Skip to content

fix(dep): upgrade grpcGo to v1.79.3, fix CVE-2026-33186#66

Merged
openshift-merge-bot[bot] merged 3 commits intoredhat-developer:masterfrom
ranakan19:choreDep
Apr 29, 2026
Merged

fix(dep): upgrade grpcGo to v1.79.3, fix CVE-2026-33186#66
openshift-merge-bot[bot] merged 3 commits intoredhat-developer:masterfrom
ranakan19:choreDep

Conversation

@ranakan19
Copy link
Copy Markdown
Contributor

What type of PR is this?

/kind bug

What does this PR do / why we need it:
fix CVE-2026-33186[gRPC-Go auth bypass (HTTP/2 path validation)] by upgrading google.golang.org/grpc dependcy to 1.79.3

Have you updated the necessary documentation?
N/A

Which issue(s) this PR fixes:
https://redhat.atlassian.net/browse/GITOPS-9319

How to test changes / Special notes to the reviewer:
other dependency changes are from go mod tidy

Signed-off-by: Kanika Rana <krana@redhat.com>
@openshift-ci
Copy link
Copy Markdown

openshift-ci Bot commented Apr 24, 2026

@ranakan19: The label(s) kind/bug cannot be applied, because the repository doesn't have them.

Details

In response to this:

What type of PR is this?

/kind bug

What does this PR do / why we need it:
fix CVE-2026-33186[gRPC-Go auth bypass (HTTP/2 path validation)] by upgrading google.golang.org/grpc dependcy to 1.79.3

Have you updated the necessary documentation?
N/A

Which issue(s) this PR fixes:
https://redhat.atlassian.net/browse/GITOPS-9319

How to test changes / Special notes to the reviewer:
other dependency changes are from go mod tidy

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci openshift-ci Bot requested review from jannfis and keithchong April 24, 2026 19:30
@ranakan19
Copy link
Copy Markdown
Contributor Author

cluster initation failed for ci/prow/v4.13-e2e :

level=error msg=Cluster operator etcd Degraded is True with ClusterMemberController_SyncError::EtcdMembers_UnhealthyMembers::MissingStaticPodController_SyncError::StaticPods_Error: ClusterMemberControllerDegraded: unhealthy members found during reconciling members
level=error msg=EtcdMembersDegraded: 2 of 3 members are available, ip-10-0-183-182.us-west-2.compute.internal is unhealthy
level=error msg=MissingStaticPodControllerDegraded: static pod lifecycle failure - static pod: "etcd" in namespace: "openshift-etcd" for revision: 6 on node: "ip-10-0-183-182.us-west-2.compute.internal" didn't show up, waited: 3m0s
level=error msg=StaticPodsDegraded: pod/etcd-ip-10-0-183-182.us-west-2.compute.internal container "etcd" is terminated: Completed: 
level=error msg=StaticPodsDegraded: pod/etcd-ip-10-0-183-182.us-west-2.compute.internal container "etcd-metrics" is terminated: Error: : connection error: desc = \"transport: Error while dialing: dial tcp 10.0.183.182:9978: connect: connection refused\""}
level=error msg=StaticPodsDegraded: {"level":"info","ts":"2026-04-24T20:06:38.038798Z","caller":"zapgrpc/zapgrpc.go:174","msg":"[balancer] base.baseBalancer: handle SubConn state change: 0xc000403f50, TRANSIENT_FAILURE"}
level=error msg=StaticPodsDegraded: {"level":"info","ts":"2026-04-24T20:06:42.696324Z","caller":"zapgrpc/zapgrpc.go:174","msg":"[core] [Channel #1 SubChannel #2] Subchannel Connectivity change to IDLE, last error: connection error: desc = \"transport: Error while dialing: dial tcp 10.0.183.182:9978: connect: connection refused\""}
level=error msg=StaticPodsDegraded: {"level":"info","ts":"2026-04-24T20:06:42.696377Z","caller":"zapgrpc/zapgrpc.go:174","msg":"[balancer] base.baseBalancer: handle SubConn state change: 0xc000403f50, IDLE"}
level=error msg=StaticPodsDegraded: {"level":"info","ts":"2026-04-24T20:06:42.696413Z","caller":"zapgrpc/zapgrpc.go:174","msg":"[core] [Channel #1 SubChannel #2] Subchannel Connectivity change to CONNECTING"}
level=error msg=StaticPodsDegraded: {"level":"info","ts":"2026-04-24T20:06:42.696445Z","caller":"zapgrpc/zapgrpc.go:174","msg":"[core] [Channel #1 SubChannel #2] Subchannel picks a new address \"10.0.183.182:9978\" to connect"}
level=error msg=StaticPodsDegraded: {"level":"info","ts":"2026-04-24T20:06:42.696519Z","caller":"zapgrpc/zapgrpc.go:174","msg":"[balancer] base.baseBalancer: handle SubConn state change: 0xc000403f50, CONNECTING"}
level=error msg=StaticPodsDegraded: {"level":"info","ts":"2026-04-24T20:06:42.708639Z","caller":"zapgrpc/zapgrpc.go:174","msg":"[core] [Channel #1 SubChannel #2] Subchannel Connectivity change to READY"}
level=error msg=StaticPodsDegraded: {"level":"info","ts":"2026-04-24T20:06:42.708691Z","caller":"zapgrpc/zapgrpc.go:174","msg":"[balancer] base.baseBalancer: handle SubConn state change: 0xc000403f50, READY"}
level=error msg=StaticPodsDegraded: {"level":"info","ts":"2026-04-24T20:06:42.70873Z","caller":"zapgrpc/zapgrpc.go:174","msg":"[roun
level=error msg=StaticPodsDegraded: pod/etcd-ip-10-0-183-182.us-west-2.compute.internal container "etcd-readyz" is terminated: Completed: 
level=error msg=StaticPodsDegraded: pod/etcd-ip-10-0-183-182.us-west-2.compute.internal container "etcdctl" is terminated: Error: 
level=info msg=Cluster operator etcd Progressing is True with NodeInstaller: NodeInstallerProgressing: 1 nodes are at revision 2; 1 nodes are at revision 3; 1 nodes are at revision 6
level=info msg=Cluster operator etcd RecentBackup is Unknown with ControllerStarted: The etcd backup controller is starting, and will decide if recent backups are available or if a backup is required
level=info msg=Cluster operator ingress EvaluationConditionsDetected is False with AsExpected: 
level=info msg=Cluster operator insights ClusterTransferAvailable is False with NoClusterTransfer: no available cluster transfer
level=info msg=Cluster operator insights Disabled is False with AsExpected: 
level=info msg=Cluster operator insights SCAAvailable is False with Forbidden: Failed to pull SCA certs from https://api.openshift.com/api/accounts_mgmt/v1/certificates: OCM API https://api.openshift.com/api/accounts_mgmt/v1/certificates returned HTTP 403: {"code":"ACCT-MGMT-11","href":"/api/accounts_mgmt/v1/errors/11","id":"11","kind":"Error","operation_id":"cbb7775c-2474-4d85-b8ec-2e8bc97ef83d","reason":"Account with ID 2DUeKzzTD9ngfsQ6YgkzdJn1jA4 denied access to perform create on Certificate with HTTP call POST /api/accounts_mgmt/v1/certificates"}
level=info msg=Cluster operator network ManagementStateDegraded is False with : 
level=error msg=Cluster initialization failed because one or more operators are not functioning properly.
level=error msg=The cluster should be accessible for troubleshooting as detailed in the documentation linked below,
level=error msg=https://docs.openshift.com/container-platform/latest/support/troubleshooting/troubleshooting-installations.html
level=error msg=The 'wait-for install-complete' subcommand can then be used to continue the installation
level=error msg=failed to initialize the cluster: Cluster operator etcd is degraded
Installer exit with code 6

retesting

/retest

Copy link
Copy Markdown
Member

@anandf anandf left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Copy Markdown

@aali309 aali309 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@anandf
Copy link
Copy Markdown
Member

anandf commented Apr 28, 2026

/approve

@anandf
Copy link
Copy Markdown
Member

anandf commented Apr 28, 2026

/lgtm

@anandf
Copy link
Copy Markdown
Member

anandf commented Apr 28, 2026

/approve

@svghadi
Copy link
Copy Markdown
Member

svghadi commented Apr 28, 2026

/lgtm
/approve

@openshift-ci openshift-ci Bot removed the lgtm label Apr 28, 2026
@openshift-ci
Copy link
Copy Markdown

openshift-ci Bot commented Apr 28, 2026

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: anandf, svghadi

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@ranakan19
Copy link
Copy Markdown
Contributor Author

ci/prow/v4.14-e2e failing with, retesting

{"component":"entrypoint","error":"wrapped process failed: exit status 5","file":"sigs.k8s.io/prow/pkg/entrypoint/run.go:84","func":"sigs.k8s.io/prow/pkg/entrypoint.Options.internalRun","level":"error","msg":"Error executing test process","severity":"error","time":"2026-04-28T16:25:55Z"}
error: failed to execute wrapped command: exit status 5 
INFO[2026-04-28T16:25:56Z] Step e2e-ipi-install-install failed after 26m42s. 
INFO[2026-04-28T16:25:56Z] Step phase pre failed after 30m43s.     

/retest

@ranakan19
Copy link
Copy Markdown
Contributor Author

/retest

@ranakan19
Copy link
Copy Markdown
Contributor Author

seems to be impacting other jobs as well
unrelated to changes on this PR, so retrying again

/retest

Signed-off-by: Kanika Rana <krana@redhat.com>
@ranakan19
Copy link
Copy Markdown
Contributor Author

ranakan19 commented Apr 28, 2026

build10 image registry was down, seems to have been fixed, retrying now
/retest

@ranakan19
Copy link
Copy Markdown
Contributor Author

/retest

@deepsm007
Copy link
Copy Markdown

/test v4.13-e2e v4.12-e2e

@anandf
Copy link
Copy Markdown
Member

anandf commented Apr 29, 2026

/lgtm

@openshift-ci openshift-ci Bot added the lgtm label Apr 29, 2026
@openshift-merge-bot openshift-merge-bot Bot merged commit 1212ec2 into redhat-developer:master Apr 29, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants