Skip to content

Fix credentialz tests and hiba cert path handling - #5768

Open
dipchauh wants to merge 2 commits into
openconfig:mainfrom
nokia:credz
Open

Fix credentialz tests and hiba cert path handling#5768
dipchauh wants to merge 2 commits into
openconfig:mainfrom
nokia:credz

Conversation

@dipchauh

Copy link
Copy Markdown
Contributor
  • Added SSH retry logic to host_certificates, consistent with other credentialz tests, so login can succeed after host certificate rotation.
  • Fixed RotateUserPassword to only set the Password field when a non-empty password is provided, so password deletion works correctly during cleanup.
  • Added hiba_certs_dir flag to hiba_authentication_test so pre-generated HIBA keys/certs can be loaded from a configurable directory instead of the process CWD.

"This code is a Contribution to the OpenConfig Feature Profiles project ("Work") made under the Google Software Grant and Corporate Contributor License Agreement ("CLA") and governed by the Apache License 2.0. No other rights or licenses in or to any of Nokia's intellectual property are granted for any other purpose. This code is provided on an "as is" basis without any warranties of any kind."

"This code is a Contribution to the OpenConfig Feature Profiles project ("Work") made under the Google Software Grant and Corporate Contributor License Agreement ("CLA") and governed by the Apache License 2.0. No other rights or licenses in or to any of Nokia's intellectual property are granted for any other purpose. This code is provided on an "as is" basis without any warranties of any kind."
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request improves the reliability and flexibility of credential testing within the OpenConfig feature profiles. It addresses intermittent failures in SSH authentication tests by implementing retry mechanisms and enhances the HIBA authentication test setup by allowing external configuration of certificate paths. Additionally, it fixes a bug in password rotation logic to ensure proper cleanup of credentials.

Highlights

  • SSH Retry Logic: Added retry logic to host certificate tests to improve reliability during host certificate rotation.
  • Password Rotation Fix: Updated RotateUserPassword to correctly handle password deletion by only setting the Password field when a non-empty value is provided.
  • HIBA Configuration: Introduced a hiba_certs_dir flag to allow loading pre-generated HIBA keys and certificates from a configurable directory.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@dipchauh dipchauh changed the title Improve credentialz test reliability and hiba cert path handling Fix credentialz tests and hiba cert path handling Jul 27, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a configurable directory (certsDir) for pre-generated HIBA CA keys and certificates, updates CreateHibaKeys to use this directory, and refactors RotateUserPassword to simplify credential rotation. Additionally, it adds a retry loop for SSH password authentication in host_certificates_test.go. Review feedback suggests failing fast with t.Fatalf if reading critical CA keys fails, and using ctx.Err() to idiomatically bound the SSH retry loop instead of manually tracking elapsed time.

Comment thread internal/security/credz/credz.go Outdated
Comment thread feature/gnsi/credentialz/tests/host_certificates/host_certificates_test.go Outdated
"This code is a Contribution to the OpenConfig Feature Profiles project ("Work") made under the Google Software Grant and Corporate Contributor License Agreement ("CLA") and governed by the Apache License 2.0. No other rights or licenses in or to any of Nokia's intellectual property are granted for any other purpose. This code is provided on an "as is" basis without any warranties of any kind."
@dipchauh
dipchauh marked this pull request as ready for review July 28, 2026 00:05
@dipchauh
dipchauh requested review from a team as code owners July 28, 2026 00:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants