Align FIPS test plan, requirements, and e2e FIPS coverage, fixed failing operator tests#2011
Open
Elmo33 wants to merge 10 commits into
Open
Align FIPS test plan, requirements, and e2e FIPS coverage, fixed failing operator tests#2011Elmo33 wants to merge 10 commits into
Elmo33 wants to merge 10 commits into
Conversation
…rements file. linked all the requirements with full coverage. updated respective steps.
…rements file. linked all the requirements with full coverage. updated respective steps.
sunsingerus
added a commit
that referenced
this pull request
Jun 23, 2026
Resolved all conflicts in favor of our local 0.27.2 work: - test-058-secret.yaml: kept our regenerated cert (valid to 2126, wildcard SAN) over the PR's 2029 cert. - test_020017 / test_010063 (-client. resolver assertion): kept ours intact. - steps_fips.py: took the PR's coherent rewrite (our 9182-plaintext intent is preserved/improved there); the -X ours auto-graft was discarded. - Brought in the PR's new content: fips_test_plan.md, consolidated fips.md/fips.py (34 reqs, zero dangling refs), new FIPS manifests, util._apply_operator_godebug. Known test bugs from the PR fixed in a follow-up commit (test_010035_2 false-green, test_010035_3 livenessProbe breakage).
sunsingerus
added a commit
that referenced
this pull request
Jun 23, 2026
PR #2011 added a livenessProbe to test-035-2-sustained-not-ready.yaml and reworked test_010035_2 to assert kubelet restartCount — a false green: the operator's sustained-NotReady pod recreation (PR #1998) was asserted nowhere, and the livenessProbe restored /tmp/ready (breaking test_010035_3's stays-NotReady premise). - Restore the manifest to readinessProbe-only (pod stays NotReady so the operator, not the kubelet, is what acts). - test_010035_2: assert the operator recreates the pod (UID change) within the sustained-NotReady window, per the actual recovery behavior. - test_010035_3 (opt-out) now holds: pod stays NotReady, UID unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR aligns the FIPS 140-3 test plan, generated requirements, and e2e operator test coverage.
Main changes:
tests/requirements/fips_test_plan.md.tests/requirements/fips.md.tests/requirements/fips.pyfrom the updated requirement definitions.test_operator.pyto reference the corrected/consolidated requirements.steps_fips.pyto better match what is actually testable.Details
This PR makes the three layers consistent:
Test plan
Requirements
Tests
:443:8443FIX
Important items to consider before making a Pull Request
Please check items PR complies to:
next-releasebranch, not intomasterbranch1. More info--
1 If you feel your PR does not affect any Go-code or any testable functionality (for example, PR contains docs only or supplementary materials), PR can be made into
masterbranch, but it has to be confirmed by project's maintainer.