Skip to content

fix(deps): bump golang.org/x/text to v0.39.0 for CVE-2026-56852 - #385

Closed
dbkreling wants to merge 23 commits into
openshift:mainfrom
dbkreling:fix/CVE-2026-56852
Closed

dbkreling wants to merge 23 commits into
openshift:mainfrom
dbkreling:fix/CVE-2026-56852

Conversation

@dbkreling

@dbkreling dbkreling commented Sep 2, 2026 •

Copy link
Copy Markdown

Summary

Bumps golang.org/x/text from v0.37.0 to v0.39.0 to resolve CVE-2026-56852.

CVE: CVE-2026-56852
Vulnerable range: < v0.39.0
Fixed in: v0.39.0
Jira ticket: KATA-5824

A norm.Iter in golang.org/x/text can enter an infinite loop when handling input containing invalid UTF-8 bytes.


This PR was created by the kata-bug-triage skill and supervised by Daniel Kreling.

lmilleri and others added 22 commits June 10, 2026 14:22
Removes TdxConfigSpec and related configuration for Intel TDX quote
verification that required connectivity to external PCCS servers. This
simplifies the operator for disconnected/air-gapped environments where
PCCS access is not available.

Changes:
- Remove TdxConfigSpec from KbsConfig API and CRD
- Delete tdx-config.json template and sample configurations
- Remove TDX helper functions and controller logic
- Clean up TDX-related documentation and test assertions

Signed-off-by: Leonardo Milleri <lmilleri@redhat.com>
Signed-off-by: Leonardo Milleri <lmilleri@redhat.com>
Updated the KbsConfigReconciler to use the new events API:
- Updated Recorder type from record.EventRecorder to events.EventRecorder
- Replaced mgr.GetEventRecorderFor() with mgr.GetEventRecorder()
- Converted all Event() calls to Eventf() calls with the new signature:
  Eventf(regarding, related, eventtype, reason, action, note, args...)

Signed-off-by: Leonardo Milleri <lmilleri@redhat.com>
This commit implements a general mechanism to automatically restart KBS
workload pods when any mounted ConfigMap changes. This solves a common
Kubernetes limitation: ConfigMap content updates don't automatically
restart pods, so configuration changes (policies, reference values, TLS
settings) wouldn't take effect without manual intervention.

Signed-off-by: Leonardo Milleri <lmilleri@redhat.com>
When deploying with a custom IMG (e.g., IMG=trustee-operator:local-test),
the Makefile now updates both:
1. The operator container image (existing behavior)
2. The OPERATOR_IMAGE_NAME environment variable (new fix)

This ensures that the secret-converter init container uses the same image
as the operator, which is critical for local development and testing.

Signed-off-by: Leonardo Milleri <lmilleri@redhat.com>
Added more PCR values to check

At the momement we don't know how to populate the following fields in RVPS database,
so commenting them out:
- measurement
- reported-tcb*
- [platform|policy] fields
- [mr_td|xfam] fields

Signed-off-by: Leonardo Milleri <lmilleri@redhat.com>
Fix attestation policy for Azure SNP/TDX
Bumped operator versions for Kubernetes 1.35
- Add ibmSE field to TrusteeConfigSpec to enable IBM SE mode
- Add pvName field to IbmSETeeConfig (accessed as spec.ibmSE.pvName)
- Add RBAC for PersistentVolumeClaims and PersistentVolumes
- Add IBM SE PVC creation and reconciliation in ibmse_helper.go
- Skip CPU/GPU attestation policies for IBM SE deployments
- Move IBM SE functions to ibmse_helper.go
- Update IBM SE docs for new TrusteeConfig-based workflow
- Add sample IBM SE resource policy config/templates/resource-policy-ibm.rego
- Update resource_policy_helper.go to use IBM SE template when ibmSE is set
- When ibmSE is removed from the trusteeconfig ,normal flow restored.
- Regenerate bundle

Signed-off-by: Chathurya Adapa <Adapa.Chathurya1@ibm.com>
Assisted-by: IBM Bob noreply@ibm.com
…r-ibmse-upstream

support IBM SE TrusteeConfig provisioning
updateKbsDeployment() unconditionally called r.Update() on every
reconciliation even when the deployment spec had not changed. Since the
controller watches its own Deployment (Owns), the resourceVersion bump
from the no-op update re-triggers reconciliation, creating a tight
infinite loop.

Add a DeepEqual check on the pod template and replicas before calling
Update, and only emit the "Updated Deployment" log/event when an actual
change was written.

Signed-off-by: Emanuele Giuseppe Esposito <eesposit@redhat.com>
buildEnvVars() merges cluster proxy settings and user-specified
KbsEnvVars via a map, then iterates the map to build []EnvVar. Go map
iteration is non-deterministic, so with multiple env vars (e.g. proxy
settings + RUST_LOG) the container env ordering can differ between
reconciliations, producing a different pod template hash and triggering
unnecessary rollouts.

Sort the resulting slice by env var name for stable ordering.

Signed-off-by: Emanuele Giuseppe Esposito <eesposit@redhat.com>
Signed-off-by: Leonardo Milleri <lmilleri@redhat.com>
Now we can have multiples cert files under the HW-ID directory.
The cert filename is prefixed with the tcb for allowing smooth firmware upgrades.
The old filename vcek.der is still valid as backward compatiblity fallback

Signed-off-by: Leonardo Milleri <lmilleri@redhat.com>
Signed-off-by: Neeraj Krishna Gopalakrishna <ngopalak@redhat.com>
Signed-off-by: Neeraj Krishna Gopalakrishna <ngopalak@redhat.com>
…e-labels

add labels to secrets created by operator
…-endpoint

Enable health endpoint on the kbs pods
@coderabbitai

coderabbitai Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 721fd25d-1ee2-49fd-84f5-de663d6937bf


Comment @coderabbitai help to get the list of available commands.

Signed-off-by: Daniel Kreling <dkreling@redhat.com>
@openshift-ci openshift-ci Bot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Sep 8, 2026
@openshift-ci

openshift-ci Bot commented Sep 8, 2026

Copy link
Copy Markdown

PR needs rebase.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@dbkreling

Copy link
Copy Markdown
Author

PR #384 also updates x/text and makes this PR reduntant. Closing in favor or #384

@dbkreling dbkreling closed this Sep 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants