Skip to content

deps: bump github.com/hashicorp/hcl/v2 from 2.20.1 to 2.23.0 - #7

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/hashicorp/hcl/v2-2.23.0
Closed

deps: bump github.com/hashicorp/hcl/v2 from 2.20.1 to 2.23.0#7
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/hashicorp/hcl/v2-2.23.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 16, 2025

Copy link
Copy Markdown
Contributor

Bumps github.com/hashicorp/hcl/v2 from 2.20.1 to 2.23.0.

Release notes

Sourced from github.com/hashicorp/hcl/v2's releases.

v2.23.0

What's Changed

Full Changelog: hashicorp/hcl@v2.22.0...v2.23.0

v2.22.0

Enhancements

  • feat: return an ExprSyntaxError for invalid references that end in a dot (#692)

v2.21.0

Enhancements

  • Introduce ParseTraversalPartial, which allows traversals that include the splat ([*]) index operator. (#673)
  • ext/dynblock: Now accepts marked values in for_each, and will transfer those marks (as much as technically possible) to values in the generated blocks. (#679)

Bugs Fixed

  • Expression evaluation will no longer panic if the splat operator is applied to an unknown value that has cty marks. (#678)
Changelog

Sourced from github.com/hashicorp/hcl/v2's changelog.

v2.23.0 (November 15, 2024)

Bugs Fixed

  • Preserve marks when traversing through unknown values. (#699)
  • Retain marks through conditional and for expressions. (#710)

v2.22.0 (August 26, 2024)

Enhancements

  • feat: return an ExprSyntaxError for invalid references that end in a dot (#692)

v2.21.0 (June 19, 2024)

Enhancements

  • Introduce ParseTraversalPartial, which allows traversals that include the splat ([*]) index operator. (#673)
  • ext/dynblock: Now accepts marked values in for_each, and will transfer those marks (as much as technically possible) to values in the generated blocks. (#679)

Bugs Fixed

  • Expression evaluation will no longer panic if the splat operator is applied to an unknown value that has cty marks. (#678)
Commits
  • 56a9aee Merge pull request #710 from hashicorp/jbardin/marked-conditions
  • b48ba6e pass marks through unknown ForExpr values
  • bbfec2d pass all marks through conditional expressions
  • d20d07f github: Pin action refs to latest trusted by TSCCR (#700)
  • 3883feb docs(ext/dynblock): recursive function call typo in detecting variables (#686)
  • 2eb163f Merge pull request #701 from hashicorp/d/fix-typo
  • 65971e8 docs: use 'by' instead of 'prior to'
  • 1dfc778 docs: fix typo
  • 78fe993 Merge pull request #699 from hashicorp/jbardin/marked-traversals
  • e2f43f4 Preserve marks when traversing unknown values
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot @github

dependabot Bot commented on behalf of github Jun 16, 2025

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: automerge, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot force-pushed the dependabot/go_modules/github.com/hashicorp/hcl/v2-2.23.0 branch 2 times, most recently from b1885fe to e8d4c35 Compare June 22, 2025 17:12
@jingle2008
jingle2008 force-pushed the main branch 4 times, most recently from 2490528 to a0c9543 Compare June 23, 2025 04:03
Bumps [github.com/hashicorp/hcl/v2](https://github.com/hashicorp/hcl) from 2.20.1 to 2.23.0.
- [Release notes](https://github.com/hashicorp/hcl/releases)
- [Changelog](https://github.com/hashicorp/hcl/blob/main/CHANGELOG.md)
- [Commits](hashicorp/hcl@v2.20.1...v2.23.0)

---
updated-dependencies:
- dependency-name: github.com/hashicorp/hcl/v2
  dependency-version: 2.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/github.com/hashicorp/hcl/v2-2.23.0 branch from e8d4c35 to e85e823 Compare June 27, 2025 04:45
@dependabot @github

dependabot Bot commented on behalf of github Jul 7, 2025

Copy link
Copy Markdown
Contributor Author

Superseded by #10.

