Skip to content

Conversation

@wking
Copy link
Member

@wking wking commented Feb 2, 2026

4.20.13 has the guard baked in, but it didn't make it in time for 4.20.12, and we want all the generally-available paths into 4.21 to be covered. This risk declaration covers the gap, and hopefully 4.21.1 will only include 4.20.13 and newer as update sources (I'm also bumping build-data).

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Feb 2, 2026
@openshift-ci-robot
Copy link

openshift-ci-robot commented Feb 2, 2026

@wking: This pull request references OCPNODE-4065 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the spike to target the "4.22.0" version, but no target version was set.

Details

In response to this:

4.20.13 has the guard baked in, but it didn't make it in time for 4.20.12, and we want all the generally-available paths into 4.21 to be covered. This risk declaration covers the gap, and hopefully 4.21.1 will only include 4.20.13 and newer as update sources (I'm also bumping build-data).

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai
Copy link

coderabbitai bot commented Feb 2, 2026

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • 🔍 Trigger a full review
✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment

Comment @coderabbitai help to get the list of available commands and usage tips.

@openshift-ci openshift-ci bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Feb 2, 2026
@wking wking force-pushed the 4.21-sigstore-mirror branch 2 times, most recently from 01d34b2 to 061b7af Compare February 2, 2026 17:34
@wking
Copy link
Member Author

wking commented Feb 2, 2026

4.20.12 cluster that knows it's exposed (build03):

image

For a cluster that knows it isn't exposed, https://amd64.ocp.releases.ci.openshift.org/ -> 4.20.12 -> aws-ovn-serial-1of2 -> PromeCIeus (with a +0.1 offset, to make the 0 result more visible):

image

4.20.13 has the guard baked in [1,2], but it didn't make it in time
for 4.20.12, and we want all the generally-available paths into 4.21
to be covered.  This risk declaration covers the gap, and hopefully
4.21.1 will only include 4.20.13 and newer as update sources (I'm also
bumping build-data).

[1]: https://amd64.ocp.releases.ci.openshift.org/releasestream/4-stable/release/4.20.13
[2]: https://issues.redhat.com/browse/OCPBUGS-73884
@wking wking force-pushed the 4.21-sigstore-mirror branch from 061b7af to 7a5d8a2 Compare February 2, 2026 17:58
@@ -0,0 +1,12 @@
to: 4.21.0
from: 4[.]20[.]12[+].*
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The impact statement states:

Updates from 4.20.(z<13) to 4.21

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

4.20.12 is the only match for 4.20.(z<13) in 4.21.0's update source metadata:

$ oc adm release info quay.io/openshift-release-dev/ocp-release:4.21.0-x86_64 | grep Upgrades
  Upgrades: 4.20.12, 4.20.13, 4.21.0-ec.0

due to #8624.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ooh, got it 🙇 Could we then simplify the statement to just mention that the affected update is 4.20.12 -> 4.21?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Works for me. I've updated the OCPNODE-4065 Description section on Which 4.y.z to 4.y'.z' updates increase vulnerability? to start with:

Updates from 4.20.12 to 4.21.0.

Then I include additional text and the earlier release info output quote to explain the assertion of just 4.20.12.

@openshift-ci openshift-ci bot added the lgtm Indicates that a PR is ready to be merged. label Feb 2, 2026
@openshift-ci
Copy link
Contributor

openshift-ci bot commented Feb 2, 2026

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: DavidHurta, wking

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci
Copy link
Contributor

openshift-ci bot commented Feb 2, 2026

@wking: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@openshift-merge-bot openshift-merge-bot bot merged commit 918976f into openshift:master Feb 2, 2026
4 checks passed
@wking wking deleted the 4.21-sigstore-mirror branch February 2, 2026 20:22
wking added a commit to wking/cincinnati-graph-data that referenced this pull request Feb 6, 2026
7a5d8a2 (blocked-edges/4.21.0-SigstoreSignatureMirroring: 4.20.12
-> 4.21 risk, 2026-02-02, openshift#8710)'s minor_min raise was picked up by
4.21.1, so it only offers updates from 4.20.13 and later, which all
have the machine-config-operator admin-ack guard:

  $ oc adm release info quay.io/openshift-release-dev/ocp-release:4.21.1-x86_64 | grep Upgrade
    Upgrades: 4.20.13, 4.20.14, 4.21.0
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants