CMP-4483: Report Not Applicable instead of ERROR when a CEL rule input type is not served - #1312
Vincent056 wants to merge 1 commit into
Conversation
When a CEL rule's kubernetes input references a resource type the cluster does not serve (missing CRD - e.g. SriovNetwork without the SR-IOV Network Operator, or any kubevirt.io type without OpenShift Virtualization), the fetch fails with NoKindMatchError, the input never binds, CEL compilation fails with 'undeclared reference', and the check reports ERROR. The rule is not in error - it is not applicable to the cluster. Classify a fetch error whose chain contains meta.NoKindMatchError in the fetcher adapter, record the rule, and map its result to NOT-APPLICABLE (with an explanatory warning) instead of ERROR in the result conversion. Genuine fetch errors (RBAC, connectivity) still report ERROR. This is the CEL-scanner half of the platform-applicability work tracked in CMP-4483; declaring an explicit platform CPE per rule/profile can build on top. Includes unit tests for the classification (wrapped NoKindMatchError vs generic error) and refreshes coverage-baseline.txt (the in-image test-unit gate requires exact equality, so the baseline also picks up cmd/celctl, absent since the baseline predates cmd/celctl's merge). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
@Vincent056: This pull request references CMP-4483 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "5.0.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Skipping CI for Draft Pull Request. |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: Vincent056 The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
🤖 To deploy this PR, run the following command: |
|
PR needs rebase. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
Stale PRs are closed after 21d of inactivity. If this PR is still relevant, comment to refresh it or remove the stale label. If this PR is safe to close now please do so with /lifecycle stale |
|
Stale PRs rot after 14d of inactivity. Mark the PR as fresh by commenting If this PR is safe to close now please do so with /lifecycle rotten |
|
We're evaluating supporting CPE in the future instead of this approach, so we're closing this PR. |
Summary
First half of CMP-4483 (platform applicability for CEL scans): when a CEL rule's kubernetes input references a resource type the cluster does not serve (missing CRD — e.g.
SriovNetworkwithout the SR-IOV Network Operator, or anykubevirt.iotype without OpenShift Virtualization), the check currently reports ERROR:The rule isn't in error — it's not applicable. This PR classifies fetch errors whose chain contains
meta.NoKindMatchErrorin the fetcher adapter and maps those rules' results toNOT-APPLICABLE(with an explanatory warning) instead ofERROR. Genuine fetch failures (RBAC, connectivity) still report ERROR. Declaring explicit platform CPEs per rule/profile (the rest of CMP-4483) can layer on top of this.Validation
NoKindMatchErrorchain the classifier targets (captured in check-result warnings on OCP 4.21, CIS OCP-Virt CEL profile: all 5 kubevirt rules ERROR'd via this path before the fix).Note for reviewers
coverage-baseline.txtis refreshed because the in-imagetest-unitgate requires exact equality — even a +0.1% improvement fails the build ("baseline is out of date"). It also picks upcmd/celctl, which merged after the baseline was created. The strict-equality behavior itself may be worth revisiting separately: improving coverage in a PR shouldn't require a baseline commit.🤖 Generated with Claude Code