upgrade_operators/security/scc/test_cnv_deployment_required_scc.py

echo '=== Smoke-marked test files ==='
rg -l '`@pytest`\.mark\.smoke' tests || true

echo '=== Gating-marked test files ==='
rg -l '`@pytest`\.mark\.gating' tests || true

echo '=== Parent conftest files and fixture dependencies ==='
for f in \
  tests/conftest.py \
  tests/install_upgrade_operators/conftest.py \
  tests/install_upgrade_operators/security/conftest.py \
  tests/install_upgrade_operators/security/scc/conftest.py
do
  if [ -f "$f" ]; then
    echo "--- $f ---"
    rg -n -C 4 '\bdiscovered_cnv_deployments\b|\bget_deployments\b|\bhco_namespace\b|\badmin_client\b|`@pytest`\.fixture|yield' "$f" || true
  fi
done

Length of output: 99561


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo="RedHatQE/openshift-virtualization-tests"
pr="5968"
head_sha="3e81247c2eed90396bf1f8a56216f3fefb135a00"
path="tests/install_upgrade_operators/conftest.py"
line="40"

body=$(cat <<'EOF'
## Test Execution Plan

- **Run smoke tests: False**. `discovered_cnv_deployments` has one consumer: `tests/install_upgrade_operators/security/scc/test_cnv_deployment_required_scc.py::test_deployment_required_scc`. The fixture is not autouse. No smoke-marked test consumes it.
- **Run gating tests: False**. No gating-marked test consumes `discovered_cnv_deployments`.

**Affected tests to run**
- `tests/install_upgrade_operators/security/scc/test_cnv_deployment_required_scc.py::test_deployment_required_scc` (`s390x`, `skip_must_gather_collection`, Polarion `CNV-11964`)

**Real tests (cluster required)**

Error path: On an s390x cluster with a discovered non-HPP CNV deployment that has a missing or incorrect `openshift.io/required-scc` annotation, run:
`pytest tests/install_upgrade_operators/security/scc/test_cnv_deployment_required_scc.py -s -o log_cli=true -m tier2 --jira`
Expected: pytest reports a failed subtest with the deployment name and the missing or incorrect annotation value. If CNV-94717 is open, `virt-template-apiserver` and `virt-template-controller` report expected failures instead.

Happy path: On an s390x cluster where all non-exempt discovered CNV deployments have `openshift.io/required-scc=restricted-v2`, run:
`pytest tests/install_upgrade_operators/security/scc/test_cnv_deployment_required_scc.py -s -o log_cli=true -m tier2 --jira`
Expected: the test passes. The test verifies every deployment returned from the HCO namespace, and excludes HPP deployments.
EOF
)

payload=$(jq -n \
  --arg body "$body" \
  --arg commit_id "$head_sha" \
  --arg path "$path" \
  --argjson line "$line" \
  '{body: $body, commit_id: $commit_id, path: $path, line: $line, side: "RIGHT"}')

for attempt in 1 2; do
  if gh api --method POST "repos/$repo/pulls/$pr/comments" --input - <<<"$payload" >/dev/null; then
    exit 0
  fi
  if [ "$attempt" -eq 2 ]; then
    exit 1
  fi
  sleep 2
done

Length of output: 2323


@openshift-virtualization-qe-bot-3: The test execution plan is available as a non-blocking inline PR comment.

You are interacting with an AI system.

Combine test_deployments_missing_required_scc_annotation and
test_deployments_with_incorrect_required_scc into a single test
using subtests over discovered_cnv_deployments. Remove the
required_scc_deployment_check fixture.

Xfail virt-template deployments while CNV-94717 is open.

assisted by: claude code claude-opus-4-6

Signed-off-by: Ohad <orevah@redhat.com>
@openshift-virtualization-qe-bot

Copy link
Copy Markdown

/build-and-push-container

@openshift-virtualization-qe-bot-3

Copy link
Copy Markdown
Contributor

New container for quay.io/openshift-cnv/openshift-virtualization-tests:pr-5968 published

@openshift-virtualization-qe-bot

Copy link
Copy Markdown

/verified

All tests passed for PR #5968.
Job: openshift-virtualization-tests-runner #6134

Execution details
pytest tests/install_upgrade_operators/security/scc/test_cnv_deployment_required_scc.py -s -o log_cli=true -m tier2 --jira
Image: openshift-virtualization-tests:pr-5968

@openshift-virtualization-qe-bot-3

Copy link
Copy Markdown
Contributor

@coderabbitai

Test execution plan request details

CRITICAL: You MUST post an inline review comment on the first changed line of the first file.
The inline comment should contain the full Test Execution Plan (smoke decision, gating decision, and specific affected tests).
Do NOT submit a blocking review event (REQUEST_CHANGES/APPROVE).
Post a single inline PR comment on Files Changed (non-blocking COMMENT flow).

As an expert software testing engineer, analyze all modified files in this PR and create a targeted test execution plan.
You will post an inline review comment with the test execution plan on the first changed file.
If you fail to run or post a comment, retry.

Analysis Requirements:

  1. Examine code changes in each modified file

  2. Identify affected code paths, functions, and classes

  3. Analyze pytest-specific elements: fixtures (scope, dependencies), parametrization, markers, conftest changes

  4. Trace test dependencies through imports, shared utilities, fixture inheritance, fixture teardown, and yield from cleanup in conftest

  5. Detect new tests introduced in the PR

  6. Utilities and libs impact (when utilities/ or libs/ changes):
    You MUST use shell scripts (rg, git diff) to trace the full impact.
    Follow these sub-steps in order:

    6a. Identify modified symbols: For each changed file under utilities/ or libs/,
    list every modified function or method.
    Example: git diff HEAD~1 --unified=0 -- utilities/hco.py | grep '^[+-]def '

    6b. Find direct callers: Search tests and conftest for each symbol from 6a.
    Example: rg -l 'get_hco_version' tests/

    6c. Trace fixture teardown and cleanup: Find fixtures that reach
    the modified symbol through yield from or context-manager wrappers.
    Example: rg -l 'yield from.*enable_common_boot|def.*enable_common_boot' tests/

    6d. Trace same-file callers: In each changed file, find other functions
    whose body calls a modified symbol (including code after yield
    in @contextmanager helpers).
    Example: rg 'get_hco_version|enable_common_boot' utilities/hco.py

    6e. Expand transitively: If function A calls modified B, then
    tests/fixtures that call A are affected — even when the test body
    never imports B directly.

    Do NOT limit impact to tests that import the modified symbol only.

  7. Smoke test impact: Intersect the affected set from step 6 with smoke-marked tests.
    Run: rg -l '@pytest.mark.smoke' tests/
    VERIFY the above command returned actual file paths before concluding False.
    Set True if either condition is met:

    • a smoke-marked file appears in the affected set from 6b-6e, OR
    • any conftest.py in the smoke test's parent-directory hierarchy (up to repo root)
      imports or calls a modified utilities/libs symbol — including autouse fixtures
      that depend on modified functions. ALL tests in that directory and below are affected.
      Example check: for each smoke_file, scan dirname(smoke_file)/conftest.py,
      dirname(dirname(smoke_file))/conftest.py, etc. for modified symbol imports
      and autouse fixtures that depend on modified symbols.
  8. Gating test impact: Intersect the affected set from step 6 with gating-marked tests.
    Run: rg -l '@pytest.mark.gating' tests/
    Set True if a gating-marked file also appears in the affected set from 6b-6e.
    Utilities/libs changes often affect gating tests without affecting smoke tests.
    Do NOT stop analysis after concluding Run smoke tests: False.

Output rules:
Do NOT include analysis step numbers (1-8) in your visible output.

Your deliverable:
Your inline informational comment will be based on the following requirements:

Test Execution Plan

  • Run smoke tests: True / False — If True, state the dependency path (test → fixture → changed symbol). True ONLY with a verified path.
  • Run gating tests: True / False — If True, state the dependency path. True if any gating-marked test is in the affected set.
  • Affected tests to run (required when utilities/, libs/, or shared conftest changes — list concrete paths even when smoke is False)

Use these formats:

  • path/to/test_file.py - When the entire test file needs verification
  • path/to/test_file.py::TestClass::test_method - When specific test(s) needed
  • path/to/test_file.py::test_function - When specific test(s) needed
  • -m marker - When a marker covers multiple affected tests (e.g. -m gating only if ALL gating tests in scope need run)
  • Tag each listed test or group with its marker when not obvious, e.g. (gating) or (smoke)

Real test commands (MANDATORY when changes affect session/runtime code):

When the affected code runs at session/collection time (conftest fixtures, pytest plugins,
config hooks, session-scoped setup) or modifies runtime behavior that unit tests mock away,
you MUST include concrete pytest commands the PR author must run on a real cluster
to verify the change works end-to-end. Include:

  • A command for the error/fix path (the scenario the PR fixes)
  • A command for the happy path (regression: the normal case still works)
  • Use lightweight tests (e.g., --collect-only for startup failures,
    a single small test for runtime behavior)
    If the PR only changes test logic (not utilities/libs/conftest), the affected test
    paths themselves serve as the real test commands — no separate section needed.

Example output for a session-startup fix:

**Real tests (cluster required)**
Error path (the fix):
`pytest tests/storage/.../test_foo.py --storage-class-matrix=nonexistent-sc --collect-only`
Expected: ValueError with clear message, not IndexError

Happy path (regression):
`pytest tests/storage/.../test_foo.py --storage-class-matrix=<valid-sc> -k test_bar`
Expected: session starts normally

Guidelines:

  • Include tests affected directly OR via fixture setup/teardown, yield from cleanup, or transitive utility call chains (caller calls modified helper)
  • Use a full file path only if ALL tests in that file require verification
  • Use file path + test name when only specific tests use an affected fixture or utility wrapper (preferred for partial file impact)
  • If a test marker can cover multiple files/tests, provide the marker
  • Balance coverage vs over-testing - Keep descriptions minimal
  • Example: if leaf helper foo() changes, include tests whose fixture teardown calls wrapper bar() where bar() calls foo(), even when the test body only imports an unrelated symbol from the same utilities module

Hardware-Related Checks (SR-IOV, GPU, DPDK):

When PR modifies fixtures for hardware-specific resources:

  • Collection Safety: Fixtures MUST have existence checks (return None when hardware unavailable)
  • Test Plan: MUST verify both WITH and WITHOUT hardware:
    • Run affected tests on cluster WITH hardware
    • Verify collection succeeds on cluster WITHOUT hardware

CRITICAL WORKFLOW COMPLETION RULES:

When responding to this test execution plan request, you MUST follow these rules EXACTLY:

  1. YOUR ONLY DELIVERABLE: Post one non-blocking inline comment containing the test execution plan on the first changed line
  2. THEN STOP IMMEDIATELY - Do NOT generate any additional response
  3. FALLBACK ONLY: If inline comment API calls fail after retrying, post as a regular PR comment
  4. SILENCE = SUCCESS: After successfully submitting the review, your task is complete. No confirmation needed.

ABSOLUTE PROHIBITIONS (violating these creates empty/meaningless reviews):

  • ❌ Do NOT post acknowledgment messages like "Test execution plan posted", "Review posted successfully", "I've successfully posted"
  • ❌ Do NOT mention review IDs, URLs, or confirmation of posting in the PR thread
  • ❌ Do NOT add any follow-up comments after submitting the review
  • ❌ Do NOT reply to confirm task completion
  • ❌ Do NOT explain what you did - just do it and stop

Remember: The pull request review is visible to users. Additional comments are redundant noise.

CRITICAL — Verification rules for smoke and gating decisions:
- For each True decision, you must have traced a concrete path: test file → fixture → utility function → modified symbol.
- Do NOT assume impact based on scope, file proximity, or infrastructure-sounding names.
Only set True when you trace a concrete path through steps 6a-6e, then 7 or 8.
WRONG: "utilities/hco.py changed → run smoke" (no traced dependency path)
WRONG: "Run smoke tests: False" with no affected-test list when gating tests use the changed utility
RIGHT: "Run smoke tests: False, Run gating tests: True" plus tests/.../test_foo.py::TestBar::test_baz (gating)
RIGHT: "Smoke test X uses fixture Y → wrapper Z → changed function W in utilities/hco.py"

@coderabbitai

coderabbitai Bot commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

Tip

For best results, initiate chat on the files or code changes.

@openshift-virtualization-qe-bot-3: The requested inline Test Execution Plan is already present. A second comment would violate the single-comment requirement.

You are interacting with an AI system.

@openshift-virtualization-qe-bot-3

Copy link
Copy Markdown
Contributor

/retest all

Auto-triggered: Files in this PR were modified by merged PR #5975.

Overlapping files

tests/install_upgrade_operators/conftest.py

Comment on lines +56 to +64
def discovered_cnv_deployments(admin_client, hco_namespace):
"""Discover all CNV deployments from the cluster."""
return list(
Deployment.get(
client=admin_client,
namespace=hco_namespace.name,
label_selector="app.kubernetes.io/part-of=hyperconverged-cluster",
)
)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

can you apply it for all other other tests using ALL_CNV_DEPLOYMENT or the deployment matrix? its a good opportunity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants