Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -49,10 +49,10 @@ require (
k8s.io/client-go v0.34.3
k8s.io/code-generator v0.34.3
k8s.io/utils v0.0.0-20250604170112-4c0f3b243397
knative.dev/hack v0.0.0-20260120115810-bf6758cba446
knative.dev/hack/schema v0.0.0-20260120115810-bf6758cba446
knative.dev/pkg v0.0.0-20260120122510-4a022ed9999a
knative.dev/reconciler-test v0.0.0-20260120140419-4301404c03ce
knative.dev/hack v0.0.0-20260420222011-c985ed3cefe8
knative.dev/hack/schema v0.0.0-20260420222011-c985ed3cefe8
knative.dev/pkg v0.0.0-20260531000007-011b23bf6dfe
knative.dev/reconciler-test v0.0.0-20260424102515-75d476349613
sigs.k8s.io/randfill v1.0.0
sigs.k8s.io/yaml v1.6.0
)
Expand Down
16 changes: 8 additions & 8 deletions go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -1092,14 +1092,14 @@ k8s.io/kube-openapi v0.0.0-20250710124328-f3f2b991d03b h1:MloQ9/bdJyIu9lb1PzujOP
k8s.io/kube-openapi v0.0.0-20250710124328-f3f2b991d03b/go.mod h1:UZ2yyWbFTpuhSbFhv24aGNOdoRdJZgsIObGBUaYVsts=
k8s.io/utils v0.0.0-20250604170112-4c0f3b243397 h1:hwvWFiBzdWw1FhfY1FooPn3kzWuJ8tmbZBHi4zVsl1Y=
k8s.io/utils v0.0.0-20250604170112-4c0f3b243397/go.mod h1:OLgZIPagt7ERELqWJFomSt595RzquPNLL48iOWgYOg0=
knative.dev/hack v0.0.0-20260120115810-bf6758cba446 h1:Y8raYHIuAL9/gUKGYD9/dD+EqUTmrpqVDowzfUVSlGs=
knative.dev/hack v0.0.0-20260120115810-bf6758cba446/go.mod h1:L5RzHgbvam0u8QFHfzCX6MKxu/a/gIGEdaRBqNiVbl0=
knative.dev/hack/schema v0.0.0-20260120115810-bf6758cba446 h1:V7TW1ZOZObhVcDuN04tYvCfCjvvikv1qZR/6lcp6g4Q=
knative.dev/hack/schema v0.0.0-20260120115810-bf6758cba446/go.mod h1:KkibP1IazICP5ClxwN5D26LDSygsqbYnVGuGFTsHNOQ=
knative.dev/pkg v0.0.0-20260120122510-4a022ed9999a h1:9f29OTA7w/iVIX6PS6yveVVzNbcUS74eQfchVe8o2/4=
knative.dev/pkg v0.0.0-20260120122510-4a022ed9999a/go.mod h1:Tz3GoxcNC5vH3Zo//cW3mnHL474u+Y1wbsUIZ11p8No=
knative.dev/reconciler-test v0.0.0-20260120140419-4301404c03ce h1:pIQCFDsDTRkzrJZDTs2laryYOI6VpcnGF5zezL0NXOw=
knative.dev/reconciler-test v0.0.0-20260120140419-4301404c03ce/go.mod h1:FUaadFiniAaqqBp/D2g2cO/FUABVR8W4yZd2azDzp7I=
knative.dev/hack v0.0.0-20260420222011-c985ed3cefe8 h1:IrUBuFRxzqUm+f//hY6XGPzXozcoXD/dSsqcid84/Eg=
knative.dev/hack v0.0.0-20260420222011-c985ed3cefe8/go.mod h1:L5RzHgbvam0u8QFHfzCX6MKxu/a/gIGEdaRBqNiVbl0=
knative.dev/hack/schema v0.0.0-20260420222011-c985ed3cefe8 h1:E/dKOJvgjHiL5OtiPuX8Z9K3myWUHntMH9NWzR8SIzw=
knative.dev/hack/schema v0.0.0-20260420222011-c985ed3cefe8/go.mod h1:KkibP1IazICP5ClxwN5D26LDSygsqbYnVGuGFTsHNOQ=
knative.dev/pkg v0.0.0-20260531000007-011b23bf6dfe h1:Qu7Nt4pvpZ7wfoc7qP0BNsVfMECObzAerv5xD1Ml42s=
knative.dev/pkg v0.0.0-20260531000007-011b23bf6dfe/go.mod h1:Tz3GoxcNC5vH3Zo//cW3mnHL474u+Y1wbsUIZ11p8No=
knative.dev/reconciler-test v0.0.0-20260424102515-75d476349613 h1:LB7Jowx8eVwJKlMmHn0FkIk8NyeFiC0b1q/yTAjThrE=
knative.dev/reconciler-test v0.0.0-20260424102515-75d476349613/go.mod h1:FUaadFiniAaqqBp/D2g2cO/FUABVR8W4yZd2azDzp7I=
rsc.io/binaryregexp v0.2.0/go.mod h1:qTv7/COck+e2FymRvadv62gMdZztPaShugOCi3I+8D8=
rsc.io/quote/v3 v3.1.0/go.mod h1:yEA65RcK8LyAZtP9Kv3t0HmxON59tX3rD+tICJqUlj0=
rsc.io/sampler v1.3.0/go.mod h1:T1hPZKmBbMNahiBKFy5HrXp6adAjACjK9JXDnKaTXpA=
Expand Down
6 changes: 3 additions & 3 deletions test/upgrade/prober/wathola/config/reader_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -61,7 +61,7 @@ address = 'http://default-broker.event-example.svc.cluster.local/
})

// then
assert.Contains(t, errors, "[toml: literal strings cannot have new lines]")
assert.Contains(t, errors, "toml: literal strings cannot have new lines")
}

func TestReadIfNotPresent(t *testing.T) {
Expand Down Expand Up @@ -139,7 +139,7 @@ func withConfigContents(t *testing.T, content string, fn func()) {
t.Helper()
configFile := ensureConfigFileNotPresent(t)
data := []byte(content)
assert.NoError(t, os.WriteFile(configFile, data, 0644))
assert.NoError(t, os.WriteFile(configFile, data, 0o644))
defer func() { assert.NoError(t, os.RemoveAll(configFile)) }()
fn()
}
Expand All @@ -150,7 +150,7 @@ func withErrorsCaptured(t *testing.T, fn func()) []string {
defer func() { logFatal = origLogFatal }()
var errors []string
logFatal = func(args ...interface{}) {
errors = append(errors, fmt.Sprint(args))
errors = append(errors, fmt.Sprint(args...))
}
fn()
return errors
Expand Down
21 changes: 14 additions & 7 deletions vendor/knative.dev/hack/library.sh
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,13 @@ if [[ ! -v GOPATH ]]; then
fi
fi

# Pinned tool versions
readonly GUM_VERSION="v0.14.1"
readonly GOTESTSUM_VERSION="v1.13.0"
readonly GOTESTFMT_VERSION="v2.5.0"
readonly TERMINAL_TO_HTML_VERSION="v3.10.0"
readonly GO_LICENSES_VERSION="v2.0.1"

# Useful environment variables
[[ -v PROW_JOB_ID ]] && IS_PROW=1 || IS_PROW=0
readonly IS_PROW
Expand Down Expand Up @@ -265,7 +272,7 @@ function gum_banner() {

# Simple info banner for logging purposes.
function gum_style() {
go_run github.com/charmbracelet/gum@v0.14.1 style "$@"
go_run "github.com/charmbracelet/gum@${GUM_VERSION}" style "$@"
}

# Checks whether the given function exists.
Expand Down Expand Up @@ -588,7 +595,7 @@ function report_go_test() {
logfile="${logfile/.xml/.jsonl}"
echo "Running go test with args: ${go_test_args[*]}"
local gotest_retcode=0
go_run gotest.tools/gotestsum@v1.13.0 \
go_run "gotest.tools/gotestsum@${GOTESTSUM_VERSION}" \
--format "${GO_TEST_VERBOSITY:-testname}" \
--junitfile "${xml}" \
--junitfile-testsuite-name relative \
Expand All @@ -601,14 +608,14 @@ function report_go_test() {
echo "Test log (JSONL) written to ${logfile}"

ansilog="${logfile/.jsonl/-ansi.log}"
go_run github.com/gotesttools/gotestfmt/v2/cmd/gotestfmt@v2.5.0 \
go_run "github.com/gotesttools/gotestfmt/v2/cmd/gotestfmt@${GOTESTFMT_VERSION}" \
-input "${logfile}" \
-showteststatus \
-nofail > "$ansilog"
echo "Test log (ANSI) written to ${ansilog}"

htmllog="${logfile/.jsonl/.html}"
go_run github.com/buildkite/terminal-to-html/v3/cmd/terminal-to-html@v3.10.0 \
go_run "github.com/buildkite/terminal-to-html/v3/cmd/terminal-to-html@${TERMINAL_TO_HTML_VERSION}" \
--preview < "$ansilog" > "$htmllog"
echo "Test log (HTML) written to ${htmllog}"

Expand Down Expand Up @@ -921,10 +928,10 @@ function run_kntest() {
}

# Run go-licenses to check for forbidden licenses.
# Extra flags can be passed via the GO_LICENSES_FLAGS environment variable.
function check_licenses() {
# Check that we don't have any forbidden licenses.
go_run github.com/google/go-licenses@v1.6.0 \
check "${REPO_ROOT_DIR}/..." || \
go_run "github.com/google/go-licenses/v2@${GO_LICENSES_VERSION}" \
check ${GO_LICENSES_FLAGS:-} "${REPO_ROOT_DIR}/..." || \
{ echo "--- FAIL: go-licenses failed the license check"; return 1; }
}

Expand Down
156 changes: 156 additions & 0 deletions vendor/knative.dev/pkg/network/tls/config.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,156 @@
/*
Copyright 2026 The Knative Authors

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/

package tls

import (
cryptotls "crypto/tls"
"fmt"
"os"
"strings"
)

// Environment variable name suffixes for TLS configuration.
// Use with a prefix to namespace them, e.g. "WEBHOOK_" + MinVersionEnvKey
// reads the WEBHOOK_TLS_MIN_VERSION variable.
const (
MinVersionEnvKey = "TLS_MIN_VERSION"
MaxVersionEnvKey = "TLS_MAX_VERSION"
CipherSuitesEnvKey = "TLS_CIPHER_SUITES"
CurvePreferencesEnvKey = "TLS_CURVE_PREFERENCES"
)

// DefaultConfigFromEnv returns a tls.Config with secure defaults.
// The prefix is prepended to each standard env-var suffix;
// for example with prefix "WEBHOOK_" the function reads
// WEBHOOK_TLS_MIN_VERSION, WEBHOOK_TLS_MAX_VERSION, etc.
func DefaultConfigFromEnv(prefix string) (*cryptotls.Config, error) {
cfg := &cryptotls.Config{
MinVersion: cryptotls.VersionTLS13,
}

if v := os.Getenv(prefix + MinVersionEnvKey); v != "" {
ver, err := parseVersion(v)
if err != nil {
return nil, fmt.Errorf("invalid %s%s %q: %w", prefix, MinVersionEnvKey, v, err)
}
cfg.MinVersion = ver
}

if v := os.Getenv(prefix + MaxVersionEnvKey); v != "" {
ver, err := parseVersion(v)
if err != nil {
return nil, fmt.Errorf("invalid %s%s %q: %w", prefix, MaxVersionEnvKey, v, err)
}
cfg.MaxVersion = ver
}

if v := os.Getenv(prefix + CipherSuitesEnvKey); v != "" {
suites, err := parseCipherSuites(v)
if err != nil {
return nil, fmt.Errorf("invalid %s%s: %w", prefix, CipherSuitesEnvKey, err)
}
cfg.CipherSuites = suites
}

if v := os.Getenv(prefix + CurvePreferencesEnvKey); v != "" {
curves, err := parseCurvePreferences(v)
if err != nil {
return nil, fmt.Errorf("invalid %s%s: %w", prefix, CurvePreferencesEnvKey, err)
}
cfg.CurvePreferences = curves
}

return cfg, nil
}

// parseVersion converts a TLS version string to the corresponding
// crypto/tls constant. Accepted values are "1.2" and "1.3".
func parseVersion(v string) (uint16, error) {
switch v {
case "1.2":
return cryptotls.VersionTLS12, nil
case "1.3":
return cryptotls.VersionTLS13, nil
default:
return 0, fmt.Errorf("unsupported TLS version %q: must be %q or %q", v, "1.2", "1.3")
}
}

// parseCipherSuites parses a comma-separated list of TLS cipher-suite names
// (e.g. "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384")
// into a slice of cipher-suite IDs. Names must match those returned by
// crypto/tls.CipherSuiteName.
func parseCipherSuites(s string) ([]uint16, error) {
lookup := cipherSuiteLookup()
parts := strings.Split(s, ",")
suites := make([]uint16, 0, len(parts))

for _, name := range parts {
name = strings.TrimSpace(name)
if name == "" {
continue
}
id, ok := lookup[name]
if !ok {
return nil, fmt.Errorf("unknown cipher suite %q", name)
}
suites = append(suites, id)
}

return suites, nil
}

// parseCurvePreferences parses a comma-separated list of elliptic-curve names
// (e.g. "X25519,CurveP256") into a slice of crypto/tls.CurveID values.
// Both Go constant names (CurveP256) and standard names (P-256) are accepted.
func parseCurvePreferences(s string) ([]cryptotls.CurveID, error) {
parts := strings.Split(s, ",")
curves := make([]cryptotls.CurveID, 0, len(parts))

for _, name := range parts {
name = strings.TrimSpace(name)
if name == "" {
continue
}
id, ok := curvesByName[name]
if !ok {
return nil, fmt.Errorf("unknown curve %q", name)
}
curves = append(curves, id)
}

return curves, nil
}

func cipherSuiteLookup() map[string]uint16 {
m := make(map[string]uint16)
for _, cs := range cryptotls.CipherSuites() {
m[cs.Name] = cs.ID
}
return m
}

var curvesByName = map[string]cryptotls.CurveID{
"CurveP256": cryptotls.CurveP256,
"CurveP384": cryptotls.CurveP384,
"CurveP521": cryptotls.CurveP521,
"X25519": cryptotls.X25519,
"X25519MLKEM768": cryptotls.X25519MLKEM768,
"P-256": cryptotls.CurveP256,
"P-384": cryptotls.CurveP384,
"P-521": cryptotls.CurveP521,
}
6 changes: 3 additions & 3 deletions vendor/knative.dev/pkg/tracker/enqueue.go
Original file line number Diff line number Diff line change
Expand Up @@ -277,8 +277,8 @@ func (i *impl) GetObservers(obj interface{}) []types.NamespacedName {
keys = append(keys, key)
}
}
if len(s) == 0 {
delete(i.exact, ref)
if len(ms) == 0 {
delete(i.inexact, ref)
}
}

Expand Down Expand Up @@ -309,7 +309,7 @@ func (i *impl) OnDeletedObserver(obj interface{}) {
for ref, matchers := range i.inexact {
delete(matchers, key)
if len(matchers) == 0 {
delete(i.exact, ref)
delete(i.inexact, ref)
}
}
}
2 changes: 2 additions & 0 deletions vendor/knative.dev/pkg/webhook/env.go
Original file line number Diff line number Diff line change
Expand Up @@ -72,6 +72,8 @@ func SecretNameFromEnv(defaultSecretName string) string {
return secret
}

// Deprecated: Use knative.dev/pkg/network/tls.DefaultConfigFromEnv instead.
// TLS configuration is now read automatically inside webhook.New via the shared tls package.
func TLSMinVersionFromEnv(defaultTLSMinVersion uint16) uint16 {
switch tlsMinVersion := os.Getenv(tlsMinVersionEnvKey); tlsMinVersion {
case "1.2":
Expand Down
Loading
Loading