@dependabot dependabot Bot closed this Jul 7, 2025
@dependabot
dependabot Bot deleted the dependabot/go_modules/github.com/hashicorp/hcl/v2-2.23.0 branch July 7, 2025 23:21
jingle2008 added a commit that referenced this pull request May 17, 2026
#6 (pkg/models/base_model): document that GetDefaultDacShape returns
   a pointer aliasing an element of the underlying
   CompatibleDACShapes slice. Mutating it is visible to every
   BaseModel that shares the same *DacShapeConfigs. Treat as
   read-only.

#7 (internal/ui/tui/reducer_actions): rename local `key` variables
   to `itemKey` in scaleUpGpuPool / cordonNode / drainNode /
   getSelectedItem. The locals were shadowing the bubbles/key
   package import (no bug — Go scopes correctly — but the rest of
   the file uses `itemKey` and the parity is worth having).

#10 (internal/cli/output/WriteJSONL): document that "_group" is a
   reserved field name used to carry the originating map key when
   flattening keyed inputs; callers must not name a JSON field
   "_group" or it will be silently overwritten.

#5 (internal/cli/output/WriteJSONL): add a TODO(perf) note about
   the marshal→unmarshal→remarshal roundtrip in the map path.
   ~3× steady-state memory of a streaming writer; acceptable for
   current dataset sizes, revisit with reflect-based streaming if
   profiles show it as a hotspot.

Minor #8 (//nolint:cyclop on emitCategory) and Minor #9 (Categories
global unused outside tests) deliberately not addressed per the
reviewer's own guidance — both were explicitly out of scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
jingle2008 added a commit that referenced this pull request May 18, 2026
Sweeps the remaining review items #6, #7, and the relevant Minors:

  - #6 + Minor #9: merge validateMutationConfig and validateScaleConfig
    into a single function with (needsKube, needsRepo) booleans. Drop
    the unreachable "missing --kubeconfig" branch — the persistent
    flag always supplies ~/.kube/config so the os.Stat guard is the
    real check.

  - #7: each mutation tool description now spells out that mutations
    target the server's startup env only; env_* fields in the
    arguments are silently ignored by the JSON unmarshaler. Header
    comment in registerMutationTools explains the reasoning.

  - Minor #8: fold requireConfirm into runMutationTool. Each handler
    now makes a single call with `in.Confirm` and a perform closure
    instead of the previous two-step gate + execute. The 4-value
    return is gone; refusal becomes the same shape as failure.

  - Minor #12: fix doc-level wording — delete.Short adds "the",
    scale.Short drops the misleading plural, reboot.Long rewords
    "fire-and-forget" so it doesn't read as "OCI finished".

Minor #10 was based on misreading the perform-vs-runMutation
ordering; the "no change" note already prints before "OK". No
change needed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
jingle2008 added a commit that referenced this pull request May 18, 2026
Addresses the second round of review feedback.

Important #1 — env_override is now an explicit opt-in:

  - New config field MutationEnvOverrideAllowed (default false) with
    matching --mutation_env_override_allowed persistent flag.
  - effectiveMutationEnv applies the agent's envOverride only when
    the operator opted in; otherwise the override is silently dropped
    AND audit-logged at info, preserving "operator's startup-env
    choice caps blast radius" as the safety story.
  - When the override IS applied AND deviates from startup, an
    info-level "level=warn" audit line records the deviation for
    SIEM visibility.
  - Tool descriptions now honestly describe the trade-off via a
    central mutationToolFooter constant. The previous "parity with
    list_*" framing understated the security cost; the new shape
    keeps the parity benefit (multi-realm operators can opt in)
    without the silent capability expansion.

Important #2 — failed-phase event name unified:
  - Both CLI mutate.go and MCP mutations.go now emit Errorw with
    event="mutation", phase="failed". Aggregators filtering on a
    single `phase` discriminator now capture all four states
    (begin / done / failed / refused).

Important #3 — env_override propagation coverage:
  - TestIntegration_MutationTool_IgnoresEnvOverride_WhenDisallowed:
    default config drops the agent's env_realm/env_region.
  - TestIntegration_MutationTool_HonorsEnvOverride_WhenAllowed:
    flag-set config honors override (renamed from prior test).
  - TestIntegration_MutationTool_PropagatesEnvOverride:
    reboot/terminate/scale all assert env reaches BOTH the resolver
    seam and the action seam — the hops where a future refactor
    could accidentally drop the override.

Minors:
  - #4: gofmt double blank line in mutate.go (mutations_test.go and
    tools.go also picked up trailing-whitespace fixes from the same
    pass).
  - #5: mutationToolFooter centralizes the env-override clause so
    drift across the seven descriptions is not possible.
  - #7: drop the resolveNodeForOCIAction / resolveGpuPoolForOCIAction
    methods — they were pure passthroughs after the prior commit. The
    handlers now call mcpResolveGpuNodeFn / mcpResolveGpuPoolFn
    directly.

newTestPair now accepts a variadic config-mutator option so tests
that need to flip the flag don't have to fork the helper.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
jingle2008 added a commit that referenced this pull request May 20, 2026
Three Important + three Minor follow-ups from the post-commit review:

Important #1 — MCP integration test for enrichment failure:
- New TestIntegration_NotifiesOnGpuPoolEnrichmentFailure (and a tiny
  fixedGpuPoolsLoader helper) drives list_gpu_pools against a
  non-empty stub loader with KubeConfig pointed at a missing file.
  Asserts: tool call succeeds (IsError=false), Terraform-derived pool
  still rendered with placeholder status, enrichment warning appears
  in BOTH the StructuredContent.warnings envelope AND as a
  notifications/message frame. Was a real coverage gap — previous
  partial-load integration test returned nil pools, taking
  EnrichGpuPools's empty-slice fast-path.

Important #2 — GpuPool JSON shape pin-test:
- New TestWriteSlice_GpuPool_JSONShape asserts every key on the
  rendered object uses the lowercase JSON tags introduced in v0.3.0
  (name / shape / actualSize / status / capacityType / …) and that no
  capitalized struct-field name leaks. The CHANGELOG claimed
  shape-unchanged; this test backs that claim.

Important #3 — Structured log for enrichment failures:
- EnrichGpuPools now emits a logger.Infow line at each failure point
  with `step=compartment_id|populate` plus the error, matching the
  Infow pattern resolve.GpuPool already uses for partial-load.
  Long-running MCP servers degrade visibly in logs instead of only
  via tool output. Logger interface has no Warnw — using Infow stays
  consistent with the existing partial-load log shape.

Minor #4 — CHANGELOG calls out the NONEXIST status:
- A Terraform-defined pool that hasn't been applied yet now shows
  `status: "NONEXIST"` after enrichment (the literal value
  PopulateGpuPools writes when OCI returns 200 but excludes the pool
  from its result). Same as TUI behavior; just wasn't documented for
  CLI/MCP consumers.

Minor #7 — CHANGELOG calls out the offline-experience change:
- `toolkit get gpupool` was previously offline-capable; one K8s
  lookup attempt is now made before any output renders. Added a
  sentence explaining the new latency on no-auth hosts.

Minor #8 — CLI warning prefix symmetry:
- Partial-Terraform failures previously printed `warning: <err>`;
  enrichment failures print `warning: gpu pool enrichment
  incomplete: <err>`. Both are now prefixed by their step
  (`warning: load gpu pools: ...` vs `warning: gpu pool enrichment
  incomplete: ...`) so a reader can tell at a glance which one fired.

Skipped from the review's Minor list:
- #5 (string→error return type for EnrichGpuPools) — pure style call,
  current shape reads cleanly at both call sites; defer to a future
  pass if/when call sites grow.
- #6 (categorized warnings field) — would require restructuring the
  warnings array into typed entries (Terraform vs enrichment). Bigger
  surface change than this review warrants.

Verified: go test ./..., make fmt-check, make goimports-check,
golangci-lint run ./... all green.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
jingle2008 added a commit that referenced this pull request May 24, 2026
Code-review follow-up to the four-commit ImportedModel feature
(02fdba7 .. 2c1090e). All review feedback addressed:

Important #1 — MCP description claimed a `source` field that was
dropped in 0d194ae. Replaced with the orthogonality guidance the Go
doc and CHANGELOG now use. Agents planning JSON paths against the
tool description will no longer be misled.

Important #2 — CHANGELOG was missing the silent BaseModel filter
change (02fdba7). Added a `### Changed` entry explicit about the
count delta — `toolkit get basemodel -o json | jq length` returns
fewer items on clusters with tenant-scoped CBMs. Points readers at
the new `importedmodel` category to recover the full set.

Important #3 — Confirmed via inventory of pkg/models that
ImportedModel is the only category with both Namespace and TenantID
(DAC, LimitTenancyOverride, ConsolePropertyTenancyOverride each
have TenantID alone). Adopting the DAC pattern: TenantID is the OCI
tenant identifier (from `tenancy-id` label, populated on any source
that carries the label); Namespace is the K8s scope (the
authoritative source-kind indicator). They're orthogonal facets,
not synonyms. Loader behavior unchanged — only documentation flips,
in three places:

  - pkg/models/imported_model.go: expanded doc-comment with the
    "orthogonal facets" framing and explicit consumer guidance
    ("which K8s scope" vs "which OCI tenant").
  - internal/mcp/tools.go (list_imported_models description): same
    clarification, replacing the stale `source` mention.
  - CHANGELOG: same framing, with the DAC-pattern reference.

Important #4 — Added a deliberate comment in LoadImportedModels
explaining the all-or-nothing semantics vs. the LoadGpuPools
partial-error idiom. The two sources here are conceptually one
catalog; a half-loaded result is more confusing than an explicit
error, and the cross-GVR RBAC asymmetry (namespaced `basemodels`
vs cluster-scoped `clusterbasemodels`) is the realistic failure
mode the comment calls out.

Minor #5 — TestList_ImportedModels_FlatShape doc-comment said the
test asserts `source` is present; corrected to reflect that the
test now asserts `source` is absent (the post-0d194ae contract).

Skipped from the review's Minor list:
- #6 (lint suppression placement) — pre-existing, no change.
- #7 (split routeLoadingDataMsg following the routeList* pattern) —
  could land in a follow-up if the next addition pushes the message
  count above the cyclop ceiling again; not urgent at 10.
- #8 (ResetScopedData consistency) — already correct.
- #9 (StorageURI placement on BaseModel vs ImportedModel) — already
  the right call, no change.
- #10 (CLI table readability) — passed review.

Verified: go test ./..., make fmt-check, make goimports-check,
golangci-lint run ./... all green.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
jingle2008 added a commit that referenced this pull request May 24, 2026
Review follow-ups for 74723fd:

Important #1 — Harmonize the orphan-tenant sentinel across DAC and
ImportedModel. DAC's V1/V2 extractors previously branched on
hasLabels and defaulted to the literal "missing" — different from
the "UNKNOWN_TENANCY" sentinel ImportedModel and tenantIDFromLabels
already use for the labels-present-but-no-tenancy-id case.
tenantIDFromLabels(nil) already returns "UNKNOWN_TENANCY", so
calling it unconditionally collapses the two sentinels into one
and matches the policy the user picked ("same convention as DAC").
The dead-`hasLabels` variables are tagged with `_ = hasLabels` to
keep the surrounding signatures unchanged.

As a follow-on, the now-redundant tenantIDFromUnstructured wrapper
in imported_model.go is inlined — its only purpose was to bridge
the "labels absent" case, which tenantIDFromLabels(labels) handles
identically. One less abstraction, one less typo surface.

Important #2 — TestSetImportedModelMap added, mirroring
TestSetDedicatedAIClusterMap line-for-line. Covers both the
matched-by-suffix path (re-keys to Tenant.Name, sets Owner pointer)
and the unmatched path (key passes through, Owner stays nil). A
small generic `keys[V any]` helper feeds the diagnostic Errorf
message.

Important #3 — TestResetScopedData now seeds ImportedModelMap and
asserts it's nil after Reset. Production code (dataset.go:78)
already resets it; this test pins the contract so a future drop
of the reset line fails fast.

Important #4 — CHANGELOG TUI column claim corrected to the
shipped order: Name, Tenant, Namespace, Display Name, Version,
DAC Shape, Flags, Status. The previous text described an
in-development layout that didn't match the final headers.go
definition. Also added a sentence on the CLI/TUI tenant-column
asymmetry (CLI shows raw OCID, TUI shows resolved Tenant.Name
via SetImportedModelMap) — same as DAC's behavior, but never
documented before.

Skipped from the review's Minor list (filed for follow-up):
- #5 (UNKNOWN_TENANCY as a `const`): three sites now share the
  same literal via tenantIDFromLabels; extracting a const is a
  micro-cleanup that's strictly post-release.
- #7 (suffix-match bug in SetXxxMap): pre-existing in DAC, not
  introduced by this work — separate fix.

Verified: go test ./..., make fmt-check, make goimports-check,
golangci-lint run ./... all green.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
jingle2008 added a commit that referenced this pull request Jun 22, 2026
…ent slog ctx

Follow-up to the Warn-level work, addressing the dead-API, missing-debug,
and minor items from the logging evaluation.

#5 Activate the previously-unused interface methods:
- WithFields: tag each session's logger with "cmd" (tui/get/mcp/mutate)
  and "version" where available, at the four logger-creation sites, so
  lines in the shared log file stay attributable per command/build.
  Keys chosen to not collide with existing per-call fields.
- DebugEnabled: guard the cty value.GoString() formatting in the
  Terraform locals resolver, which previously ran unconditionally at
  Info; now a debug-only breadcrumb.

#6 Add counts-only debug breadcrumbs at the main load chokepoints
(LoadGPUPools pool/source counts, LoadGPUNodesByPool, LoadGPUWorkloadsByNode)
so `--log-level debug` yields a useful load trace. No payloads logged.

#7 Document why the slog adapter uses context.Background() (interface is
context-free by design; the installed JSON handler ignores context) and
what to change if a context-aware handler is ever added.

#8 Flatten the empty-level branch in parseZapLevel/parseSlogLevel into a
dedicated case for readability. Rotation defaults and NewLogger left as-is.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
jingle2008 added a commit that referenced this pull request Jun 23, 2026
…save

Resolves seven review findings across the TUI/CLI/config layers; each fix
is covered by a test that fails before the change.

- DAC delete (dac_actions.go): guard nil OpcRequestId in the delete error
  path via a new derefOr helper, and reject a nil work-request id in
  waitForWorkRequest instead of dereferencing/polling it; skip endpoint
  summaries with a nil DedicatedAiClusterId rather than panicking the whole
  deletion. [findings #2, #3]
- GPU pool enrichment (gpu_node_actions.go): skip instance-pool summaries
  missing DisplayName/Id/Size (extracted applyInstancePoolSummaries) so a
  partial OCI response can't crash get/list/scale. [finding #5]
- Lazy loading (model.go): add GPUWorkload to lazyLoadedCategories so
  `toolkit -c gpuworkload` issues the category load on direct startup. A
  contract test now asserts every kube-backed category is lazy-loaded.
  [finding #4]
- DAC delete timeout (model_state.go, update_list_ops.go): run the
  multi-minute deletion under a new uncapped longOpCtx instead of the 30s
  opCtx, so its own internal timeout governs. [finding #6]
- Atomic metadata save (metadata_save.go): writeFileAtomic writes a temp
  file, fsyncs, then renames, so an interrupted write can't corrupt the
  existing file. [finding #8]
- stderr sink (redirect_stderr_unix.go): 0644 -> 0600 to keep captured
  auth-plugin output and panic stacks private. [finding #7]

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants